Privacy Policy
Updated 25 September 2026. Controller: Väder AB, Sweden.
01
Who we are
Väder AB, Sweden (“Sprid”, “we”, “us”), provides Sprid’s websites, apps, downloadable tools and connected services. Contact us about privacy at hello@sprid.studio.
We are the controller of personal data used to manage our customer relationship, billing, service security and our own usage analysis. Where we handle personal data in a customer’s workspace on their instructions, we act as a processor. The customer determines that use, as explained in section 06b.
02
Information we collect
Depending on the features you use, we collect:
- Account and contact details: email, display name, sign-in identifiers, authentication records, workspace membership and messages you send us.
- Content and instructions: uploaded or generated media, drafts, captions, prompts, schedules, settings and instructions submitted by you or an authorised integration.
- Connected-service data: access credentials, account and channel identifiers, profile information, publishing status, comments, Instagram direct messages, reviewer names, review text, campaign information and performance reports.
- App reporting: store, website, product, search and revenue information from services you connect. This may include usage and transaction records needed to calculate reports, as well as aggregate totals. We do not collect your customers’ full payment card numbers.
- Usage and diagnostics: features and commands used, timestamps, IP address, browser and device information, request and error details, performance measurements and account or workspace identifiers.
- Billing: billing contact details, plan, purchase, invoice and payment-status information. Payment providers handle full card details; Sprid does not store them.
Sources are you, people authorised in your workspace, your device, sign-in providers and connected services. Comments and reviews may contain information about people who do not have a Sprid account. Providing account and billing details is necessary for the corresponding service; connections and uploaded content are optional, but the associated features need them.
03
Limits on use
We do not sell personal data or share it for cross-context behavioural advertising. We do not use workspace content or connected-platform data to train our own AI models. We do not build advertising profiles of commenters or reviewers. Connected data is used for the requested features, subject to platform restrictions.
04
Purposes and legal bases
Where Sprid is the controller, we use personal data on these bases:
- Contract: to provide your account and requested features, process payments and communicate about the Service.
- Legitimate interests: to administer business customer relationships, support users, protect the Service, prevent abuse, diagnose faults, understand usage and improve the product. We consider the impact on your rights when relying on these interests.
- Legal obligations: to keep required financial records and respond to lawful requests.
- Consent: where required for optional communications or processing. You may withdraw it at any time without affecting the lawfulness of earlier processing.
Authorising a connection gives us permission to access that service; it does not mean that every subsequent use relies on GDPR consent. For Customer Data, we follow the customer’s instructions and the data processing terms.
05
Automated features
AI may help prepare content, classify comments and produce summaries or recommendations. Relevant content and context are processed for those features. You should review results before acting on them. We do not use these features to make decisions about individuals that produce legal or similarly significant effects.
06
Connected platforms
We use data from connected platforms to identify your account and provide the publishing, comments, advertising and reporting features you request. This may involve account identifiers, profile details, post and video information, comments, statistics and campaign data. We do not use that data for unrelated profiling, data brokerage, surveillance, eligibility decisions or AI model training.
You can disconnect a channel in Sprid and revoke permission in the platform’s settings. Disconnecting stops new access using that connection; it does not automatically erase all reporting history or content you supplied. Platform-specific deletion requirements still apply. You can request deletion at our data deletion page.
Instagram, Facebook, TikTok, LinkedIn and X. We process the connected account’s profile, submitted content and available performance data. Where supported and authorised, we process comments, replies and advertising information. If you connect Instagram messaging, we store direct-message conversations so you can read and answer them in your Inbox. TikTok publishing requires your choices in the publishing flow. Each platform also processes data under its own terms and privacy policy.
YouTube and Google. Sprid uses YouTube API Services to identify your channel, upload videos you submit, read and answer comments, and report video performance. Use is subject to the YouTube Terms of Service; Google’s handling is described in the Google Privacy Policy. Google Ads connections support the campaigns you request.
YouTube comment text is retained for up to 30 days. Public statistics and permitted derived metrics are retained for up to 36 months under the applicable additional YouTube terms; our own calculations are identified as such. Other stored API data is subject to YouTube’s applicable refresh or deletion requirements. You can revoke Google access at Google security settings. Requests to delete YouTube data, including account deletion, require erasure within 7 calendar days; this takes precedence over the general account recovery window. Deleting data held by Sprid does not delete it from YouTube.
Pinterest. We use the authorised account’s profile and boards, including secret boards you own, to let you choose destinations, create boards and publish Pins you request. We read Pin analytics for reporting. Manage access in Pinterest’s connected-app settings, or request deletion through the page above.
06b
Personal data in customer workspaces
A customer controls the purposes for personal data they submit or connect, including comments, reviews and app reporting. Sprid processes that data to provide the features they request. Our binding processing obligations, including confidentiality, security, assistance, sub-processors and deletion, are in section 09b of the Terms.
If your data appears in a customer’s content or connected reporting, contact that customer to exercise your rights. You may also contact us; we will help route the request and assist the customer as required. We do not use that data for independent advertising or to build profiles of their users.
07
AI providers and agents
AI features send relevant prompts, content and context to the provider needed to perform the request. We do not authorise our processors to use Customer Data for their own model training. Processing and retention needed to deliver and secure a provider’s service are separate from training.
If you supply your own provider key or connect an external agent, your agreement and settings with that provider also govern what it receives and retains. An agent you authorise may receive workspace information through the access you grant. Revoke its access in Sprid when it is no longer needed. Our own processing remains subject to this policy.
We retain saved outputs as workspace content and keep usage records needed for billing, support and security. Contact us for the providers relevant to a feature and their processing arrangements.
08
Who receives information
We disclose information only as needed for the purposes described here:
- Service providers: hosting, storage, communications, payments, AI processing, analytics and error monitoring. Providers acting as processors must process personal data under our instructions and appropriate contractual protections.
- People and services you authorise: workspace members and administrators, connected agents, publishing destinations and other integrations. Their access depends on the permissions you grant. Payment services and connected platforms may also act as independent controllers.
- Professional advisers and authorities: where necessary for legal claims, compliance, security or protection of rights, subject to applicable law.
- Business transfers: where necessary for a proposed or completed merger, financing or sale, subject to confidentiality and applicable data protection requirements.
Publishing makes content available to the destination’s audience. Media links used for sharing or delivery may be accessible to anyone who has the link; avoid placing confidential material in content intended for sharing. Request the current sub-processor list, including locations and functions, at hello@sprid.studio.
09
International transfers
Our providers may process personal data outside the European Economic Area, including in the United States. Where required, transfers must be covered by an adequacy decision or appropriate safeguards, such as the European Commission’s Standard Contractual Clauses and supplementary measures. Contact us for information about relevant destinations and a copy of applicable safeguards, subject to necessary redactions.
10
Security
We use technical and organisational safeguards appropriate to the data and risks, including encrypted connections, protection of stored credentials and access controls. No service can guarantee absolute security. Report suspected unauthorised access or a security issue to hello@sprid.studio.
11
Retention
We keep data only as long as needed for the purposes described, considering the type of data, your instructions, legal duties, security needs and applicable platform limits.
- Accounts and content: generally kept while the account or workspace is active. In-app account deletion starts a 30-day recovery window before permanent deletion is processed. Shorter platform deadlines take precedence.
- Connections and reporting: credentials are removed when you disconnect. Existing content and history may remain for your use until deleted, subject to platform limits in section 06.
- Usage, diagnostics and support: kept for the period needed to investigate issues, secure the Service, support you and resolve disputes. Relevant records may be preserved for a specific incident or legal claim.
- Financial records: retained for statutory accounting periods, normally seven years after the relevant financial year ends.
Residual backup copies are restricted from ordinary use and removed through the applicable backup cycle, subject to legal and platform requirements. Information retained for legal obligations or claims is used only for those purposes.
12
Your rights
Depending on applicable law and the processing, you may request access, correction, erasure, restriction or a portable copy of your data. You may object to processing based on legitimate interests and withdraw consent where we rely on it. These rights are subject to the conditions and exceptions in law.
Email hello@sprid.studio to make a request. We may need proportionate information to verify identity or authority. Under GDPR we respond without undue delay and normally within one month. If a lawful extension is necessary, we will explain it within that month. Shorter platform deletion deadlines are unaffected.
You may complain to Integritetsskyddsmyndigheten (IMY) in Sweden or your local supervisory authority. You need not contact us first.
13
Deletion and disconnection
Use the account deletion control in personal settings or email hello@sprid.studio. See deletion instructions for the recovery window and how to request earlier erasure or deletion of specific connected data.
Deleting your login does not give you authority to erase another customer’s workspace. We assess shared workspace data against ownership, the customer’s instructions and applicable rights. Disconnecting a provider, cancelling a subscription and erasing stored data are separate actions.
Content already published and advertising at a destination remain there until removed at that destination. Cancel app-store subscriptions through the store and manage active campaigns directly with the advertising platform.
13b
Mobile apps and device permissions
The app uses photo and video access to import media you select and save exports you request. It may use notification permission and a device push identifier to deliver enabled notifications. You can manage permissions in device settings.
Local creation features process selected media on the device until you choose an upload or sharing action. Home-screen widgets use stored access credentials to retrieve the reports you select; those figures may be visible to anyone who can see the widget. Crash and performance diagnostics may be sent to our error-monitoring provider.
14
Cookies, analytics and telemetry
We use cookies and local device storage for sign-in, connection flows and preferences. Blocking essential storage may prevent those features from working.
Our website and web app use PostHog’s EU-hosted cookieless analytics for visit statistics and to count which setup commands are copied from the website. It processes request and device information without analytics cookies or browser storage. Autocapture and session replay are disabled. A browser’s Global Privacy Control signal disables this analytics collection.
The iOS and Android apps send product usage events to the same EU-hosted PostHog project: screens opened, features used, app opens and closes, and app, device and operating-system versions. When you are signed in these events are linked to your account identifier, so we can see how the app is used after sign-up. They do not include your email, the content of your posts or media, and location is not derived from your IP address. Session replay is disabled. Development builds send nothing.
Once a day, signed in or not, the Sprid CLI sends an anonymous install report: a random identifier created on your machine, how the Sprid skills were installed, CLI, skills, Node and operating-system versions, whether it runs in CI and whether a login exists. It carries no account or workspace, and we do not store the IP address it came from. When signed in, the CLI also reports command and subcommand names, outcome, duration, software and operating-system versions, execution context and account or workspace identifiers. Telemetry excludes command arguments, file paths, output and file contents. Turn it off with sprid telemetry off or DO_NOT_TRACK=1. Essential authentication, billing and security records continue.
14b
Other privacy rights
Where California privacy law applies, residents may have rights to know, access, correct and delete personal information, and to use an authorised agent. The categories, purposes and recipient categories are described above. We do not sell personal information, share it for cross-context behavioural advertising, or use sensitive information to infer personal characteristics.
Contact hello@sprid.studio to exercise applicable rights. We verify requests proportionately and do not discriminate against people for exercising them.
15
Children
Sprid accounts are intended for adults aged 18 or over. If you believe a child has provided account information, contact us so we can investigate and delete it where appropriate. Customers are responsible for the lawfulness of any personal data about children in content they submit.
16
Legal requests
We assess requests for customer information for legal validity and scope and disclose only what is necessary and lawful. Where legally permitted, we notify affected users before disclosure. A request from a foreign authority does not by itself remove applicable data protection or transfer requirements.
17
Policy updates
We update this notice when our practices or requirements change and show the revision date here. We notify you of material changes by email or in the Service. An updated notice does not itself supply consent for processing that requires it; we will request that separately where necessary.
18
Contact
Questions about this policy or about how we handle your data can be sent to hello@sprid.studio.
Data controller: Väder AB, Sweden.