Privacy Policy
This policy covers the SparkleTrip main website and its connected creative services. The service operator can be contacted at the support address below for questions about data processing or your rights.
Updated:Account and access
SparkleTrip shares identity and Credits with CF Mail. After CF Mail verifies your identity, a one-time authorization code establishes your SparkleTrip session. Model keys and database credentials are never sent to your browser. You can only access your own conversations, tasks and private artwork.
AI conversations
When you send a message, relevant history is sent through the privately operated NewAPI service to the configured AI provider. Conversations are encrypted in the operator's private server database, with processing on privately operated servers. We request that models do not store conversations, but providers may retain security or billing records under their policies. Avoid submitting unnecessary passwords, keys or other sensitive information.
Web search and sources
For questions that need current information, the assistant can send relevant keywords to search engines through our privately operated SearXNG service and read public webpages. It does not send your full conversation, account identity or attachments to search engines. Search engines and visited websites receive the query or page request and our server IP, and may process them under their own policies. Source links, short excerpts and lookup times are stored with your encrypted conversation and removed when that conversation is deleted. You can ask the assistant not to search. Search results may be incomplete or outdated; page access restrictions are respected. Model calls used to research and write the answer are billed by actual usage.
Conversation attachments
Uploaded images and files are stored privately in R2 for 7 days. Generated PDF, Word, Excel, PowerPoint and Markdown files are encrypted on the private server for 7 days. Filenames, reading caches and conversations are encrypted and isolated by account; reading caches expire no later than the source file. Access requires sign-in and download tickets are single-use. DeepSeek files are parsed locally first; scanned PDFs and layout analysis use an available GPT model. Other models may receive selected files directly. Relevant content is processed by model providers and billed by usage. Older or expired files may be omitted from context; upload them again when needed.
User input safety checks
User input checks currently use Waffo Prompt Sift through the platform’s NewAPI gateway. They check newly submitted user text, image descriptions and prompt-polishing inputs. AI replies, AI-generated prompts, history and existing option selections are not resubmitted; new or edited text is checked. This check does not upload images, invoke a second classifier, or inspect PDF and Office document contents. Account email and login credentials are not added to scan requests. The per-user cache stores keyed content digests and structured verdicts: approvals for 24 hours, blocks for 5 minutes, review outcomes for 30 seconds and service failures for 15 seconds. Reasons, categories, semantic status and correlation IDs are kept for up to 7 days for troubleshooting. Input text and images are not saved in moderation logs. Provider data handling follows its policies. Review does not mean prohibited content, and service failures are not blocks; generation proceeds only after explicit approval.
Human safety review
To investigate abuse and periodically check service safety, specifically authorized administrators may view generated images and creative-assistant conversations, including messages, image prompts and attached-file names, in a separate access-controlled admin service. This does not make your content visible to other users. This interface does not read mailbox messages, attachment contents or internal model execution state. Access and review actions are logged; review records contain account and content identifiers, reviewer, time, classification and short notes rather than copied content. Manual-review records are retained for 90 days and then removed by scheduled cleanup; account deletion also removes current review decisions. Access logs expire on the same 90-day schedule. Reviewing does not extend image or conversation retention, create additional content copies, or send outputs to another AI moderation provider. Conversation text is encrypted at rest with operator-held keys, not end-to-end encrypted. Contact support@sparkletrip.com about review errors, privacy rights or deletion requests.
Image storage and sharing
Generated images are private and stored in Cloudflare R2 for 7 days after completion. Permanently saved images do not expire automatically. Each account has 1 GB of permanent storage by default, adjustable by the administrator. Downloads require authentication and a short-lived, single-use ticket.
Anyone who receives a link you explicitly share can view that image. You can revoke sharing. The link does not include conversations, prompts, emails or account information.
Deletion and retention
Deleting a conversation also deletes its generated private server documents, but does not automatically delete generated images. Temporary attachments and reading caches are cleaned up on expiry. Removing images from permanent storage revokes sharing; images past their temporary retention period become inaccessible. CF Mail and the Credits service manage account, billing and email data. Request account deletion in CF Mail privacy settings. This blocks access here; the administrator completes cleanup across services.
Service scope
The assistant can ask questions, generate images, read selected files and export documents. It does not automatically read email, other conversations or other users’ data. Cloudflare and model providers may process data outside your country or region. Consider your data requirements before submitting content. Network and third-party services may affect availability.
Your analytics preferences
Only with your consent, the SparkleTrip main website loads Google Analytics 4 to measure visits, devices, approximate regions and feature usage. We do not send names, email addresses, account IDs, prompts, conversations, attachment names or artwork links. Conversation identifiers, full query strings and free-text search terms are removed. For shared promotional links, we use a small predefined set of public channel and content labels, such as X and product photography; after consent, these are kept in session storage for up to 30 minutes to retain the source across navigation and sign-in. Google processes analytics data, which may involve international transfers. You can withdraw consent here at any time; the saved campaign labels are cleared and creative features remain available.
Feedback
Feedback is optional and provided by Feedlog. Its embedded service loads only after you choose Continue to feedback. It uses your verified account email and display name to identify your feedback. Only content you submit in the feedback panel is sent; conversations, prompts, images, files and private page addresses are not automatically attached. Feedback can become visible on the public feedback board, so do not include sensitive information. Feedlog may process data outside your region and retains feedback under its policies. Hiding the button closes its connection; collapsing the panel keeps your draft for this page session. You can reopen it from the sidebar. Contact support@sparkletrip.com for account, payment, privacy or deletion requests.
Purposes and legal bases
We process account identifiers, requests, files and usage information to provide the features you ask for, maintain access and keep the Credits balance accurate. We use limited operational information to protect the service and resolve problems. Billing records may be retained to satisfy legal and accounting obligations.
Where applicable law requires a legal basis, these activities rely on performance of the service agreement, applicable legal duties, or legitimate service-security interests as appropriate. Optional analytics relies on your consent. Optional feedback sharing starts only after your action. Where additional consent or a different legal basis is required, that requirement still applies.
Cookies and browser storage
Essential session cookies support sign-in and security. Browser storage also remembers choices such as language, draft controls, analytics consent and whether the feedback button is hidden. Rejecting optional analytics does not disable essential account functions.
If you accept analytics, Google Analytics cookies may remain for up to 180 days under the current configuration. You can withdraw consent above and clear browser data. A shared or public computer may retain local preferences after a session; sign out when you finish.
Purchases and payment providers
Waffo Pancake provides hosted checkout. We send the product, amount and a server-generated order reference; the order is linked internally to your signed-in account. Waffo collects the billing and payment details you enter, processes applicable taxes and returns payment status. We do not receive full card numbers or security codes. NewAPI records successful purchases and Credits. Test mode uses simulated payments and does not grant spendable Credits. Support can also arrange manual purchases and handle refund requests. Necessary billing records may be retained after account deletion for legal obligations.
Your rights and requests
Depending on your location, you may have rights to access, correct, delete or receive a copy of your data, restrict or object to processing, withdraw consent and complain to the relevant data-protection authority. Contact support from the account email where possible. We verify requests proportionately and respond within the time required by applicable law.
Deletion can require coordination across the creative service, CF Mail, the Credits service and relevant providers. Information required for security incidents, disputes or legal accounting records may be retained for the necessary period with restricted use. Provider retention follows the applicable provider terms; we do not promise immediate deletion from every independent provider.
The service is intended for adults. Do not submit unnecessary sensitive data or children’s personal information. Contact support if such information was submitted by mistake.
Providers, international processing and updates
Cloudflare supplies web and object-storage infrastructure; the configured AI and safety providers process relevant input; when enabled, Waffo Prompt Sift processes user-written text for safety classification (not the application templates or AI-written responses); Google provides optional analytics; Feedlog provides optional feedback. Some processing may occur outside your country. The provider and region can depend on the selected feature and model.
We do not describe this service as end-to-end encrypted or guarantee a particular country of storage. Contact support for the current processing arrangements before submitting data that has geographic or contractual restrictions. Any safeguards or permissions required by applicable law must be satisfied; this notice alone is not a substitute for them.
Material changes to how data is used will be communicated through the service or the account contact method as appropriate. The update date appears at the top of this policy.