Spark (“Spark,” “we,” “us,” or “our”) is an iMessage booking assistant for NYC restaurants and bars (iPhone and Messages), provided by Faro.io Corp (“Hello Faro”). This policy explains what information the app handles.
The short version: Spark works without an account and keeps your plans on your device. Creating one — in the app, or on our website — is what lets us sync your nights and act on your behalf. We don’t sell your data, run ads, or track you.
The short version
- No account required. You can use Spark fully without signing in. Your saved plans and preferences live on your device.
- Optional Sign in with Apple. If you choose to sign in, we create an account so your saved nights and plan history sync across your devices — nothing more.
- No tracking, no ads, no analytics SDKs. We don’t track you across apps or sites and don’t sell or share personal information for advertising.
- We call a few services to make the app work — restaurant availability, photos, and review highlights — but those requests are about venues, not about you.
Information we collect
If you don’t sign in
Nothing personal. Your saved itineraries, preferences (budget, dates, cuisines, neighborhoods), and settings are stored locally on your iPhone and are not sent to us. Uninstalling the app removes them.
Location (only for “Spark it”)
If you use the “Spark it” nearby feature and grant permission, Spark uses your device’s approximate location while you’re using the app to show and sort venues near you. This happens on your device — we don’t store your location on our servers. You can decline, and the app falls back to a default neighborhood.
If you choose to Sign in with Apple
Signing in is optional and exists to sync your saved nights. When you use Sign in with Apple, we receive:
- A unique Apple user identifier for your account (an opaque ID, not your name).
- Your email address, only if you choose to share it. Apple lets you hide your real email with a private relay address; either way, we use it only to identify your account and to contact you about the service if necessary. We never receive your Apple ID password.
We do not receive your name, contacts, precise location, or payment information.
Data that syncs to your account
When you’re signed in, the following is stored on our backend (hosted on Convex) so it can sync across your devices. Every query is scoped to the signed-in account, and none of them accepts another person’s identifier as an argument, so only you can read it:
- Saved itineraries (“saved nights”) you bookmark.
- Plan history — nights you’ve planned or matched on (used to improve your experience, e.g. avoiding repeats).
Your device remains the source of truth; signing in merges your on-device saved nights with your account so nothing is lost. Signing out stops syncing and leaves your data on the device.
Information we do not collect
- We do not collect your name, contacts, or precise GPS location.
- We do not track you across other apps and websites, and we use no advertising identifiers or third-party advertising/analytics SDKs.
- We do not sell or rent personal information to anyone.
Information shared inside iMessage
When you use Spark inside an iMessage conversation, your choices for that night (your vibe, the deck of options, your likes) are encoded into the iMessage message itself and exchanged with the person you’re messaging, through Apple’s end-to-end-encrypted iMessage — not routed through or stored on our servers. Only you and the person in your conversation can see it.
Information processed by our backend (about venues, not you)
To show live information, the app sends requests to our backend and the third-party services below. These requests contain information about the venues being planned — a restaurant’s name, neighborhood, identifier, and the date you’re considering — and, when you’re signed in, your account’s access token so your private data can be retrieved securely. As with any internet service, our servers and providers automatically receive standard technical data such as your device’s IP address, used only to operate, secure, and debug the service.
Specifically, the app may request:
- Restaurant availability — whether a venue has reservations on your chosen date (Resy’s public availability data).
- Venue photos — restaurant images (Google Places).
- “What people say” review highlights — short summaries generated from publicly available venue reviews. To create these, venue names and public review text are processed by an AI provider (OpenAI or Google Gemini). No information about you is included.
We cache venue data (availability, photos, review summaries) on our backend to keep the app fast. That cache is about venues, not users.
Reservations and maps
Spark can help you get a table in two ways:
- Hand-off links. When you tap to book or open directions, Spark may open a third-party app or website (Resy, OpenTable, Apple Maps, or Google Maps). What you do there is governed by that company’s terms and privacy policy.
- In-chat booking (when available). With your explicit say-so, Spark can ask Ophelia to complete a reservation on your own Resy or OpenTable account. To do that we store the reservation details you provide (name, email, phone) so they match that account. Ophelia drives the booking flow; the table lands under your identity and remains cancellable by you there. If the dining network requires a one-time code, you paste it into the Spark chat — we use it only to continue that booking and do not keep it as a password. Spark never asks for your Resy or OpenTable password and does not process card payments itself; if a venue needs a card, you enter it on their own page.
In-chat booking is rolling out and is not available for every venue or every ask. Where it is not available, Spark falls back to a link or says so plainly rather than claiming a reservation it did not place.
Third-party services we rely on
Their handling of any data they receive is governed by their own privacy policies:
- Apple — App Store, TestFlight, iMessage, and Sign in with Apple. (policy)
- Convex — backend hosting, authentication, and storage of synced account data. (policy)
- Vercel — hosting our website. (policy)
- Resend — sending you email, such as a sign-in link. (policy)
- RevenueCat and Stripe — subscriptions and payment. Card details are entered on their pages; we never receive or store them. (RevenueCat / Stripe)
- Ophelia — when you ask Spark to book in chat, Ophelia completes the reservation on your own dining account (identity + optional one-time code you paste). (site)
- Resy — restaurant availability and booking links; your own account holds the reservation. (policy)
- Google Maps Platform / Places — venue photos, place data, and map directions. (policy)
- Anthropic and/or OpenAI — generating short summaries from public venue reviews, and replying when you message Spark. (Anthropic / OpenAI)
Children’s privacy
Spark is intended for adults planning a night out and is not directed to children under 13 (or the equivalent minimum age in your region). We do not knowingly collect personal information from children.
Data retention
- On your device: kept until you delete it in the app or uninstall Spark.
- In your account (if you sign in): kept until you delete it or ask us to. We retain only your synced saved nights and plan history, plus the minimal account identifier.
- Venue cache and technical logs: retained as long as reasonably necessary to operate and secure the service.
Your choices and rights
- Use Spark without an account at any time.
- Sign out to stop syncing (your data stays on your device).
- Delete your account yourself, at any time: in the app under Profile → Account, or on our website under Your account → Delete your account. This removes the account, your saved nights, photos you contributed and lists you own. You can also email peter@hellofaro.io.
- Deleting your account does not cancel a restaurant reservation. Those are held in your own Resy or OpenTable account, and you cancel them there.
- We do not “sell” or “share” personal information as defined under laws such as the California Consumer Privacy Act (CCPA). Where the EU/UK GDPR applies, our processing of account data is based on performing the service you requested and our legitimate interest in operating and securing the app.
Security
We use reputable infrastructure providers and reasonable measures to protect the limited data the service handles, including per-user access controls on your synced data. No method of transmission or storage is 100% secure, but Spark is designed to hold as little personal information as possible.
Changes to this policy
If we change how the app handles data, we’ll update this policy and revise the “Effective date” above. Material changes will be reflected in the app or on this page.
Contact
Faro.io Corp (“Hello Faro”)
Email: peter@hellofaro.io
© 2026 Hello Faro · Spark