Spryly™

Privacy Policy

Last updated: August 24, 2026

This Privacy Policy describes how Spryly™ ("Spryly™," "we," "us," or "our"), a product of LateralTranslucence, collects, uses, and protects information when you use spryly.io (the "Service").

1. Information We Collect

Account Information

When you create a Spryly™ account, we collect your email address and a password (which is securely hashed and never stored in plain text). We use Supabase as our authentication and database provider to store this information.

Package and Project Data

Spryly™ stores the information you provide to use the Service, including:

Service Status Data

If you use the Services tab to track the status of platforms you depend on (such as Cloudflare, AWS, GitHub, Slack, or Stripe), we store:

We do not store the historical status data itself — current status is fetched from each platform's public status page each time it's checked.

GitHub Account Connection (Optional)

If you choose to connect GitHub to use the repository scanning feature, we collect:

Spryly™ connects as a GitHub App holding Contents: read-only and Metadata: read-only permissions, on the repositories you select when installing it. We store no GitHub access token. Access is issued for one hour at a time using our own signing key and is never written to our database. You can remove an installation at any time from GitHub or from your profile settings.

What We Read From Your Repositories

When you run a scan, we read dependency manifests and lockfiles — files such as package.json, package-lock.json, requirements.txt, composer.json, or go.mod — to identify dependency names and versions.

When you request an upgrade briefing on a Pro account for a project backed by a GitHub repository, we additionally read source files from that repository in order to locate where the identifiers named in a release's notes appear in your code. This happens only at the moment you request a briefing, and only for that repository.

Those repository contents are searched in memory and discarded when the request finishes. We do not store your source code, and we never send it to an AI model or any other third party — only publicly published release notes are sent for summarization. See our AI Policy for exactly what is and is not sent.

GitLab Account Connection (Optional)

If you choose to connect a GitLab account, we collect:

We request read-only scopes only (read_api and read_user). GitLab tokens are stored server-side, are never sent to your browser, and are removed when you disconnect the account from your profile settings. The reading described above applies equally, except that per-codebase impact matching is currently available for GitHub repositories only.

Payment Information

If you subscribe to Spryly™ Pro, payment is processed by Stripe. We do not store your credit card number or payment details — Stripe handles all payment processing and stores your billing information on our behalf. We store only a Stripe customer ID in order to manage your subscription.

Automatically Collected Information

With your consent, we use Google Analytics 4 to understand how visitors use the Service in aggregate. Google Analytics collects information such as pages visited, time spent on the Service, browser type, device type, and approximate geographic location (derived from your IP address). This data is processed by Google and is not used to personally identify you. You can opt out of Google Analytics tracking using Google's opt-out browser add-on, or by declining analytics in our cookie banner.

We also use Fathom Analytics to measure page views and a small number of product actions, such as starting a repository scan or sending us a message. Fathom sets no cookies, stores nothing on your device, and collects no personal data — its measurements are anonymous and aggregate, and cannot be traced back to you or followed across other websites. Because there is nothing personal to collect, Fathom runs without consent and there is no profile of you to opt out of.

We also collect basic technical information as part of standard server logging (such as IP address and browser type) necessary to operate the Service.

2. How We Use Your Information

We use the information we collect to:

3. Third-Party Services

Spryly™ relies on the following third-party services to operate:

We do not sell your personal information to third parties.

4. Data Retention and Deletion

We retain your account and package data for as long as your account remains active. If you delete your account, we immediately and permanently delete your profile, tracked packages, tracked platforms, project associations, and all connected GitHub and GitLab account tokens. Any active paid subscription is cancelled at the same time.

You can delete your account at any time through your profile settings, or by contacting us at hi@spryly.io.

5. Data Security

We take reasonable measures to protect your information, including encryption in transit (HTTPS), access controls on our database via Supabase's row-level security policies (which ensure each user can only access their own data), and secure storage of authentication tokens. However, no method of transmission or storage is 100% secure, and we cannot guarantee absolute security.

6. Your Rights

Depending on your location, you may have rights under applicable data protection laws (such as the GDPR or CCPA), including the right to:

To exercise any of these rights, contact us at hi@spryly.io.

7. Children's Privacy

Spryly™ is not directed to individuals under the age of 16, and we do not knowingly collect personal information from children.

8. International Users

Spryly™'s infrastructure is hosted via Supabase, which may store data in data centers located outside your country of residence. By using the Service, you consent to the transfer of your information to these locations.

9. Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify users via the Service or by email. Continued use of the Service after changes take effect constitutes acceptance of the revised policy.

10. Contact Us

If you have questions about this Privacy Policy or how your data is handled, contact us at:

hi@spryly.io LateralTranslucence

Contact us