Legal
Spark Tray — Privacy Policy
Effective date: August 4, 2026
Product: Spark Tray
Provider: Clearware, LLC, a Delaware limited liability company ("Clearware," "we," "us," or "our")
Contact: info@clearware.co · https://sparktray.io
The short version (plain-language summary)
This summary highlights the key points. The full policy below controls.
- Spark Tray runs on your device. The media you download, transcribe, or edit, and the settings and history that go with it, stay on your computer. We do not upload them.
- We do not collect your files, URLs, or filenames. Our crash and usage reporting is built with a code-level filter designed to strip out URLs, file paths, filenames, and media content before anything is sent.
- How Spark Tray is funded: bandwidth sharing. While the app is installed, it shares a portion of your idle internet bandwidth through a bundled partner network (Massive) to relay other parties' traffic. This runs in the background and keeps sharing even after you close Spark Tray, until you turn it off or uninstall. It does not read or upload your data. See Section 3. This is disclosed in the EULA and shown by an in-app status indicator and by Massive's own system-tray control.
- To operate the network, Massive processes some device data (such as your IP address, an anonymous device identifier, city-level location, device specifications, and bandwidth statistics). Massive is an independent data controller for that processing under its own privacy policy. See Section 3.
- What the app collects is optional and anonymous: crash reports, basic usage counts, and a one-time install signal. You can turn each of these off.
- The one exception is an email address you type in yourself. If you ask the website to email you the download link (the option shown on phones, since Spark Tray is a Windows app), we store that address to send it. Nothing else on the site asks for one. See Section 7.
- The website measures our own ads. If you arrive from one of our Microsoft/Bing ads, sparktray.io stores that ad's click id in your browser for 90 days and reports the resulting download or install back to Microsoft Advertising, so we can tell which ads actually work. It is measurement only — no advertising profiles, no remarketing, no audience building. See Section 7.
- We do not sell your personal information.
- You have rights to access, delete, and control your data. See Sections 12-13.
1. Who we are
Clearware, LLC develops and distributes Spark Tray, a free Windows desktop utility app. This policy explains what information the Software and our related services handle, how, and your choices. It applies to the Spark Tray application and the sparktray.io website's interactions with it. It is incorporated into the End User License Agreement.
2. Our core principle: local-first
Spark Tray is designed to keep your data on your device:
- Media processing is on-device. Downloading, audio extraction, bulk downloading, background removal, and transcription all run using binaries and models bundled with the app. The files you process are not sent to us or to any Clearware server.
- Your settings and job history are local. Preferences and job history are stored on your device. We do not have a copy.
- No account required. Spark Tray does not require you to create an account or give us your name, email, or other identifying details to work.
3. The bandwidth exchange (how the app is funded)
Spark Tray is free because, while it is installed, it shares a portion of your device's idle, unused internet bandwidth through a bundled third-party network operated by Massive and/or its partners (the "Exchange"). Your connection relays third-party internet traffic. This is how we generate revenue instead of charging you or showing ads.
The Exchange runs in the background, including after you close Spark Tray. The Massive agent starts with your Windows user session and keeps sharing while you are signed in, even after you close or quit Spark Tray, until you turn sharing off or uninstall.
The Exchange does not access your data. It does not read, upload, or share your files, the media you process, your browsing or search history, the sites you visit, your credentials, cookies, keystrokes, or screen contents. It relays other parties' traffic, not yours.
What Massive processes to operate the network. To route traffic, Massive processes a limited set of device data: your IP address (during active sessions), an anonymous device identifier, city-level location, device specifications, and connection and bandwidth statistics. Massive retains this data on a capped schedule (currently up to 60 days) and is an independent data controller for it, governed by Massive's own terms and privacy policy, not ours. See:
- Massive license: https://joinmassive.com/en/terms
- Massive privacy policy: https://joinmassive.com/en/privacy
- Massive SDK privacy policy: https://joinmassive.com/en/monetization-sdk-privacy-policy
- Massive FAQ: https://joinmassive.com/faq
Resource use. Sharing uses network bandwidth and a small amount of CPU.
Your control. You can turn sharing off at any time from Spark Tray's settings, Spark Tray's tray menu, or Massive's own system-tray control; a stop from Massive's control is honored and the app will not restart sharing behind you. Note: Spark Tray's utilities do not run while sharing is off (see the EULA, Section 4). To end participation permanently, uninstall the app, which stops and removes the Massive agent.
4. Information the Software collects
Everything below is optional, off-switchable, and designed to carry no personal identifiers, URLs, filenames, or content.
| Data | What it is | Purpose | Default | Third party |
|---|---|---|---|---|
| Crash reports | Anonymized error type and stack trace with URLs, file paths, filenames, and local variables scrubbed out before sending | Diagnose and fix crashes | On (opt-out) | Sentry |
| Usage analytics | A small, fixed set of events (e.g. app launched, a utility opened, a job started/succeeded/failed, a dependency self-updated, the app-update lifecycle). The only details attached are a module id, a coarse error category, the update channel, a public version number, and component/model names | Understand which features are used and whether updates are adopted | On (opt-out) | Aptabase |
| Install-attribution signal | A one-time first-launch ping containing a random install identifier (a UUID). No name, email, or device profile | Measure how many downloads become active installs | On (opt-out) | Clearware (sparktray.io) |
| Update checks | A request to our update server to see whether a newer version exists | Deliver security and functionality updates | On (needed to update) | Clearware / update host |
How the "no PII" design is enforced. In the Software, every analytics event passes through an allow-list that permits only the fixed event names and non-identifying properties above; anything else is dropped. Every crash report passes through a scrubbing step that removes user/identity fields and redacts URLs, file paths, and media filenames before transmission. This is a design safeguard, not an absolute guarantee.
5. Information we do NOT collect
We do not collect, and the Software is built not to transmit:
- the URLs, links, or search terms you enter;
- the names or contents of the files you download, transcribe, edit, or export;
- the media itself (video, audio, images, transcripts);
- your browsing history or the websites you visit;
- your name, email address, passwords, payment details, or precise location;
- persistent cross-site advertising identifiers. The Spark Tray application does not set, read, or transmit any advertising identifier — not from the installer, not at runtime, not on uninstall. The website is a different surface: sparktray.io does use advertising-measurement identifiers, for the single purpose of counting conversions from ads we paid for. That is set out in full in Section 7, and it is the only place it happens.
One narrow exception, and it is on the website, not in the app: if you type your email address into the "email me the download link" form on sparktray.io, we store that address in order to send you the link. The Software itself never collects or transmits an email address. See Section 7.
6. How we use information
We use the limited, anonymous information we do collect only to:
- keep the Software stable (diagnose crashes and errors);
- understand which features are used and how reliably, to prioritize improvements;
- measure install activation in aggregate;
- measure which advertising campaigns produce downloads and installs (website only — see Section 7);
- deliver updates.
We do not use it to identify you, and we do not build advertising profiles or advertising audiences. The one advertising-related use is measurement: on the website we count how many visitors who arrived from one of our own ads went on to download and install, so we can tell which campaigns are worth paying for. That is reporting an outcome, not building a picture of you, and it is never used to target you with advertising afterwards. Section 7 describes exactly what is stored and what is sent.
7. The website (sparktray.io)
Cookies and tracking. The Spark Tray desktop application does not use advertising cookies or cross-site trackers. The website does, and rather than describe that in the abstract, here is the exact list of what runs on sparktray.io and why:
| What | Who runs it | What it does | How long it lasts |
|---|---|---|---|
| Google Analytics 4 | Google, as our analytics provider | Counts page views and navigation so we can see which pages lead to a download | Per Google's retention settings (Google privacy policy) |
| Microsoft UET tag | Microsoft Advertising | A conversion-tracking tag — an advertising cookie — that tells Microsoft when a visitor who clicked one of our Microsoft/Bing ads reached the site | Per Microsoft's retention schedule (Microsoft privacy statement) |
Microsoft click id (msclkid) | Us, first-party | When you arrive from one of our Microsoft ads, the ad's landing URL carries a click id. We store it in your browser (local storage plus a first-party cookie) so a download you make later can be matched back to the ad that produced it | 90 days from your most recent ad click, then it expires. A newer click replaces an older one |
Google click id (gclid) | Us, first-party | When you arrive from one of our Google ads, the ad's landing URL carries a click id. We store it in your browser (local storage plus a first-party cookie) so a download you make later can be matched back to the ad that produced it | 90 days from your most recent ad click, then it expires. A newer click replaces an older one |
Anonymous install id (st_iid) | Us, first-party | A random identifier (a UUID) with no name, email, or device profile attached, used to join "visited the site → downloaded → installed" into one count | The cookie lasts 180 days and is refreshed each time you visit; the copy kept in your browser's local storage stays until you clear this site's data |
What we send to Microsoft Advertising, and what we do not. When a download or install happens, our server reports that conversion to Microsoft Advertising. Each report contains exactly: the Microsoft click id, the random install id, your browser's user-agent string, the name of the event (for example download, install, or first_open), and a number we assign to weight how meaningful that event is. It does not contain your IP address, your email address, your phone number, or any hashed version of them. That is not an accident of implementation — we never store a full IP address anywhere in this measurement chain (only a truncated prefix), the one email address we ever hold — the download-link address described below — is never joined to this chain or sent to an advertising platform, and we deliberately declined to start collecting either one in order to improve ad matching.
What we send to Google Ads, and what we do not. The same arrangement runs one platform over, with one difference worth stating plainly: there is no Google Ads conversion tag and no remarketing tag on this site. Nothing in the page reports to Google Ads at all. When a download or install happens, our server reports that conversion directly to Google, and each report contains exactly: the Google click id, which conversion it counts as, when it happened, a value we assign to weight how meaningful it is, and a transaction id — built from the random install id — that stops the same event being counted twice. It does not contain your IP address, your email address, your phone number, or any hashed version of them. Google's API accepts all of those as additional matching signals; we do not send them, and we did not start collecting them in order to.
This is measurement, not targeting. These identifiers exist to count conversions from ads we already paid for. We do not use them to build advertising audiences, we do not run remarketing or dynamic remarketing, the consent signal we send Google explicitly withholds permission to personalise ads from these conversions, and we do not operate Microsoft's ID Sync pixel — which is the mechanism that would make cross-site targeting possible in the first place. If we ever adopt any of that, this policy changes before it is switched on, not after.
Your controls. The site and the download work with all of this blocked. Your browser's cookie and tracking-protection settings, or any ad/tracker blocker, will stop the Google and Microsoft tags loading and prevent either click id being stored — nothing on sparktray.io depends on them. You can also use Google's and Microsoft's own opt-outs, linked in their policies above.
The cookie notice. Where consent is required — the EEA, the UK and Switzerland — sparktray.io asks before any of this runs. Until you answer, the Google and Microsoft tags are held in a no-storage mode in which they neither read nor write cookies, and the click ids and install id described above are not stored at all. Choosing Decline keeps it that way, and a download you make afterwards is counted only against the campaign, with no identifier attached and nothing reported to Microsoft Advertising or Google Ads about you. Your answer is remembered in your browser and travels with you; declining here stays in force even if you later visit from elsewhere. You can reopen the notice at any time from Cookie settings in the site footer.
Changing your mind later. If you accepted and then decline — from Cookie settings at any time — we do two things, not one. Your browser's copies of the click ids, the install id and the stored campaign record are erased, and we also tell our own server to stop reporting you, because a click id recorded while you were consenting would otherwise still be sitting there. From that point no further conversion of yours is sent to Microsoft Advertising or Google Ads. Reports already delivered to those platforms are subject to their retention schedules, not ours.
"Email me the download link." Spark Tray runs on Windows, so a visitor on a phone cannot install it there. On small screens the download button offers to email you the link instead. If you use it:
| Data | What it is | Purpose |
|---|---|---|
| Your email address | Exactly what you type in | Send you the download link, once |
| Referral context | The referring site and the utm_* campaign tags on the URL you arrived through, plus a random identifier and a truncated IP prefix (never a full IP) and coarse OS family | Measure which channels produce installs, and limit abuse of the form |
What we do with it:
- We send one email. It is a one-off transactional message containing the download link. You are not subscribed to anything, added to a mailing list, or sent marketing as a result.
- We do not sell, rent, or share it with anyone for their own purposes.
- We do not use it to identify you inside the app. Addresses collected here are never joined to install, usage, or crash data — those remain anonymous by design.
- Our email provider (Resend) processes it on our behalf solely to deliver that message, as a service provider under our instructions.
- Legal basis (EEA/UK): performing a step you requested prior to entering a contract, and our legitimate interest in measuring marketing effectiveness.
Retention and deletion. We keep the address so we can tell a repeat request from a new one and measure the channel that produced it. Email info@clearware.co with "Privacy Request" in the subject and we will delete it — the record is stored keyed on your address specifically so that deletion is a single, complete operation.
8. Legal bases for processing (EEA/UK users)
Where the GDPR or UK GDPR applies, we rely on these legal bases:
- Legitimate interests for anonymous crash and usage reporting and aggregate install measurement, balanced against your privacy (and you can opt out).
- Consent where required, including your acceptance of the bandwidth exchange and telemetry at first run; you may withdraw consent by disabling the relevant option or uninstalling.
- Performance of a contract to provide the Software and deliver updates under the EULA.
9. How information is shared
We share information only as follows:
- Service providers (sub-processors): Sentry and Aptabase process the limited data described above on our behalf, and Resend delivers the download-link email described in Section 7.
- Advertising and analytics platforms: where you arrived from one of our Microsoft/Bing ads, we report the resulting download or install to Microsoft Advertising so that campaign can be measured, using exactly the identifiers listed in Section 7. Google receives site analytics through Google Analytics. The purpose in both cases is limited to measuring our own site and our own advertising. We do not send either of them a customer list, an audience, or any contact information, and we do not use Microsoft's ID Sync or remarketing features.
- The Exchange operator: Massive and/or its partners operate the bandwidth-sharing network as an independent data controller, subject to their own terms and privacy practices. Massive is not our service provider or processor for that activity.
- Update and website hosting providers deliver updates and run sparktray.io.
- Legal and safety: we may disclose information if required by law, or to protect the rights, safety, or property of Clearware, our users, or others.
- Business transfers: if Clearware is involved in a merger, acquisition, or asset sale, information may transfer as part of that transaction, subject to this policy.
We do not authorize our sub-processors to use the data for their own unrelated purposes. Google and Microsoft additionally process some of this data under their own terms as operators of their advertising and analytics platforms; that layer is governed by their policies, linked in Section 7, and we state above the limits we place on our own use.
10. We do not sell your personal information
We do not sell your personal information. We do not exchange it for money or for anything else of value.
On "sharing" for cross-context behavioral advertising. The California Consumer Privacy Act (CCPA/CPRA) and similar U.S. state laws use "share" as a term of art for disclosing personal information so that you can be targeted with advertising on other sites based on what you did here. That is not what our advertising measurement does. The Microsoft UET tag and the Microsoft click id described in Section 7 report the outcome of ads we already paid for. They are not used to build audiences, to retarget you elsewhere, or to profile you across sites, and we do not operate Microsoft's ID Sync pixel, which is the mechanism cross-site targeting would require.
We would rather state the limit than lean on the label, because regulators and browsers reasonably treat any advertising tag as higher-risk by default: the only advertising use of website data is counting conversions from our own ads. If we ever adopt remarketing or audience building, we will update this section before turning it on, and provide whatever opt-out the law requires at that point.
Because the Software itself is built to avoid collecting personal identifiers in the first place, there is very little personal information involved at all — and you can switch off even the website measurement with your browser's cookie controls or a tracker blocker (Section 7).
11. Data retention
- On your device: your files, settings, and job history remain until you delete them or uninstall the app.
- Crash and usage data: retained by our providers for a limited period consistent with diagnosing issues and understanding trends, then deleted or aggregated.
- Microsoft click id (
msclkid): stored in your browser for 90 days from your most recent ad click, then it expires; a newer click replaces an older one. Where it has been used to report a conversion, Microsoft Advertising's own copy is subject to Microsoft's retention schedule, not ours. - Google click id (
gclid): stored in your browser for 90 days from your most recent ad click, then it expires; a newer click replaces an older one. Where it has been used to report a conversion, Google's own copy is subject to Google's retention schedule, not ours. - Install-attribution signal: retained in aggregate/measurement form. The install id is a random UUID; it is not linked to your name, email, or any account, and we do not attempt to resolve it to a person. It is sent to Microsoft Advertising, and carried inside the transaction id sent to Google Ads, only as the anonymous key that stops one conversion being counted twice (Section 7), never as a way to identify you to either of them.
- Consent withdrawal: if you decline after having accepted, we keep a minimal record that you withdrew — the anonymous install id and the date — because that record is what stops any further conversion being reported for you. It contains nothing else.
- Download-link email addresses: retained until you ask us to delete them (Section 7), so we can recognize a repeat request and attribute the channel.
- Exchange data processed by Massive: governed by Massive's own retention schedule (currently capped at up to 60 days), under Massive's privacy policy.
12. Your privacy rights
Depending on where you live, you may have rights to: access, correct, delete, object to or restrict certain processing, withdraw consent, port your information, and not be discriminated against for exercising these rights.
Because Spark Tray is local-first and largely anonymous, the fastest way to exercise most of these rights is directly in the app: turn off telemetry, turn off bandwidth sharing, delete your local data, or uninstall. To make a formal request, or if you are in the EEA/UK, California, or another region with statutory rights, email info@clearware.co and we will respond as required by law. You may also have the right to lodge a complaint with your local data-protection authority.
For rights relating to the data Massive processes to operate the Exchange, contact Massive through the privacy policy linked in Section 3.
13. Your choices and controls
You are in control of the optional data flows:
| Control | Where | Effect |
|---|---|---|
| Crash reporting | First-run consent screen and Settings | Turn off to stop sending any crash reports |
| Usage analytics | First-run consent screen and Settings | Turn off to stop sending usage events |
| Install-attribution | Settings | Turn off to suppress the first-open signal |
| Website ad & analytics measurement | The site's cookie notice ("Cookie settings" in the footer), your browser's cookie/tracking settings, or an ad or tracker blocker | Declining puts the Microsoft and Google tags into a no-storage mode and prevents the ad click id and install id being stored. The site and the download work without them |
| Bandwidth sharing on/off | Spark Tray Settings, Spark Tray tray menu, or Massive's tray control | Stops sharing immediately. While off, the app's utilities do not run (see EULA Section 4) |
| End sharing permanently | Uninstall | Uninstalling stops and removes the Massive agent and ends participation |
| Download-link email | Don't use the form; or email info@clearware.co | The form is optional — the download page works without it. Ask us and we delete the stored address |
14. Security
We design the Software to minimize the data at stake: processing is local, the renderer runs sandboxed and isolated from system APIs, privileged work is confined to the app's main process behind a typed bridge, and bundled or downloaded binaries and models are integrity-verified (SHA-256) before they run. No method of transmission or storage is completely secure, but we take reasonable measures to protect the limited information we handle.
15. Children's privacy
Spark Tray is not directed to children under 13 (or the minimum age required in your jurisdiction), and we do not knowingly collect personal information from them. If you believe a child has provided us personal information, contact info@clearware.co and we will address it.
16. International data transfers
We are based in the United States, and our service providers may process data in the U.S. and other countries. Where required, we use appropriate safeguards (such as standard contractual clauses) for transfers of personal data out of the EEA, UK, or other regions with transfer restrictions.
17. Changes to this policy
We may update this Privacy Policy to reflect changes to the Software, our practices, or the law. When changes are material, we will update the effective date and provide reasonable notice (for example, in-app or on sparktray.io). Your continued use of the Software after an update takes effect constitutes acceptance of the updated policy.
18. Contact us
Clearware, LLC
Email: info@clearware.co
Web: https://sparktray.io
For privacy requests, please put "Privacy Request" in the subject line so we can route it quickly.