Privacy Policy
Last updated: 24 May 2026
1. Overview
This Privacy Policy describes how Swarming Labs LTD collects, uses, discloses, and protects information when you use Sparkling, an AI-powered trading agent operating within Telegram and accessible at sparkl.ing and through the Sparkling Telegram bot.
The policy applies globally. By using the Service, you acknowledge understanding these practices.
2. Data Controller
Swarming Labs LTD
Intershore Chambers, Road Town, Tortola
British Virgin Islands
Email: [email protected]
For EEA or UK users, contact the Data Protection Officer at [email protected].
3. Information We Collect
3.1 Information You Provide
- Account information: Telegram identifier, username, email address
- Authentication credentials: One-time passwords for wallet recovery (not stored retrievably)
- Identity verification: Government ID, proof of address, date of birth, biometric verification (processed by regulated partner)
- Communications: Messages to Sparkling, trade instructions, support requests
- Preferences and settings: Strategy parameters, notification preferences, language selection
3.2 Information Collected Automatically
- Transaction data: Swap quotes, signed transactions, agent strategy executions, transaction hashes
- Technical data: Device type, OS, Telegram client version, IP address (retained max 30 days unless fraud investigation), geographic region
- Usage data: Feature interactions, error logs, performance metrics, session metadata
3.3 Information From Third Parties
- Custodial wallet provider: Wallet addresses, transaction status, authentication events
- Settlement and routing partners: Execution data, routing decisions, pricing information
- Sanctions and compliance screening providers: Screening results for sanctions verification
3.4 On-Chain Information
Public blockchain data (wallet addresses, transaction amounts, counterparties, timing) is accessible to anyone and analyzed in connection with operating the Service and meeting compliance obligations.
4. How We Use Information
(a) To provide the Service. Routing instructions, executing transactions, displaying balances, operating configured Agents. Legal basis: contract performance.
(b) To authenticate and secure your account. Verifying logins, sending passwords, detecting suspicious access. Legal basis: contract performance; account security interests.
(c) To communicate with you. Sending transactional notifications and responding to support. Legal basis: contract performance; customer support interests.
(d) To improve the Service. Analyzing aggregated patterns, debugging errors, testing features. Legal basis: product development interests.
(e) To prevent fraud and abuse. Detecting bots, market manipulation, account takeovers. Legal basis: service integrity interests; anti-fraud and AML obligations.
(f) To comply with legal obligations. Responding to regulators, courts, and law enforcement; meeting record-keeping requirements. Legal basis: legal obligation.
(g) To verify identity where required (KYC/AML). Conducting identity verification, sanctions screening, transaction monitoring. Legal basis: legal obligation; compliance interests.
(h) To send service-related updates. Notifying of material changes to policies, terms, fees, or features. Legal basis: contract performance; service interests.
We do not use information for marketing without opt-in consent. We do not sell personal information.
5. How We Share Information
5.1 Service Providers
We share information with vendors including cloud infrastructure providers, email services, analytics providers, identity verification providers, and customer support tools. Each is bound by written data processing agreements.
5.2 Partners Integrated With the Service
- Wallet (by Telegram): Custodial wallet partner receiving provisioning instructions, signing requests, authentication events
- Liquidity providers and aggregators: Receive routing and execution data
- Settlement and clearing partners: Receive transaction data
Each is subject to their own privacy policy.
5.3 Legal and Regulatory Disclosure
We may disclose information to comply with law, regulation, legal process, or governmental requests; enforce Terms of Service; detect or address fraud or security issues; protect rights, property, or safety.
Where legally permitted, we notify users in advance.
5.4 Business Transfers
In merger, acquisition, or similar transaction, information may be transferred. The acquiring party will be bound by equally protective privacy commitments.
5.5 With Your Consent
We share information for other purposes only with express consent, which you may withdraw anytime.
6. International Data Transfers
Information may be transferred to and processed in countries outside your residence, including jurisdictions with lesser data protection.
For transfers from EEA, UK, or Switzerland to inadequate jurisdictions, we rely on:
- European Commission Standard Contractual Clauses (and UK International Data Transfer Addendum where applicable)
- Supplementary technical and organizational measures consistent with Schrems II
- Explicit consent or other lawful mechanisms
Copies of safeguards are available upon request to [email protected].
7. Data Retention
| Category | Retention Period |
|---|---|
| Account information | Duration plus 12 months after closure |
| Transaction records | 7 years from transaction date |
| KYC Information | 5 years after account closure |
| Support correspondence | 3 years from last interaction |
| Technical logs and IP addresses | 30 days (90 for security investigations) |
| Aggregated, de-identified analytics | Indefinite |
| Marketing consent records | Until withdrawal, plus 3 years |
Local law mandates different retention where applicable.
8. Your Rights
8.1 Rights Under GDPR (EEA, UK, Switzerland)
- Access: Request copy of personal information held
- Rectification: Request correction of inaccurate information
- Erasure: Request deletion, subject to retention obligations
- Restriction: Request processing restrictions in certain circumstances
- Portability: Receive information in structured, machine-readable format
- Objection: Object to processing based on legitimate interests or direct marketing
- Withdraw consent: Withdraw consent anytime; withdrawal doesn't affect prior processing legality
- Complaint: Lodge complaint with local data protection authority (EEA list: edpb.europa.eu; UK: ico.org.uk)
8.2 Rights Under CCPA/CPRA (California Residents)
- Right to know what personal information is collected, used, disclosed, sold, or shared
- Right to delete personal information, subject to exceptions
- Right to correct inaccurate information
- Right to opt out of sale or sharing — we do not sell or share personal information
- Right to limit use of sensitive personal information
- Right to non-discrimination for exercising rights
Contact [email protected] to exercise these rights.
8.3 Other Jurisdictions
Residents of Brazil (LGPD), Canada (PIPEDA), Australia (Privacy Act 1988), and other comprehensive data protection jurisdictions have similar rights. Contact us to exercise them.
8.4 How to Exercise Your Rights
Email [email protected] with:
- Your request and specific right being exercised
- Sufficient identity verification information (only necessary details requested)
- Email address associated with your Sparkling account
We respond within 30 days, extendable by 60 days for complex requests with notification.
9. Security
We implement technical and organizational measures protecting information against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access, including:
- TLS 1.3 encryption in transit
- Encryption of sensitive data at rest
- Multi-factor authentication for internal systems
- Role-based access controls with least-privilege principles
- Regular external security audits and penetration testing
- Vulnerability disclosure program (report to [email protected])
- Access logging and monitoring
- Employee data protection training
No system is completely secure. Report security issues to [email protected].
10. Children's Privacy
The Service is not directed to individuals under 18. We don't knowingly collect children's information. Upon learning of such collection, we promptly delete it. Contact [email protected] if you believe we've collected a child's information.
11. Automated Decision-Making
The Service uses automated processing for:
- Agent strategy execution: Agents propose trades based on your rules; you confirm each trade
- Fraud and security detection: Automated systems flag suspicious activity for human review
- Transaction monitoring: Automated systems screen against AML and sanctions criteria
Decisions with legal or significant effect (account suspension for fraud) involve human review before finalization. You have rights to request human intervention, express your viewpoint, and contest decisions.
12. Cookies and Tracking Technologies
The Sparkling website (sparkl.ing) uses strictly necessary cookies only. We don't use advertising cookies, identifying analytics cookies, or third-party tracking pixels.
The Sparkling Telegram bot doesn't place cookies. See our Cookie Policy for details.
13. Links to Third-Party Services
The Service may contain links to third-party websites, blockchain explorers, partner sites, and educational resources. This Policy doesn't apply to them. Review their privacy policies before sharing information.
14. Changes to This Policy
We may update this Policy. Material changes are notified at least 30 days before taking effect via in-app notification, email, or both. The “Last updated” date reflects the current version. Continued use after the effective date constitutes acceptance.
Material revision history is available upon request.
15. Contact Us
| Purpose | |
|---|---|
| General privacy inquiries | [email protected] |
| Data subject rights requests | [email protected] |
| Data Protection Officer (EEA/UK) | [email protected] |
| Security vulnerabilities | [email protected] |
| Legal notices | [email protected] |
Postal address:
Swarming Labs LTD
Intershore Chambers, Road Town, Tortola
British Virgin Islands