Privacy Policy
SprintGraph LLC ("SprintGraph," "we," "us," or "our") respects the privacy of the people who use SprintGraph.
This Privacy Policy explains how SprintGraph handles personal information when you visit the SprintGraph website, use the SprintGraph web application and workspace, create an account, use a Free or Pro plan, communicate with us, submit feedback, or otherwise interact with services that link to this Privacy Policy (collectively, the "Services").
One of the most important features of SprintGraph's privacy architecture is its local-processing model.
During the ordinary figure-building workflow, research datasets you enter, paste, or import into SprintGraph are processed locally in your browser and are not uploaded to or stored on SprintGraph servers as part of that workflow.
That research dataset is different from account, subscription, communications, analytics, and technical information SprintGraph or its service providers may receive to operate the Services.
1. Who We Are
SprintGraph is operated by SprintGraph LLC, a North Carolina limited liability company based in the United States.
SprintGraph is a browser-based figure-building and data-visualization application designed for researchers and other users who want to create, customize, save, and export figures.
Questions or requests concerning this Privacy Policy may be sent to support@sprintgraph.com.
2. Research Datasets Are Processed Locally in Your Browser
During the ordinary figure-building workflow, research datasets you enter, paste, or import into SprintGraph are processed locally in your browser and are not uploaded to or stored on SprintGraph servers as part of that workflow.
This local-processing architecture applies to tabular data you work with through the SprintGraph workspace, including data entered directly into the grid or imported from supported CSV, TSV, and TXT files.
SprintGraph therefore does not receive a server copy of your research dataset merely because you use it to build or customize a figure.
SprintGraph's analytics are configured so that raw research dataset contents are not transmitted through the analytics system.
The fact that SprintGraph processes research datasets locally does not mean SprintGraph receives no information when you use the Services. SprintGraph may separately receive account information when you register, subscription information when you use Pro, communications when you contact us, product-usage information through analytics, and technical information associated with delivering, understanding, and protecting the online service.
3. Locally Saved SprintGraph Projects
When you use SprintGraph's supported project-saving functionality, saved projects are stored locally in your browser using browser storage, including IndexedDB.
These locally saved projects are not uploaded to SprintGraph servers as part of the ordinary project-saving process.
Locally saved projects contain information SprintGraph needs to preserve and reopen your saved work.
SprintGraph's analytics are configured so that the contents of locally saved SprintGraph projects are not transmitted through the analytics system.
Because these projects are stored on your device rather than in a SprintGraph cloud-storage account, SprintGraph may not possess a copy and may be unable to recover a project that is deleted or lost.
Clearing browser storage, changing devices or browsers, resetting a browser, using privacy or device-management tools, or other actions affecting local browser storage may remove locally saved projects.
If a Pro account returns to the Free plan while more projects are locally saved than the Free plan permits, SprintGraph does not automatically delete those existing projects solely because the subscription ended. SprintGraph may instead restrict the creation of additional locally saved projects while the user remains above the applicable Free-plan limit.
4. Information SprintGraph Receives
The information SprintGraph receives depends on how you interact with the Services.
Account and Authentication Information
If you create a SprintGraph account, SprintGraph and service providers that support account functionality receive information necessary to create, authenticate, secure, and operate the account.
This may include your email address, account identifier, authentication-related information, account status, and records associated with signing into or securing the account.
SprintGraph does not require an account merely to enter the workspace and begin using certain figure-building functionality. An account is currently required for certain features, including exporting or downloading figures and using supported locally saved project functionality.
Subscription and Transaction Information
If you start a SprintGraph Pro trial or become a paid Pro subscriber, SprintGraph receives information necessary to administer your subscription.
This may include your selected plan, subscription status, trial dates, renewal dates, transaction amounts, payment status, billing history, customer or subscription identifiers, and related transaction information.
Payment-card processing is handled through Stripe. Payment information you provide through the Stripe payment process is processed by Stripe in connection with the transaction.
SprintGraph uses subscription and transaction information to provide paid functionality, administer trials and renewals, process and reconcile payments, provide billing support, prevent fraud or abuse, maintain appropriate business records, and comply with legal obligations.
Communications and Support Information
If you email SprintGraph, contact support, respond to us, or otherwise communicate with SprintGraph, we receive the information contained in that communication.
This may include your name, email address, account information, the content of your message, and materials you voluntarily provide.
The local-processing architecture described above does not apply to material you intentionally send to SprintGraph through email, support, a feedback form, or another communication channel.
For example, if you voluntarily send SprintGraph a screenshot, dataset, SprintGraph project file, figure, or other research material as part of a support request, SprintGraph will receive the material you send even though SprintGraph would not ordinarily receive it through the normal figure-building workflow.
Do not send protected health information or similarly highly regulated research information to SprintGraph through support, feedback forms, email, or other SprintGraph-controlled communications unless SprintGraph has entered into a separate written agreement expressly authorizing and governing SprintGraph's receipt of that information.
When possible, use a redacted or synthetic example when requesting support involving sensitive research.
Forms, Surveys, and Feedback
If you submit a form, questionnaire, survey, beta response, product feedback, or similar submission to SprintGraph, we receive the information you choose to provide.
SprintGraph currently uses Tally for certain forms, questionnaires, surveys, and feedback processes. Information submitted through a Tally form may therefore also be processed by Tally in providing that service.
Participation in optional feedback or research activities is voluntary unless otherwise clearly stated.
Information From Social or Other Third-Party Platforms
If you choose to interact with SprintGraph through a third-party platform, SprintGraph may receive information you choose to provide through that interaction, such as your public profile information, name, username, message, or other content.
Your use of those third-party services is also governed by their own privacy practices.
Technical and Service Information
When you access an online service, SprintGraph and providers that help deliver and protect the Services may receive technical information associated with the connection and operation of the service.
This may include information such as IP address, browser or device type, operating system, user-agent information, request information, timestamps, referring or destination pages, general service activity, and security or diagnostic information.
SprintGraph uses technical information to operate and deliver the Services, maintain reliability, understand technical performance, secure accounts and infrastructure, detect or prevent abuse, troubleshoot problems, and comply with legal obligations.
Analytics and Product-Usage Information
SprintGraph uses analytics to understand how its website and product are used, evaluate performance, identify product issues, and improve functionality and user experience.
Analytics may include page views, feature interactions, product events, technical performance information, browser or device information, and similar usage information.
SprintGraph's analytics implementation does not receive:
- raw research dataset contents; or
- the contents of locally saved SprintGraph projects.
SprintGraph also does not use behavioral-advertising technology or session-replay technology inside the figure-building workspace.
5. Information SprintGraph Does Not Receive Through the Ordinary Figure-Building Workflow
During the ordinary figure-building workflow, research datasets you enter, paste, or import into SprintGraph are processed locally in your browser and are not uploaded to or stored on SprintGraph servers as part of that workflow.
SprintGraph also does not receive a server copy of a locally saved SprintGraph project merely because you save the project through SprintGraph's supported local project-saving functionality.
SprintGraph's analytics do not receive the raw contents of those research datasets or locally saved projects.
Information may nevertheless reach SprintGraph if you intentionally transmit it through another channel, such as email, support, a form, or a feature that expressly states that information will be transmitted to SprintGraph or another service.
If SprintGraph introduces a feature in the future that materially changes how research datasets or project contents are processed or stored, SprintGraph will update its disclosures as appropriate.
6. How SprintGraph Uses Personal Information
SprintGraph uses personal information it receives for purposes connected with operating and improving SprintGraph, including to:
- provide and maintain the Services;
- create, authenticate, and secure accounts;
- provide Free and Pro functionality;
- administer trials, subscriptions, renewals, and payments;
- communicate about accounts or transactions;
- respond to questions and support requests;
- operate forms, surveys, and feedback programs;
- understand product usage and technical performance;
- troubleshoot and improve the Services;
- protect SprintGraph, its users, and its infrastructure from fraud, abuse, unauthorized access, or security threats;
- enforce our Terms of Service;
- maintain records reasonably necessary for business, accounting, tax, and legal purposes; and
- comply with applicable law and legal process.
SprintGraph does not use locally processed research datasets for these purposes because SprintGraph does not ordinarily receive those datasets through the figure-building workflow.
If you intentionally provide research material to SprintGraph through support, feedback, or another communication, SprintGraph may use that material only as reasonably necessary to respond to the communication, provide requested support, investigate or troubleshoot the issue, protect service security, or otherwise fulfill the purpose for which you submitted it.
7. How SprintGraph Discloses Information
SprintGraph may disclose personal information to service providers and other parties where reasonably necessary to operate the Services or conduct legitimate business functions.
These recipients may include providers that support:
- account and authentication functionality;
- application and network infrastructure;
- hosting and service delivery;
- payment and subscription processing;
- analytics and performance measurement;
- communications and email;
- forms, surveys, and feedback;
- security, fraud prevention, diagnostics, and troubleshooting; and
- professional services such as legal, accounting, insurance, or auditing.
Current providers include Stripe for payment and subscription processing, Google Workspace for business communications and email, Tally for certain forms and feedback processes, and technical infrastructure providers including Supabase and Cloudflare.
The particular providers SprintGraph uses may change as the Services evolve.
SprintGraph may also disclose information where reasonably necessary to comply with applicable law or valid legal process; respond to lawful government requests; investigate fraud, security incidents, abuse, or violations of our Terms; protect the rights, safety, or property of SprintGraph, our users, or others; or establish, exercise, or defend legal claims.
If SprintGraph is involved in a merger, acquisition, financing, reorganization, sale of assets, or similar corporate transaction, information SprintGraph actually controls may be disclosed or transferred in connection with that transaction as permitted by applicable law.
A business transaction involving SprintGraph does not by itself give SprintGraph possession of research datasets or projects that exist only in users' local browser storage.
8. Payments
SprintGraph uses Stripe to process Pro subscription payments.
When you provide payment information through the subscription process, Stripe processes that information in connection with providing payment services. Stripe's handling of information it receives is also governed by Stripe's own privacy practices.
SprintGraph receives information needed to administer your subscription and account, such as whether a payment was successful, the amount and date of a transaction, applicable subscription or customer identifiers, and other billing or subscription information made available through the payment service.
SprintGraph may retain transaction-related records where reasonably necessary for subscription administration, accounting, tax compliance, fraud prevention, dispute resolution, and legal obligations.
The payment process is separate from SprintGraph's local research-dataset processing. Providing a payment method does not give Stripe or SprintGraph access to the research dataset you are using in the SprintGraph workspace merely because you subscribe to Pro.
9. Browser Storage, Cookies, Analytics, and Similar Technologies
SprintGraph uses local browser storage, including IndexedDB, for functionality such as locally saving supported SprintGraph projects.
Browser storage may persist on your device until it is removed by you, your browser, your operating system, device-management tools, SprintGraph functionality operating locally on your device, or other circumstances affecting local storage.
SprintGraph and its service providers may use cookies or similar browser technologies in connection with authentication, security, preferences, service operation, analytics, or performance measurement.
SprintGraph uses analytics to understand visits to and interactions with the Services and to improve performance and functionality.
SprintGraph does not use behavioral-advertising technology or session replay inside the figure-building workspace, and SprintGraph's analytics do not receive raw research dataset contents or locally saved project contents.
Third-party service providers used on SprintGraph's website or in connection with technical or analytics functions may receive technical or interaction information necessary to provide their services. Depending on the technology, configuration, and provider, other parties may also be able to recognize or process information relating to activity across different websites or services.
Do Not Track and Privacy Preference Signals
Some browsers transmit a legacy "Do Not Track" signal. There is no universally accepted standard governing how websites and online services should interpret that signal.
SprintGraph does not rely on the legacy Do Not Track signal as the mechanism for submitting privacy requests under this Privacy Policy. You may contact support@sprintgraph.com regarding a privacy request.
Some jurisdictions recognize specific opt-out preference signals, such as Global Privacy Control, for particular forms of processing. Where applicable law requires SprintGraph to recognize and honor such a signal for a particular processing activity, SprintGraph will do so as required by law.
10. Sale, Sharing, and Advertising
SprintGraph does not sell or monetize your raw research dataset or locally saved SprintGraph project contents. SprintGraph ordinarily does not possess those materials through the figure-building or local project-saving workflow.
SprintGraph does not use behavioral-advertising technology inside the figure-building workspace.
SprintGraph may disclose other technical, account, transaction, communication, or interaction information to service providers and other parties for the purposes described in this Privacy Policy.
Some privacy laws use terms such as "sale," "sharing," or "targeted advertising" to cover certain advertising or cross-site data practices even where personal information is not sold for money. Where such a law applies to SprintGraph and gives you an applicable right to opt out of a particular practice, SprintGraph will provide and honor that right as required.
11. Data Retention
SprintGraph retains information it actually receives for as long as reasonably necessary for the purposes described in this Privacy Policy, taking into account the nature of the information, why it was collected, applicable legal requirements, security and fraud-prevention needs, accounting and tax obligations, dispute-resolution requirements, and the need to establish or defend legal claims.
Different categories of information may therefore be retained for different periods.
For example, SprintGraph may retain account information while an account is active and for an appropriate period afterward; transaction and subscription records as necessary for accounting, tax, payment, and legal requirements; support communications for as long as reasonably useful for support, product, security, or legal purposes; and analytics, security, or technical records for periods appropriate to their operational purposes.
SprintGraph does not control retention of locally saved SprintGraph projects in the same manner because those projects are stored in your browser rather than on SprintGraph servers.
Similarly, SprintGraph cannot delete a server copy of a research dataset that SprintGraph never received.
Information processed by SprintGraph's service providers may also be retained according to their contractual roles, legal obligations, and applicable practices.
12. Your Privacy Choices and Requests
You may contact SprintGraph at support@sprintgraph.com if you want to ask about personal information associated with you, request correction of information SprintGraph maintains, request deletion of information, or raise another privacy concern.
SprintGraph will respond to privacy requests as required by applicable law and may take reasonable steps to verify the identity or authority of the person making a request before acting on it.
Certain information may need to be retained even after a deletion request where retention is permitted or required for payment records, tax or accounting compliance, security, fraud prevention, legal obligations, dispute resolution, or establishing or defending legal claims.
Research datasets and locally saved projects that exist only in your browser are managed through your local SprintGraph workspace, browser, and device rather than through SprintGraph's server-side privacy-request systems.
Depending on where you live and which privacy laws apply to SprintGraph, you may have additional rights concerning personal information, such as rights to access, correct, delete, obtain, or opt out of particular forms of processing. SprintGraph will honor those rights when applicable law requires it.
13. Children's Privacy
SprintGraph is a general-audience research and productivity service and is not directed to children under 13.
Children under 13 should not use SprintGraph or provide personal information to SprintGraph.
SprintGraph does not knowingly seek to collect personal information from children under 13.
If SprintGraph learns that it has collected personal information from a child under 13 in circumstances requiring parental consent under applicable law and no valid consent applies, SprintGraph will take appropriate steps to delete the information or otherwise comply with applicable requirements.
A parent or legal guardian who believes a child under 13 has provided personal information to SprintGraph may contact support@sprintgraph.com.
14. Sensitive, Health, and Regulated Information
The standard Services are not offered as HIPAA-compliant services.
Users must not use SprintGraph in a manner that requires SprintGraph to act as a HIPAA business associate unless SprintGraph has separately entered into an appropriate written agreement governing that use.
The ordinary SprintGraph figure-building workflow is designed so that research datasets remain in the user's browser rather than being transmitted to SprintGraph as part of that workflow.
Users are responsible for determining whether their local use of SprintGraph is appropriate under laws, institutional policies, research protocols, contracts, data-use agreements, consent requirements, or other obligations applicable to their work.
The local-processing model does not extend to information you intentionally send to SprintGraph.
Do not send protected health information or similarly highly regulated research information to SprintGraph through support, feedback forms, email, or other SprintGraph-controlled communications unless SprintGraph has entered into a separate written agreement expressly authorizing and governing SprintGraph's receipt of that information.
When possible, use a redacted or synthetic example when requesting support involving sensitive research.
If you work with sensitive data, you are responsible for taking appropriate steps to de-identify, redact, secure, or otherwise protect information where required by your obligations.
15. Security
An important part of SprintGraph's privacy and security architecture is data minimization.
During the ordinary figure-building workflow, research datasets you enter, paste, or import into SprintGraph are processed locally in your browser and are not uploaded to or stored on SprintGraph servers as part of that workflow.
SprintGraph also configures its analytics so that raw research dataset contents and locally saved project contents are not transmitted through the analytics system.
No online service, device, browser, transmission method, or storage system can be guaranteed to be completely secure. You are responsible for taking reasonable steps to secure your device, browser, accounts, credentials, and locally stored SprintGraph projects.
Additional information about SprintGraph's local-processing and security practices is available on SprintGraph's Security page.
16. International Users
SprintGraph LLC is based in the United States.
If you access SprintGraph from outside the United States, personal information SprintGraph actually receives may be processed in the United States and in other locations where SprintGraph's service providers operate, subject to applicable law.
SprintGraph's availability in a country does not by itself mean that SprintGraph represents that the Services have been specifically designed for every legal or regulatory regime in that country.
Where an applicable privacy law gives you rights and applies to SprintGraph's processing of your personal information, SprintGraph will handle those rights as required by that law.
17. Third-Party Websites and Services
The SprintGraph website or Services may contain links to third-party websites, services, or resources.
SprintGraph does not control the privacy practices of independent third parties. Information you provide directly to another company is subject to that company's privacy practices.
This Privacy Policy does not apply to an independent third-party service merely because SprintGraph links to it.
18. Changes to This Privacy Policy
SprintGraph may update this Privacy Policy as the Services, our practices, or applicable law changes.
When we update the Privacy Policy, we will change the effective date shown at the top of the policy.
If a change is material to how SprintGraph handles personal information, SprintGraph will provide additional notice where appropriate or required by law, such as through the Services, by email, or through another reasonably conspicuous method.
SprintGraph will not rely on this section to retroactively make materially different use of personal information where doing so would be unlawful or inconsistent with promises applicable to information already collected.
19. Contact Us
If you have questions, requests, or concerns about this Privacy Policy or SprintGraph's privacy practices, contact:
SprintGraph LLC
North Carolina, United States
support@sprintgraph.com
