Privacy Policy
Last updated: 14 March 2026
Overview
Orca Family Trust (ABN 64 765 430 829), trading as Sprigr ("Sprigr", "we", "us") operates sprigr.com, Sprigr Search, and Sprigr Team. This policy covers how we handle your data.
Information we collect
Account information
When you create a Sprigr account we collect your name, email address, and authentication credentials. If you sign in via Google OAuth, we receive your name, email address, and profile picture from Google. We do not receive or store your Google password.
Usage data
We collect API request logs (timestamps, endpoints, response codes), search query metadata (query length, result counts, latency), and page views. We do not log search query content or data stored in your indexes.
Payment information
Payments are handled by Fat Zebra. We don't store credit card numbers or bank details. We keep transaction records (amounts, dates, plan details) for billing.
Data you store with us
Sprigr Search stores JSON objects in search indexes. Sprigr Team stores conversation history, knowledge bases, and agent config. This data is yours. We don't access or use it for anything other than running the service.
How we use your information
- To provide, operate, and maintain our services
- To process transactions and send billing notifications
- To respond to your enquiries and support requests
- To monitor and improve service performance and reliability
- To detect and prevent fraud, abuse, or security incidents
- To comply with legal obligations
We don't sell your data. We don't use it to train models. No ads.
Data storage and security
Data is stored on dedicated edge infrastructure. All connections use TLS. Sprigr Team uses a dedicated database per company, isolated at the infrastructure level.
API keys are hashed before storage. OAuth tokens and secrets are encrypted at rest.
Data retention
Account data is kept while your account is active. If you delete your account, we delete your data within 30 days, except where law requires retention (e.g. billing records for tax).
API request logs are kept for 90 days, then deleted.
Third-party services
We use these third-party services:
- Edge infrastructure provider - Infrastructure, hosting, DNS
- Google - OAuth authentication
- Anthropic - AI models for Sprigr Team
- Fat Zebra - Payment processing
We share the minimum information needed for each service to work.
Your rights
You have the right to:
- Access the personal information we hold about you
- Request correction of inaccurate information
- Request deletion of your account and associated data
- Export your stored data (search indexes can be exported via the API)
- Withdraw consent for optional data processing
EEA residents have additional rights under GDPR. Australian residents have rights under the Privacy Act 1988. See the OAIC for more info.
Cookies
sprigr.com doesn't use tracking cookies or third-party analytics. We use one session cookie (sprigr_session) for authentication when you're signed in.
Children’s privacy
Sprigr is not for children under 16. If you think a child has given us personal information, contact us and we'll delete it.
Changes to this policy
We may update this policy. We'll notify you of material changes by email or on the website.
Contact
Questions about this policy or your data:
Orca Family Trust (ABN 64 765 430 829), trading as Sprigr
Gold Coast, Queensland, Australia