Saltar para o conteúdo

Legal

Política de privacidade

Como a Sydentia Oy recolhe, utiliza e protege os teus dados na Sparky.

Última atualização 27 September 2026

Controller: Sydentia Oy, Hämeenkatu 17 B 57, 33200 Tampere, Finland Contact: info@sydentia.com Applies to: the Sparky mobile app (com.sydentia.sparky) and the Sparky backend service at api.sydentia.com. Last updated: 27 September 2026


1. Who we are

Sparky is a private, reflective wellbeing companion. Sydentia Oy ("Sparky", "we", "us") is the data controller for the personal data described here. Because we are established in Finland, this policy is written to meet the EU General Data Protection Regulation (GDPR) and the Finnish Data Protection Act.

Sparky is not a medical, clinical, or therapeutic product and is not a crisis service. See our Terms of Service for the full disclaimer.

2. A note on what Sparky is for

Sparky invites you to write personal reflections about your life and to talk things through with an AI companion. This means you may choose to share sensitive information — how you feel, your health, your relationships, your finances. We treat that content as private and describe below exactly how it is handled, who processes it, and how you stay in control.

3. The data we collect

We collect only what the app needs to work. We do not buy personal data, and we do not sell your personal data to anyone.

3.1 Account and identity

  • Email address (from email sign-up or from Google/Apple sign-in).
  • Display name (optional) — the name other people see for you in Sparky: next to your @handle and profile photo, and on the invitations you send asking people close to you how they see you. You set it yourself, and you can change or clear it at any time (up to 80 characters).
  • Sign-in identifiers from Google or Apple (the provider's subject id and email) when you use social sign-in.
  • Password — only if you sign up with email/password. It is stored solely as a salted Argon2id hash; we never store or transmit your plaintext password, and the hash is never shared with any third party.
  • Public @handle you choose, used to connect with contacts.
  • Session tokens (stored hashed on our servers; stored in the device's secure keystore/keychain on your phone).

3.2 Profile you provide

  • Optional profile details: year of birth, sex, marital status, country and place of residence, current life status, language. Some of these are treated as sensitive (see §4).

3.3 Reflection and wellbeing content (sensitive)

  • Life entries — the journal/reflection text you write.
  • Life-area summaries and assessments — including how satisfied, stressed, confident, safe, or fulfilled you feel (0–100 scales) and related notes. This is wellbeing/mental-state data and is sensitive.
  • Personality profile — your Big Five results and history, if you take the questionnaire. This is sensitive.
  • Memory items — short summaries and semantic embeddings Sparky keeps so your reflections build on each other. You control what Sparky remembers.
  • Lens answers — your answers and notes in guided reflections ("lenses"), and your progress through them. See §8 for the narrow, consent-only way a lens's maker can receive any of this.

3.4 Conversations

  • Your chats with the Sparky AI — the message text you send and Sparky's replies are stored on our servers so your conversation has continuity.
  • People chats (human-to-human) — if you use the social features, the messages you send to other members are stored on our servers to deliver them, along with read markers and group membership. See §5 for how AI does and does not touch these.
  • Photos you send in a people chat — if you attach a picture to a message, the image itself is stored on our servers so we can deliver it to the members of that chat, together with which chat it belongs to, its file type, its size, its pixel dimensions, and when it was uploaded. We keep nothing else about it — no filename, no album, no separate index. Before a photo leaves your phone the app re-encodes it — shrinking it if it is large — and drops the embedded EXIF metadata, including any GPS coordinates your camera recorded, so where you took a picture is not something you send by accident. Sparky handles still images only (JPEG, PNG or WebP, up to about 5 MB each) — there is no video, no audio, and no other kind of file attachment.
  • Who can open a photo is decided in the database itself, not by app code: only the members of the chat it was sent to. If you leave a group, you keep the photos sent before you left and cannot open ones sent after. There are no public or shareable links — every time a photo is displayed, the app asks our servers for it with your signed-in session, and access that has been taken away applies from the very next request.
  • Profile photo (optional) — if you add a photo of yourself to your profile, the image is stored on our servers together with its file type, its size, its pixel dimensions, and when it was uploaded; you have at most one at a time. It is shown next to your name to your contacts, to the members of chats you are in, to people you send a contact request to or receive one from, and to anyone who looks you up by your exact @handle. People you have blocked cannot see it. Before it leaves your phone the app crops it to a square, shrinks it to 512 × 512 pixels and re-encodes it, dropping the embedded EXIF metadata, including any GPS coordinates. Our servers accept only a JPEG, PNG or WebP image of up to about 1 MB and 1024 pixels on each side, and check that the file really is the kind of image it claims to be. As with chat photos, there are no public or shareable links: whoever's app displays your photo asks our servers for it with their own signed-in session, and the database re-checks each time that they are still allowed to see it.

3.5 Contacts and social graph

  • In-app contacts you add by @handle, the private "closeness ring" you place them in, contact requests (including any note you write), and any blocks you set.
  • We do not access your device address book or phone contacts, and the app does not request that permission.

3.6 Device and technical

  • Push token for your device (to deliver notifications), plus platform and app language. This is a persistent device identifier.
  • We do not collect precise location, advertising IDs, or hardware identifiers, and the app contains no third-party analytics, advertising, or crash-reporting SDKs.

3.7 Purchases

  • Subscription and in-app-purchase records — store, product, transaction id, and the store's purchase token/receipt, used to verify and maintain your subscription. Card/payment details are handled by Apple or Google, not by us.

3.8 Sponsored content and preferences

  • Your ad preferences (whether you allow sponsored suggestions, personalization, and — separately — health- or finance-related suggestions), and which advertisers/suggestions you have hidden.
  • Interaction events with sponsored suggestions (shown, tapped, dismissed, hidden, reported). See §6 for how these are kept unlinkable to advertisers.

3.9 Safety

  • Crisis-safety signals. To keep you safe, incoming messages are screened for signs of acute distress. We store only the signal metadata (that a signal occurred, its severity, and what the app did) — never the message text — and this is highly sensitive and access-restricted.
  • Reports you make about other people. If you report a message or a person, we store your report: who reported, who was reported, the reason you chose, any note you wrote, and — where you reported a specific message — a copy of that message's text. The copy is taken by our server from the message you reported, and is kept so that our team can still act on the report if the sender deletes the message afterwards. The person you report is never told who reported them, and cannot see that a report exists. Reports are readable only by you and by the staff who review them.

3.10 Logs

  • Operational and audit logs and an AI-usage cost ledger. By design these hold only references/identifiers and metadata (timestamps, counts, costs) — never the text of your reflections, chats, or messages.

4. Sensitive (special-category) data

Sparky is designed for you to reflect on your wellbeing, so you may provide data that GDPR treats as special-category — in particular data concerning health/mental wellbeing, and revealing details such as sex or marital status. Your Big Five personality profile and your wellbeing assessments are also sensitive by nature. We process this data only to provide the reflection features you choose to use, and our legal basis is your explicit consent (see §7), which you can withdraw at any time by turning off the relevant feature or deleting the content or your account.

5. How AI is used, and what is sent to OpenAI

Sparky's AI replies, summaries, and reflections are generated using OpenAI as our AI processor. Here is exactly how your content is and is not used:

  • When you use an AI feature (chat with Sparky, generate a summary or assessment from an entry, run a guided reflection/"lens", or the safety screen), the relevant reflection or message text and minimal profile context are sent to OpenAI to produce the result. Your email, password, and account identity are never sent to OpenAI.
  • The models used are OpenAI's gpt-5.6-luna (by default) for text and text-embedding-3-small for embeddings. Safety screening uses OpenAI's gpt-4o-mini. We may move to another OpenAI model of a comparable kind as models are updated or retired; the processor (OpenAI), the categories of content sent, and the safeguards described here do not change when we do.
  • People-chat (human-to-human) messages are not sent to OpenAI during normal messaging. They are only processed by AI if a subscriber turns on the optional "Sparky listens" setting for a specific chat. That setting is off by default, requires an active paid subscription, applies only to that one chat, and produces private insights only for the person who turned it on. When it is on, the recent messages in that chat (including other members' messages) may be sent to OpenAI to generate that person's private insight. The disclosure shown before you use people chats explains this.
  • Photos are never sent to OpenAI, or to any other AI provider — neither the photos you send in chats nor your profile photo. This holds whether or not "Sparky listens" is on: no part of Sparky reads a photo's image data for an AI feature. A photo sent with a caption is, as far as AI is concerned, an ordinary message — the caption text follows the people-chat rule above, and the picture itself does not travel with it. A photo sent with no caption is left out of what the AI is shown altogether.
  • We do not use your content to train third-party AI models. OpenAI processes the content to return Sparky's response on our behalf as a data processor.

6. Sponsored content, and why advertisers can't identify you

Sparky may show clearly labelled sponsored suggestions. We never share your identity or your reflection/chat content with advertisers, and no user data is sent to any external advertising network. Ad matching happens on our own servers.

Where any record could relate to an advertiser, we replace your identity with a one-way, keyed pseudonym (an HMAC) that is different for every advertiser, so the same person cannot be linked across advertisers, and the pseudonym cannot be reversed to your account. Any reporting we provide to a partner is aggregated and k-anonymised (small groups are suppressed) and never includes your wellbeing, personality, message, or reflection data. You can turn off sponsored suggestions and personalization, or hide individual advertisers, at any time in Settings.

7. Legal bases (GDPR Article 6 and 9)

  • Performance of a contract (Art. 6(1)(b)) — creating and running your account, storing and processing your reflections and messages to deliver the features you use, and managing subscriptions.
  • Explicit consent (Art. 6(1)(a) and Art. 9(2)(a)) — processing sensitive wellbeing/health, personality, and profile data; the optional "Sparky listens" AI evaluation of people chats; sharing your lens results with that lens's maker when you choose to (§8); and personalized sponsored suggestions. You can withdraw consent at any time.
  • Legitimate interests (Art. 6(1)(f)) — keeping the service secure, preventing fraud and abuse, and safety screening for signs of acute distress. Where safety processing involves sensitive data, we also rely on protecting your or another person's vital interests (Art. 9(2)(c)).
  • Legal obligation (Art. 6(1)(c)) — retaining certain transaction and accounting records.

8. Who processes your data (sub-processors) and international transfers

We use a small set of processors, each limited to a specific purpose:

Processor Purpose Data Location
OVH (EU hosting) Application + database hosting All stored data, at rest — including the photos you send in chats and your profile photo EU/EEA
OpenAI AI replies, summaries, evaluations, embeddings Reflection/chat/message text you submit for an AI result + minimal profile context; never email/password/identity US
Brevo Transactional email (verify + password-reset) Email address + the message with the link EU
Google Firebase Cloud Messaging Push notification delivery Device push token, and the notification itself: the sender's name, the conversation's title, and a short preview (up to 140 characters) of the message. For a photo, that preview is its caption, or the words "📷 Photo" if there is none — never the image US
Google Play / Apple Social sign-in verification + subscription billing Sign-in subject id + email; store purchase tokens US

Photos — those you send in chats and your profile photo alike — add no processor to this list: they are stored in the same EU-hosted database as the rest of your data, and there is no image host, storage bucket, or content-delivery network involved.

Lens makers (partner organizations)

Some guided reflections ("lenses") in Sparky are made by partner organizations — for example a coach, an educator, or another professional. Lens makers are recipients you choose, not processors working for us, and none of your reflection content reaches a maker unless you explicitly send it:

  • By default, a maker sees only aggregated, anonymised usage statistics about their lens. These never include your identity, your answers, your free text, your messages, or your wellbeing or personality data, and figures for small groups are suppressed so no individual can be picked out.
  • Inside a lens you can choose "Share information with the maker." Before anything is sent, the app shows you exactly what the maker will see. You choose the scope of the share — the default is the least revealing one, and your written answers are included only if you select that — and you separately choose whether the share carries your name or an unlinkable pseudonym. The pseudonym is different for every lens, so a maker cannot connect your shares across lenses, and different makers cannot link them to the same person.
  • You can stop sharing at any time in the lens. Revocation takes effect immediately — the maker loses access the moment you revoke — and we retain only the record that consent was given and withdrawn.

Sponsored-content partners are a separate topic with stricter rules still — see §6. Advertisers never receive any of the above.

Where a processor is outside the EU/EEA (currently OpenAI, FCM, Google/Apple), transfers are protected by the European Commission's Standard Contractual Clauses and appropriate safeguards. Our current sub-processor register is available on request. We update this list when a processor changes.

9. How long we keep data, and deletion

  • We keep your personal data while your account is active.
  • You can delete your account at any time in the app (Settings → Delete account), or by contacting us at info@sydentia.com. Deletion is immediate and irreversible.
  • When you delete your account, we permanently delete your reflections, summaries, assessments, memories, personality profile, AI-chat history, contacts and social graph, the photos you sent in chats, your profile photo and display name, devices/push tokens, ad preferences, and safety signals.
  • Photos have their own controls, before you get as far as deleting your account:
    • You can unsend a photo for up to 48 hours after sending it. Unlike a text message — which leaves a "message deleted" placeholder so the conversation keeps its shape — an unsent photo is destroyed: the image is removed from our database and stops being viewable for everyone, not just hidden.
    • A photo you chose but never actually sent (the app was closed mid-send, the send failed) is deleted automatically within 24 hours.
    • When you delete your account, your photos are erased outright, including from other people's chats — unlike your messages, which stay as content-free placeholders so the other participants' conversation remains readable.
    • A photo you sent and did not unsend is kept for as long as your account exists; we do not delete delivered photos on a timer.
    • You can change or remove your profile photo at any time. The old photo is destroyed when you do — deleted from our database, not hidden — and a new one is stored as a new picture.
    • On your phone, photos you have viewed — including other people's profile photos — and photos still waiting to be sent are stored in the app's own storage. They are erased when you sign out and when you delete your account.
  • Abuse reports (§3.9) are deleted when either account involved is deleted — yours if you filed it, and the reported person's if they delete theirs, which also removes the stored copy of their message. What remains afterwards is only the content-free audit record that staff reviewed something.
  • Some records are retained but de-identified or minimised, because we cannot link them to you afterwards and we need them for legal, accounting, or shared-integrity reasons:
    • Financial/transaction and AI-cost records are kept as monetary aggregates with your identity removed.
    • Messages you sent in group chats are stripped of your content and identity ("tombstoned") so the other participants' conversation remains intact. Any photo that message carried is deleted, not retained.
    • A security/audit log that does not contain your account identifiers is retained.
  • We retain operational logs only for as long as necessary for the purposes described above.

10. Your rights

Under the GDPR you have the right to access, rectify, erase, restrict, and object to the processing of your personal data, to data portability, and to withdraw consent at any time (without affecting processing already carried out). Many of these you can exercise directly in the app (edit your profile and reflections, control what Sparky remembers, manage ad preferences, delete your account).

Note on "download your data": you can export a copy of your own records in the app (Settings → Privacy → Export your data), which produces a JSON file. It includes the record of each photo you sent — which chat it went to, when, and its type, size and dimensions — and the same kind of record for your profile photo, but not the image files themselves. If you need a copy of anything the export does not cover, including the photos, ask us at info@sydentia.com.

To exercise any right, contact info@sydentia.com. You also have the right to lodge a complaint with your supervisory authority; in Finland this is the Office of the Data Protection Ombudsman (Tietosuojavaltuutetun toimisto, tietosuoja.fi).

11. Security

We protect your data with encryption in transit (TLS), strict per-user access controls (row-level security so each account can only reach its own data), salted Argon2id password hashing, and secure token storage on your device. Passwords and reset tokens never leave our own systems. No method of transmission or storage is completely secure, but we work to protect your information and to limit who and what can access it.

Photos — chat photos and profile photos alike — are held under those same controls. Each one is served only in response to a signed-in request whose right to see it is re-checked in the database — there are no public or shareable image links — and the copies your phone keeps are erased when you sign out or delete your account.

12. Children

Sparky is not directed to children. You must be at least 16 years old to use Sparky. We do not knowingly collect personal data from children under this age; if you believe a child has provided us data, contact us and we will delete it.

13. Changes to this policy

We may update this policy as the app evolves. We will post the updated version with a new "Last updated" date and, for material changes, notify you in the app.

14. Contact

Questions or requests: info@sydentia.com Sydentia Oy, Hämeenkatu 17 B 57, 33200 Tampere, Finland