Legal

Privacy Policy.

Last updated: August 3, 2026

1. Who we are

Sparcle Inc. ("Sparcle," "we," "our," or "us") operates the website at sparcle.app, the Bolt AI platform, and the Aeira enterprise data plane. Contact us at [email protected].

2. Information we collect

We collect information you provide directly (e.g., name, email when contacting us), usage data (pages visited, browser type, referral source), and, for Bolt and Aeira platform customers, data necessary to operate the service under a Data Processing Agreement.

3. How we use information

We use collected information to respond to inquiries, improve our website and products, communicate product updates (with your consent), and fulfill contractual obligations to customers.

4. Data sharing

We do not sell your personal data. We may share data with trusted service providers who assist in operating our website or platform, under confidentiality obligations. We may disclose data if required by law.

5. Enterprise customer data

Data processed through the Bolt platform and Aeira data plane on behalf of enterprise customers is governed by the applicable Data Processing Agreement (DPA). Bolt and Aeira's on-premises and VPC deployment options are designed so that customer data remains within the customer's environment; when Bolt is pointed at an external LLM, only PII-masked prompts leave the perimeter, and never to Sparcle infrastructure. Sparcle does not operate an inference gateway; you bring your own LLM under your own provider contract. Aeira enforces per-user ACL filtering: users only see data accessible under their own identity token.

6. Google user data (Bolt desktop app) and Limited Use

The Bolt desktop application ("Bolt by Sparcle") can connect to your Google Account, at your request, using Google OAuth. When you connect, Bolt accesses only the data covered by the scopes you approve, which may include: reading your Gmail messages (gmail.readonly), sending or drafting mail that you compose (gmail.send), your Google Calendar (calendar), your Contacts (contacts), your Google Tasks (tasks), reading your Google Drive files so you can search and open them (drive.readonly), and the specific Drive files you open or create in Bolt (drive.file).

This data is processed entirely on your own device. Bolt fetches your Google data directly from Google to your computer and uses it locally to power features such as search, context, drafting, and scheduling. Your Google user data is never transmitted to, stored on, or logged by Sparcle's servers. Any copy Bolt retains is stored only on your device, under your control, and can be deleted by you at any time. On the device, Bolt's local databases are encrypted at rest and its stored credentials are encrypted with AES-256-GCM, with the keys held in your operating system's keychain and gated by your login, so a copy taken off the machine is not readable. To let local search answer without decrypting everything, Bolt keeps a small index of fields such as subjects, names, and dates readable on the device; that index is protected by your account's file permissions, and we recommend enabling FileVault or BitLocker so that it is covered by full-disk encryption as well. None of it is ever transmitted to Sparcle.

We do not sell your Google user data, do not use it for advertising, do not allow humans to read it, and do not use it to train generalized or AI/ML models. If you choose to ask an AI model a question, only the specific content you direct Bolt to send is transmitted, from your device directly to the AI provider you selected, over a zero-retention path with personal information masked at the boundary; Sparcle is never in that request path.

Bolt's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

7. Cookies

Our website uses only essential cookies (e.g., theme preference). We do not use advertising or cross-site tracking cookies.

8. Your rights

Depending on your jurisdiction, you may have rights to access, correct, delete, or export your personal data. Contact us at [email protected] to exercise these rights.

9. Data retention

We retain personal data only as long as necessary for the purposes described above or as required by law. Google user data accessed by the Bolt desktop app is retained only on your own device, under your control, and is not held by Sparcle.

10. Security

We implement industry-standard security measures including TLS encryption, access controls, and audit logging to protect your data.

11. Changes to this policy

We may update this policy periodically. The "Last updated" date at the top reflects the most recent revision. Continued use of the site constitutes acceptance of the updated policy.

12. Contact

For privacy-related questions: [email protected]