Privacy Policy
Last Updated: September 12, 2026 • Effective Date: January 1, 2026
01. Overview & Scope
SprintLabs AI (“SprintLabs”, “we”, “us”, or “our”) operates sprintlabsai.com and provides software engineering, code auditing, application rescue sprints, and fractional CTO advisory services. This Privacy Policy outlines our strict policies regarding the collection, processing, protection, and disclosure of personal data and proprietary source code shared with us by clients and website visitors.
We adhere to global privacy frameworks including the General Data Protection Regulation (GDPR - EU), California Consumer Privacy Act (CCPA - USA), and applicable data protection regulations in India and international jurisdictions.
02. Source Code & Proprietary Data Protection
When you submit code repositories, Lovable/Bolt/Cursor snapshots, database connection schemas, or API credentials for a free technical code audit or rescue sprint:
- Strict Confidentiality: Your code is treated as strictly confidential under non-disclosure obligations.
- No Model Training: We never use your proprietary codebase, business logic, or customer data to train public or third-party AI models.
- Ephemeral Access: Code audits are conducted in sandboxed, isolated environments. Repositories submitted for audits are purged from diagnostic servers within 30 days of completion unless an active engineering retainer is maintained.
- 100% IP Ownership: You retain complete, unencumbered ownership of all pre-existing and delivered intellectual property.
03. Information We Collect
We collect information in three primary ways:
A. Information You Provide Directly
When filling out intake forms, scheduling calendar sessions, or interacting with our engineering team: Name, work email address, company name, live application URL, primary AI tools used (e.g. Lovable, Bolt, Cursor), and technical pain point descriptions.
B. Automatically Collected Technical Telemetry
Browser type, operating system, IP address, referral URLs, time on page, and anonymous interaction metrics collected via privacy-first analytics to maintain platform performance and prevent abuse.
04. How We Use Your Information
We use your information exclusively to:
- Generate and deliver confidential 24-hour technical code audit reports.
- Execute agreed fixed-price engineering rescue sprints and hotfixes.
- Facilitate calendar scheduling and technical video advisory calls.
- Send critical project updates, milestone deliverables, and invoices.
- Comply with applicable legal, accounting, and security obligations.
05. Third-Party Subprocessors
We partner with industry-leading, SOC 2 / ISO 27001 compliant infrastructure providers to operate our services:
06. Your Data Subject Rights (GDPR & CCPA)
Regardless of your geographic location, you retain full rights over your data:
- Right to Access & Portability: Request a copy of all personal records associated with your email.
- Right to Rectification: Request correction of inaccurate information.
- Right to Erasure (“Right to be Forgotten”): Request immediate and permanent deletion of your inquiry logs, diagnostic reports, and code snippets.
- Right to Object & Restrict Processing: Opt out of communications at any time.
07. Security Measures
We enforce modern cryptographic standards including TLS 1.3 encryption in transit, AES-256 encryption at rest, strict least-privilege role-based access controls (RBAC), and multi-factor authentication (MFA) across all administrative tools.
Contact Data Protection Officer (DPO)
For privacy inquiries, GDPR data deletion requests, or NDA execution, contact our data protection team:
