Privacy Policy
At Sparktrail, we take your privacy, confidentiality, and data sovereignty seriously. This Privacy Policy outlines what information we collect, how we protect it through cryptographic standards, and the strict boundaries governing access to your data.
1 Information We Collect
We collect only the minimum necessary information required to operate, secure, and maintain Sparktrail:
- Account Information: Your email address, registration date, and password hash (cryptographically hashed via Django's default PBKDF2-SHA256 algorithm with individual salts).
- Profile Metadata: Optional display name, custom avatar photo, preferences, or fallback avatar emoji.
- Workspace Data: Your Sparks, Glints, custom categories (including color accents and icon selections), tags, and Markdown notes.
- Security PIN: If enabled, a cryptographically salted, PBKDF2-SHA256 hashed 4-digit PIN. Your raw PIN is never stored or transmitted to our servers in plaintext.
- Billing Information: Payment and recurring subscription processing is handled entirely by our PCI-compliant third-party processor, Stripe. Sparktrail never stores or has access to your credit card number, CVV, or banking credentials.
2 Data Encryption in Transit and at Rest
Sparktrail enforces multi-layered encryption protocols across every layer of the infrastructure:
- Data in Transit: All communication between your web browser or client device and Sparktrail's servers is encrypted in transit using industry-standard TLS 1.3 (Transport Layer Security over HTTPS) with modern forward-secret cipher suites, preventing interception, tampering, or eavesdropping.
- Data at Rest: All user workspace content—including all Sparks, Glints, Categories, and Tags—is encrypted at rest using industry-standard AES-256 encryption across our database tables and underlying cloud storage volumes.
- Network Integrity & Firewalls: All public endpoints are shielded behind Cloudflare edge proxies and Web Application Firewalls (WAF) to defend against DDoS attacks, automated scraping, and unauthorized intrusion.
3 The 4-Digit PIN Vault Security Model
Sparktrail features an optional 4-digit Security PIN challenge engineered for client- and session-level confidentiality:
- Local Snooping & Shoulder-Surfing Defense: The PIN Vault provides a local security barrier designed specifically to protect your sensitive thoughts from casual onlookers, shoulder-surfers, or unauthorized users when working in coffee shops, offices, or on shared/family computers.
- 15-Minute Sliding Session with Full Redaction: When Vault Protection is turned on for any Spark, its title, notes, Glints, and tags are completely masked and redacted across your dashboard list, stream columns, search results, and interactive Constellation maps. Entering your 4-digit PIN starts a 15-minute sliding session window; every action you take in your workspace automatically refreshes this window so you can write uninterrupted. You can also manually lock your vault at any time via the lock button.
- PBKDF2 Hashing Transparency: Your 4-digit PIN is cryptographically salted and hashed using PBKDF2-SHA256 before it is saved. Raw PIN digits are never stored in plaintext or written to server logs. Because PBKDF2 is a mathematical one-way hash, a forgotten PIN cannot be recovered, viewed, or decrypted by anyone—including Sparktrail administrators.
- Brute-Force Rate Limiting: Automated rate limiting prevents brute-force guessing. If 5 incorrect PIN attempts are made, the system triggers an automatic 15-minute lockout.
4 Developer Access & Feature Availability (Server-Side Processing)
We believe in complete, honest transparency regarding how our feature set operates:
- Server-Side Decryption for Core Features: To power advanced real-time tools—such as our Google-style multi-operator search engine (supporting inclusions, exclusions, and exact phrases), real-time inline Glint extraction, server-side PDF print compilation, and dynamic Constellation orbit calculations—user notes are decrypted in memory at the secure server application layer solely to satisfy authenticated user requests.
- Strict Developer Access Policy: Sparktrail engineering personnel only access database infrastructure for system maintenance, operational troubleshooting, or at your explicit request to resolve technical support issues. Staff are bound by strict confidentiality and never browse or inspect user content without your authorization.
- Zero Data Selling, Advertising, or AI Training: Sparktrail is an independent, subscriber-supported product. We do not display ads, sell or monetize your data, or license your private sparks and notes to third parties. Furthermore, your content is never used to train machine learning or AI models.
5 Data Location and Infrastructure
- Primary Dedicated Server: Your primary data is stored securely in a dedicated MySQL database housed on our primary cloud server in Newark, USA (hosted via Linode/Akamai). All application processing, search parsing, and encrypted storage are consolidated on this dedicated production server to ensure strict data consistency and eliminate cross-cloud synchronization vulnerabilities.
6 Data Portability, Deletion, & Deactivation
- Self-Serve Export: You can export your entire workspace at any time as either a tabular CSV spreadsheet or a structured, single-document Markdown book ("AI-Native Hearth Book") directly from your account settings. PIN-Protected Sparks: To safeguard confidential information from plaintext leakage, your 4-digit security PIN is strictly required to decrypt and include any PIN-protected (Vaulted) Sparks in your export. If an export is generated while your PIN session is locked, Vaulted Sparks will either be omitted or have their notes and highlights redacted.
- Permanent Account Deletion: You can request or execute account deletion at any time. Upon deletion, your user profile, Sparks, categories, Glints, and tags are permanently and irreversibly purged from our active MySQL database tables.
Your privacy is built into the architecture
Read our complete Terms of Service or create your account today.