Privacy Policy

Effective July 24, 2026

sproutUGC LLC, a Missouri limited liability company ("sproutUGC", "we", "us"), operates a workspace for UGC creators to manage brand deals, invoicing, finances, and client collaboration. We are the controller of the personal information described here. This policy explains what we collect, why, and the choices you have. The short version: your business data belongs to you, we collect only what the product needs to work, and we never sell it.

Information we collect

Account information. Your name, email address, and a password (stored only as a salted hash — we cannot read it).

Workspace content you create. Brand contacts, deals, deliverables, tasks, invoices, expenses, notes, portfolio content, and files you upload (contracts, briefs, receipts, media). This is your business data; we store it to provide the service.

Client portal data. If you enable a brand portal, we store the email addresses of the client contacts you invite, the sign-in links we send them, and a session cookie on their device so they stay signed in.

Connected services. If you connect a social account (e.g. Instagram or TikTok) we store the access tokens needed to fetch your metrics, encrypted at rest. If you connect your own Stripe or PayPal account for payments, we store the credentials you provide to create checkout sessions on your behalf. Payments from your clients settle directly to your own accounts — sproutUGC never holds your money.

Usage basics. Standard technical logs (IP address, browser type, device type, timestamps) and your last sign-in time, used for security and support. We also record page views, referring pages, and campaign attribution (UTM tags) on our public marketing site, and basic daily-activity records inside the product — see "Cookies & analytics" below.

Onboarding emails. When you create a trial account, we share your email address with our email platform (Mailchimp) to send you the onboarding email sequence that helps you get set up. This happens regardless of the marketing-updates checkbox below, since it's about your own account, not marketing.

Marketing email opt-in. If you separately opt in to product updates (at signup or via a "get updates" form), we store your consent status and share it with Mailchimp so you continue receiving those updates afterward. You can unsubscribe at any time from any email we send, or by emailing us.

How we use information

To operate the product: rendering your workspace, generating invoices and PDFs, sending the emails you trigger (client sign-in links, invoices, weekly digests, password resets), and syncing metrics from services you connect.

AI features. Some Creator Tools (like caption or pitch drafting) send the text you provide to our AI provider (Anthropic) to generate a result. We send only what the feature needs, and we don't use your data to train models.

We do notsell your personal information, and we don't use your business data for advertising.

Who we share it with

Only the service providers that run the product: cloud hosting and databases (Amazon Web Services), payment processing you connect (Stripe, PayPal), email delivery (our SMTP provider and Mailchimp, for onboarding and opted-in marketing email), and AI processing (Anthropic) when you use an AI feature. Each receives only what it needs to do its job.

Content you deliberately publish or share — your public portfolio page, media kit links, or a brand portal — is visible to the people you share it with.

We may disclose information if required by law or to protect the service from abuse.

Cookies & analytics

We use cookies for signing you in, keeping brand-portal visitors signed in, and remembering your theme preference.

We also run first-party product analytics — no third-party advertising or tracking pixels. On our public marketing pages, a first-party cookie lets us see which page a visitor came from (including UTM campaign tags on links we create) so we can tell which marketing efforts actually bring people in. Inside the product, we log basic usage activity (that you were active that day) so we can understand how the product is actually used. Both are used only to improve sproutUGC and are never sold or shared with advertisers.

Security

Passwords are hashed with bcrypt, social access tokens are encrypted at rest (AES-256), traffic is encrypted in transit (HTTPS), and client-portal access uses expiring, single-use sign-in links instead of passwords.

Data retention & deletion

We keep your workspace data for as long as your account is active. You can delete it yourself at any time from Settings → Business → Delete this workspace — no need to email us and wait.

What happens when you delete. Immediately: you're signed out, your public portfolio, media kit, and brand portals go offline, and we stop sending you email. Your data then sits in a 30-day recovery window— sign back in during that time and you can restore everything. After 30 days it is permanently erased: your contacts, deals, deliverables, invoices, transactions, portfolio content, chat messages, and every file you uploaded, along with your entry in our email lists and our email provider's. This is irreversible and we cannot recover it afterwards.

Export first. Before you delete, you can download your business records — contacts, deals, invoices, transactions, and portfolio content — as a data file, from the same screen. Uploaded files stay downloadable from the Files tab for the whole 30 days.

Backups. We take routine encrypted database backups for disaster recovery. Deleted data can persist in those backups for a short period after the purge, until they age out on their normal rotation — after which it's gone from those too. We don't restore backups to recover individual deleted accounts.

Client and brand contacts. If you're a brand contact who was invited to a creator's portal, your details sit inside that creator'sworkspace and they control them — ask them to remove you, or email us and we'll pass the request on. Deleting a creator's workspace also deletes the portal contacts within it.

If you'd rather we handled deletion for you, or you can't sign in, email info@sproutugc.com and we'll take care of it.

Children

sproutUGC is for business use and not directed at children under 16.

Changes & contact

If we make material changes to this policy, we'll note it here with a new effective date. Questions or requests: info@sproutugc.com.