Launch a coin for your favorite creatorThey earn fees on every tradesprk.ggTokens live on pump.funCreators: claim your feesBuilt for creators
sprk

Spark Privacy Policy

This Privacy Policy explains how Spark Social Inc. ("Spark," "we," "us," or "our") collects, uses, discloses, and safeguards information when you use Spark, our web application available at sprk.gg that helps you launch memecoins on pump.fun (a third-party protocol on the Solana blockchain) and helps named TikTok creators claim creator fees. Last updated: August 18, 2026. This document is a draft prepared for review by a licensed attorney and does not constitute legal advice. By using Spark, you agree to the practices described here. If you do not agree, do not use Spark. Spark Social Inc. is a wholly owned subsidiary of OnlyUp Corp.

Who We Are and Scope

Spark is operated by Spark Social Inc. We are a software provider only. We are not a broker, dealer, exchange, money transmitter, custodian for investment purposes, investment adviser, or financial institution, and we provide no financial, investment, legal, or tax advice.

This Privacy Policy applies to information we process through the Spark web application and website at sprk.gg. It does not apply to third-party services and protocols that operate independently of us, including pump.fun, the Solana blockchain, TikTok, IPFS networks, or wallet providers such as Reown/WalletConnect. We are not affiliated with, endorsed by, or sponsored by any of these parties, and their handling of your information is governed by their own policies, not this one.

Trading of tokens occurs on pump.fun and on the Solana blockchain, not on Spark.

Information We Collect

We collect the following categories of information when you use Spark:

Information You Provide

  • TikTok creator identifiers: When you launch a token, you must name a TikTok creator. The username or handle you provide is collected and stored so we can associate the token, generate the creator's fee wallet, and enable verification and claiming.
  • Token metadata and images: The token name, ticker, description, image, and any optional links you supply when launching a token.
  • Wallet addresses: The self-custodial wallet address you connect via WalletConnect to sign the creation transaction, any address you designate to receive withdrawn creator fees, and the on-chain address of the custodial creator-fee wallet.

Information We Read for Verification

  • Public TikTok profile and bio data: To verify that a person claiming a creator wallet controls the named TikTok account, we read the public profile page and bio of that TikTok account to confirm the presence of a unique claim link (sprk.gg/<code>). We read only publicly available information. We do not log in to TikTok, do not access private messages or non-public account data, and do not act on your behalf inside TikTok.

Information Generated by the Service

  • Claim codes: The unique code embedded in your claim link (sprk.gg/<code>) used to match a claim to a token and creator wallet.
  • Custodial private keys: For each named TikTok creator, we generate a custodial Solana wallet on our backend and temporarily hold its private key in encrypted form until the verified creator claims and withdraws or exports it. See 'Custodial Keys' below.

Information Collected Automatically

  • IP addresses and request logs: We collect IP addresses, timestamps, user-agent strings, and basic request logs.
  • Rate-limiting and anti-abuse data: Data used to detect and prevent abuse, fraud, and automated attacks, which may be derived from IP addresses and request patterns.
  • Cookies: A signed HMAC session cookie used to maintain your claim session, and a per-browser claim nonce cookie used during the claim flow. See 'Cookies' below.

How We Use Information

We use the information we collect to:

  • Operate, maintain, and provide the Spark service, including creating tokens on pump.fun and enabling the claim flow.
  • Verify that a person claiming a creator fee wallet controls the named public TikTok account, by reading the public bio for the claim link.
  • Manage custodial fee wallets, including securely generating, encrypting, storing, and releasing custodial private keys to verified creators.
  • Maintain security and prevent abuse, fraud, and unauthorized access, including rate-limiting and detecting automated or malicious activity.
  • Communicate with you about the service, respond to requests sent to contact@sprk.gg, and enforce our terms.
  • Comply with applicable law and legal obligations.

We do not sell your personal information.

Custodial Keys

When a token is launched, Spark generates a custodial Solana wallet for the named TikTok creator and sets it as the token's on-chain creator-fee recipient on pump.fun. The private key for that wallet is encrypted at rest and held by us only temporarily.

The private key is revealed only to the creator who successfully proves control of the named TikTok account through the verification process. Once verified, the creator may withdraw the wallet's SOL to any address or export the private key.

You acknowledge the inherent risks of custodial and blockchain systems, including key compromise or loss, smart-contract and protocol risk on pump.fun and Solana, the irreversibility of blockchain transactions, and the fact that lost keys and mistaken transfers cannot be recovered. We provide the service 'as is' and disclaim liability to the maximum extent permitted by law, as described in our Terms.

Public Blockchain Data

Spark interacts with public blockchains. Token creation, trading, fee routing, transfers, and wallet addresses are recorded on the Solana blockchain and, through pump.fun and IPFS, token metadata and images may be published to public, decentralized networks.

Information recorded on a public blockchain or a decentralized storage network is permanent, public, and outside our control. We cannot modify, delete, or restrict access to on-chain data or to metadata and images once they are published. Do not submit any information you are unwilling to make permanently public.

Third Parties and Subprocessors

We rely on the following third-party service providers to operate Spark. These providers process information on our behalf or as part of the service:

  • Supabase: database hosting and storage of application data.
  • Vercel: application and website hosting.
  • Helius: Solana blockchain RPC and network access.
  • pump.fun and IPFS: token creation, trading, and hosting of token metadata and images.
  • TikTok public pages: read for the sole purpose of verifying creator ownership via the public bio.

Each third party operates under its own terms and privacy practices, which we do not control. We may also disclose information where required by law, to enforce our terms, to protect the rights, safety, or property of Spark Social Inc. or others, or in connection with a corporate transaction such as a merger or acquisition.

Cookies

Spark uses a small number of cookies that are necessary for the service to function:

  • HMAC session cookie: a signed cookie used to maintain your authenticated claim session.
  • Claim nonce cookie: a per-browser cookie used to secure the claim flow against replay and cross-site attacks.

These cookies are essential to operating the claim process and security features. If you block or delete them, parts of the service, including claiming, may not work. We do not use these cookies for advertising.

Data Retention

We retain information for as long as necessary to provide the service, comply with our legal obligations, resolve disputes, and enforce our agreements.

Custodial private keys are retained in encrypted form only until the verified creator withdraws or exports the wallet, after which we aim to remove our stored copy of the key in the ordinary course. Application data such as token metadata, TikTok usernames, wallet addresses, and claim codes may be retained to maintain records of launched tokens and to operate verification and claiming.

Logs, IP addresses, and rate-limiting data are retained for a limited period sufficient for security and operational purposes.

Information recorded on public blockchains or decentralized storage networks cannot be deleted by us and will persist regardless of our retention practices.

Security

We take reasonable technical and organizational measures designed to protect information, including encrypting custodial private keys at rest and restricting access to sensitive data.

No method of transmission or storage is completely secure, and we cannot guarantee absolute security. You are responsible for safeguarding your own self-custodial wallet, your exported private keys, and your access credentials. To the maximum extent permitted by law, we disclaim liability for unauthorized access, key compromise, or loss of funds.

Children

Spark is not directed to and may not be used by anyone under 18 years of age. You must be at least 18 and legally permitted to use Spark. We do not knowingly collect personal information from anyone under 18. If we learn that we have collected such information, we will take reasonable steps to delete it. If you believe a minor has provided information to us, contact us at contact@sprk.gg.

International Users and Data Transfers

Spark is operated from the United States, and our service providers may process information in the United States and other countries. If you access Spark from outside the United States, you understand that your information may be transferred to, stored in, and processed in jurisdictions whose data protection laws may differ from those of your own.

You are responsible for complying with the laws that apply to you. You may not use Spark if you are located in a sanctioned jurisdiction, are on a sanctions list, or are otherwise prohibited from using the service. By using Spark, you consent to the transfer and processing of your information as described in this policy.

Your Rights and How to Exercise Them

Depending on where you live, you may have rights regarding your personal information, such as the right to access, correct, delete, or restrict the processing of certain data, or to object to processing. To exercise any available right, or to ask a question about this policy, contact us at contact@sprk.gg.

We will respond to verifiable requests consistent with applicable law. Please note two important limits: we cannot alter or delete information recorded on public blockchains or decentralized storage networks, and we may need to retain certain information to comply with legal obligations, provide the service, or protect against fraud and abuse.

Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will revise the 'Last updated' date above. Material changes may be communicated through the service or by other reasonable means. Your continued use of Spark after an update becomes effective constitutes acceptance of the revised policy.

Contact and Governing Law

If you have questions or requests regarding this Privacy Policy or your information, contact us at contact@sprk.gg.

This Privacy Policy is governed by the laws of the State of Delaware, USA, without regard to its conflict-of-laws principles (governing law is adjustable and should be confirmed by counsel).

This is a draft for review by a licensed attorney and is not legal advice.