Overview
SprigR Pty Ltd (ABN 55 697 506 068), trading as Sprigr ("Sprigr", "we", "us") operates sprigr.com, Sprigr Search, and Sprigr Team. This policy covers how we handle your data.
Information we collect
Account information
When you create a Sprigr account we collect your name, email address, and authentication credentials. If you sign in via Google OAuth, we receive your name, email address, and profile picture from Google. We do not receive or store your Google password.
Usage data
We collect API request logs (timestamps, endpoints, response codes), search query metadata (query length, result counts, latency), and page views. We do not log search query content or data stored in your indexes.
Payment information
Payments are handled by Fat Zebra. We don't store credit card numbers or bank details. We keep transaction records (amounts, dates, plan details) for billing.
Data you store with us
Sprigr Search stores JSON objects in search indexes. Sprigr Team stores conversation history, knowledge bases, and agent config. This data is yours. We don't access or use it for anything other than running the service.
How we use your information
- To provide, operate, and maintain our services
- To process transactions and send billing notifications
- To respond to your enquiries and support requests
- To monitor and improve service performance and reliability
- To detect and prevent fraud, abuse, or security incidents
- To comply with legal obligations
We don't sell your data. We don't use it to train models. No ads.
Data storage and security
Data is stored on dedicated edge infrastructure. All connections use TLS. Sprigr Team uses a dedicated database per company, isolated at the infrastructure level.
API keys are hashed before storage. OAuth tokens and secrets are encrypted at rest.
Data retention
Account data is kept while your account is active. If you delete your account, we delete your data within 30 days, except where law requires retention (e.g. billing records for tax).
API request logs are kept for 90 days, then deleted.
Third-party services
We use these third-party services:
- Edge infrastructure provider - infrastructure, hosting, DNS
- Google - OAuth authentication
- Anthropic - AI models for Sprigr Team
- Fat Zebra - payment processing
We share the minimum information needed for each service to work.
Google user data
Sprigr Team lets you connect your own Google account (Gmail, Google Drive, Google Calendar, Docs, Sheets, Contacts, Google Ads, Merchant Center, and Search Console) so your workspace and AI assistant can act on your data at your instruction. What we access and why:
- Gmail - your messages sync into your company's private workspace so you and your assistant can read, search, summarise, send, and organise your own mail. Actions you take in Sprigr (read, archive, label, trash) are mirrored back to your mailbox.
- Drive, Docs, Sheets - find and read files you ask about, and create or update documents you ask for, in your own Drive.
- Calendar - check availability and book, reschedule, or cancel your own appointments on request.
- Contacts - look up a recipient's address when you compose or send.
- Ads, Merchant Center, Search Console - read and manage the accounts and product listings you connect.
Sprigr's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. In particular: we use Google user data only to provide the user-facing features described above; we do not transfer it to third parties except as necessary to provide those features (for example, sending relevant message content to our AI provider to answer your request), to comply with applicable law, or as part of a merger or acquisition with prior notice to you; we do not use it for advertising; we do not allow humans to read it except with your explicit consent, where necessary for security or to comply with law, or when aggregated and anonymised; and we do not use Google user data, including Google Workspace or Gmail data, to develop, improve, or train generalised artificial intelligence or machine-learning models.
Google data synced into your workspace is stored in your company's isolated database, encrypted at rest, and deleted when you disconnect the integration or delete your account (per the retention terms above). You can disconnect at any time from your workspace settings, or revoke Sprigr's access from your Google account permissions.
Your rights
You have the right to:
- Access the personal information we hold about you
- Request correction of inaccurate information
- Request deletion of your account and associated data
- Export your stored data (search indexes can be exported via the API)
- Withdraw consent for optional data processing
EEA residents have additional rights under GDPR. Australian residents have rights under the Privacy Act 1988. See the OAIC for more info.
Cookies
sprigr.com doesn't use tracking cookies or third-party analytics. We use one session cookie (sprigr_session) for authentication when you're signed in.
Children's privacy
Sprigr is not for children under 16. If you think a child has given us personal information, contact us and we'll delete it.
Changes to this policy
We may update this policy. We'll notify you of material changes by email or on the website.
Contact
Questions about this policy or your data:
SprigR Pty Ltd (ABN 55 697 506 068), trading as Sprigr
Gold Coast, Queensland, Australia