Privacy Policy

Last updated: September 5, 2026

1. Introduction

Sprawl ("Company," "we," "us," or "our") operates Sprawl ("Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service.

By using Sprawl, you consent to the data practices described in this policy. If you do not agree with the terms of this Privacy Policy, please do not access the Service.

2. Information We Collect

2.1 Account Information

When you create an account, we collect:

  • Email address
  • Name (if provided)
  • Profile picture (if provided)
  • Authentication credentials (managed by Clerk)

2.2 Usage Data

We automatically collect information about how you interact with the Service:

  • Chat messages and conversations with the AI
  • Run transcripts from your agents and automations, including the tools they call, the arguments passed to those tools, and the results returned
  • Documents and files you create
  • Automations and their configurations
  • Prompts and customizations you save
  • Feature usage and interaction patterns
  • Device information (browser type, operating system)
  • IP address and approximate location
  • Access times and session duration

2.3 Integration Data

When you connect third-party services, we may collect:

  • OAuth tokens and authentication credentials
  • Data retrieved from connected services to fulfill your requests, including summaries, extractions, and AI-generated insights derived from that data
  • Metadata about your connected accounts

Before any retrieved data is stored, Sprawl automatically redacts financial and credential information (card numbers, bank account details, passwords, API keys and tokens) and truncates contact details such as email addresses and phone numbers.

2.4 Payment Information

Payment information (credit card numbers, billing addresses) is collected and processed directly by Stripe. We do not store your full payment card details on our servers.

3. How We Use Your Information

We use the information we collect to:

  • Provide, maintain, and improve the Service
  • Process your AI chat requests and execute tasks
  • Enable and manage third-party integrations
  • Process payments and maintain your account balance
  • Send service-related communications
  • Respond to your comments and support requests
  • Monitor and analyze usage trends and preferences
  • Detect, prevent, and address technical issues and fraud
  • Comply with legal obligations

4. Third-Party Services

We share data with the following categories of third-party services:

4.1 Authentication (Clerk)

We use Clerk for user authentication and account management. Depending on the sign-in method you choose (email/password or a third-party provider), Clerk processes your login credentials and basic profile information — such as your email address and, for third-party sign-in, your name and profile picture — solely for account creation and identification. See Clerk's Privacy Policy.

4.2 Payment Processing (Stripe)

We use Stripe to process payments. When you make a purchase, your payment information is handled directly by Stripe. See Stripe's Privacy Policy.

4.3 Integrations (Composio)

We use Composio to connect to third-party services on your behalf. Composio is not a one-time step in the connection flow: it stores the authorization your provider issues and it carries out every action your agents take on that account. So the arguments your agents send to a connected service, and the data that service sends back, pass through Composio on the way. See Composio's Privacy Policy.

4.4 AI Models (Vercel AI Gateway and model providers)

Every request your agents make to a model is routed through the Vercel AI Gateway, which forwards it to the provider of the model that agent is set to use. Your prompts, the contents of your run, and the results of the tools your agents call all pass through the Gateway on the way to that provider.

Which provider receives them depends on the model, and the model is a per-agent setting rather than a fixed default. Sprawl's recommended models come from Anthropic and OpenAI. The Gateway also makes models from other providers selectable for an agent — including Google, xAI, Mistral, Meta, DeepSeek and Alibaba (Qwen) — and when you select one of those, that provider receives the request instead. The current list is shown wherever you choose an agent's model.

These providers process your input to produce outputs. We encourage you not to share sensitive personal information in your requests. See Vercel's Privacy Policy for the Gateway, and the privacy policy of whichever model provider your agents use.

4.5 Content Moderation (OpenAI)

We also use OpenAI's Moderation API to screen inputs for potentially harmful content before processing. See OpenAI's Privacy Policy.

4.6 Analytics (PostHog)

We use PostHog to understand how the Service is used. Our analytics are not anonymous: when you are signed in, we identify you to PostHog by your account ID and attach your email address, your name (if you provided one) and the date you signed up, so that product events can be tied to an account. PostHog also records page views, feature usage, device and browser information, and approximate location derived from your IP address. See PostHog's Privacy Policy.

4.7 Infrastructure

The Service runs on infrastructure operated by the following providers, each of which necessarily stores or handles your data:

  • Neon — the database. It holds everything the Service stores about you: your operations, agents, automations, run transcripts, documents, notes, connection metadata, and your encrypted integration credentials. See Neon's Privacy Policy.
  • Vercel — application hosting and request logs, and Vercel Blob storage for files you upload and documents the Service generates. See Vercel's Privacy Policy.
  • Browser push services — if you enable push notifications, the notification itself is delivered by the push service your browser uses (Google for Chrome, Mozilla for Firefox, Apple for Safari). Those notifications contain the summary being shown to you, which can include what an agent is asking approval for and the outcome of a run.
  • GitHub — when the Service hits an internal error, a diagnostic report is filed to a private repository we control. Email addresses and account identifiers are stripped from the report before it is sent.

4.8 MCP servers you connect

Sprawl lets you connect your own MCP servers, and some integrations are provided that way. This is a different kind of sharing from the services above, and worth stating separately: we do not choose these endpoints, you do. When one of your agents calls a tool on a server you connected, the arguments of that call and the data it returns go to that server's operator under whatever terms they publish. We do not review, endorse, or control them, and their handling of your data is not covered by this policy. Disconnecting the server in Sprawl stops us sending anything further to it; it does not reach back into what that operator already holds.

4.9 Shopify Catalog and agentic discovery

We publish limited, public product information — such as Sprawl's title, description, image, price, availability, and external product URL — to Shopify Catalog so participating AI channels can recommend Sprawl. An AI channel's handling of your conversation and other information you provide to that channel is governed by that channel's privacy policy.

Selecting the Sprawl listing sends you to sprawl.to. Account creation, usage, and payment take place on Sprawl, with payments processed by Stripe. We do not use Shopify to collect customer orders or fund a Sprawl balance, and the catalog feed does not include your Sprawl account data, balance, run history, or data from connected services. You can learn more about Shopify's agentic-storefront data sharing in the Shopify Help Center.

5. Data Retention

We retain your information for as long as:

  • Your account is active
  • Necessary to provide you with the Service
  • Required to comply with legal obligations
  • Needed to resolve disputes or enforce agreements

You can request deletion of your account and associated data at any time through your account settings or by contacting us.

After deletion, residual copies may persist for a limited period in database backups and point-in-time recovery snapshots — no longer than 90 days. We do not read those copies or use them to restore a deleted account; they age out on our database provider's schedule and are then gone.

6. Data Security

We implement appropriate technical and organizational security measures to protect your personal information, including:

  • Encryption of data in transit (TLS/SSL)
  • Encryption of sensitive data at rest
  • Regular security assessments and updates
  • Access controls and authentication requirements
  • Secure hosting infrastructure

However, no method of transmission over the Internet or electronic storage is 100% secure. While we strive to protect your information, we cannot guarantee absolute security.

7. Your Rights and Choices

Depending on your location, you may have certain rights regarding your personal information:

7.1 Access and Portability

You have the right to request a copy of the personal information we hold about you.

7.2 Correction

You can update or correct your account information through your account settings.

7.3 Deletion

Deleting your account removes your data from our systems: your operations and the agents, connections, knowledge and run history inside them, your notes and memories, your saved credentials and API keys, and any pending approvals. We also revoke every integration account you connected, at the provider.

Two things are treated differently, and this is the whole of it. Billing records — purchases and the usage they paid for — are kept for accounting and tax obligations, with your user ID replaced by a pseudonym that cannot be linked back to you. And if you created an operation inside an organization, that operation stays with the organization rather than being deleted, because the other people in it are still using it — ownership passes to another administrator of that organization. If you are that organization's only administrator, we cannot complete the deletion: we will tell you, and you can make someone else an administrator or delete the operation first. Your connected accounts are never handed over — they are deleted with your account, and whoever takes over the operation connects their own.

7.4 Opt-Out

You can opt out of marketing communications by following the unsubscribe instructions in our emails.

7.5 Integration Revocation

You can disconnect third-party integrations at any time through your account settings.

8. GDPR Rights (European Users)

If you are located in the European Economic Area (EEA), you have additional rights under the General Data Protection Regulation (GDPR):

  • Right to Access: Request copies of your personal data
  • Right to Rectification: Request correction of inaccurate data
  • Right to Erasure: Request deletion of your data
  • Right to Restrict Processing: Request limitation of processing
  • Right to Data Portability: Receive your data in a structured format
  • Right to Object: Object to processing based on legitimate interests
  • Right to Withdraw Consent: Withdraw consent at any time

To exercise these rights, please contact us using the information provided below.

9. CCPA Rights (California Residents)

If you are a California resident, you have rights under the California Consumer Privacy Act (CCPA):

  • Right to Know: What personal information is collected, used, and shared
  • Right to Delete: Request deletion of your personal information
  • Right to Opt-Out: Opt out of the sale of personal information
  • Right to Non-Discrimination: Equal service regardless of exercising privacy rights

We do not sell your personal information. To exercise your CCPA rights, please contact us.

10. Cookies and Tracking

We use cookies and similar tracking technologies to:

  • Maintain your session and authentication state
  • Remember your preferences and settings
  • Analyze how the Service is used
  • Improve Service performance

You can control cookies through your browser settings. Note that disabling cookies may affect the functionality of the Service.

11. Children's Privacy

The Service is not intended for children under the age of 13 (or 16 in the EEA). We do not knowingly collect personal information from children. If we become aware that we have collected personal information from a child without parental consent, we will take steps to delete that information.

If you believe we have collected information from a child, please contact us immediately.

12. International Data Transfers

Your information may be transferred to and processed in countries other than your own. These countries may have different data protection laws. When we transfer data internationally, we use appropriate safeguards to protect your information, including:

  • Standard contractual clauses approved by relevant authorities
  • Adequacy decisions where applicable
  • Other legally-approved transfer mechanisms

13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last updated" date.

We encourage you to review this Privacy Policy periodically. Your continued use of the Service after any changes constitutes acceptance of the updated policy.

14. Contact Us

If you have any questions about this Privacy Policy or our data practices, please contact us:

Sprawl
Email: support@sprawl.to

For GDPR inquiries, you may also contact your local data protection authority.