Privacy Policy
Last updated: June 10, 2026
The Short Version
TomSparkBox is a privacy-first product built by a privacy-first company. We don't want your data, we don't collect your data, and we don't sell your data. The software runs entirely on your hardware. We have no access to what runs on your server, who uses it, or what they do with it.
This policy explains the small amount of data we do collect — exclusively to run the website, deliver licenses, and provide support.
What We Don't Collect
- No tracking, profiling, or ads in the TomSparkBox software. The dashboard, modules, and apps don't build a profile of you, serve ads, or carry any per-install identifier. When you update, the software sends an anonymous release-health ping — which version you moved to, whether it succeeded, and which (if any) apps failed to come back healthy, with no identifier and nothing tied to your box — so we can catch a bad release. Crash reporting is separate, opt-in, and off by default; if you turn it on, crash reports carry a random per-install ID (a UUID generated on your box, not derived from anything about you) so we can tell whether ten reports are one box or ten. License activation is described below. That's the whole of it.
- No data from your self-hosted apps. Your Pi-hole logs, Vaultwarden passwords, Jellyfin library, Nextcloud files, and everything else stays on your server. We never see it.
- Sanitized logging of AI Troubleshooting conversations for product improvement. The AI Troubleshooting feature routes through our Anthropic API to provide diagnostic help. Before any message leaves your TomSparkBox server, an on-device sanitizer strips credential-shaped strings (API keys, passwords, tokens, SSH/PGP keys). The resulting credential-free conversation — your question and the assistant's reply — is logged on our side for up to 90 days and used to find class-level TomSparkBox bugs faster and turn recurring problems into shipped patches, guides, and docs updates. Your raw, unsanitized chat history stays only on your own server (
state/chat-sessions/) and is never collected. We never sell these conversations and never share them for third-party AI training. See the "When you use AI Troubleshooting" section below for details.
- Sanitized fix outcomes for product improvement. When Tom AI's agentic mode proposes a fix you choose to run (e.g. restarting a service or repairing permissions), it records — for the same diagnostic-improvement purpose above — which fix ran, whether it resolved the issue, and a credential-free, truncated description of the symptom. This carries no conversation text and no
.env values. We use it to learn which fixes actually work and to stop recommending ones that don't. You can opt a server out entirely by setting SB_AGENT_TELEMETRY=0.
- No analytics on the website beyond basic privacy-respecting hit counts. We do not use Google Analytics or any tracking scripts.
- No tracking pixels, no third-party cookies, no ad networks.
What We Do Collect
When you visit tomsparkbox.com
- Anonymous request logs. Our hosting provider (Cloudflare) receives standard web request logs: IP address, timestamp, page requested, user agent. These are retained by Cloudflare for security purposes and are not used for tracking.
- A preference cookie only if you interact with features that need it. No tracking cookies.
When you activate a free license
- Email address. Required to mint your free personal-use license key. We use it only to deliver the key, to look it up if you lose it, and to send a one-time legal notice if anything important changes about your license.
- License key history. We store your license key associated with your email so we can re-send it or help recover access if you lose it.
When TomSparkBox checks for updates
- An anonymous HTTP request to get.tomsparkbox.com to check the latest version. This request includes no identifying information beyond a standard HTTP user agent and your server's IP address (visible to any HTTP request).
When TomSparkBox validates your license
- On activation and periodically thereafter (roughly once per week), your TomSparkBox dashboard makes an HTTPS request to
webhook.tomsparkbox.com. The request contains: your license key, a random install ID (generated once per install, used only to count activations against the 3-install cap), and optionally your email if you're activating on a second or third install. No container names, no module list, no usage data, no IP-geo info beyond what any HTTPS request reveals.
- Our service responds with whether the key is valid and how many activations remain. The response is cached on your server so day-to-day dashboard use continues to work offline.
- License activation is optional. TomSparkBox runs without it; activation only enables auto-updates with rollback.
When you opt into anonymous diagnostics (off by default)
- Nothing is sent unless you switch it on. The toggle lives in Settings and defaults to off; turning it off stops all sending immediately.
- What an opted-in box sends: a random install ID (a UUID your box generated — never derived from you or your hardware), your SparkBox version, coarse system facts (Linux distro name, CPU architecture, RAM as a range like "8-16GB"), the health of each SparkBox app (app name + running/unhealthy + exit code — never logs or file contents), your license tier as a word ("free"/"backer"/"legend"), your fleet number if you're a Legend, and — only if you typed them — your ship's public name and design code.
- Crash reports additionally include an error fingerprint with all IP addresses, file paths, and hostnames stripped on your box before sending.
- What we never receive: files, filenames, photos, passwords, emails, container logs, hostnames, or your IP address in any stored record (requests naturally reveal an IP in transit; we use it only for transient rate-limiting, deleted within 24 hours, and never store it with your install ID).
- Retention: health snapshots expire after 30 days, crash events after 90 days, anonymous aggregate counters after 180 days.
Support
- Product support is delivered through the public d/sparkbox community forum on demox.world (email at support@tomsparkbox.com handles billing and refunds only). Posts in d/sparkbox are public — anyone (including search engines) can read them. Do not include passwords, API keys, license keys, or other sensitive data in your post.
- The forum is monitored daily by the TomSparkBox team and by other community members — every thread gets an answer, usually within a day; community members often jump in faster.
- Support replies are AI-assisted. Replies from the @tomspark account are a mix of Tom and an AI support agent running under his guidance (this is also noted on the account's profile). If you ask whether you're talking to the AI, it will tell you honestly.
- For legal, privacy, or DMCA matters only, you may contact legal@tomsparkbox.com. This address is not for product support.
The Fleet Map
The live fleet map at tomsparkbox.com shows ships for boxes whose owners opted into anonymous diagnostics. Here is exactly what it can and cannot know:
- Your ship's id is the first 8 characters of a one-way hash of a random identifier your box generated at install. It is not derived from your name, email, IP address, or hardware, and it cannot be reversed into any of them.
- Your ship's name exists only if you typed one in Settings. Pick a call sign — there's no reason to use anything identifying, and we sanitize it either way.
- What the map shows per ship: the optional name, the hull design, and the kinds of apps aboard (app names only — e.g. "Jellyfin"). Never files, accounts, IP addresses, locations, or anything from inside your apps.
- Backers & Legends: your fleet number is issued with your license, so our billing records connect that number to your purchase — that's how the perk works. The public map never shows anything beyond the number itself, and your ship id is not connected to your purchase.
- Opting out: switch off anonymous diagnostics in Settings and your ship leaves the reporting map; the fleet counters still count your box, anonymously, via the license system.
Why the Fleet asks for a little anonymous data
Let us be direct about how TomSparkBox makes money, because it is the whole reason you can trust this. TomSparkBox is a business — the software is free, and the optional Legend tier keeps the lights on. But look at what we sell: we sell privacy. People pay us precisely because SparkBox keeps their photos, files, and passwords on their own hardware, out of the cloud, away from everyone. That is the product. Which means selling your data is not just something we won't do — it is the one thing that would burn the whole business down. Our incentive is the opposite of Big Tech's: we make money by protecting your data, not by mining it.
And that is really what the Fleet is. Every SparkBox out there is one more box that slipped the corporate cloud — no landlord, no flag, nobody harvesting the crew. We are not a company with users; we are a fleet of independent people who all decided the same thing: our data is ours, and we would rather help each other keep it than hand it over. Nobody sails alone out here.
So here is the honest ask, and it is a fleet thing. TomSparkBox is built by one developer, mostly sailing blind — when something breaks on your box, we usually only find out if you happen to post about it. For every person who writes in, dozens quietly hit a snag and give up. Turning on anonymous diagnostics is how you stand watch for the rest of the fleet: your box signals things like which apps are running and whether they are healthy, what kind of error happened when something failed, and whether a setup step or the phone app worked — counts and categories, nothing more. One ship reporting a reef it hit means every ship behind it steers clear. It is never tied to you, you can read exactly what has been sent, and you can strike it any second in Settings. No landlord, no data brokers, no one flying alone — just a fleet that looks out for its own.
Third Parties We Use
We use a small number of third-party services to run the product. Each only receives the minimum data needed:
- Cloudflare — hosts the website, serves release files, provides CDN and DDoS protection. Receives standard web traffic metadata.
- Resend (transactional email service) — used to deliver license keys to your email address on activation. Subject to their own privacy policy.
- Email — license keys and one-time legal notices are delivered via Resend (above); support@tomsparkbox.com receives billing/refund emails you choose to send.
- Anthropic — powers the AI Troubleshooting feature. When you use AI Troubleshooting, your messages are sent through our account to Anthropic's Claude API for response generation. Anthropic does not train their models on customer API data. On our side, we log the sanitized (credential-free) conversation for up to 90 days for diagnostic improvement, and keep a short-lived rate-limit counter per license (see "When you use AI Troubleshooting" above).
- Amazon Associates / affiliate networks — if you click an affiliate link on our website (UGREEN, Corsair, Hostinger, Surfshark, Incogni), you are taken to that third party's site, where their own privacy policy applies. We receive anonymous commission tracking data from these networks.
Cookies
The tomsparkbox.com website uses minimal cookies:
- Essential cookies required for basic site functionality (e.g., remembering mobile menu state).
- Cloudflare security cookies used for DDoS protection and bot detection.
We do not use analytics cookies, advertising cookies, or social media tracking pixels. You can block all cookies in your browser without breaking the site.
Data Retention
- License key records: retained indefinitely so we can re-send lost keys (the license is perpetual).
- Payment records: retained as required by tax and accounting law (typically 7 years).
- Legal/privacy emails (legal@): retained for 2 years after the matter is resolved, then deleted.
- Product support emails (support@): retained for 1 year after the conversation closes so we can reference prior threads if the same customer reaches out again. Deleted after that.
- AI Troubleshooting conversations: the sanitized, credential-free version of each conversation is logged on our servers for up to 90 days and used to improve TomSparkBox (finding bugs, shipping patches, writing better guides). We never sell it and never share it for third-party AI training. Your raw, unsanitized chat history lives only on your own TomSparkBox server in
state/chat-sessions/, is never collected, and you control its lifecycle (delete the files or run sparkbox reset --soft). We also keep a per-license request counter for rate-limiting.
- Web server logs: retained by Cloudflare according to their policy (typically 7-30 days).
Your Rights
You have the right to:
- Access any personal data we hold about you (primarily your email and license record).
- Correct inaccurate data.
- Delete your data. Note: deleting your email from our records will make it impossible for us to re-send a lost license key in the future. Your license itself continues to work because it validates offline on your server.
- Export your data in a machine-readable format.
- Opt out of any non-essential communications.
To exercise any of these rights, email legal@tomsparkbox.com. For product support, ask d/sparkbox on Demox — replies in seconds.
Children
TomSparkBox is not directed at children under 13. We do not knowingly collect personal information from children.
International Users
TomSparkBox is distributed globally. The small amount of data we collect (email, license records) may be stored on servers located outside your country. By activating a license, you consent to this transfer.
If you are in the EU or UK, you have rights under GDPR. We consider ourselves bound by GDPR principles globally, regardless of your location.
Security
We take reasonable security precautions to protect the data we hold: encrypted transport (HTTPS), encrypted storage where appropriate, and limited access to sensitive records. However, no system is perfectly secure. We will notify affected users of any data breach as required by applicable law.
Changes to This Policy
We may update this policy from time to time. Material changes will be announced on the website. Continued use of TomSparkBox after changes constitutes acceptance.