SproutOS

Legal

Privacy Policy

What we collect, where it goes, and how long we keep it.

Last updated 24 August 2026 · Ur LLC, 1617 Washtenaw Ave, Ann Arbor, Michigan 48104, United States

Who is responsible

Ur LLC, 1617 Washtenaw Ave, Ann Arbor, Michigan 48104, United States, is the controller of the personal data described here. Questions and requests go to legal@sproutos.me.

What we collect about you

Account information. Your name, email address and avatar, from GitHub or Google when you sign in. We store an identifier from that provider so we recognise you next time, and an access token so we can act on repositories you have authorised. Tokens are encrypted at rest.

Billing information. Purchases, credit balance and usage. Card details are handled by Stripe and never reach our servers.

Usage records. Metered consumption per project — compute time, stored bytes, queue memory, search and transfer — which is what your bill is computed from.

Audit records. Security-relevant actions: signing in, revealing a secret, changing permissions, deleting a project. These include the IP address and browser the action came from.

What we hold on your behalf

Your source code, your databases, your queues, your search indexes and your uploaded files. We process these to run your projects. We do not read them except where we must to operate the service or where you ask us to — for example when an agent modifies your code.

If your users’ personal data ends up in a database we host, you are its controller and we are your processor. You are responsible for having a lawful basis to hold it.

Where your data physically is

United States. Our control-plane database, your applications when they run, object storage, and the cache that routes requests.

France. Tenant search indexes, tenant queues, and runtime logs, on a machine we rent. Data therefore crosses between the United States and the European Union in normal operation.

Elsewhere, if you choose it. Selecting a model provider for the agent features sends code to that provider’s infrastructure under their terms.

Runtime logs

Output from your running applications is collected so you can search it in your dashboard. It is kept for three days and then deleted automatically. If your application logs personal data, that is what will be stored — the three-day limit exists partly for that reason.

How long we keep the rest

Account and billing records are kept while your account exists and afterwards for as long as tax and accounting law requires. Audit records are kept for the same reason.

Project data is deleted when you delete the project, and 48 hours after your credit runs out — see the Terms for exactly how that works.

Who else sees it

Stripe processes payments. Amazon Web Services and OVH provide infrastructure. GitHub and Google provide sign-in. Anthropic, OpenAI or OpenRouter receive code when you use the agent features. Amazon Simple Email Service delivers our email.

We do not sell your data, and we do not use it to train models.

Your rights

You can ask for a copy of your data, correct it, or have it deleted. The dashboard exports your data and deletes your projects without needing to ask us. For anything it does not cover, write to legal@sproutos.me and we will respond within 30 days.

If you are in the European Union or the United Kingdom you may also complain to your data protection authority. If you are in California you have rights under the CCPA, including the right not to be discriminated against for exercising them.

Cookies

We set a session cookie when you sign in, and short-lived cookies during sign-in to prevent request forgery. That is all — no advertising or analytics cookies.

Security, and its limits

Credentials are encrypted at rest and connection secrets are stored as one-way hashes where the protocol permits it, so a database leak does not yield anything usable. Access between tenants is mediated by proxies that check ownership on every request.

No system is perfectly secure. If we discover a breach affecting your personal data we will tell you and the relevant authority within the time the law requires.

Children

SproutOS is not intended for anyone under 16, and we do not knowingly collect their data.

Changes

We will post changes here and update the date at the top, and tell you before a material change takes effect.