Privacy Policy
Last updated: 26 July 2026
Effective date: 27 June 2026
1. Who we are
Spronta ("Spronta", "we", "us", "our") is operated by Spronta Ltd, a company registered in England and Wales (Company number 16278102). Our registered address is 128 City Road, London, EC1V 2NX.
If you have any questions about this Privacy Policy or how we handle your data, contact us at hello@spronta.com.
Data Controller: Spronta Ltd is the data controller for the personal data we collect through the Spronta website (spronta.com), the hosted Spronta app (app.spronta.com, together with our other hosted subdomains of spronta.com and spronta.app), and any related hosted services (collectively, the "Service").
2. What data we collect
2.1 The Spronta CLI, MCP server, and desktop app
The Spronta CLI, MCP server, and desktop app connect to our hosted services and require an account. When you run a crawl, the sites you point them at, the findings, and the reports generated from them are sent to and stored on our servers against your account. What we collect through them, and how long we keep it, is the same as for the hosted app — see 2.5 below.
The desktop app may also contact GitHub to check for updates, which involves a standard network request to GitHub's servers.
2.2 Website and app usage, and technical data
When you visit spronta.com or use Spronta, we automatically collect limited technical data, including:
- Your IP address, and the approximate location (country/region) we derive from it
- Browser type and version, and operating system
- Referring URL, pages visited, and time spent
- Device type
- A randomly generated visitor identifier, and basic attribution data (the page you landed on and the site that referred you) — see section 7
2.3 Email subscriptions
If you subscribe to our updates, we collect your email address in order to send you the Spronta digest and release notifications. You can unsubscribe at any time using the link in any email.
2.4 Communication data
If you contact us by email, or open an issue or discussion on our public GitHub repository, we retain the content of those communications to resolve your query and improve the Service.
2.5 Your Spronta account
Using Spronta — through the app at app.spronta.com and our other hosted subdomains of spronta.com and spronta.app, or through the CLI, MCP server, or desktop app — requires an account, and the data you create is stored on our servers. Across all of them we collect:
- Account data — your name, email address, and authentication details
- Content you create — the sites you configure, your crawl targets, findings, and reports
- Session records — including your IP address, which we store and retain against your account for the duration of each session, to keep you signed in and to detect abuse
- Billing data — if you subscribe to a paid plan, your billing name and address, and a record of your transactions. Payments are processed by Stripe (see section 4). Your card details are entered directly with Stripe and are never stored on our servers.
3. How we use your data
We use your personal data for the following purposes:
| Purpose | Legal basis (UK GDPR) |
|---|---|
| Operating and securing the Service | Legitimate interests (Art. 6(1)(f)) |
| Providing Spronta to you, including keeping you signed in | Contract (Art. 6(1)(b)) |
| Taking payment and managing your subscription | Contract (Art. 6(1)(b)) |
| Keeping transaction records for tax and accounting purposes | Legal obligation (Art. 6(1)(c)) |
| Sending the email digest and release updates you signed up for | Consent (Art. 6(1)(a)) — you can opt out at any time |
| Analysing website and app usage to improve Spronta | Legitimate interests (Art. 6(1)(f)) |
| Responding to your enquiries and support requests | Legitimate interests (Art. 6(1)(f)) |
| Detecting and preventing abuse, fraud, or security threats | Legitimate interests (Art. 6(1)(f)) |
| Complying with legal obligations | Legal obligation (Art. 6(1)(c)) |
We do not use your data for:
- Selling to third parties
- Advertising or ad targeting
- Training AI or machine learning models
- Profiling for automated decision-making
4. Who we share your data with
We share personal data only with the following processors, and only to the extent necessary to provide the Service:
| Processor | Purpose | Location | Data shared |
|---|---|---|---|
| Vercel | Website hosting and privacy-friendly analytics | Global (edge network) | Technical/usage data |
| Cloudflare | Hosted infrastructure for the Service, including our database and authentication | Global (edge network) | Technical data, including your IP address, for all traffic to our sites and the hosted app; and the account data, content, and session records we store in our database |
| PostHog | Product analytics for the hosted app. It is not installed on the marketing site. | Data hosted in the European Union; PostHog, Inc. is US-based | Usage events, pseudonymous user and visitor identifiers, and the attribution data described in section 7 |
| Stripe | Payment processing and subscription billing | United States | Name, email address, billing address, and transaction records |
| Loops | Email digest and release notifications | United States | Email address |
| GitHub (Microsoft) | Source code hosting, releases, issues, and discussions | United States | Any data you submit to the repository; update-check requests from the desktop app |
Each processor is bound by a Data Processing Agreement (DPA) and processes data only on our instructions. Where data is transferred outside the UK, we rely on appropriate safeguards — including the Standard Contractual Clauses together with the UK International Data Transfer Addendum, and adequacy decisions such as the UK extension to the EU–US Data Privacy Framework. If we add or change processors, we will update this policy accordingly.
We may also disclose your data if required by law, regulation, legal process, or enforceable governmental request.
5. How long we keep your data
| Data type | Retention period |
|---|---|
| Email subscription | Until you unsubscribe, plus a short period to process the request |
| Website analytics data | Up to 12 months |
Attribution cookie (sp_attr) | 90 days, refreshed on each visit to spronta.com |
| Account data | For the life of your account, and deleted within 30 days of closure |
| Content you create in Spronta, including crawl targets, findings, and reports | For the life of your account, and deleted within 30 days of closure |
| Session records (including IP address) | For the life of your account, and deleted within 30 days of closure |
| Billing and transaction records | 6 years from the end of the financial year they relate to, as required by UK tax law. These are kept even if you close your account. |
| Support communications | 2 years from resolution |
6. Your rights
Under UK GDPR, you have the following rights:
- Access — Request a copy of the personal data we hold about you.
- Rectification — Request correction of inaccurate data.
- Erasure — Request deletion of your data (subject to legal retention requirements).
- Restriction — Request that we limit how we process your data.
- Portability — Request your data in a structured, machine-readable format.
- Objection — Object to processing based on legitimate interests.
- Withdraw consent — Where processing is based on consent, withdraw it at any time.
To exercise any of these rights, email us at hello@spronta.com. We will respond within 30 days.
If you are not satisfied with our response, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):
- Website: ico.org.uk
- Phone: 0303 123 1113
7. Cookies and tracking
spronta.com aims to be light on tracking. On the marketing site, everything below is first-party — served from our own domains, not from an advertising network.
- Vercel Analytics — privacy-friendly usage analytics. It does not use cross-site tracking cookies.
- Attribution cookie (
sp_attr) — set on.spronta.comso it is readable across our subdomains, including the app, and kept for 90 days. It records the page you landed on, the site that referred you, and a timestamp. Where those values are present in the URL you arrive on, it also records campaign parameters (utm_source,utm_medium,utm_campaign,utm_term,utm_content) and advertising click identifiers (such asgclid,fbclid,msclkid,ttclid,li_fat_idandtwclid) added by the ad platform you clicked through from. We use this to understand which channels bring people to Spronta, and the app attaches it to your signup event so we can attribute the signup to its source. - Measurement and experimentation identifier — a randomly generated visitor identifier stored in your browser's local storage so repeat visits can be recognised and so we can run A/B tests on our own pages. It is pseudonymous — not derived from your name or email address — but it does persist across visits until you clear your browser storage.
- Spronta Search identifier — a randomly generated identifier stored in local storage by the search box, used to keep search sessions coherent.
In the hosted Spronta app we additionally use:
- PostHog — product analytics, which tells us how the app is used so we can improve it.
PostHog sets its own cookies and identifiers to distinguish sessions and to recognise you across
visits, and your signup event carries the attribution data from the
sp_attrcookie above. Unlike the tools on the marketing site, PostHog is a third-party processor; our instance is hosted in the European Union.
We do not use:
- Google Analytics
- Third-party advertising or retargeting pixels, such as the Meta Pixel or Google Ads remarketing tags
- Any third-party tracking cookies
- Any cross-site tracking of your activity on other people's websites
You can control cookies through your browser settings. Clearing cookies and site data for spronta.com removes the attribution cookie and resets the identifiers described above.
8. Security
We take the security of your data seriously. Our measures include:
- All data transmitted over HTTPS/TLS encryption
- Access controls and audit logging on our internal systems
- Data minimisation by design — we collect only what we need in order to provide the Service
- Regular security reviews of our infrastructure
No system is 100% secure. If you discover a security vulnerability, please report it to hello@spronta.com.
9. Children
Spronta is not directed at individuals under the age of 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us at hello@spronta.com and we will delete it.
10. Changes to this policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email or by posting a notice on the Service at least 14 days before the changes take effect.
The "Last updated" date at the top of this page indicates when this policy was last revised.
11. Contact
For any questions, concerns, or requests regarding this Privacy Policy or your personal data:
Email: hello@spronta.com
Postal address:
Spronta Ltd
128 City Road
London, EC1V 2NX
England
ICO registration number: ZC017195