Legal

Privacy Policy.

Last updated: September 25, 2026

1. The short version: Sparcle has no server that receives your data

Bolt runs entirely on your own computer. It is a desktop application, not a cloud service. Your mail, files, clipboard, chats, notes, documents and prompts are read, indexed, encrypted and stored on your device. There is no Sparcle account to create, no Sparcle cloud to sync to, and no Sparcle endpoint that any of it is sent to. We do not hold your data, because it never reaches us. That is an architectural fact, not a promise about how we behave: there is nothing on our side to read, retain, subpoena, breach, or sell.

Three things are true alongside that, and we would rather state them plainly than let you find them:

  • The AI model you choose is not us. When you ask Bolt a question, only the specific content you direct it to send leaves your device, and it goes from your device straight to the AI provider you selected, under your own contract with that provider, over a zero-retention path with personal information masked at the boundary. Sparcle does not operate an inference gateway and is never in that request path.
  • Bolt checks for updates. It asks sparcle.app whether a newer version exists; that request is answered by a redirect to our public GitHub releases. It carries nothing from your device beyond the fact that a computer at your IP address asked, and for which platform. It contains none of your content.
  • An organisation can run its own Bolt server, and it is theirs, not ours. Bolt ships with its engine bundled on the device. A company may instead point its installs at a central Bolt server it deploys in its own infrastructure. That server belongs to the company, is operated by the company, and is still not Sparcle: we neither host it nor receive anything from it.
  • Your licence is verified offline. A Bolt licence is a signed token checked on your own machine against a public key. Installing, activating or running Bolt does not call home, and we cannot see whether or how you use it.

Everything below is the detail behind those statements, plus what this website collects, which is a separate and much more ordinary matter, described in section 6.

2. Who we are

Sparcle Inc. ("Sparcle," "we," "our," or "us") makes the Bolt desktop application and the Aeira enterprise data plane, and operates the website at sparcle.app. Contact us at [email protected].

It is worth being precise about the three, because they have very different privacy properties. Bolt is software you install and run; we operate no servers for it. Aeira is software our enterprise customers deploy inside their own infrastructure; we operate no servers for it either. sparcle.app is a website we do operate, and it behaves like a website.

3. Bolt desktop app: what stays on your device

Everything Bolt touches on your behalf is processed and stored locally: the content you paste or drop into it, the connectors you link, the files it indexes, the conversations you have, and the history it keeps so you can search it later. Bolt's local databases are encrypted at rest, with the exceptions described below, and its stored credentials are sealed with authenticated encryption.

On a signed release build the device key is held in your operating system's keychain and gated by your login; a copy of that same key, together with the keys that seal Bolt's own credential and pseudonymization stores, is also kept as a file in Bolt's data directory at mode 0600, so that a keychain Bolt cannot reach never locks you out of your own data. Those key files therefore sit beside the data they protect, and your account's file permissions are what separate them. The same is true of the small index of fields such as subjects, short facts, names, dates, file paths, and URLs that Bolt keeps readable on the device so local search can answer without decrypting everything. If Bolt cannot save its key, conversation and memory bodies are stored unencrypted, with a warning in its log, rather than sealed under a key that would be lost on restart; and its logs are scrubbed of personal data rather than encrypted. We recommend enabling FileVault or BitLocker so that the whole directory is covered by full-disk encryption; that, rather than the keychain, is what protects a copy taken off the machine. None of it is ever transmitted to Sparcle.

Because the data is on your device, deleting it is also on your device: removing Bolt's data directory removes it, and there is no copy of it with us to ask about.

4. Google user data (Bolt desktop app) and Limited Use

The Bolt desktop application ("Bolt by Sparcle") can connect to your Google Account, at your request, using Google OAuth. When you connect, Bolt accesses only the data covered by the scopes you approve, which may include: reading your Gmail messages (gmail.readonly), sending or drafting mail that you compose (gmail.send), your Google Calendar (calendar), your Contacts (contacts), your Google Tasks (tasks), reading your Google Drive files so you can search and open them (drive.readonly), and the specific Drive files you open or create in Bolt (drive.file).

This data is processed entirely on your own device. Bolt fetches your Google data directly from Google to your computer and uses it locally to power features such as search, context, drafting, and scheduling. Your Google user data is never transmitted to, stored on, or logged by Sparcle's servers. Any copy Bolt retains is stored only on your device, under your control, and can be deleted by you at any time, protected as described in section 3.

We do not sell your Google user data, do not use it for advertising, do not allow humans to read it, and do not use it to train generalized or AI/ML models. If you choose to ask an AI model a question, only the specific content you direct Bolt to send is transmitted, from your device directly to the AI provider you selected, over a zero-retention path with personal information masked at the boundary; Sparcle is never in that request path.

Bolt's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

5. Enterprise customer data (Bolt and Aeira deployments)

Bolt and Aeira are deployed on-premises or in the customer's own VPC, and are designed so that customer data remains within the customer's environment. Sparcle does not host, receive, or process that data, and operates no data plane on the customer's behalf; where a deployment is nonetheless governed by a Data Processing Agreement (DPA), that DPA controls.

When Bolt is pointed at an external LLM, only PII-masked prompts leave the customer's perimeter, and they go to the customer's own model provider, never to Sparcle infrastructure. Sparcle does not operate an inference gateway; you bring your own LLM under your own provider contract. Aeira enforces per-user ACL filtering: users only see data accessible under their own identity token.

6. What this website collects

This section is about sparcle.app only. It does not describe Bolt, and nothing here reaches into the application on your machine.

Like most websites, this one collects some data, and we would rather name it than hide behind "usage data":

  • No analytics or tracker. This site runs no analytics product and no third-party tracking script. We removed Google Analytics rather than disclose it, because a tracker on the site that tells you no Sparcle server receives your data is the one place that claim would not hold. We read traffic from our CDN's aggregate logs instead.
  • Things you type into a form. If you contact us, request a design-partner conversation, or ask for a checklist, we receive what you submit (typically your name, email address and message) and it is emailed to us so we can reply. Submissions pass through Cloudflare Turnstile, a bot check.
  • Download counts. When an installer is downloaded through an attributed campaign link, we record enough to count and de-duplicate that download, including the requesting IP address and network. It is used to pay referral credit and to size demand, not to profile you.
  • Ordinary server and CDN logs kept by our hosting provider for security and abuse handling.

We do not run advertising, and we do not sell or rent any of this.

7. Cookies

The website sets essential cookies only, such as your theme preference. There are no analytics cookies, no advertising cookies, and no cross-site tracking cookies, because there is no analytics or advertising script on the site to set them. The Bolt desktop application does not use cookies for tracking of any kind.

8. Data sharing

We do not sell your personal data, and we have no Bolt user data to sell. For the website data described in section 6, we use a small number of service providers for hosting and CDN, email delivery, and bot protection, under confidentiality obligations and only to operate the site. We may disclose data if required by law; in practice, a legal demand for the contents of your Bolt installation is one we cannot satisfy, because we do not have it.

9. Data retention

Data held on your device is retained for as long as you keep it, and is deleted when you delete it; Sparcle holds no copy and therefore retains nothing. For website data, we keep contact-form correspondence as long as needed to handle your enquiry and meet our legal obligations, and CDN log data for the limited period our hosting provider retains it.

10. Your rights

Depending on your jurisdiction, you may have rights to access, correct, delete, or export your personal data. For anything in Bolt, those rights are exercised directly on your own machine, because the data is yours and is already in your possession. For website data, contact us at [email protected] and we will action it.

11. Security

The strongest security property of this product is that the data is not in our custody. Beyond that: Bolt encrypts its local stores as described in section 3; traffic between your device and the services you connect it to is TLS-encrypted; and our website and internal systems use access controls and audit logging.

12. Changes to this policy

We may update this policy periodically. The "Last updated" date at the top reflects the most recent revision. Continued use of the site constitutes acceptance of the updated policy.

13. Contact

For privacy-related questions: [email protected]