This Privacy Policy explains how the operator of the Spoonspring website and related services (“Spoonspring”, “we”, “us”, or “our”) collects, uses, stores, discloses, and otherwise processes information when you use Spoonspring. It is designed to meet disclosure expectations under the EU/UK General Data Protection Regulation (GDPR / UK GDPR), the EU ePrivacy rules for essential cookies, the California Consumer Privacy Act as amended by the CPRA (“CCPA”), other US state privacy laws that use similar categories, and the US Children’s Online Privacy Protection Act (“COPPA”).
This policy is a disclosure document. It is not legal advice to you, and it does not create rights beyond those the law already gives you. If you do not agree with this policy, do not use Spoonspring.
Who we are. Spoonspring is operated by the person or organization that publishes this website (the “operator”). For GDPR purposes, the operator is the data controller of personal data processed through Spoonspring, unless a hosting or other provider is independently a controller of its own logs. Because this service may be self-hosted or run without a registered company name on the site, the controller is the operator of the domain or instance you are using. Contact the operator using any contact method they publish, or by emailing privacy@ followed by the domain name of this site (for example, if you are using example.com, try privacy@example.com). If that mailbox is not monitored, use the operator’s published contact details.
1. Scope
This policy covers the public “Pot”, private sprung workspaces, cookie-based anonymous sessions, uploads (text, photos, audio, sketches), feeding layers, skill pledges, workspace messages, scratchpads, and browser notifications you enable. It does not cover third-party websites you reach by following links, or the privacy practices of other people who post on Spoonspring.
2. Age and children
Spoonspring is not directed to children under 13, and we do not knowingly collect personal information from children under 13 (COPPA). If you are under 13, do not use Spoonspring. If you believe a child under 13 has provided information, contact us and we will delete it.
If you are in a country in the EEA, UK, or Switzerland where the digital age of consent is 16 (or another age set by local law), you must be that age, or your parent or guardian must consent, before you use Spoonspring. Parents and guardians may contact us to review or delete a child’s information.
3. Information we collect
We collect the following categories. We do not require a name, email, or password.
- Anonymous session identifier. A random ID stored in an HTTP-only cookie named
spoonspring_sid. This is how we know which spoons, pledges, and rooms are yours on this browser. If you clear cookies, you lose access to that identity. We cannot recover it. - Generated handle. A public nickname we create for you (for example on feeding layers, pledges, and workspace rosters). It is not your legal name.
- User-generated content you choose to post. Spoon text (up to 280 characters), captions, photos, sketches, voice recordings (about 30 seconds), feeding layers (including critique), skill pledges, workspace chat messages, and scratchpad text. Photos, audio, and sketches are stored as files we host so they can be displayed to others as described below.
- Activity and product data. Energy scores, whether a spoon has sprung or wilted, timestamps, expiration dates, which skills you pledged, workspace membership and role, and spring notices we store so we can tell you that your spoon sprung.
- Technical data. Your browser may send an IP address, user agent, and similar connection data to the server that hosts Spoonspring. We also use Google Analytics (measurement ID
G-S0C06PHDST) to understand aggregate traffic and how the site is used, and Google AdSense (publisher IDca-pub-1566573312352415) to show ads. Google may collect device and usage data, including IP address, pages viewed, approximate location, and advertising identifiers, under Google’s privacy policy. Hosting, reverse-proxy, or server logs (if enabled by the operator or their host) may retain connection data for security, abuse handling, and reliability, typically for a short period. - Device preferences you set. Accessibility settings (contrast, text size, motion, underlined links) and whether you dismissed a notification prompt are stored in your browser’s localStorage, not on our servers.
- Notification permission. If you allow browser notifications, your browser (not our server) holds that permission. We send a notification from this device when we learn that your spoon has sprung, including a short preview of the spoon text.
We do not intentionally collect government IDs, payment card numbers, precise GPS, health data, or login passwords. Do not post sensitive personal data about yourself or others. If you do, it may become public on The Pot and we may still process it as user-generated content in order to host the service and, where appropriate, to remove it.
Audio you record is used only to play back your voice note as content. We do not use audio for biometric identification, voiceprints, or advertising.
4. Sources
We collect information directly from you (posts, uploads, pledges, messages, settings) and automatically from your device (the session cookie, ordinary HTTP request data, Google Analytics, and Google AdSense). We do not buy personal data from data brokers.
5. How The Pot and workspaces treat your content
The Pot is public. Live spoons, photos, sketches, audio, captions, feeding layers, and pledge skills are visible to anyone using the service. We hide your identity as creator on public cards, but we do not promise anonymity. Handles appear on layers and pledges. Do not post anything you need to keep secret, confidential, or unpublished. Ideas dropped into The Pot are not a substitute for a patent filing, NDA, or other legal protection.
Sprung workspaces are restricted to the creator and users who pledged a skill on that spoon. They are not a guarantee of confidentiality. Members can copy content. The operator can access workspace data as needed to run, secure, and legally operate the service.
Live spoons expire after 14 days if they do not spring (“wilt”). Wilted spoons leave The Pot but may remain associated with your session on the Yours page. Sprung workspace content remains until the operator deletes it or the service is shut down.
6. Purposes and legal bases (GDPR / UK GDPR)
If EU/UK data protection law applies, we process personal data on these bases:
- Contract / requested service (Art. 6(1)(b)). Creating your anonymous session, hosting your spoons and uploads, showing The Pot, counting energy, opening a workspace, delivering spring notices, and keeping Yours in sync with your cookie.
- Legitimate interests (Art. 6(1)(f)). Keeping the service stable and secure, preventing abuse and illegal content, debugging, and understanding coarse usage so the product still works. You may object as described below.
- Consent (Art. 6(1)(a)). Optional browser notifications. You can refuse or later revoke permission in your browser settings. Accessibility preferences stored only on your device are not a server-side consent collection.
- Legal obligation (Art. 6(1)(c)). Where we must retain or disclose information to comply with law, a valid legal request, or to establish or defend legal claims.
The session cookie is strictly necessary to provide the service you requested (so you can have “your” spoons without an account). It is not used for advertising. Under the ePrivacy Directive, strictly necessary cookies do not require a marketing-style consent banner. This policy is the disclosure.
7. Cookies and similar technologies
spoonspring_sid— HTTP-only, SameSite=Lax, path=/, up to 365 days. Purpose: anonymous session. Essential.spoonspring_a11yandspoonspring_ping_dismissed— in localStorage on your device. Purpose: accessibility and whether you dismissed the ping prompt. Not sent to us automatically.- Google Analytics cookies such as
_gaand_ga_*, set by Google’s gtag script. Purpose: usage analytics (pages viewed, sessions, approximate geography). These are not required to use Spoonspring. You can block them with a browser or extension that refuses analytics cookies. - Google AdSense cookies and similar identifiers set by Google’s ads script (publisher
ca-pub-1566573312352415). Purpose: select, measure, and limit ads. These are advertising cookies. You can block them with a browser, extension, or Google’s ad settings.
Real-time updates use a Socket.IO connection from your browser to this site’s server. Google AdSense may use personal information for advertising, including interest-based ads, as described in Google’s policies. You can opt out of personalized ads via Google’s ad settings or industry tools such as the Network Advertising Initiative opt-out.
Fonts are self-hosted by the application where Next.js font loading is used, so your browser is not sent to Google Fonts at runtime for those faces.
8. When we disclose information
We disclose information:
- Publicly, when you post to The Pot (content you chose to publish).
- To workspace members, when a spoon springs.
- To service providers who host, store, transmit, measure, or monetize the site (for example a VPS, object storage, CDN, Google Analytics, or Google AdSense), only as needed to run Spoonspring, under their terms.
- If required by law, regulation, legal process, or governmental request, or to protect the rights, safety, or property of users, the public, or the operator.
- In a merger, sale, or transfer of the service, subject to this policy or notice of changes.
We do not sell your personal information for money. We do not use your content to train public AI models as a product feature of Spoonspring. The operator’s own devices may process data as needed to maintain the instance.
9. Retention
- Session cookie: up to 13 months unless you clear it sooner.
- Live spoons: until they spring or wilt (14 days from drop), then they leave The Pot.
- Wilted spoons: may remain tied to your session for your Yours page until deleted.
- Sprung workspaces, messages, and scratchpads: until deleted by the operator or you lose the session.
- Uploads: for as long as the related spoon or layer is stored.
- Spring notices: until they are no longer needed to inform you, then they may be deleted.
- Server logs (if any): typically days to weeks, unless needed for security or legal matters.
Because identity is a cookie, we may not be able to find “your” data if you contact us from a different browser. Describe the handle, approximate time, and content if you want help deleting public posts.
10. Security
We use reasonable technical and organizational measures appropriate to a small anonymous idea board (HTTPS where the operator enables it, HTTP-only session cookie, workspace membership checks). No method of transmission or storage is 100% secure. Public posts should be treated as public. Do not upload content you cannot afford to have copied or leaked.
11. International transfers
The operator and their hosting provider may process data in a country other than yours, including the United States or the country where the server is located. Where GDPR requires a transfer tool, the operator relies on the necessity of the transfer to perform the service you requested and/or standard contractual clauses or the host’s published transfer mechanism, as applicable to that instance.
12. Your rights (EEA, UK, Switzerland)
Subject to the law, you may have the right to access, rectify, erase, restrict, or object to processing, to data portability, and to withdraw consent (for notifications) without affecting prior processing. You may complain to your local supervisory authority (for example the ICO in the UK, or your EU member state DPA). You can often erase much of your live identity yourself by clearing this site’s cookies, which drops the session link; public copies of content you posted may remain until we remove them.
To exercise rights, contact the operator as described above and tell us what you want deleted or exported. We may need enough information to locate the records. We will not honor requests that appear abusive or that would violate others’ rights.
13. Your rights (California and other US states)
If you are a California resident, we provide this Notice at Collection. In the past 12 months we may have collected the categories in section 3: identifiers (session ID, handle), internet / electronic activity, audio/visual content you upload, and inferences limited to product state (energy, sprung, wilted). We use them for the purposes in sections 5–6. We do not sell personal information for money. Google AdSense may use information for advertising that some US state laws treat as “sharing” or targeted advertising. Use Google’s ad settings or a browser/extension block to opt out. We do not use or disclose sensitive personal information for purposes that require a CPRA right-to-limit notice, because we do not seek sensitive PI; if you embed it in a post, treat it as user content.
You may request to know, access, correct, or delete personal information, and to not be discriminated against for exercising CCPA rights. We will not be able to verify a request as easily as a password account would; the session cookie on your device is the primary authenticator. Authorized agents may contact us with proof of authorization. Other state laws (for example Virginia, Colorado, Connecticut, Utah, Texas, Oregon, and similar) may give comparable rights to know, delete, correct, or opt out of targeted advertising or sales; AdSense advertising is described above.
We do not currently respond to Do Not Track signals with a separate change in behavior. Clearing cookies, using a blocker, or Google’s ad settings is the practical opt-out of analytics and ads cookies. Clearing this site’s cookies also drops the Spoonspring session.
14. Automated decision-making
Energy reaching 100 automatically opens a workspace for the creator and pledgers. That is product logic you can see, not credit scoring, employment, or similarly significant legal effects under GDPR Art. 22. Google may profile browsing for ads under its own terms; Spoonspring does not run a separate advertising profile of your spoons or workspaces.
15. User content, photos, and voice
You choose what to upload. You should not upload images or recordings of other people without a legal basis (for example their permission). You should not upload illegal content. We may remove content that appears to violate the law or our terms. Public photos are displayed on cards and can be enlarged; treat them as public.
16. Changes
We may update this policy. The “Last updated” date will change. Continued use after an update means the new policy applies to subsequent processing. Material changes should be posted on this page.
17. Contact and complaints
Privacy requests: contact the operator of this Spoonspring instance (see “Who we are” above). EU/UK users may also contact their data protection authority. California residents may contact the operator for CCPA requests; the California Privacy Protection Agency and the Attorney General also publish consumer information.
If this instance lists a more specific privacy email or postal address elsewhere, use that address instead of the domain guess above.
