Legal
Sprout privacy policy
Draft for legal review, October 2026
This policy explains how we handle personal information when you use Sprout, including the website at https://feat-sprout-preview-profile-5ea7a2a.ocd.dev, the apps hosted on Sprout, Sprout's Agent, and the connection between Sprout and AI apps such as ChatGPT, Claude and Cursor. It doesn't replace the privacy notice of an app that someone else builds and runs on Sprout.
Who we are
OpenCloud Solutions Limited (company number [company number to be supplied], registered office [registered office to be supplied]) operates Sprout. In this policy, "we", "us" and "our" mean OpenCloud Solutions Limited. We are the controller of the personal information described here, except where this policy says that an app owner decides how it is used.
Scope and roles
We decide how account, plan, support, security and service-operation information is used to run Sprout.
When you build an app, you decide what it collects from the people who use it, and we host the app and its data for you. You are responsible for telling those people how your app uses their information and for getting any permission the law requires.
If you use an app that someone else built, that person runs the app and decides how it uses your information, so please ask them first. You can report an app that collects information deceptively.
When you build with your own AI app, such as ChatGPT, Codex, Claude or Cursor, the company behind it processes your conversation, including what it sends to and receives from Sprout, under its own terms and privacy policy. We receive only the requests your AI app sends to Sprout, not the rest of your conversation, unless your AI app includes it in a request.
When you use Sprout's Agent, we send your messages, any files you attach and the parts of your app the Agent works on to the AI provider you connected, OpenAI or Anthropic, so it can do what you ask. That provider processes them under your agreement with it and its own privacy policy.
Information we handle
We may handle:
- Account and profile: your email address, name, profile picture link, account identifiers, plan, and whether you have confirmed your email.
- Sign-in and security: a one-way scrambled form of your password (never the password itself), sign-in sessions, the status of one-time sign-in links, the AI apps you have connected and what they are allowed to do, and security events.
- Payments: your plan, your subscription status and the payment records Stripe shares with us. Stripe collects your card details, and we never see your full card number.
- Connected AI accounts: which provider you connected, the sign-in or API key you gave Sprout's Agent, which we store encrypted, and records of the AI work run with it.
- Agent conversations: your messages and attachments, the Agent's replies, and a protected record of each Agent run, which can include app code.
- Your apps: app names and addresses, whether each app is private or public, code, settings, the data and files your apps store, backups, and app secrets. Secret values are kept apart from everything else and are never shown back in lists.
- App email: addresses, delivery status and a limited copy of each message your apps send or receive, with attachment details but not the attachment files.
- Service records: IP address, request times, browser and device details, app identifiers, actions and their results, scheduled task history, limited logs, usage totals, measurements your apps record, alerts and error details.
- App visitor statistics: a one-way code that changes every day and is made from a visitor's IP address and browser details, plus the general traffic source, country, browser and operating system. These statistics never keep the raw IP address, browser details, referring page or page address.
- Requests from AI apps: the requests your AI app sends to Sprout, our replies, and the connection details needed to do what you asked.
- Support and reports: the messages and attachments you send us, including abuse and security reports.
How we use information
We use information to:
- create and manage your account, your apps and your sign-in sessions
- build, check, preview, publish, back up and run apps when you or your AI ask
- run Sprout's Agent with the AI account you connected
- send sign-in, confirmation and account emails
- manage your plan and payments with Stripe
- keep Sprout secure, keep each person's apps and data separate, investigate abuse and fix failures
- answer support requests and tell you about important changes to Sprout or this policy
- meet our legal obligations, and establish, exercise or defend legal claims
Our legal reasons for using information are:
- Contract: to provide Sprout and your plan, as you ask.
- Legitimate interests: to keep Sprout secure, prevent abuse, fix failures and improve the service, in ways that respect your rights.
- Legal obligation: to meet tax, accounting and other legal duties, and to respond to lawful requests.
- Consent: where we ask for it. You can withdraw your consent at any time.
We don't sell personal information, and we don't use it for targeted advertising.
Who we share information with
We share information only when it is needed to run Sprout, or in the situations below:
- Service providers that process it for us: Amazon Web Services, for email delivery through Amazon SES and for storage and hosting infrastructure where applicable, and Cloudflare, for network and DNS services.
- Stripe, which handles payments for paid plans through Stripe Managed Payments. Stripe is the merchant of record, so it also uses your payment information under its own privacy policy.
- The AI provider you connect, OpenAI or Anthropic, when you use Sprout's Agent or AI features in your apps, so it can do the work you ask.
- The AI app you use, such as ChatGPT, Claude or Cursor, when you ask it to work with Sprout. It processes your conversation under its own terms.
- People using apps, according to whether an app is private or public and the app's own data rules.
- Sprout administrators, in the limited ways described below.
- Authorities and others, when the law requires it or when it is reasonably necessary to protect people who use Sprout, the public or us.
- A buyer or investor, as part of a merger, financing, reorganisation or sale of Sprout or our business, with appropriate confidentiality protections.
Review by Sprout administrators
People at OpenCloud Solutions Limited who run Sprout may open any live app, including private apps, with their own administrator account. They may look at an app's limited logs and read a Sprout Agent conversation in a read-only view. They may also download the protected record of a single Agent run, which can contain conversation text and app code, and each download is recorded. They do this for safety, abuse and security reviews, and to work out why something failed.
This access doesn't let them act as you, send messages, use your AI account, edit your app, see secret values or get round your app's own data rules.
International transfers
Our service providers, Stripe and the AI companies you choose to use may process information outside the UK, including in the United States. Where the law requires it, we protect these transfers with safeguards such as UK adequacy regulations or approved contract terms for data transfers.
How long we keep information
We keep account and app information while your account or app is active and for as long as we need it to provide Sprout. We keep other information for as long as we need it for security, backups, resolving disputes and meeting legal duties.
- One-time sign-in and confirmation links expire.
- Measurements your apps record (custom metrics) are kept for up to 14 days.
- App visitor statistics are kept for up to 366 days.
- Backups, audit records and security records can outlast the data they came from until their own retention period ends. Protection against early deletion can delay final removal from backup storage.
When you delete your account from your preferences, we take your apps offline and then delete your account, your apps and their data, your Agent conversations and your connected AI accounts. We keep a limited set of records, such as security and audit records, where the law or security requires it, and Stripe keeps its own payment records.
Security
We protect information with encrypted connections, credentials that can do only what they need to, separate data for each app, checks on who can open private apps, data rules inside each app, limited and redacted logs and results, and a separate way to enter secrets. No system is completely secure, so we can't promise that information will never be accessed or lost without permission.
Your choices and rights
You can update your name and profile picture, change your email address and delete your account from your preferences. You can manage your apps through Sprout or your AI.
Under UK data protection law, you have the right to:
- ask for a copy of your personal information
- have inaccurate information corrected
- have your information deleted
- receive your information in a format you can take elsewhere
- ask us to restrict how we use it
- object to how we use it
- withdraw your consent, where we rely on it
You may have similar rights under the law where you live.
To make a request, email support@sprout.is with Privacy request in the subject. We may need to check that you control the account before we respond. We will reply within one month, or longer where the law allows. Some information may be kept when we need it for security, fraud prevention, legal duties or to protect other people's rights.
If you're unhappy with how we handle your information, you can complain to the Information Commissioner's Office, the UK data protection regulator, or to the regulator where you live. We'd appreciate the chance to put things right first.
Children
Sprout is not directed to children under 13, and you must be an adult to hold a Sprout account (see our terms). Please don't create an account for a child, or give us a child's personal information, unless you have the legal right to do so and any consent the law requires.
Families can still use Sprout together. A parent or guardian holds the account and is responsible for the apps they build, including apps that family members use. If children will use your app, think carefully about what it collects and whether it suits them.
Changes to this policy
We may update this policy as Sprout changes. We'll show the new date at the top of this page and, where the law requires, tell you in another way too, such as by email.
Contact
Questions and privacy requests: support@sprout.is
Post: OpenCloud Solutions Limited, [registered office to be supplied]
Help with Sprout: Sprout support