Legal Requests & Law Enforcement
Last updated: September 26, 2026
The short version
SparkBox runs on our customers' own hardware, and we built it so that we hold as little as possible about them. We disclose customer data only when valid legal process requires it (or when the customer asks us to), we produce only what that process covers, and we can only produce what we actually have. This page says what that is, and what we do not have.
SparkBox is made by Cloakpoint Media LLC. Requests go to legal@tomsparkbox.com; postal address: [BUSINESS MAILING ADDRESS]. Copyright notices about material on our hosted services follow our Copyright & DMCA Policy instead.
How we handle a request
- One channel. Every request for customer data goes to legal@tomsparkbox.com and is reviewed with our lawyer. Nobody else, including our support staff and our AI support agents, will confirm or deny whether we hold data about anyone.
- Valid legal process. We require a subpoena, court order, search warrant or other legal process that is valid, properly served and enforceable against us, and appropriate to the data sought. Informal requests, letters from rights holders or their agents, and threats of litigation are not legal process, and we do not hand over customer data in response to them.
- Narrow scope. We check each request and produce only the data it specifically requires, from records we already hold. We may push back on, or ask a court to narrow or quash, a request that is overly broad, unclear or defective.
- Telling the customer. Where the law allows, we tell the affected customer about the request before we disclose anything, so they can object. We do not give notice when a law or court order forbids it, or when our lawyer advises that notice would put someone in danger; in that case we tell them once the restriction ends, if we can.
- Preservation. Our routine deletion runs on fixed schedules set in advance and published on our Privacy Policy. It never happens because of a particular request or dispute. Once we receive a request or a preservation notice, or expect a legal claim, we stop deleting the data it covers for as long as the law requires.
- Record keeping. We keep a record of each request: who sent it, the legal basis, what it asked for and what, if anything, we produced.
What we hold
The complete list, with what each record contains and how long it is kept, is on the Privacy Policy. In summary:
- Licence records: email address, licence key, tier, purchase reference and the random install IDs that activated the licence. Kept indefinitely, because the licence is perpetual and a lost key can be re-sent.
- Payment records (held by Stripe): name, email, billing country, amount. Kept as tax law requires.
- Tom AI records (only if a customer uses Tom AI): conversation records and support cases are kept for 90 days, with media titles, indexer and tracker names, addresses and user names replaced by labels, and a keyed reference in place of the licence key. We hold the key to that reference, so we can match a record to a licence. Fix outcomes (which fixes ran and whether they worked) are kept, with a scrubbed problem label.
- Older Tom AI records: conversation records and support cases written before September 25, 2026 still carry the licence key and install ID, and may contain download titles and indexer names as the customer's box sent them. They expire on their original 90-day schedule; the last of them expire by December 24, 2026.
- Support tickets and forum accounts on demox.world: account details, what the customer wrote, and any diagnostics they chose to attach, kept as the Demox privacy page describes.
- Off-site backups: encrypted files we cannot open, with their date, size and the subscription they belong to.
- Hosted Hearth: encrypted messages and files we cannot open, plus the metadata our servers need in plain form (user and display names, channel names, file names and sizes, timestamps) and the purchase email.
- Network data: our hosting provider's short-lived web request logs, and, for about two weeks, a keyed hash of the address each box used to check for updates (used to count boxes).
What we do not have
- The contents of anyone's SparkBox. Customers' media, files, photos, app databases, download history and watch history stay on their own hardware. We have no standing access to it.
- What customers download or watch. We do not collect download or watch activity, and our records do not link a customer to a title, torrent, info-hash, tracker or indexer (except the older Tom AI records above, until they expire). SparkBox 1.6.790 and later replace titles and similar names with labels on the customer's own box before a Tom AI request leaves it, so we never receive them. Earlier releases send them to our server as part of a Tom AI request; our server replaces them in memory before storing anything or passing anything to an AI provider, and does not keep the originals. In every release, a title a customer types into Tom AI as plain words, with nothing marking it as a title, may pass through unrecognised.
- Readable backups or Hearth messages. They are encrypted with keys we never receive, so we cannot decrypt them for anyone.
- A way to watch a box. We have not built any capability to monitor customers' boxes or what they download, and we will resist any demand to build one to the full extent the law allows.
Customers asking about their own data
To see, correct, export or delete the data we hold about you, see Your Rights in the Privacy Policy.
Changes
We may update this page. The date at the top shows when it last changed.