Privacy Policy
Last updated: October 2, 2026
The Short Version
SparkBox runs your apps on your own hardware, and your apps' data stays there. A few optional features use our services and send some data to us: Tom AI (the AI Troubleshooting assistant), licence checks, support tickets, off-site backup, and diagnostics if you turn them on. This page lists what each one sends, what we keep, and for how long. We do not sell your data. TomSparkBox is made by Cloakpoint Media LLC, which is responsible for the data described here.
On September 25, 2026 we changed what we keep: Tom AI conversation records and support cases no longer carry your licence key or install ID. Download titles, indexer and tracker names, magnet links, IP addresses, host, domain and user names are replaced with labels before these records are stored, and before anything reaches an AI provider. Where that replacement happens depends on your SparkBox version:
- SparkBox 1.6.790 and later: your box replaces them before a Tom AI request leaves it, so our server and the AI provider receive labels, not the names.
- Earlier releases: your box sends the real names to our server as part of the Tom AI request. Our server replaces them in memory before it stores anything or contacts an AI provider, and does not keep the originals. Update to 1.6.790 or later if you want the names never to leave your box.
Records written before September 25, 2026 still exist until they expire on their original schedule (the last by December 24, 2026), as described under Data Retention.
Who can see what you download and watch
"Titles" below means movie, show, music and book titles, release and file names, magnet links and info-hashes, tracker and indexer names, search terms, your library and your watch history.
| Where | SparkBox 1.6.790 and later | Earlier releases |
| Your box | Yes. Your apps and your Tom AI chat history keep the real names, on your hardware. | Same. |
| Our server, while answering a Tom AI request | No. Your box sends labels such as [movie release 1] and indexer A. | Yes, in transit: the real names arrive with the request and are replaced with labels in memory. They are not written to storage. |
| The AI provider (OpenAI) | Labels only. | Labels only (since September 25, 2026). |
| Our stored records (Tom AI conversations, support cases, fix outcomes) | Labels only. | Labels only for records written since September 25, 2026. Records written before then carry your licence key and may carry titles as your box sent them, until they expire (the last by December 24, 2026). |
| Support tickets you send us | What you choose to write or attach. The diagnostics bundle is described under Support. |
What no release can catch: a title you type into Tom AI as plain words, with nothing (a year, an episode number, a quality tag) marking it as one, may pass through unrecognised. And none of this applies if you never use Tom AI: then nothing about your media leaves your box. How we answer legal requests, and what we could and could not produce, is on the Legal Requests page.
What We Don't Collect
- No tracking, profiling, or ads in the TomSparkBox software. The dashboard, modules, and apps don't build a profile of you or serve ads. When you update, the software sends an anonymous release-health ping: which version you moved to, whether it succeeded, and which (if any) apps failed to come back healthy. It carries no identifier and nothing tied to your box, so we can catch a bad release. Crash reporting is separate, opt-in, and off by default; if you turn it on, crash reports carry a random per-install ID (a UUID generated on your box, not derived from anything about you) so we can tell whether ten reports are one box or ten. The features below that you choose to use are the other exceptions.
- Your apps' data stays on your server unless you use Tom AI or send a support ticket. SparkBox never uploads your files, photos, passwords, Pi-hole logs or media library on its own. When you ask Tom AI for help, it reads parts of your box to answer, and some of that reaches us and our AI provider. The next section lists exactly what. If you never use Tom AI and never attach diagnostics to a ticket, none of it leaves your server.
- No analytics scripts on the website. Google Analytics was removed from every page on September 13, 2026. Page traffic is measured only from Cloudflare's server-side request counts, which never run code in your browser.
- No ad networks and no social-media pixels. Two attribution scripts run on some pages, and we list them below: an affiliate referral script (so a partner who sent you here is credited if you buy) and a ChatGPT-ads conversion tag (so we know a purchase came from an ad we paid for). We use them for that attribution only. Block them and the site works the same.
When you use AI Troubleshooting
Tom AI answers questions about your box and can fix some problems. To do that it runs read-only checks on your box and sends your message, those check results and the conversation so far to our server. Our server de-identifies them, forwards them to an AI model provider and streams the answer back.
What Tom AI reads on your box
- App health (which SparkBox containers are running), the
sparkbox doctor result, recent log lines of the app you are asking about, which settings exist in .env (names only, never values) and the app's compose file.
- If you ask about downloads or media: your Radarr/Sonarr download queue (progress, state and the app's own error message), your Prowlarr and download-client setup (how many indexers, which download client, root folders and the apps' health messages), your Jellyfin library when you ask what to watch, and Jellyfin watch history when you ask what was watched.
- If you ask about the box itself: disk use by folder, which apps can be reached from the internet, what changed recently, and your box's local addresses.
What the AI provider receives
- De-identified text only. Before any request reaches an AI provider, our server replaces everything we can recognise as identifying or as media content with a label: licence keys and install IDs, email addresses, IP addresses, your box's host name and local (
.local) names, your own domain names, Tailscale and dynamic-DNS names, user names in a shell prompt or a home folder, SMB share names, Jellyfin user names in watch history, the person who made a Seerr request, download and library titles, release names, indexer and tracker names, magnet links and info-hashes. The model sees labels such as [movie release 1], indexer A, [person 1], [domain 1] or [LAN address 1], and answers with them. This applies to every SparkBox release, since September 25, 2026.
- Your names come back only to your box. On releases before 1.6.790, when the answer returns, our server puts the real names back in the reply to the box that sent them, so you see the real title rather than a label and Tom AI can still act on the right item. That means our server holds those names in memory while it answers; it does not write them down. The provider never receives them, and our stored copy keeps the labels.
- SparkBox 1.6.790 and later do this on your box, before anything leaves it, with the same labels kept for the whole conversation. Your box swaps the real names back in when the answer arrives, so our server never receives them.
- What we cannot catch: a plain name or title you type in a sentence with nothing around it that marks it as one (for example "is my son's show stuck?" is fine; a bare show name with no year, episode number or quality tag passes as written). From 1.6.790 your box also knows the titles in its own library and the names of its Jellyfin and Seerr users, and replaces those even when you type them bare — except a one-word title that is also an everyday word (such as "Up" or "Heat"), which is left as written so your question still reads right. On releases before 1.6.790, a title that Tom AI named in an earlier answer can reach the provider again on a later turn of the same conversation if it has no such marker. Don't type anything you don't want to share.
- Passwords, API keys, tokens and private keys are removed on your box before anything leaves it, as before.
- Request settings: every OpenAI request is sent with storage turned off (
store: false). The only identifier attached is OpenAI's safety_identifier, which we set to a code derived from a secret key only our server holds. It changes every week, so OpenAI cannot link your requests from one week to the next or tie them to your install. We do not have a Zero Data Retention agreement with OpenAI; under its standard API terms OpenAI may keep requests for up to 30 days to monitor for abuse, and does not train on them.
- Before September 25, 2026 the requests themselves were not de-identified this way: download queues, indexer names, library titles and watch history, host and domain names reached the provider as your box sent them (IP addresses, emails, licence keys and Tailscale, dynamic-DNS and
.local names were already removed on OpenAI requests), one internal request that picks a help article received your question without that removal, and the safety_identifier was a fixed hash of your install ID.
What we keep
- Conversation records, 90 days. Each conversation (your messages and Tom AI's replies, sanitized and with titles, indexer names, magnet links and addresses replaced by labels) is stored for 90 days to find bugs and improve answers. The record carries a keyed reference in place of your licence key and install ID: it lets us tell that several conversations came from the same licence without storing the key or your email with it. We hold the key to that reference, so we can still match it to your licence if we need to. The "Share to demox" button sends the same kind of record and also creates the public forum post you asked for.
- Support cases, 90 days. When Tom AI can't fix something, your box files a support case unless you set
SB_AGENT_TELEMETRY=0. A case holds the check results Tom AI saw (app health, the download queue, the media setup, the doctor findings), the fixes it tried and how they went, the first line of your question, your SparkBox version and tier. Titles, indexer names, addresses and similar are replaced with labels. It carries a keyed reference in place of your licence key and install ID, and never the conversation itself. Support staff may copy a case onto our internal support server to answer it (see Support), and our engineering tools, which run on Anthropic's Claude, read it with identity fields removed to fix the cause in SparkBox; groups of similar cases are counted by app and failed check only.
- Fix outcomes. Unless you set
SB_AGENT_TELEMETRY=0, your box reports which fixes Tom AI ran and whether they worked, with a short label of the problem (the first few words of your question, scrubbed as above). The reports hold only which fixes ran, whether they worked and that scrubbed label; we keep them, because they are how we learn which fixes work across all boxes. A record that stops one licence from reporting for more than three boxes keeps a keyed reference of the licence email, never the address, for 90 days. After an update your box re-runs its own checks for problems Tom AI could not fix there and, when one now passes, tells you on the box; that happens entirely on your box. Only the number of such problems in the last 30 days is included in these reports.
- Anonymous case notes, 90 days. When a Tom AI conversation has been quiet for two hours, our server writes a short case note from the record above: the problem and Tom AI's suggestion in the conversation's own, already-sanitized words, which SparkBox apps, fixes and help articles were involved, your SparkBox version, and whether it worked (your "Did that fix it?" answer, what you wrote afterwards, or the same problem coming back). A case note carries no licence key, install ID, conversation ID, keyed reference, name, email, address, host name, title or indexer name, and any text that a second pass of our scrubber would change is left out. For 10 days a separate, expiring link lets us update whether it worked; after that nothing ties a note to you or your box, and we do not try to re-identify notes. Our scrubber cannot recognise every personal name a message may contain, which is one reason the text stays internal and is never shown to other customers. Notes are made and stored on Cloudflare (our servers and Workers AI). Apart from Cloudflare's AI, which reads a note once to label it when it is made, no person and no AI reads a note's text: our support and engineering tools see only its labels (which apps, fixes and help articles were involved, and whether it worked) and counts of how often each kind of problem came up. No outside AI company sees case notes. They help Tom AI and our support staff solve the same problem faster for everyone. Each note is deleted after 90 days; what remains are counts of how often each kind of problem came up, kept while it keeps happening and for 180 days after it was last seen. Case notes are made only from conversations on SparkBox releases from October 2026 onwards, and never when you set
SB_AGENT_TELEMETRY=0; if you set it partway through a conversation, no note is made from that conversation (we keep a mark that it opted out, with no content, for as long as the conversation record), and a note already made from it is deleted if its last message was less than 10 days earlier; after that nothing links the note to your box, and it is deleted at 90 days like every note.
- Short heads of questions and answers, 14 days, used to measure answer quality; they carry no licence key or install ID. A list of the most-asked questions Tom AI had no help article for, in the same scrubbed form, is copied daily to our internal support server so we know which articles to write; each is kept there for up to 28 days. Usage and rate-limit counters per licence (how many messages and how much AI spend today) are kept for a day or two and are keyed by your licence key; counters per IP address are keyed by a hash whose key is thrown away daily.
- Your full, raw chat history (including the real names the labels stand for) stays on your server in
state/chat-sessions/. We never collect it. Delete the files, or run sparkbox reset --soft, to remove it.
What We Do Collect
When you visit tomsparkbox.com
- Request logs. Our hosting provider (Cloudflare) receives standard web request logs: IP address, timestamp, page requested, user agent. Cloudflare keeps these for security purposes; we do not use them for tracking.
- Attribution cookies on a few pages. If you arrive through an affiliate link (
?via=), the PromoteKit referral script (homepage, backer and affiliate pages) sets a first-party cookie so that partner is credited if you buy. OpenAI's ChatGPT-ads tag (homepage, backer, roadmap, ships and thank-you pages) sets a cookie so a purchase is credited to the ad you came from. No other tracking cookies.
When you activate a free license
- Email address. Required to mint your free personal-use license key. We use it only to deliver the key, to look it up if you lose it, to send a one-time legal notice if anything important changes about your license, and, for paid customers, a short Friday email rounding up that week's fixes. Free keys minted on or after September 14, 2026 also get one follow-up email about a week later describing what Tom AI (the Legend feature) would do on your box; there is nothing after it. Every one of these emails carries a one-click unsubscribe link, and unsubscribing never affects your license-key emails.
- License key history. We store your license key with your email, tier and purchase reference so we can re-send it or help recover access if you lose it.
When TomSparkBox checks for updates
- An HTTP request to get.tomsparkbox.com to check the latest version. It includes no identifying information beyond a standard HTTP user agent and your server's IP address (visible to any HTTP request). We use it to count how many boxes are out there: the server keeps a keyed hash of the address and the calendar week, so each box counts once a week, and deletes it after about two weeks. Nobody without our key can turn the hash back into an address; we hold the key, so in principle we could check whether a given address checked for updates in the last two weeks. The count is a number per week, paid and free, and nothing else.
When TomSparkBox validates your license
- On activation and periodically after that (roughly once per week), your dashboard makes an HTTPS request to
webhook.tomsparkbox.com. The request contains your license key, a random install ID (generated once per install, used to count activations against the 3-install cap), and optionally your email if you're activating on a second or third install. No container names, no module list, no usage data.
- Your licence record lists the install IDs that activated it (so the cap works and a reinstall can free its slot). That means we can match an install ID to your licence, and so to your email.
- Our service responds with whether the key is valid and how many activations remain. The response is cached on your server so day-to-day dashboard use continues to work offline.
- License activation is optional. TomSparkBox runs without it; activation only enables auto-updates with rollback.
When you opt into anonymous diagnostics (off by default)
- Nothing is sent unless you switch it on. The toggle lives in Settings and defaults to off; turning it off stops all sending immediately.
- What an opted-in box sends: a random install ID (a UUID your box generated, never derived from you or your hardware), your SparkBox version, coarse system facts (Linux distro name, CPU architecture, RAM as a range like "8-16GB"), the health of each SparkBox app (app name + running/unhealthy + exit code, never logs or file contents), your license tier as a word ("free"/"backer"/"legend"), your fleet number if you're a Legend, and, only if you typed them, your ship's public name and design code.
- Crash reports additionally include an error message and stack trace with IP addresses, MAC addresses, email addresses, paths under your home and mount folders, domain names and (from 1.6.790) download paths and magnet links stripped on your box before sending. A plain machine name that appears inside an error message (one without a domain) may not be caught.
- What we never receive through diagnostics: files, photos, passwords, container logs, or your IP address in any stored record. Requests reveal an IP in transit; we use it only for rate limiting, stored as a hash with a key that is thrown away daily, and never with your install ID.
- Retention: health snapshots expire after 30 days, crash events after 90 days, anonymous aggregate counters after 180 days.
Off-site backup
- If you use off-site backup, your box encrypts each backup with a key that never leaves it before uploading. We and Cloudflare hold ciphertext only, plus the file name (a date), its size, when it was uploaded and which subscription it belongs to.
Support
- Public product support is delivered through d/sparkbox. Private account, license, billing, security, and diagnostic support uses Demox private tickets. Public posts are searchable; private tickets and replies are restricted to the submitting account and support staff. Do not include passwords, API keys, full license keys, payment-card numbers, or recovery codes in either channel.
- A ticket from the dashboard carries your subject and message, a reply-to email, your SparkBox version and a short licence reference (never the full key). From 1.6.790 two boxes start unticked and are sent only if you tick them. "Include host info" adds your OS, Docker version, CPU and memory and container counts (no hostname from 1.6.790). "Attach a diagnostics bundle" adds app states, the doctor result, folder permissions, setting names (never values) and, from 1.6.790, recent logs of SparkBox's own system apps only (dashboard, proxy, monitoring) with addresses removed. Dashboards before 1.6.790 had both boxes ticked by default and attached logs from more apps, including media apps such as Sonarr, Radarr and Jellyfin; since September 25, 2026 the support server keeps only system-app logs from those bundles and removes IP addresses and hostnames before storing them.
- How long tickets are kept: see the Demox privacy page. In short: a resolved ticket closes automatically after 30 quiet days, and closed tickets are deleted 24 months after their last activity. Shorter limits (clearing the contact email and diagnostics 30 days after a ticket is resolved, and deleting it after 90 days) are being prepared and are not switched on yet.
- Anthony is our AI Senior Support agent. New automated support replies use Anthony's labeled AI identity; human staff replies are labeled separately. Anthony's replies are drafted with Anthropic's Claude, which receives the ticket text and its diagnostics to do so. Chris, our AI agent on the public forum, uses OpenAI (Anthropic before September 17, 2026). He reads public posts and, to investigate a problem, the support cases described above (identity and credential fields removed); he never reads private tickets or case notes.
- Public forum answers: when a forum thread gets a reply to a support answer, we keep the question, the answer and the reply (no usernames) for up to 180 days to learn which answers worked, with titles, indexer names and addresses replaced by labels.
- Our internal support server (at DigitalOcean) keeps working copies of forum threads, tickets and support cases while they are being answered. We are introducing a 30-day limit on those copies; until that job is switched on they are deleted by hand.
- For legal, privacy, or DMCA matters only, you may contact legal@tomsparkbox.com. This address is not for product support.
The Fleet Map
The live fleet map at tomsparkbox.com shows ships for boxes whose owners opted into anonymous diagnostics. Here is exactly what it can and cannot know:
- Your ship's id is the first 8 characters of a one-way hash of a random identifier your box generated at install. It is not derived from your name, email, IP address, or hardware, and it cannot be reversed into any of them.
- Your ship's name exists only if you typed one in Settings. Pick a call sign; there's no reason to use anything identifying, and we sanitize it either way.
- What the map shows per ship: the optional name, the hull design, and the kinds of apps aboard (app names only, e.g. "Jellyfin"). Never files, accounts, IP addresses, locations, or anything from inside your apps.
- Backers & Legends: your fleet number is issued with your license, so our billing records connect that number to your purchase; that's how the perk works. The public map shows nothing beyond the number itself. Behind the map, the diagnostics record for your box holds your fleet number next to its install ID, so we could connect your ship to your purchase. We don't use it that way.
- Opting out: switch off anonymous diagnostics in Settings and your ship leaves the reporting map; the fleet counters still count your box, anonymously, via the license system.
Why the Fleet asks for a little anonymous data
Let us be direct about how TomSparkBox makes money, because it is the whole reason you can trust this. TomSparkBox is a business: the software is free, and the optional Legend tier keeps the lights on. But look at what we sell: we sell privacy. People pay us precisely because SparkBox keeps their photos, files, and passwords on their own hardware, out of the cloud, away from everyone. That is the product. Which means selling your data is not just something we won't do; it is the one thing that would burn the whole business down. Our incentive is the opposite of Big Tech's: we make money by protecting your data, not by mining it.
And that is really what the Fleet is. Every SparkBox out there is one more box that slipped the corporate cloud: no landlord, nobody harvesting the crew. We are not a company with users; we are a fleet of independent people who all decided the same thing: our data is ours, and we would rather help each other keep it than hand it over. Nobody sails alone out here.
So here is the honest ask, and it is a fleet thing. TomSparkBox is built by one developer, mostly sailing blind: when something breaks on your box, we usually only find out if you happen to post about it. For every person who writes in, dozens quietly hit a snag and give up. Turning on anonymous diagnostics is how you stand watch for the rest of the fleet: your box signals things like which apps are running and whether they are healthy, what kind of error happened when something failed, and whether a setup step or the phone app worked. Counts and categories, nothing more. One ship reporting a reef it hit means every ship behind it steers clear. You can read exactly what has been sent, and you can switch it off any second in Settings.
Third Parties We Use
We use a small number of third-party services to run the product. Each only receives the data needed for its job:
- Cloudflare: hosts the website, serves release files, runs our back-end workers and stores their data, provides CDN and DDoS protection. Receives standard web traffic metadata. Cloudflare Workers AI scores Tom AI answers (see above).
- Resend (transactional email service): delivers license keys, receipts, ticket-reply notifications and emails you opted into. Subject to their own privacy policy.
- Demox (our own forum and support site): stores private support tickets, replies, account identity, and any contact or diagnostic details you submit so support can respond.
- AI providers: OpenAI (current) and, in the past, Anthropic, DeepSeek, Moonshot AI and OpenRouter (now only a standby route to Anthropic's Claude for our internal tools), as described under When you use AI Troubleshooting. Anthropic also drafts Anthony's private-ticket replies and runs our own support and engineering tools, which see anonymous case-note labels and counts, never their text.
- PromoteKit (affiliate attribution): its script runs on the homepage, backer and affiliate pages and, only when you arrive through a partner link, records which partner referred you so they are paid a commission if you buy. It receives the referral code and a random visitor id, not your name or email.
- OpenAI (ChatGPT ads): when we run ads inside ChatGPT, OpenAI's attribution tag on the homepage, backer, roadmap, ships and thank-you pages tells us a purchase came from that ad. It receives the click id OpenAI itself set and the fact that a purchase happened, so we can see whether the ad paid for itself. It is not used to show you anything.
- Amazon Associates / affiliate networks: if you click an affiliate link on our website (UGREEN, Corsair, Hostinger, Surfshark, Incogni), you are taken to that third party's site, where their own privacy policy applies. We receive anonymous commission tracking data from these networks.
Sub-processors
Companies that process data on our behalf, what they see, and where. This list changes only with a dated update to this page.
- Cloudflare (US/global): runs our workers (licence checks, telemetry, Tom AI proxy, chat feedback, off-site storage) and stores their data in Workers KV, R2 and Vectorize; runs Workers AI (answer scoring and anonymous case notes); serves the website and the release CDN.
- OpenAI (US): model provider for Tom AI (since September 16, 2026), for SparkMacro's calorie estimates and for Chris, our public-forum support agent (public posts and the support cases he investigates). Requests are sent with storage off; OpenAI may keep them up to 30 days for abuse monitoring.
- Anthropic (US): model provider for Tom AI until September 16, 2026 and our standby; drafts Anthony's private-ticket replies; runs our own support and engineering tools, which see anonymous case-note labels and counts, never their text.
- DeepSeek (China) and Moonshot AI (China): served some Tom AI requests between August 13 and September 15, 2026; no longer used.
- OpenRouter (US): served some Tom AI requests between August 13 and September 15, 2026. It remains a standby route to Anthropic's Claude for our internal support and engineering tools, used only when our direct Anthropic access is out of capacity; through it those tools can see support tickets, support cases and forum threads they are working on, but never case notes.
- Stripe (US): payments for Legend, Ultimate and the hosted add-ons; we never see card numbers.
- DigitalOcean (US): hosts the demox.world community and support server and our internal support server, which holds working copies of support tickets, support cases and forum threads so they can be answered.
- Resend (US): sends transactional email (receipts, ticket replies, notifications you opted into).
- GitHub (US): source hosting and the release build pipeline; no customer data beyond what is in public bug reports.
Off-site storage: the bytes are encrypted on your box before upload with a key that never leaves it; Cloudflare and we hold ciphertext only.
Ultimate bundle apps
Ultimate includes three hosted apps with their own data paths:
- SparkMacro: you describe meals and movement in text; that text goes to our AI provider (OpenAI) to estimate calories and macros, and the estimate comes back. Your journal stays in your browser; if you turn on encrypted cloud backup it is encrypted with a recovery key you keep, so we cannot read it. Because meals, weight and goals can say something about your health, treat SparkMacro as sensitive: nothing you enter is used for anything but your own estimate, it is never combined with your SparkBox account beyond the licence check, and you can delete your journal from the app at any time.
- TomSparkCal: date parsing runs locally; the optional AI helper uses a key you supply, not ours. Shared calendars are encrypted before upload; the hosting sees account and connection metadata only.
- Hearth (hosted): group chat hosted at yourname.hearthchat.net. Message text and file contents are end-to-end encrypted, so we cannot read them. The server does see, in plain form: user and display names, channel names and topics, the names, types and sizes of attached files, reactions, timestamps and who replied to whom. Your hosted Hearth is linked to the email you bought it with, and today that link is not deleted when a hosted Hearth is cancelled. Name channels and files with that in mind.
Cookies
The tomsparkbox.com website uses minimal cookies:
- Essential cookies required for basic site functionality (e.g., remembering mobile menu state).
- Cloudflare security cookies used for DDoS protection and bot detection.
The only third-party cookies are the two attribution cookies described above (affiliate referral and ChatGPT-ads conversion). We do not use analytics cookies or social media tracking pixels. You can block all cookies in your browser without breaking the site.
Data Retention
- License key records: kept indefinitely so we can re-send lost keys (the license is perpetual), including the install IDs that activated the licence. A separate lookup from an install ID to its licence is kept for up to 400 days.
- Payment records: kept as required by tax and accounting law (typically 7 years).
- Tom AI conversation records: 90 days. Records written before September 25, 2026 carry your licence key and install ID; they expire on the same 90-day schedule, the last of them by December 24, 2026.
- Tom AI support cases: 90 days. Cases filed before September 25, 2026 carry your licence key and the download titles as your box sent them; they expire on the same 90-day schedule, the last of them by December 24, 2026.
- Fix outcomes: kept (counts of which fixes worked, with a scrubbed problem label). Labels in reports sent before September 25, 2026 are scrubbed whenever they are read into the fleet totals.
- Anonymous case notes: 90 days. Counts of how often each kind of problem came up are kept while it keeps happening and for 180 days after it was last seen. For 10 days a separate, expiring link lets us update whether a note's fix worked; after that nothing ties a note to you or your box.
- Remote-support audit records (only if you ever used
sparkbox support): 90 days. From September 25, 2026 they no longer record your IP address.
- Older IP records: an activation-monitoring record that stored IP addresses per licence with no expiry was retired; any remaining entries are being reviewed for deletion.
- Support tickets: see Support above and the Demox privacy page.
- Working copies on our internal support server: see Support above.
- Legal/privacy emails (legal@): kept for 2 years after the matter is resolved, then deleted.
- Product support emails (support@): kept for 1 year after the conversation closes so we can reference prior threads if the same customer reaches out again. Deleted after that.
- Web server logs: kept by Cloudflare according to their policy (typically 7-30 days).
Requests from Authorities and Rights Holders
We disclose customer data only when valid legal process requires it, and we tell the affected customer first where the law allows. Letters from rights holders are not legal process. Routine deletion follows the fixed schedules above and never happens because of a particular request; once a request or preservation notice arrives, we keep the data it covers as the law requires. The details, and what we do not have, are on the Legal Requests page. Copyright notices about material on our hosted services follow the Copyright & DMCA Policy.
Your Rights
You have the right to:
- Access any personal data we hold about you (primarily your email and license record).
- Correct inaccurate data.
- Delete your data. Note: deleting your email from our records will make it impossible for us to re-send a lost license key in the future. Your license itself continues to work because it validates offline on your server.
- Export your data in a machine-readable format.
- Opt out of any non-essential communications.
To exercise any of these rights, email legal@tomsparkbox.com. For product support, open a private support ticket on Demox.
Children
TomSparkBox is not directed at children under 13. We do not knowingly collect personal information from children.
International Users
TomSparkBox is distributed globally. The data described on this page may be stored or processed on servers outside your country, including in the US and, for the AI providers named above for August and September 2026, in China. By activating a license, you consent to this transfer.
If you are in the EU or UK, you have rights under GDPR. We consider ourselves bound by GDPR principles globally, regardless of your location.
Security
We take reasonable security precautions to protect the data we hold: encrypted transport (HTTPS), encrypted storage where appropriate, and limited access to sensitive records. However, no system is perfectly secure. We will notify affected users of any data breach as required by applicable law.
Changes to This Policy
We may update this policy from time to time. Material changes will be announced on the website. Continued use of TomSparkBox after changes constitutes acceptance.