Privacy
Effective 18 October 2026. (Changed from the 7 October version: sections on which tools you use and how you found Spryloom, and Discord added to the providers.) This says what Spryloom stores, why, where, and how to get it removed. It is written to be read, not skimmed past. If something here is unclear, write to hello@spryloom.com.
Spryloom is two things: this website, and the platform that runs the apps people publish. They store different things, so they are described separately.
In short
What personal data we collect. Your email address. The email addresses of people you invite. A record of what each person did (signing in, inviting, publishing), and which tools they did it with (which version of spry, which coding agent, how it was installed). The apps and pages you publish, with whatever is in them, and the output your app writes to its logs. What people save in a page that saves data, with who saved each record and when. On this website, Google Analytics data only if you accept it.
What we use it for. To sign you in. To decide who may open each app. To build, run and store what you publish. To send sign-in, invitation and notification emails. To keep a record of who did what in each workspace. To help when something breaks. We do not sell it, use it for advertising, or train AI models on it.
Who receives it. The providers that run the service, each holding only what its part needs: Fly.io, Neon, Tigris, Postmark, Vercel and Cloudflare, plus Google Analytics on this website if you accept. They are listed under Where it lives, below. Nobody else.
How long we keep it.
| What | How long |
|---|---|
| Your account (email address and workspace) | Until you ask us to delete it |
| A sign-in link | 10 minutes, or until it is used |
| A terminal's sign-in | 90 days |
| A browser session for one app | 30 days |
| An invitation link | 7 days |
| An app or page, its versions, its database and its secrets | Until you delete it, or ask us to |
| A folder uploaded to publish | Deleted when the publish finishes |
| Notifications an app sends | 30 days |
| A record saved in a page | Until the person who saved it, or the page's owner or admins, deletes it, or the page is deleted |
| The history of changes to a page's records (who changed which record, and when) | 90 days |
| Records in a list a page no longer declares | 30 days, then deleted |
| A page's saved records once it becomes an app | Copied into the app's own database; the page's copy is kept 30 days, then deleted |
| The audit log | For the life of the workspace |
Your controls. You can delete an app with spry delete, export a page's saved data with spry data export if you own it or are an admin, and ask us for a copy of your data, a correction, or the deletion of your account, as described under What you can ask for, below. On this website, you can accept or reject analytics and change your mind at any time.
The rest of this page gives the detail.
This website
spryloom.com asks before it uses Google Analytics. Until you choose Accept, nothing from Google is loaded and no analytics cookie is set. If your browser sends the Global Privacy Control signal, we treat that as Reject and do not ask.
If you accept, Google Analytics sets cookies in your browser and sends Google the pages you view, your browser and device, roughly where you are, and how you arrived. We use it only to understand how the website is read. Google signals and ad personalisation are turned off, and nothing is sold or shared for advertising. It is on this website only: the platform, the dashboard, and the apps people publish run no analytics.
You can change your mind at any time with Cookie settings at the bottom of every page. Rejecting after accepting stops the measurement and removes the analytics cookies. The site works the same either way.
The site also keeps two choices in your browser, stored by the page itself and never sent anywhere: whether you chose the light or dark theme, and your cookie choice.
The site is served by Vercel, which keeps ordinary web server logs (your IP address, browser, and the pages requested) for a short period to run and secure the service. We do not receive or use them.
The platform
When you sign in to Spryloom, publish an app, or open an app somebody shared with you, this is what exists about you.
Your email address
It is your account. There is no password. Sign-in is a link sent to that address, and it decides the workspace you belong to. When your domain's email runs on a business mail service such as Google Workspace, Microsoft 365 or Zoho Mail, everyone at acme.com is in the acme-com workspace; to tell, we look up where the domain's mail is delivered, which is public. Any other address, including a personal one such as Gmail, gets a workspace of its own, keyed on the whole address, never shared with other people at the same provider.
Sign-in tokens and sessions
A sign-in link carries a token that exists in plain text only between the click and its use, and is deleted at whichever comes first: use or expiry. A terminal token stops working after ninety days. A session in the browser is scoped to one app; signing in to one app grants nothing on another.
The audit log
Every sign-in, invitation, role change, publish, and administrative action is written to an audit log with who did it and when. The log is append-only: nothing in the product changes or deletes an entry. It exists so that a coworker can trust an app somebody else built, and so that we can answer the question "who did what" after the fact. It is kept for the life of the workspace.
Your app, and what it stores
When you publish, we receive the folder you publish: the code, the manifest, and whatever else is in it. We build it, run it, and keep each version so you can roll back. If your app declares a database, it is given one of its own, with its own role, that no other app can reach. We do not read inside your app's database. It is your data and your coworkers' data, and the app is the only thing that touches it.
We do not use your code, your app's data, or your coworkers' data to train AI models.
When you invite somebody, we store their email address so that we know they may open the app, and we send them one email saying so.
What a page saves
A page can declare lists, and its own scripts can save records to them: a checklist, a sign-up sheet, an equipment checkout. Spryloom keeps those records, separately from the page's files and from every app's database, in a database that only its own service reaches.
- Each record is stamped by Spryloom with who saved it and when, taken from their sign-in. The page can't set or change either.
- Who can read it is what the page declares: everyone who can open the page, or only the person who saved it (and the page's owner and admins).
- Who can change or delete it: the person who saved it, and the page's owner and admins.
- Agents. Someone's coding agent can read a page's records as that person, and add or change only records that person saved. Every change is in the page's history, marked as made by an agent.
- We do not read it. No part of the product shows a page's records to anyone at Spryloom. Direct access to that database is for emergencies, and every use is recorded.
- When your account is deleted on request, records you saved in other people's pages stay, because they are those pages' content, but your address is replaced with "a former member" in them and in their history.
Secrets
A value you set as a secret is encrypted at rest, bound to the one app it belongs to, injected when the app starts, and never shown back to anyone, including you. There is no command that reads one.
Which tools you use
When you run spry, or a coding agent uses Spryloom's tools for you, spry says on each request how it is being used: its version, whether it was a terminal command or an agent's tool, which coding agent ran it (for example Claude Code, Codex or Cursor) when that agent identifies itself, how spry was installed (for example the Claude plugin or npx), and your operating system. It works this out from the names of a short, fixed list of settings that coding agents are known to set, and from where spry is installed. It never sends the values of those settings, a file path, your code, or anything about your project. We keep one line per person, tool and day, so we know which agents and installs to support and test. It is kept for the life of the workspace.
How you found Spryloom
After your first sign-in, the page in your browser asks, once, how you found Spryloom. Answering is optional, skipping it counts as an answer, and anything you type in the box is kept as you wrote it. We keep the answer with your email address to learn which places bring people to Spryloom.
Logs
We keep your app's own output, so you can read it with spry logs and so we can help when something breaks. Secrets never appear in logs; the platform refuses to write an entry containing one.
Where it lives
The platform runs on the following providers, each of which holds only what its part needs.
| Provider | What it holds |
|---|---|
| Fly.io | Your app's running code, in a machine of its own |
| Tigris | Pages you publish, and a folder you upload while it is being published |
| Neon | Your app's database, in a project of its own; and what pages save, in a separate project of its own |
| Postmark | The sign-in and invitation emails it sends, and their delivery records |
| Vercel | This website |
| Google Analytics | Visits to this website, only if you accept, as described above |
| Cloudflare | DNS for spryloom.com, and its traffic as a proxy |
| Discord | Notices to the Spryloom team about sign-ups, publishes, failed publishes and invitations, with the email addresses and app names involved, in a private channel only the team can read |
Nothing is sold, shared for advertising, or given to anyone else. We use these providers to run the service and for no other purpose.
What you can ask for
- A copy of your data. Release 1 has no export command. Ask, and we will give you a dump of your app's database and a copy of every version of the app.
- Deletion. Archive an app and its data is kept so the app can be restored. Ask for deletion and the app, its versions, its database, and its secrets are removed. Your account is removed on request too. Audit log entries that record what you did are kept, because they are the record for the other people in the workspace.
- A correction. If something about you is wrong, tell us and we will fix it.
Write to hello@spryloom.com. Expect a reply within a few days; this is a small team.
Security
The security model is on the homepage, and each claim on it is checked by a script that tries the attack. If you find something that page gets wrong, write to security@spryloom.com. We will answer, and we will not pursue anyone who reports a problem in good faith.
Children
Spryloom is for people at work, and is not directed at anyone under sixteen. We do not knowingly hold data about children.
Changes
If this page changes in a way that matters, everyone with an account is told by email before it takes effect. The date at the top is the date it last changed.