Spriga

Privacy Policy

Spriga works with a real credential to a real account, so privacy is not a formality here. This page describes what we collect, where it lives, and how to make it disappear.

1. What we collect

Your Spriga account: email address and a password (stored as a salted hash — never in plain text), or your Google account email if you sign in with Google.

Your Instagram connection: the credential or session you provide is encrypted on your own device with a public-key sealed box before it is sent — our servers only ever store ciphertext. See how we protect your account.

Activity data: the follows, likes and comments performed for you, targeting settings, and follower statistics — this is what powers your dashboard.

Billing: payments are handled by Stripe. We never see or store your card number; we keep only your subscription status and Stripe customer reference.

2. How we use it

Only to run the service: signing in to your connected Instagram account, performing the growth actions you configured, showing your results, billing your subscription, and sending you essential emails such as password resets. We do not sell your data, use it for advertising, or share it with anyone beyond the processors listed below.

3. Where it lives

Your data is stored on Convex, our backend platform. We rely on a small set of processors to operate: Convex (database and backend), Stripe (payments) and Brevo (transactional email). Each receives only the minimum needed for its role.

4. Retention and deletion

Disconnecting an Instagram account immediately and permanently erases its stored credential and session, along with the account’s data. Deleting your Spriga account removes everything else — profile, settings and activity history. There is no cold-storage copy of your credentials. Invoices may be retained by Stripe where bookkeeping law requires it.

5. Your rights

Wherever you live — and specifically under the GDPR if you are in the EU/EEA — you can ask us to access, correct, export or erase your personal data, or object to how it is processed. Most of this you can do yourself from the dashboard; for anything else, email support@spriga.co and we will respond within 30 days. You also have the right to complain to your local data-protection authority.

6. Cookies

We use only the cookies required to keep you signed in to Spriga. No third-party advertising or cross-site tracking cookies.

7. Changes to this policy

If we change what we collect or who processes it, we will update this page and notify you by email or in the app before the change takes effect.

Last updated: 21 July 2026.