Privacy Policy

Privacy Policy

This policy describes the data SpringRoll needs to operate accounts, deploy applications, govern access, and keep an audit record.

Account data

We process your email address, organization membership, role, and authentication events to create and secure your account. Passwordless sign-in emails are delivered through Resend.

Application data

SpringRoll stores application manifests, source references or uploaded bundles, releases, deployments, approvals, access grants, and audit events so your organization can operate and review its internal apps.

Company data

SpringRoll does not store your company data. It queries approved sources through the connector boundary and returns only the approved view of a Data Product to the application. Source credentials are encrypted inside SpringRoll and are never given to the application.

Cookies and analytics

Two kinds of cookie may be set on this site. Strictly necessary cookies sign you in, protect the sign-in form against forgery, and remember your analytics choice; they cannot be turned off, because without them the site cannot do the thing you came for. Analytics cookies are optional, are not set before you accept them, and can be refused at any time from Cookie Settings in the footer.

Analytics are processed by PostHog. We record page views, which features are used, and unhandled errors, and we capture session replay with every form input masked, so what you type is never transmitted. Web addresses are stripped of sign-in tokens, authorization codes, and verification parameters in your browser before anything is sent. Analytics traffic is proxied through this domain rather than to a third-party host directly, so no other party sees your IP address on our behalf.

Refusing analytics stops browser analytics collection and clears what analytics had already stored in your browser. Operational records such as authentication, deployment, and audit outcomes are still processed when needed to provide and secure the service. We do not use advertising, cross-site tracking, or profiling cookies, and we do not sell or share personal data with advertisers.

Cookies this site may set
CookiePurposeLifetime
springroll_cookie_consent_v1Strictly necessary. Records whether you accepted or refused analytics. Holds no identifier.12 months
authjs.session-tokenStrictly necessary. Keeps you signed in.Until you sign out or the session expires
authjs.csrf-token, authjs.callback-urlStrictly necessary. Protects the sign-in flow and returns you to the page you asked for.Session
ph_*Analytics. PostHog device and session identifiers. Set only while analytics is accepted.Up to 12 months

Service providers and retention

SpringRoll uses service providers required to deliver email, hosting, and infrastructure. Data is retained while the account or organization needs the service and as required to protect security and audit integrity.

Your choices

You can accept or refuse analytics cookies at any time from Cookie Settings in the footer of any public page; see Cookies and analytics for what each one does. Organization administrators can revoke memberships, agent connections, app identities, and data grants. To request access, correction, or deletion of personal data, use the contact page.