Privacy
Sprig’s privacy policy can be found here.Data Security, PII, and GDPR
Sprig is Data Privacy Framework certified, PCI DSS compliant, SOC2 Type 2 compliant, HIPAA certified, and regularly runs 3rd-party penetration tests to identify possible vulnerabilities proactively. All Sprig SDK and the Sprig backend communication is done securely over SSL, and your data is stored in a database that is encrypted at rest. Sprig will not implicitly collect any personally identifiable information (PII) about your users. If you wish to send user PII to Sprig, it must be done explicitly through the Sprig data collection APIs for attributes or events. In compliance with General Data Protection Regulation (GDPR) and other data regulatory frameworks, Sprig offers functionality for data access, erasure, and opt-out for Enterprise customers. Please reach out to your customer service representative to learn more.AI: Data Privacy & Retention
Sprig AI Analysis leverages OpenAI’s language model services through their API platform. Sprig processes AI data across secure internal networks and has a zero-data-retention policy for AI-related operations with OpenAI.- Per OpenAI’s published policies, OpenAI does not use business data or API inputs to train its models by default.
- Sprig does not use business, customer, or user data to train models.