Privacy notice
For early-access requests, we store your email address, language, request and confirmation dates, and the notice version. We use them with your consent to confirm your request and contact you about access. Write to hello@feedloom.app to withdraw consent and remove your request.
Effective date and last updated: 1 October 2026 · Version 2026-10-01
This policy explains how Sprout LLC ("we", "us") collects and uses personal data when you visit feedloom.app, create an account, use the Feedloom web app, MCP server or API, or contact us. It applies to our customers, their team members, the people who review posts through approval links and the visitors of our website.
Content that our customers put in Feedloom. When a customer uploads photos, connects sources or social accounts, or writes posts that contain personal data, the customer decides how that data is used, and we process it only for the customer (see section 4). If your data is in a customer's posts, contact that customer first.
1. Who we are
The controller of your personal data is Sprout LLC, a Delaware limited liability company, 299 NW 46th St, Boca Raton, FL 33431, USA. Email: facundomartin@sproutco.io. Phone: +1 (786) 375-8064.
For privacy questions or requests, write to facundomartin@sproutco.io. This address is also our contact for data protection matters under the Brazilian LGPD (encarregado channel).
2. Personal data we collect
| Category | Examples | Source |
|---|---|---|
| Account data | Name, email address, password (stored only as a secure hash), language, organization name, role, team invitations | You, your team |
| Billing data | Billing name and address, tax ID, plan, invoices, payment status, last four digits and brand of your card | You, Stripe |
| Contract and consent records | The version of the Terms, Privacy Policy and refund policy that you accepted, your automatic-renewal and immediate-access consents, with date, time, IP address and browser user agent; Stripe customer and session IDs | You, our systems |
| Content and workspace data | Brand kits, uploaded photos and logos, sources and snippets, planner conversations and prompts, posts, rendered images, approvals, schedules | You, your team, the sources you connect |
| Connected social accounts | Account and profile identifiers, names and handles, profile pictures, connection status, publication results (post IDs, links, errors). The sign-in tokens are held by our publishing provider, Zernio, not in our database. | You, Zernio, the social networks |
| AI assistant and API access | Names of the MCP or API clients that you authorize, access grants, tool calls and their results | You, your AI assistant |
| Usage and security data | Sign-ins and sessions (time, IP address, user agent, device), actions in the account (for example downloads, publications, approvals), usage counters (renders, AI usage, storage), audit records, security and error logs | Your device, our systems |
| Communications | Emails and support requests, refund, cancellation and withdrawal requests, and our answers; delivery data for our emails (for example message IDs) | You, our email provider |
We do not ask for sensitive personal data. Do not upload it unless you need it for a post and you have a lawful basis.
3. Why we use your data and our legal bases
The legal bases apply if the EU or UK GDPR applies to you. The LGPD bases apply if Brazilian law applies to you.
| Purpose | Data | Legal basis (EU/UK GDPR) | LGPD basis |
|---|---|---|---|
| Create and manage your account and provide the Service (brand kits, planning, rendering, approvals, scheduling, publishing, downloads) | Account, content, connected accounts, AI access, usage | Contract (Art. 6(1)(b)) | Contract (art. 7, V) |
| Take payments, issue invoices, calculate taxes, keep accounting records | Billing, contract records | Contract and legal obligation (Art. 6(1)(b), (c)) | Contract; legal obligation (art. 7, II, V) |
| Send service emails (sign-in links, receipts, renewal reminders, cancellation confirmations, reconnect and publication notices) | Account, billing, usage | Contract; legal obligation for consumer-law notices (Art. 6(1)(b), (c)) | Contract; legal obligation |
| Keep records of your acceptance and consents, prove the contract, defend chargebacks and legal claims | Contract records, usage, communications | Legal obligation; legitimate interests in proving the contract and defending claims (Art. 6(1)(c), (f)) | Legal obligation; regular exercise of rights (art. 7, II, VI) |
| Enforce plan limits and measure usage (renders, AI, storage, connected accounts) | Usage | Contract (Art. 6(1)(b)) | Contract |
| Keep the Service secure, prevent fraud and abuse, protect our relationships with social networks, enforce our Terms | Usage and security, content when needed to investigate abuse | Legitimate interests in security and fraud prevention (Art. 6(1)(f)) | Legitimate interests; fraud prevention |
| Answer support requests | Communications, account | Contract; legitimate interests (Art. 6(1)(b), (f)) | Contract; legitimate interests |
| Understand and improve the Service with event counts in our own logs | Usage | Legitimate interests in improving the Service (Art. 6(1)(f)) | Legitimate interests |
| Send optional product emails (only if you opted in) | Email, preferences | Consent (Art. 6(1)(a)) | Consent (art. 7, I) |
| Comply with the law and answer valid requests of authorities | Any relevant data | Legal obligation (Art. 6(1)(c)) | Legal obligation |
Where we rely on legitimate interests, we have weighed them against your rights. You can object (section 9). Where we rely on consent, you can withdraw it at any time with the link in each email or by writing to us. Withdrawal does not affect use before it.
If you do not give us the data that we need for the contract (for example your email address), we cannot provide the Service.
AI. When you use our planner, we send the relevant sources, brand information and your instructions to our AI provider to create a proposal. We do not use your content to train AI models. We do not make decisions about you based only on automated processing that have legal or similarly significant effects. Stripe uses automated fraud checks on payments under its own policy.
4. Data we process for our customers
Personal data inside a customer's content (for example people in photos, names in posts, the data of the customer's clients) and the data of a customer's connected social accounts are processed by us on behalf of the customer. For this data, the customer is the controller and we are its processor. Our Data Processing Addendum governs it. When the customer publishes a post, the social network receives it and processes it under its own privacy policy.
5. Who receives your data
We do not sell your personal data. We do not share it for cross-context behavioral advertising.
We share personal data only with:
- Service providers (processors) that help us run the Service, under contracts that limit their use of the data. The current list is in our subprocessor list. The main providers are DigitalOcean (hosting and database, USA), Cloudflare (network, security, rendering of images and media storage), Postmark (email delivery), Zernio (connection of social accounts and publishing), OpenAI (AI planning, when enabled) and Stripe (payments).
- Social networks that you connect, when you ask us to publish. They act as independent controllers under their own privacy policies.
- AI assistants that you connect through MCP or the API. They receive the data that you ask them to read and act under their providers' policies.
- Stripe also acts as an independent controller for some payment data, for example to prevent fraud and to meet its legal duties. See stripe.com/privacy.
- Your organization and your clients. Owners and members of your organization can see its content. People to whom you send an approval link can see the posts in that link.
- Professional advisers (lawyers, accountants, auditors) under confidentiality duties.
- Authorities and courts, when the law requires it, or to establish, exercise or defend legal claims, including card-network chargeback procedures (we send your bank the records listed in section 2 that are relevant to the dispute).
- A buyer or successor of our business, if we sell or reorganize it. The successor must protect your data as described in this policy.
6. International transfers
Sprout LLC is in the United States, and we host the Service in the United States (DigitalOcean, New York). Some providers process data in other countries. If you are in the EEA, the UK, Switzerland, Brazil or Argentina, your data is transferred to countries that may not have the same level of protection as yours.
For these transfers we use: the EU–US Data Privacy Framework and its UK Extension and Swiss framework, where the recipient is certified; otherwise the European Commission's Standard Contractual Clauses (2021/914), the UK International Data Transfer Addendum, and the equivalent contractual clauses for Brazil and Argentina where required. You can ask us for a copy of the relevant safeguards at facundomartin@sproutco.io.
7. How long we keep data
| Data | Retention |
|---|---|
| Legacy waitlist records | Until withdrawal or 12 months after public signup opens, whichever comes first. |
| Account data, content and workspace data | While your account exists. We delete them within 30 days after you delete your account (stored images are deleted from our storage provider by an automatic cleanup), except the records listed below. Posts already published stay on the social networks until you delete them there. |
| Connected-account data | Until you disconnect the account or delete your Feedloom account. When you disconnect, we ask Zernio to remove the connection. |
| Billing data and invoices | As long as tax and accounting law requires, normally up to 7 years after the end of the tax year (up to 10 years where EU law requires it). |
| Contract and consent records, refund, cancellation and withdrawal requests | At least 3 years after your subscription ends, or until a dispute or claim is closed if that is later. Never less than 18 months after the last charge. |
| Usage, audit and security records | Up to 24 months, or longer if needed for an open security investigation or dispute. |
| Server and error logs | Up to 30 days. |
| Preferences for optional emails | Until you unsubscribe or delete your account. |
8. Security
We use technical and organizational measures that fit the risk. Examples: encryption in transit (HTTPS with HSTS), sign-in with single-use links or hashed passwords, encrypted session cookies, access control by role and by organization, private media storage with short-lived signed links, an append-only audit log, a database that is not reachable from the internet, regular dependency and security checks, and least-privilege access for staff. No system is fully secure. If a breach affects your data, we tell you and the authorities when the law requires it.
9. Your rights
You can contact us at facundomartin@sproutco.io to use your rights. We may ask you to confirm your identity, normally by a reply from your account email. We answer without undue delay.
9.1. EEA, UK and Switzerland
You have the right to: access your data; correct it; delete it; restrict its use; receive it in a portable format; object to processing based on legitimate interests; and withdraw consent at any time.
Your right to object. You can object at any time, for reasons that relate to your situation, to our use of your data based on legitimate interests. You can object at any time to direct marketing; we then stop.
We answer within one month after we receive your request. If a request is complex or you send many, we can extend this by up to two more months. We tell you within the first month if we do this, and why.
You can complain to the data protection authority of the EU country where you live, work, or where the issue happened (list: https://www.edpb.europa.eu/about-edpb/about-edpb/members_en). UK: you can complain to us first; we acknowledge your complaint within 30 days, investigate it without undue delay and tell you the outcome. You can also complain to the Information Commissioner's Office (ico.org.uk/make-a-complaint). Switzerland: you can complain to the FDPIC (edoeb.admin.ch).
9.2. California (notice at collection and privacy rights)
This section applies to California residents, to the extent the California Consumer Privacy Act (CCPA) applies to us.
Categories collected in the past 12 months (with the categories of Cal. Civ. Code §1798.140): identifiers (name, email, IP address, account, customer and social-account IDs); customer records (billing name and address, tax ID; Cal. Civ. Code §1798.80(e)); commercial information (plans, purchases, invoices); internet or other electronic network activity (sign-ins, use of the Service, security logs); geolocation data (approximate location derived from your IP address only); audio, electronic, visual or similar information (photos and images that you upload or render); professional information (organization and role); sensitive personal information (account login: email and password). We do not collect other categories.
Sources: you, your devices, your organization, your connected social networks and Zernio, Stripe, and the sources that you connect.
Purposes: the purposes in section 3.
Disclosures for a business purpose: we disclose identifiers, customer records, commercial information, network activity, geolocation data and visual information to service providers (hosting, rendering and storage, AI, email, publishing, payments) and to professional advisers, for the purposes in section 3. At your request, we send your posts to the social networks that you connect.
Sale and sharing: we do not sell or share personal information, and we did not do so in the past 12 months. We have no actual knowledge that we sell or share personal information of consumers under 16. We use sensitive personal information only for the purposes allowed by Cal. Code Regs. tit. 11, §7027(m), so the right to limit does not apply.
Retention: see section 7.
Your rights: to know what personal information we collected about you, including specific pieces; to delete it; to correct it; to opt out of sale or sharing (we do not sell or share); and not to be discriminated against for using these rights.
How to make a request: email facundomartin@sproutco.io. We operate only online and have a direct relationship with our users, so email is our request method. We verify requests to know, delete and correct by matching the information you give us with the information we hold, normally by asking you to reply from your account email. An authorized agent can make a request for you with your signed permission; we may ask you to confirm your identity directly.
Global Privacy Control: we treat a GPC signal as a valid request to opt out of sale and sharing for the browser that sends it and, when you are signed in, for your account. Because we do not sell or share personal information, this does not change how our site works for you.
Shine the Light: we do not disclose personal information to third parties for their direct marketing.
9.3. Other US states
If you live in a US state with a consumer privacy law (for example Virginia, Colorado, Connecticut, Texas or Oregon), you can have the rights to access, correct, delete and port your data, and to opt out of targeted advertising, sale and certain profiling. We do not sell personal data, do targeted advertising or do such profiling. To use your rights, email us. If we decline your request, you can appeal by replying to our answer with the word "Appeal". We answer the appeal within the time the law requires. If the appeal is denied, you can contact your state Attorney General.
9.4. Brazil (LGPD)
You have the rights in article 18 of the LGPD: confirmation that we process your data, access, correction, anonymization, blocking or deletion of unnecessary or unlawful data, portability, deletion of data processed with consent, information about who we share data with, information about the possibility of not giving consent and its consequences, and withdrawal of consent. You can also complain to the Autoridade Nacional de Proteção de Dados (ANPD, gov.br/anpd).
9.5. Argentina
You can access your data free of charge at intervals of not less than six months, unless you show a legitimate interest to do so earlier. We answer access requests within 10 calendar days, and correction, update or deletion requests within 5 business days (Ley 25.326, arts. 14 and 16).
"La AGENCIA DE ACCESO A LA INFORMACIÓN PÚBLICA, en su carácter de Órgano de Control de la Ley N° 25.326, tiene la atribución de atender las denuncias y reclamos que interpongan quienes resulten afectados en sus derechos por incumplimiento de las normas vigentes en materia de protección de datos personales."
10. Cookies
We use only cookies and similar storage that are strictly necessary or that remember a choice you make. We do not use advertising or analytics cookies. See our Cookie Policy.
Do Not Track and online tracking. No third party collects information about your online activities over time and across different websites through feedloom.app. Our site does not respond differently to browser "Do Not Track" signals, because we do not track you across sites.
11. Emails
We send service emails that you need to use the Service (for example sign-in links, receipts, renewal reminders, cancellation confirmations and alerts when a social account disconnects). You cannot unsubscribe from them while you have an account. Optional product emails are sent only with your consent, and each one has an unsubscribe link. We honour unsubscribe requests within 10 business days.
12. Children
The Service is for adults and businesses. It is not directed to children under 16, and we do not knowingly collect their personal data. If you think that a child gave us personal data, contact us and we will delete it.
13. Changes to this policy
We may update this policy. We show the date of the last update at the top. If we make a material change, we post a notice on feedloom.app and email account holders before the change takes effect, and we ask for your consent where the law requires it.
14. Contact
Sprout LLC · 299 NW 46th St, Boca Raton, FL 33431, USA · facundomartin@sproutco.io · +1 (786) 375-8064 · Product support: hello@feedloom.app