Overview
SprigR Pty Ltd (ABN 55 697 506 068), trading as Sprigr ("Sprigr", "we", "us") operates sprigr.com, Sprigr Search, and Sprigr Team. This policy covers how we handle your data.
Information we collect
Account information
When you create a Sprigr account we collect your name, email address, and authentication credentials. If you sign in via Google OAuth, we receive your name, email address, and profile picture from Google. We do not receive or store your Google password.
Usage data
We collect API request logs (timestamps, endpoints, response codes), search query metadata (query length, result counts, latency), and page views. We do not log search query content or data stored in your indexes.
Payment information
Payments are handled by Fat Zebra. We don't store credit card numbers or bank details. We keep transaction records (amounts, dates, plan details) for billing.
Data you store with us
Sprigr Search stores JSON objects in search indexes. Sprigr Team stores conversation history, knowledge bases, agent and workflow config, mail synced from connected mailboxes, files you upload or generate, collections (typed tables), and the content of websites you host with us. This data is yours. We don't access or use it for anything other than running the service.
How we use your information
- To provide, operate, and maintain our services
- To process transactions and send billing notifications
- To respond to your enquiries and support requests
- To monitor and improve service performance and reliability
- To detect and prevent fraud, abuse, or security incidents
- To comply with legal obligations
We don't sell your data. We don't use it to train models. No ads.
Data storage and security
Data is stored on dedicated edge infrastructure. All connections use TLS. Sprigr Team uses a dedicated database per company, isolated at the infrastructure level.
API keys are hashed before storage. OAuth tokens and secrets are encrypted at rest.
Data retention
Account data is kept while your account is active. If you delete your account, we delete your data within 30 days, except where law requires retention (e.g. billing records for tax).
API request logs are kept for 90 days, then deleted.
Third-party services
We use these third-party services:
- Cloudflare - infrastructure, hosting, DNS, and the isolated per-tenant databases and storage that hold your workspace data
- Google - OAuth authentication, and Google Analytics on sprigr.com (see Cookies and analytics below)
- Microsoft - OAuth authentication for Microsoft 365 integrations, and Microsoft Clarity on sprigr.com
- Anthropic - AI models for Sprigr Team
- Dropbox - access to your own Dropbox when you connect it (see Dropbox user data below)
- Amazon Web Services - SMS delivery for phone verification codes
- Fat Zebra - payment processing
We share the minimum information needed for each service to work.
Google user data
Sprigr Team lets you connect your own Google account (Gmail, Google Drive, Google Calendar, Docs, Sheets, Contacts, Google Ads, Merchant Center, and Search Console) so your workspace and AI assistant can act on your data at your instruction. What we access and why:
- Gmail - your messages sync into your company's private workspace so you and your assistant can read, search, summarise, send, and organise your own mail. Actions you take in Sprigr (read, archive, label, trash) are mirrored back to your mailbox.
- Drive, Docs, Sheets - find and read files you ask about, and create or update documents you ask for, in your own Drive.
- Calendar - check availability and book, reschedule, or cancel your own appointments on request.
- Contacts - look up a recipient's address when you compose or send.
- Ads, Merchant Center, Search Console - read and manage the accounts and product listings you connect.
Sprigr's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. In particular: we use Google user data only to provide the user-facing features described above; we do not transfer it to third parties except as necessary to provide those features (for example, sending relevant message content to our AI provider to answer your request), to comply with applicable law, or as part of a merger or acquisition with prior notice to you; we do not use it for advertising; we do not allow humans to read it except with your explicit consent, where necessary for security or to comply with law, or when aggregated and anonymised; and we do not use Google user data, including Google Workspace or Gmail data, to develop, improve, or train generalised artificial intelligence or machine-learning models.
Google data synced into your workspace is stored in your company's isolated database, encrypted at rest, and deleted when you disconnect the integration or delete your account (per the retention terms above). You can disconnect at any time from your workspace settings, or revoke Sprigr's access from your Google account permissions.
Dropbox user data
Sprigr Team lets each person connect their own Dropbox so they, and the AI assistant working for them, can find, read, organise and share their files on request. Sprigr acts only as the person who connected, using their own Dropbox authorisation, and only to carry out their requests or keep their search index current. What we access and why:
- Files and folders - browse, search, read and preview files, and create, edit, convert, move, copy, rename, delete or restore files you ask about. Reversible changes can be undone from Sprigr for 7 days.
- Sharing - show who can see a file or folder, and create links, invitations, folder memberships and file requests when you ask. Anything that reaches another person or widens access needs your approval in Sprigr first.
- Account details - your Dropbox account name, email and whether you are on a team, to identify the connection.
- Team administration - only for Dropbox team admins who separately connect as an admin, to manage members, groups and team folders at their instruction.
Sprigr stores your Dropbox authorisation encrypted. If you turn on file search, Sprigr keeps file names, paths, details and extracted text in your company's private search index, where each file is visible only to the people your Dropbox sharing allows. A shared link never makes a file searchable by anyone else. Sprigr may keep extracted text for up to 60 days, and keeps copies of files only when you ask to save them into Sprigr. Dropbox sends Sprigr change notifications so your search stays current; only your account identifier is used from them.
Our AI provider processes file content to answer your requests. Sprigr may also extract facts from your indexed files into your company's memory, visible only to the people the file's Dropbox sharing allowed when the fact was extracted. These facts are deleted within a day of the file leaving Sprigr's search index (because you deleted it, it was unshared from you, you disconnected Dropbox, or your company removed the app), and narrowed within a day when the file's sharing narrows. Facts that also came from another source your company still holds, or that someone repeated in a chat, are kept.
We do not sell Dropbox data, use it for advertising, or use it to develop, improve, or train generalised artificial intelligence or machine-learning models, and we do not allow humans to read it except with your explicit consent, where necessary for security or to comply with law, or when aggregated and anonymised.
You can disconnect Dropbox at any time from your workspace. Disconnecting revokes Sprigr's access at Dropbox and deletes your stored authorisation, search entries, extracted text, undo history and the copies of files you saved into Sprigr; a large number of saved copies may take a few hours to finish deleting. We keep a record that you connected and disconnected, with your Dropbox email, for security auditing until your company removes the Dropbox app. You can also revoke Sprigr's access from your Dropbox connected apps.
Your rights
You have the right to:
- Access the personal information we hold about you
- Request correction of inaccurate information
- Request deletion of your account and associated data
- Export your stored data (search indexes can be exported via the API)
- Withdraw consent for optional data processing
EEA residents have additional rights under GDPR. Australian residents have rights under the Privacy Act 1988. See the OAIC for more info.
Cookies and analytics
sprigr.com uses Google Analytics and Microsoft Clarity to understand how visitors use the marketing site (pages viewed, approximate location, device type, and anonymised session recordings). These tools set their own cookies. We do not use the data for advertising and we do not sell it. You can block these tools with a browser extension or your browser's tracking protection without affecting the site.
When you sign in, the Sprigr Platform sets one session cookie (sprigr_session) on the sprigr.com domain for authentication across Sprigr products. No advertising cookies are set.
Children's privacy
Sprigr is not for children under 16. If you think a child has given us personal information, contact us and we'll delete it.
Changes to this policy
We may update this policy. We'll notify you of material changes by email or on the website.
Contact
Questions about this policy or your data:
SprigR Pty Ltd (ABN 55 697 506 068), trading as Sprigr
Gold Coast, Queensland, Australia