Last updated: 27.09.2026
We collect only what we need to run the service. Your bot tokens are encrypted. We don't sell your data. You can delete your account anytime.
When you create an account, we collect:
If you link your Telegram account to Sprout, we store:
When you deploy instances and configure channels, we store:
Encryption: Channel credentials (bot tokens) you add on an instance's page are encrypted at rest using AES-256-GCM. API keys for integrations are stored with your instance's configuration and are used only to set up your agent.
We automatically collect:
We use collected information to:
We do not sell your personal information. We share data only in these circumstances:
We use third-party services that may process your data:
| Provider | Purpose | Data Shared |
|---|---|---|
| PostHog | Product analytics, only if you opt in | Pages visited, actions taken, account ID and email when signed in |
| Resend | Email delivery | Email address |
| Neon | Database | Account data |
| Vercel | Hosting | Technical data |
| RentAMac | Hardware provisioning | Instance config |
We may disclose information if required by law, court order, or government request, or to protect our rights, property, or safety.
We implement industry-standard security measures:
No system is 100% secure. If you discover a security vulnerability, please report it to security@sprout.boutique.
You have the right to:
Request a copy of all data we have about you by contacting support.
Update your account information through the dashboard or contact support.
Request account deletion. All personal data will be removed within 30 days, except records required for legal compliance.
Request your data in a machine-readable format (JSON).
We don't send marketing emails. You can refuse or withdraw analytics consent at any time through "Manage Cookies" in the footer.
We use cookies for:
We do not use advertising cookies. You can disable cookies in your browser, but this may affect Service functionality. See our full Cookie Policy for details.
Sprout is operated by a company established in Poland, and your data is processed within the European Union on infrastructure hosted in EU regions. Where any provider processes data outside the EU, we rely on appropriate safeguards (such as Standard Contractual Clauses) consistent with the GDPR section below.
The Service is not intended for users under 18. We do not knowingly collect information from children. If you believe a child has provided us with personal information, please contact us immediately.
We may update this Privacy Policy periodically. We will publish material changes on this page with a new "Last updated" date. Your continued use after changes constitutes acceptance.
For privacy-related questions or to exercise your rights:
Email: privacy@sprout.boutique
Contact Form: sprout.boutique/contact
Under GDPR, we process data based on: (a) contract performance (providing the Service), (b) legitimate interests (improving the Service), and (c) your consent (optional features).
You have additional rights including the right to lodge a complaint with your local data protection authority.