Sparrowkeep Privacy Policy
Effective date: August 31, 2026
Sparrowkeep is operated by Jaigirdar Capital LLC, a Pennsylvania limited liability company ("Sparrowkeep," "we," "us"). Sparrowkeep exists to hold your family's most important information, so we take privacy seriously and we've written this policy in plain English. If anything here is unclear, email us at hello@sparrowkeep.com and a person will answer.
The short version: We collect only what we need to run the service. Your vault contents are encrypted at rest and our staff does not read them. We never sell your personal information, and we don't run ads.
What we collect
Account information. Your name, email address, password (stored in hashed form — we can't see it), your phone number and mailing address if you choose to provide them (both are optional, and we use them only to contact you about your own account — never for marketing), and the names and email addresses of the keyholders you designate.
Vault contents. The information you choose to enter: where your accounts are held, insurance policies, locations of legal documents, key contacts, personal wishes, and anything else you add. You decide what goes in. Vault contents are encrypted at rest, and our staff does not access or read them except in the rare case that you explicitly ask us to for support and grant permission.
Payment information. Payments are processed by Stripe. Your card number goes directly to Stripe and never touches our servers or our database. We receive only confirmation of payment, the last four digits of your card, and billing details Stripe shares for receipts and refunds.
Chat transcripts. If you use our AI chat assistant, we keep the conversation so we can improve support and follow up if you ask us to. If you give the assistant a phone number for a callback, we store that number for the purpose of calling you back.
Technical information. Basic logs and analytics: IP address, browser type, pages visited, and timestamps. We use this to keep the service secure and working, not to build advertising profiles.
What we do NOT collect or do
- We do not sell your personal information, and we have not sold it in the past. Ever, to anyone.
- We do not show ads or share your data with advertisers.
- We do not read your vault contents.
- We do not knowingly collect information from anyone under 18. Sparrowkeep is not directed at children. If you believe a minor has created an account, contact us and we will delete it.
How we use your information
We use your information to: provide and maintain the service; process your purchase and any refund; send transactional emails (receipts, security alerts, emergency-access notifications — these are part of how Sparrowkeep works and can't be fully opted out of while you have an account); respond to support requests, including callbacks you request; run the emergency-access process you configure; keep the service secure and prevent abuse; and comply with legal obligations.
Service providers (our "processors")
We use a small number of companies to run Sparrowkeep. They process data on our behalf, under contracts limiting what they can do with it:
- Stripe — payment processing.
- Supabase — authentication and database hosting (where your encrypted vault lives).
- Anthropic — powers the AI chat assistant. Chat messages you send to the assistant are processed by this provider to generate responses. Don't put sensitive vault details into chat; the chat is for questions about using Sparrowkeep.
- Resend — sends transactional email (receipts, notifications, emergency-access alerts).
We may also disclose information if required by law (for example, a valid subpoena), to protect the rights and safety of our users or others, or in connection with a sale or reorganization of our business — in which case this policy would continue to apply to your data and we would notify you.
Emergency access and your keyholders
If a keyholder you named requests emergency access, we email you immediately and start the waiting period you chose (7–30 days; 14 by default). If you cancel the request, nothing is shared. If the waiting period passes without cancellation, that keyholder receives read access to your vault. This sharing happens only because you set it up — you control who your keyholders are and how long the waiting period is.
Encryption and security
Vault contents are encrypted at rest. Data moving between your browser and our servers is encrypted in transit (TLS). Access to production systems is restricted and logged. No system is perfectly secure, and we can't promise absolute security — but protecting this data is the core of our product, not an afterthought.
If a breach happens: if we learn of a data breach affecting your personal information, we will notify you without unreasonable delay, consistent with applicable state breach-notification laws, and tell you what happened and what we're doing about it.
Cookies
We use minimal cookies: session and authentication cookies needed to keep you logged in, and basic analytics as described above. We do not use third-party advertising cookies or cross-site tracking. Because we don't track you across other sites, there's nothing for a "Do Not Track" signal to turn off — but where state law treats such signals (like Global Privacy Control) as an opt-out request, we honor them.
Retention
We keep your account and vault data as long as your account is active. If you delete your account, we delete your vault contents and personal information within 30 days, except for records we're required to keep (like payment records for tax purposes) and short-lived backups, which are purged on a rolling basis within 90 days. Chat transcripts are kept for up to 24 months and then deleted or de-identified.
Your rights
No matter what state you live in, you can:
- Access and export your data. You can export your vault contents at any time from your account.
- Correct anything that's inaccurate (you can edit your vault directly).
- Delete your account and data, from your account settings or by emailing us.
We will not discriminate against you for exercising any privacy right.
California residents (CCPA/CPRA)
If you live in California, you have the right to know what personal information we collect, use, and disclose (it's what this policy describes); to access, correct, and delete it; to receive a portable copy; and to opt out of the "sale" or "sharing" of personal information. We do not sell or share your personal information as those terms are defined in California law, and we do not use or disclose sensitive personal information for purposes beyond providing the service you asked for. In the past 12 months we have collected the categories described in "What we collect" and disclosed them only to the service providers listed above. To exercise your rights, email hello@sparrowkeep.com. You may use an authorized agent; we'll verify the request by confirming control of the account email. If we decline a request, you may appeal by replying to our decision.
Other state privacy rights
Residents of Colorado, Connecticut, Virginia, Texas, Oregon, and other states with comprehensive privacy laws have similar rights of access, correction, deletion, and portability, and the right to opt out of targeted advertising, sale, and certain profiling. We don't do targeted advertising, selling, or profiling of that kind, so there's nothing to opt out of — but the other rights work as described above, including a right to appeal a refused request.
Changes to this policy
If we change this policy, we'll post the new version here with a new effective date, and for material changes we'll email you before they take effect. We will never change this policy to permit selling your personal information.
Contact us
Jaigirdar Capital LLC — 1260 Fuller St, Philadelphia, PA 19111 — hello@sparrowkeep.com