Privacy Policy
Last updated 27 August 2026
Who we are
MessageKit is a product of SparrowSoft. In this policy “we” and “us” mean SparrowSoft, and “you” means the person or business using MessageKit. You can reach us at legal@sparrowsoft.co.
Whose data this is
There are two different relationships in this policy and it matters which one applies.
- Your own account. For information about you — the person who signs in — we decide what is collected and why. This policy governs it.
- Your contacts. For the subscriber lists you upload or collect through MessageKit, you decide what is collected and why, and we act on your instructions. You are responsible for having the right to hold those addresses and for the privacy notice you give the people on them. We keep each organization's contacts separate from every other organization's; the same address appearing under two customers is two unrelated records, and unsubscribing from one has no effect on the other.
What we collect
- Account information — your email address, the sign-in codes we send you, any passkeys you enrol, and your role in an organization.
- What you create — organizations, brands, colours, fonts, logos and other uploaded images, posts, emails, and content modules.
- Contact data you provide — the email addresses, names and consent records of the people on your audiences, and whether each of them is pending, confirmed or unsubscribed.
- Billing information — your subscription and payment history. Card numbers go directly to our payment processor and never reach our servers.
- Security and technical records — sign-in attempts, active sessions, IP addresses, and ordinary server logs.
We do not buy personal information, we do not sell it, and we do not track you across other websites.
How we use it
To run the service, sign you in, generate and publish the content you ask for, deliver the messages you send, bill you, keep accounts secure, and answer you when you get in touch. We do not use your content or your contacts to train machine-learning models, and we do not send you marketing you did not ask for.
Service providers
We use the following companies to run MessageKit. Each receives only what it needs for its part of the job.
| Provider | What it does |
|---|---|
| Railway | Hosts the application and its database |
| Cloudflare R2 | Stores uploaded images and generated artwork |
| Anthropic | Generates draft copy and suggestions from the prompts you submit |
| Amazon SES | Delivers the email campaigns you send to your audience |
| Postmark | Delivers sign-in codes and subscription confirmations |
| Twilio | Delivers the text messages you send, and receives replies to them |
| Buffer | Publishes your posts to the social accounts you have connected |
| Stripe | Processes subscription payments |
| Unsplash | Provides stock photography when you search for it |
| Google Fonts | Serves the typefaces the interface is set in |
We may also disclose information if the law requires it, or if a business transfer means somebody else takes over running MessageKit — in which case this policy travels with the data.
Consent and unsubscribing
Somebody joining one of your audiences is not subscribed until they confirm it: signing up sends a confirmation email, and nothing is delivered to an address that never answers it. Every confirmation and unsubscribe link is a signed link rather than a stored token, so there is no table of secrets to leak, and an unsubscribe link does not expire.
If an address bounces hard or somebody reports a message as spam, we suppress that address across all of your lists at once and record why. Importing a list requires you to state where the consent came from, and importing can never resurrect somebody who has already unsubscribed.
Cookies
We set two, both strictly necessary: one that keeps you signed in, and one short-lived cookie that ties the sign-in code we email you to the browser that asked for it. There are no advertising cookies and no third-party analytics on this site.
Keeping it safe
Traffic is encrypted in transit. Sensitive values such as your publishing credentials are encrypted in our database. Sign-in is by emailed code or passkey — we do not store passwords — and requests for codes are rate limited. Every query the application makes is scoped to a single organization, which is how one customer's data stays invisible to another.
How long we keep it
Your content stays until you delete it or close your account. When an account or organization is deleted we remove its data, including uploaded images, within 30 days, apart from anything we must keep for legal or accounting reasons and suppression records — we keep the fact that an address must not be mailed, because losing it would mean mailing somebody who asked us not to.
Your rights
Depending on where you live you may have the right to see the personal information we hold about you, correct it, delete it, or receive a copy of it. Write to legal@sparrowsoft.co and we will respond within 30 days. If your request concerns an address on a customer's mailing list rather than your own MessageKit account, we will pass it to that customer, who is the one who decides.
Where the data lives
MessageKit is operated from the United States and the providers above may process information there. If you are using it from elsewhere, that is where your information is going.
Children
MessageKit is a tool for businesses and is not directed at children. We do not knowingly collect information from anyone under 16.
Changes
If we change this policy we will update the date at the top, and we will tell account holders by email before anything material takes effect.
Questions: legal@sparrowsoft.co. See also our Terms of Service.