App privacy

Effective date: set when this goes live #26

What the JSpark app sends over the network, and what it keeps on your computer. The website has its own notice, under Privacy.

This policy covers the JSpark app for Mac and Windows, in both editions (JSpark and JSpark+). The jspark.app website has its own notice, under Privacy.

Who is responsible

Ananda Rizki, an individual based in Indonesia, who makes JSpark (“I”, “me”). Little Spark is a brand name I use on the Polar store. It is not a separate legal entity. Contact: support@jspark.app.

In short

  • No account, no sign-in, no cloud. Your code, Snippets, Library and settings stay on your computer.
  • No tracking. No analytics, no telemetry, no usage metrics, no crash reports, no ads.
  • The app connects to the internet only for the things listed below. None of them sends your code, your files or how you use the app.

What stays on your computer

The app keeps its data in ~/Library/Application Support/JSpark on a Mac, and in %APPDATA%\JSpark on Windows Windows folder to be confirmed #25:

  • snippets.json: the tabs you have open, with their code
  • library.db: your Library of saved Snippets, with their titles, notes and tags
  • settings.json: your settings
  • working-folder.json: which folder Node.js Snippets work in, if you chose one
  • packages/: the npm packages you installed, and what the app needs to run them
  • the saved Activation of your License Key, for JSpark+
  • the page engine’s own caches and storage, for the web pages your Snippets show

Files your Node.js Snippets write go to the Working Folder. An exported Library goes wherever you save it. None of this is sent anywhere, and I can’t see any of it. These files are not encrypted, so anyone with access to your user account can read them. To remove everything, delete the app and that folder.

What leaves your computer, and when

1. Checking for updates

What: a plain request for the list of released versions at https://updates.jspark.app/. It carries no identifier, key or usage data. Who receives it: Cloudflare, which hosts that address for me. Like any web request, it reveals your IP address and the usual request details to the host. When: at launch and every few hours after. Your choice: turn off Check for updates in Settings, and the app never checks on its own. Downloading an update fetches it from the download host, to be confirmed, #23 which also sees your IP address.

2. Your License Key, with Polar (JSpark+ only)

What: to activate, the License Key, my store’s identifier at Polar, and a label for the Activation: the word “Mac” or “Windows”, never your device’s name. To check the key, and when you press Deactivate this device, the License Key, the store identifier and the Activation’s identifier. Never your code, your files, how you use the app, or a hardware fingerprint. Who receives it: Polar Software, Inc., which issues the keys and counts the devices. It sees your IP address. When: once when you activate; then at most once a day, when your device is online, to check the key is still valid (for example, not refunded); and when you deactivate. Using only JSpark, the free edition, sends nothing to Polar.

3. npm packages, when you use the Packages window

What: your search text, and the names and versions of the packages you look at or install. Who receives it: the npm registry (registry.npmjs.org, or the registry, proxy and access token set in your own ~/.npmrc), api.npmjs.org for weekly download counts, and esm.sh, which prepares packages for web pages. A package’s README may show images hosted elsewhere (GitHub, badge services and others), which load from those hosts. Each of these sees your IP address. When: only when you search, open a package, or install or update one. A package installed while offline is prepared for web pages when a connection returns, in the background.

4. The code you run

The app does not watch, record or report what your code does. But your code can reach the network itself: a Node.js Snippet can connect anywhere, and a web page loads the libraries and data its code names, for example from a CDN. Those connections are made by your code, to the places it chooses, and follow those services’ own policies.

Buttons such as Buy JSpark+, Manage plan, Lost your key? and package pages open in your web browser, and email links open your mail app. What happens there is covered by that website’s own policy.

Buying JSpark+

Polar Software, Inc. sells JSpark+ as merchant of record. At checkout Polar collects what it needs to take payment and handle tax, such as your name, email address, billing address, tax number if you give one, and your card details (processed by Stripe), under Polar’s Privacy Policy. I never see your full card details.

Polar shares with me the order details: your name, email address, billing country, what you bought, the amount, your License Keys and their Activations. I use them only to provide JSpark+, answer you, handle refunds and keep the records tax law asks of me. I don’t sell them, and share them only with services that help me run JSpark, such as email, or when the law requires it. I don’t send marketing email unless you ask for it.

When you email me

If you write to support@jspark.app, I keep your email and what you include, only to answer you and to fix problems. Mail to jspark.app is handled by Apple iCloud. Help → Report a Problem… opens an email to that address in your own mail app, prefilled with the app’s diagnostics, and Settings → About → Copy Diagnostics copies the same diagnostics to your clipboard. They are the app’s version and build date, edition, the Node, Chromium and V8 versions, operating system version, architecture and the last update check, and never your code, file contents or folder paths. Nothing is sent until you send the email yourself, and you can edit it first.

How long I keep things

Order records: for as long as tax law requires. Support emails: for as long as I need them to help you, and then deleted. Polar keeps its own records under its own policy.

Your rights

You can ask me to show, correct or delete the personal data I hold about you (except what the law requires me to keep, such as order records), or to stop using it, by emailing support@jspark.app. For the data Polar holds, you can also write to privacy@polar.sh. Depending on where you live, you may have more rights, including to complain to your data protection authority. I rely on performing our agreement (to provide JSpark+ and refunds), on legal obligations (tax records), and on a legitimate interest in answering support requests. This section is waiting for a legal review. #22

Children

JSpark is not directed at children under 16, and I don’t knowingly collect their data.

Changes

If this policy changes, the new version is published at jspark.app/legal/app-privacy with a new effective date. If a new version of the app sends anything not listed here, this policy is updated before that version is released.