SprigaSpriga

Privacy Policy

Spriga works with a real credential to a real account, so privacy is not a formality here. This page describes what we collect, where it lives, and how to make it disappear.

1. What we collect

Your Spriga account: email address and a password (stored as a salted hash — never in plain text), or your Google account email if you sign in with Google.

No Instagram credential. Spriga never asks for and cannot accept your Instagram password or session. The handle you ask us to promote is a public username, and everything we read about it and about the posts we target is public information.

Promotion data: the handle you promote, your targeting (the accounts and keywords you name), the comment lines we may post, the public posts we selected, the orders we placed and what was confirmed delivered. This is what powers your dashboard.

Public third-party data: to find posts worth commenting on we collect public post URLs, public engagement counts, and the public usernames of people who commented on them. We do not collect private accounts, private posts, direct messages, or contact details.

Billing: payments are handled by Stripe. We never see or store your card number; we keep your Stripe customer reference, whether a card is saved, your credit balance and its full transaction history.

Ad attribution: if you arrive from one of our ads, the click identifier in the link (fbclid) and the landing path are recorded once against your account.

Advertising:Meta’s pixel runs on this site. It sets a cookie in your browser and tells Meta which Spriga pages you viewed, so we can advertise to people who have visited us. See section 6.

2. How we use it

Only to run the service: finding posts that match your targeting, writing and placing the promo comments, charging credits as comments are confirmed delivered, showing your results, and sending the account and billing emails described below. We do not sell your data.

One exception to the advertising point, stated plainly: when you start a checkout or complete a purchase we send Meta a hashed record of that event so we can measure which ads work. It contains a one-way hash of your email address and the purchase value — never your name, your handle, or anything you promote.

3. Who processes it

Your data is stored on Convex, our backend platform. We rely on a small set of processors, each receiving only the minimum needed for its role:

  • Convex — database, backend and file storage.
  • Stripe — payments and card storage. Your card details go to Stripe directly and never reach us.
  • Brevo — transactional email (verification, password reset, and the wallet and payment notices).
  • Apify — collects the public Instagram data we use to find posts to comment on. It receives the handles and keywords you targeted, not your identity.
  • Google (Gemini) — writes the draft comment lines for your niche. It receives your promoted handle, your niche keywords and any context you type into the comment settings.
  • Our delivery partner — the third-party service whose accounts actually post the comments. It receives the target post link and the comment text, and nothing about you.
  • Meta — where ad measurement is enabled, receives the hashed purchase events described above, and, through its pixel, the pages you visit on Spriga, so we can show ads to people who have visited the site.
  • Sentry — where error reporting is enabled, receives technical error reports. Identifiers and secrets are stripped before sending.

4. Retention and deletion

Deleting a promotion removes its targeting, discovered posts, mined public usernames and delivery history. Deleting your account, from Settings, removes everything: your promotions and their data, your credit balance and ledger, your billing profile, and your login. It cannot be undone, and any remaining credits are forfeited.

Accounts that never verify their email address are removed automatically after 7 days. Payment records may be retained by Stripe where bookkeeping law requires it, and anonymous counts we keep for our own metrics contain no personal data.

5. Your rights

Wherever you live — and specifically under the GDPR if you are in the EU/EEA — you can ask us to access, correct, export or erase your personal data, or object to how it is processed. Deletion you can do yourself from Settings; for anything else, email support@spriga.co and we will respond within 30 days. You also have the right to complain to your local data-protection authority.

If you believe a Spriga comment mentions or targets you without your agreement, write to the same address and we will stop it.

6. Cookies

We use the cookies required to keep you signed in to Spriga, and Meta’s advertising cookie (_fbp), which is set when you visit the site so that we can show ads to people who have been here before. It is set on arrival, without asking you first.

The fbclid attribution described above is separate: it is stored against your account, not in a browser cookie.

7. Changes to this policy

If we change what we collect or who processes it, we will update this page and notify you by email or in the app before the change takes effect.

Last updated: 17 August 2026.