Privacy Policy

We don't want your data. Here is exactly what we hold, who touches it, and how to take it back.

What we collect

To register you give us a username and a password (stored only as a hash). Optionally you can add an email address for reply notifications; it is stored in plain text and used only for those emails and a one-click unsubscribe. We store what you post, comment, vote, save and send in direct messages; your profile (display name, bio, avatar image); and, if you turn on browser push notifications, the push endpoint and a device label. We do not ask for your real name, phone number or address, and we do not track you across the internet.

If you buy a Backer or Legend badge, Stripe handles the payment and we store the checkout email, amount, tier and Stripe session ID. If you link a SparkBox licence, we store the tier and the date it was linked (never the licence key).

Private support tickets

If you open a private ticket, we store its subject, messages, replies, product, category and your Demox account ID so support can answer you. Tickets opened from a SparkBox dashboard may also include the contact email, install ID, version and diagnostics you chose to send, and a redacted licence reference — never the full key. Tickets are not public or indexed; only the submitting account, anyone holding the ticket's private link (the link does not expire) and support staff can read them. Please don't paste passwords, API keys, card numbers or recovery codes into a ticket.

Diagnostics bundle.If you tick “Attach a diagnostics bundle” in the SparkBox dashboard, the ticket also carries facts about your box: SparkBox version, operating system and hardware summary, the state and health of each SparkBox container, the results of SparkBox's self-check, the owner and permissions of a few SparkBox folders, the namesof the settings in your configuration file (never their values), and the last lines of log output from SparkBox's own system containers (the dashboard, proxy, monitoring and remote-access helpers), with passwords, keys and tokens removed. You see the bundle before it is sent. Since 25 September 2026 we also remove, when a ticket arrives: the computer's hostname, IP addresses (replaced with “LAN address” or “public address”), and any log lines from other apps. Bundles sent by older SparkBox versions before that date can include recent log lines from apps such as Sonarr, Radarr or Jellyfin, which may name users (titles and addresses in them are replaced as described next).

What we take out.Since 26 September 2026, before a ticket, a reply, a support message copied from a direct message, or the short snippet sent to our support server is stored, we replace the names of films, shows, music and books, release and file names, magnet links, torrent hashes, tracker and indexer names, search terms, IP addresses and host names with labels such as “[a movie release]” or “indexer A”. Error messages, versions, app and container names and your contact email are kept so we can still help you. Tickets stored before that date were rewritten the same way. Your direct messages themselves are not changed.

Who processes it

  • DigitalOcean hosts our server and database (United States).
  • OpenAI receives the text of posts and comments for automated moderation, link-safety checks and short summaries, and the text of public support threads and messages to our AI support account Chris so it can draft replies. OpenAI does not train on this API data by default; under its API terms it may keep requests for up to 30 days for abuse monitoring.
  • Anthropic (Claude) is used by our staff tooling to read private support tickets, including the contact email and any diagnostics bundle, and to draft the replies our AI support account Anthony sends. Anthropic's data terms for that account apply.
  • Cloudflare Workers AI scores the text of posts, comments and tickets (for example, whether a post breaks the rules or how urgent a ticket is), through our SparkBox service on Cloudflare. It returns scores only.
  • Resend sends the emails you opted into.
  • Stripe handles payments; we never see your card.
  • Cloudflare stores uploaded and preview images (R2).
  • Direct messages to our support accounts are copied into a private ticket. Short snippets (up to 300 characters) of new posts, comments, those messages and ticket replies, with the author's username, are sent to our own support server (also at DigitalOcean) so our support agent notices them.

Server logs. Our web server records requests (IP address, time, page, browser) for security and troubleshooting and discards them through routine log rotation. Requests to private support pages and the support-ticket API are not written to that log.

We run no analytics, no advertising trackers and no third-party scripts. We do not sell personal data. We do not use your content to train AI models, and our providers are bound not to either.

Cookies

Only httpOnly, same-site session cookies to keep you signed in. They expire when you sign out or after a set time. No third-party cookies, no tracking cookies.

AI moderation

Every post and comment is reviewed by an AI moderator against the content rules. Each review is stateless — nothing is learned about you and no profile is built. The decision is recorded in the public moderation log, and that record keeps up to 500 characters of the reviewed text so appeals can be checked; the text is visible only to administrators, and the public log hides usernames.

How long we keep it

  • Your account and everything you posted: until you delete them.
  • Moderation log: indefinitely — it is a public, tamper-evident record of decisions. It is not removed when you delete your account.
  • Uploaded images: stored as uploaded (including any photo metadata, such as location, that the file carries) and currently not removed from storage when the post is deleted. Please strip location data from photos before uploading.
  • Support tickets: a ticket marked resolved is closed automatically after 30 days with no new messages. Closed tickets are deleted 24 months after their last activity.
  • Shorter ticket retention (being introduced): we have built, but not yet switched on, two rules — the contact email, install ID, diagnostics and diagnostics bundle cleared 30 days after a ticket is resolved, and the whole ticket deleted 90 days after it is resolved. Until they are switched on, the 24-month rule above is what applies. We will update this page when they are.
  • Server error logs: 90 days.
  • Database backups: one per night, each kept 7 days. Anything you delete can remain in a backup for up to 7 days.
  • Payment records: 7 years, as tax law requires.

Your data, your controls

  • Export — Settings → “Download my data” gives you everything above as one JSON file.
  • Delete — Settings → “Delete account” (password required) permanently deletes your account, posts, comments, votes, saved items, direct messages, push subscriptions and profile from the live database. Copies survive in these places: nightly backups (up to 7 days); support tickets, including copies of messages you sent to our support accounts, which are detached from your account but kept for the period above; the moderation log; uploaded image files; and payment records, kept as the law requires. An older copy of the forum database (content up to August 2026) also exists in the history of our private source-code repository; removing it is pending.
  • Correct or object — edit your profile and content in the app, or email us.

Deleting a post from a public forum is like taking a screenshot off the internet: we remove it here and from search engines' view of us, but we can't recall copies others already made.

Legal basis and your rights

We process your data to provide the service you signed up for (GDPR Art. 6(1)(b)) and, for moderation and abuse prevention, in our legitimate interest in keeping the forum safe (Art. 6(1)(f)). If you are in the EU or UK you have the rights of access, rectification, erasure, restriction, portability and objection, and you may complain to your supervisory authority. If you are in California, the CCPA rights to know, delete and correct apply, and we do not sell or share personal information as the CCPA defines it. We do not knowingly allow accounts for children under 13 (16 in the EU); if you believe a child has an account, tell us and we will remove it.

Contact

Questions, requests and complaints: legal@tomsparkbox.com. The site is operated by Cloakpoint Media LLC, [BUSINESS MAILING ADDRESS]. We disclose personal data only when valid legal process requires it, and tell the affected user first where the law allows; see tomsparkbox.com/legal-requests. For copyright notices see /copyright; for how we use AI see /ai.

Last updated: 26 September 2026