Every version bump in apps/api/src/modules/legal/legal-registry.ts lands here with a rationale. Typo fixes and formatting changes do NOT bump the version — only edits that change user rights, data flows, pricing, retention, or the processor list trigger a bump (and a re-acceptance prompt for every user).
When you bump:
- Update the
versionin the registry - Add a row here with the reasoning
- The next time each user opens the app, they'll be prompted to re-accept
Versions
Privacy Policy 1.4.0 — 2026-08-25
- Disclosed Spark's first-party structured usage-session and diagnostic store, its active-account retention, and the content categories it explicitly excludes.
- Clarified that confirmed account deletion also removes linked detailed usage sessions, API spans, and diagnostic occurrences before completion is reported, while anonymous aggregate issue groups may remain.
Implementation clarification — 2026-08-05 (no version bump)
- Documented that PostHog client IP storage and GeoIP enrichment are disabled. This aligns implementation with the existing disclosure that Spark does not collect precise or coarse device location and narrows processing; it does not add a data category, processor, purpose, or user obligation.
Privacy Policy 1.3.0 — 2026-07-18
- Added a prominent disclosure that Spark sends task-relevant personal data to configured third-party AI providers to provide AI features.
- Clarified the categories of data that may be shared, the purpose of sharing, provider training restrictions, and the controls available to limit future AI processing.
- Clarified that confirmed account deletion removes user-scoped uploaded files as well as active database records; the deletion flow now enforces that behavior in object storage.
EULA 1.2.0 — 2026-07-18
- Replaced Spark's custom mobile-app license with Apple's Standard End User License Agreement for the iOS application.
- Clarified that Spark's Terms of Service and Subscription Terms continue to govern use of the Spark service.
Subscription Terms 1.2.0 and Refund Policy 1.2.0 — 2026-06-30
- Subscription and refund language now reflects Android/Google Play Billing activation alongside Apple In-App Purchase.
- Sub-processor list updated to include Google Play distribution, billing, subscription status, and refund handling under the existing Google vendor entry.
Privacy Policy 1.2.0 and launch policy pack 1.1.0 — 2026-06-16
- Privacy Policy bumped to 1.2.0 for launch-readiness updates: voice mode/audio processing, current AI providers, file storage, analytics/diagnostics, account deletion behavior, in-app export, and the current sub-processor list.
- Terms, Subscription Terms, Refund Policy, EULA, AUP, Cookie Policy, DMCA Policy, and DPA bumped to 1.1.0 and moved out of placeholder status.
- Subscription and refund language now reflects the launch purchase path: Apple In-App Purchase for Pro and Power, with Android/Google Play deferred until Android subscriptions are active.
- App Store Privacy Nutrition Label updated to track Privacy Policy 1.2.0, including Audio Data for voice mode and Purchase History for App Store subscriptions.
- Account deletion language now reflects the shipped deletion flow: active product records are deleted, account identifiers are anonymized, and narrow legal/subscription/admin/fraud/cost audit records may be retained.
Privacy Policy 1.1.0 — 2026-05-16
- Disclosed the AI-driven CSV import data flow: when the user uploads a CSV, the column headers + first 5 rows are sent to Anthropic for column mapping. Material change → version bump → re-acceptance required.
- Sub-processor list updated to reflect Anthropic now also sees CSV-import samples.
1.0.0 — 2026-05-15
Initial draft pack.