Skip to legal content
Sparkle

Legal

Privacy and cookies

How Sparkle handles account data, property photos, AI processing, payments, analytics, diagnostics, support, cookies, and browser storage.

Last updated

1. Controller and scope

BYRDS CONSULTING, 88 rue Armand Silvestre, 92400 Courbevoie, France, RCS Nanterre 982 951 915, is the controller for personal data processed to provide Sparkle. Contact us at contact@byrds.consulting.

This policy applies to sparkle.estate, its dashboard and APIs, account and billing journeys, AI image enhancement, product emails, analytics, diagnostics, and support. Your organisation remains responsible for personal data that it decides to include in listing details or photographs and may itself be a controller for that data.

2. Data we process

Account and authentication

Data
Name, email address, password hash, account ID, session token, session dates, and security metadata.
Source
You and the authentication service operated within Sparkle using Better Auth.

Listings, images, and workspace settings

Data
Listing title, property address, description, uploaded originals, generated and comparison images, filenames, dimensions, image state, watermarks, and uploaded workspace logo.
Source
You, your authorised users, and generated results returned by the AI provider.

AI and usage metadata

Data
Internal user, listing, and image IDs; fixed enhancement prompt; model and quality; generation ID; duration, dimensions, token usage, cost metadata, errors, and warnings. Sparkle does not send the image itself to PostHog analytics.
Source
Your use of the enhancement feature and provider responses.

Billing

Data
Plan, usage period, listing counts, Stripe customer/subscription/checkout/payment identifiers, status, amount, currency, tax, refunds, and invoice-related metadata. Full card details go directly to Stripe.
Source
You, Sparkle usage records, Stripe Checkout, the billing portal, and Stripe webhooks.

Analytics and diagnostics

Data
Sanitised page path, product events, stable account ID for signed-in product analytics, environment, plan, coarse action metadata, device/browser/network data, performance traces, logs, errors, and sampled session replay. Query strings, listing IDs in URLs, filenames, raw image URLs, listing copy, email, and name are removed from PostHog events.
Source
Your browser, Sparkle servers, PostHog, self-hosted Plausible, and Sentry.

Support and product contact

Data
Email address submitted for examples or product news; Crisp chat cookie, account email when signed in, IP address, device data, messages, attachments, and support history when chat is used.
Source
You, your browser, Sparkle, and Crisp.

3. Purposes and legal bases

Provide the Service

Create and secure accounts, store listings and images, generate enhancements, provide downloads, and deliver plan features.
Legal basis
Performance of the contract and steps requested before entering it.

Payments and records

Take payment, administer subscriptions and metered usage, prevent duplicate charges, handle refunds, and keep accounting evidence.
Legal basis
Contract, legitimate interests in reliable billing and fraud prevention, and legal accounting/tax obligations.

Security, reliability, and product analytics

Detect abuse, diagnose failures, monitor performance, understand feature use, measure aggregated traffic, and improve the product. Sentry replay is sampled at 10% of sessions and on errors under the current configuration; text inputs are masked by Sentry defaults, but a replay may still show page interactions and rendered interface state.
Legal basis
Our legitimate interests in operating a secure, reliable, and useful professional service. You may object as described below.

Support and communications

Answer requests, continue a chat, send requested examples, and send infrequent product news.
Legal basis
Contract or legitimate interests for support; consent for optional product emails, which you may withdraw at any time.

Legal claims and compliance

Enforce terms, respond to lawful requests, and establish, exercise, or defend legal rights.
Legal basis
Legal obligation and legitimate interests in protecting Byrds, users, and third parties.

4. AI image processing

When you select Enhance, Sparkle preprocesses the image on its server and sends the resulting image, a fixed real-estate enhancement instruction, requested size and quality, and technical identifiers through Vercel AI Gateway. Routing is restricted to OpenAI, currently using openai/gpt-image-2. OpenAI returns one generated image, which Sparkle validates, resizes, watermarks where required, and stores alongside a comparison image.

Vercel operates the gateway and OpenAI performs inference. Sparkle records the model, provider generation ID, usage, cost, dimensions, latency, and error state. The analytics event contains the fixed instruction and a textual output summary, not the uploaded or generated pixels. See the Vercel AI Product Terms, OpenAI API data controls, and OpenAI privacy policy.

OpenAI states that API content is not used to train its models unless the API customer opts in; Byrds does not opt in. Under the standard provider controls, OpenAI may retain abuse-monitoring logs containing prompts, images, outputs, and related metadata for up to 30 days, longer only where legally required or where content is flagged for safety review. Sparkle does not currently request provider-level Zero Data Retention in application code.

Do not upload images containing people, private documents, access codes, vehicle plates, family photographs, or sensitive information unless this is necessary, lawful, and appropriately disclosed. No solely automated decision with legal or similarly significant effects is made about you; the AI only proposes an edited image for your review.

5. Cookies and browser storage

Sparkle does not use advertising cookies. Authentication and preference storage are necessary to provide the requested service. Audience and product analytics are configured without persistent browser identifiers: Plausible sets no analytics cookie, and PostHog uses in-memory persistence that ends when the page context closes. Other functional or diagnostic storage is listed below.

__Secure-better-auth.session_token

Named better-auth.session_token outside HTTPS production.
Provider and purpose
Sparkle / Better Auth — signed, HttpOnly authentication and session security.
Duration
Up to 30 days, refreshed at most once per day while the account is active; removed on sign-out.
Category
Strictly necessary.

sidebar_state

Provider and purpose
Sparkle — remembers whether the dashboard navigation is expanded.
Duration
7 days.
Category
Functional preference.

sparkle-theme

Provider and purpose
Sparkle local storage — remembers light or dark appearance.
Duration
Until changed or browser storage is cleared.
Category
Functional preference.

crisp-client/*

Provider and purpose
Crisp — binds the browser to a support-chat session and restores message history; not an advertising or cross-site tracking cookie.
Duration
Up to 6 months and renewed when the chatbox loads. A server-side session with no conversation is normally removed after 30 minutes; a conversation and its technical logs may be retained by Crisp for support, security, and legal purposes.
Category
Support functionality.

sentryReplaySession and trace state

Provider and purpose
Sentry session storage — links sampled diagnostic replay and performance events within a browser session.
Duration
Session storage; replay expires after inactivity and is limited to one hour per replay session by the SDK.
Category
Reliability and diagnostics.

Stripe storage on stripe.com

Provider and purpose
Stripe may set security, fraud-prevention, checkout, and preference cookies after you choose to open Stripe Checkout or the billing portal.
Duration
As described by Stripe for the relevant cookie and service.
Category
Payment and security on Stripe's domain.

6. Recipients and providers

We may also disclose data to professional advisers, auditors, insurers, authorities, or courts where necessary and lawful, and to a successor in a merger, financing, restructuring, or sale subject to appropriate confidentiality and notice. We do not sell personal data or use it for behavioural advertising.

Hosting, database, and image storage

Infrastructure managed by Byrds through Coolify and MongoDB Atlas/GridFS stores application data and image files. Access is limited to authorised operations and personnel.
Data
Account, listing, image, settings, usage, billing-reference, and operational data.

Vercel AI Gateway and OpenAI

Route and perform image generation as detailed above.
Data
Prepared image, instruction, requested settings, technical identifiers, generated image, and provider metadata.

Stripe

Provides hosted checkout, recurring and usage billing, tax calculation where enabled, refunds, invoices, fraud prevention, and the billing portal.
Data
Contact and billing details, plan, amounts, tax, payment method, transaction and technical data.

PostHog and self-hosted Plausible

Measure product events and aggregated page traffic under the minimised configurations described above.
Data
Sanitised path and event metadata; stable account ID for signed-in PostHog events; technical audience data for Plausible.

Sentry

Provides error reporting, performance traces, logs, and sampled session replay.
Data
Error and trace context, URLs, device/network details, rendered interface interactions, and masked input state under the configured SDK.

Crisp

Provides the support chat on the production site and receives the signed-in account email to continue the conversation.
Data
Cookie/session ID, email when signed in, IP, device data, messages, attachments, and support history.

7. International transfers

Some providers are established in or may process data from countries outside the European Economic Area, including the United States. Depending on the provider and account configuration, transfers are protected by an adequacy decision such as the EU–US Data Privacy Framework, European Commission Standard Contractual Clauses, and supplementary contractual and security measures. Provider data locations and subprocessors can change; contact us for the current safeguards relevant to your account.

8. Retention

Account and content

Period
While the account is active. A listing and its stored images are deleted when you delete that listing or image. Account-wide deletion is available on request, subject to records we must retain and the normal rotation of protected backups.

Authentication sessions

Period
30 days from creation or renewal, unless revoked or signed out sooner.

AI provider data

Period
Sparkle stores inputs and results as account content. Vercel's gateway layer states that it deletes prompt and output content after inference; OpenAI standard abuse-monitoring logs may be kept for up to 30 days, subject to safety and legal exceptions.

Billing and accounting

Period
Transaction, invoice, and supporting accounting records are kept for 10 years where required by French law. Stripe may keep data for its own payment, fraud, and regulatory obligations.

Leads and product emails

Period
Until unsubscribe or objection, and no longer than three years after the last meaningful contact unless a longer period is required to establish or defend a claim.

Analytics, logs, diagnostics, and support

Period
For the shortest period reasonably needed to compare product trends, secure the Service, diagnose incidents, and keep support context, under provider retention settings that Byrds reviews periodically. Identifiable event data is deleted or anonymised when it is no longer necessary; you may ask for the current configured periods or object to legitimate-interest processing.

9. Security

We use measures appropriate to the risk, including TLS in transit, signed HttpOnly session cookies, origin checks for mutations, access controls, isolated production credentials, restricted provider keys, webhook signature verification, file validation and normalisation, and owner checks before accessing listings or images. No system is perfectly secure; contact us promptly if you believe your account or data has been compromised.

10. Your rights and choices

Subject to applicable law, you may request access, correction, deletion, restriction, and portability of your data, and object to processing based on legitimate interests. Where processing relies on consent, you may withdraw it at any time without affecting earlier lawful processing. You may also define instructions concerning your personal data after death where French law applies.

Email contact@byrds.consulting from the address associated with your account. We may ask for information necessary to verify your identity and protect other users. You may also complain to your local supervisory authority or to the CNIL.

You can delete individual images and listings in the dashboard, sign out to remove the active authentication cookie, clear cookies or site storage in your browser, unsubscribe from optional emails, and object to PostHog, Plausible, Sentry, or other legitimate-interest analytics by contacting us. Blocking strictly necessary storage may prevent account or dashboard features from working.

11. Third-party data in your uploads

If a photograph or listing contains personal data about another person, you are responsible for informing them and establishing a lawful basis where required. Sparkle is designed for property imagery, not biometric identification or decisions about people. Minimise third-party data and avoid uploading people or sensitive details. Contact us if a person asks about data that may only be identifiable through your workspace.

12. Changes and contact

We may update this policy to reflect product, provider, security, or legal changes. The date above identifies the current version. Material changes will be highlighted in the Service or sent to the account email before they take effect where appropriate.

For a privacy request, provider list, transfer safeguard, retention detail, or question, contact BYRDS CONSULTING at 88 rue Armand Silvestre, 92400 Courbevoie, France, or contact@byrds.consulting.