Cornerstone SparkExtension privacy policy

Cornerstone Spark

Cornerstone Spark signs you in to Cornerstone and synchronises the Spark work you choose to keep in your personal or shared workspace.

Effective date: 9 August 2026

Scope of this policy

This policy applies specifically to the Cornerstone Spark Chrome extension. The broader Cornerstone platform remains covered by the general privacy policy. Spark does not collect browsing history or the contents of websites you visit.

Information Spark handles

  • Account information used for Firebase email authentication, including your email address, Cornerstone user identifier, authentication state, and authentication tokens. Your password is sent to Firebase for authentication and is not stored in Spark application data.
  • Profile and workspace metadata needed to show the personal and shared workspaces available to your account.
  • Spark content you create or edit, saved revisions, the workspace you select, and navigation state used to restore your place.
  • Limited technical request information processed by Firebase and Cornerstone services to authenticate, operate, secure, and diagnose the extension.

Local data on your device

Spark may keep authentication state, small interface preferences, and templates in extension-local browser storage. Spark also supports an optional offline snapshot. When you deliberately save one, that snapshot can contain Spark content and navigation state and remains on the device until you remove it, clear the extension's data, or uninstall the extension.

Network access and Chrome permissions

Spark requests no Chrome API permissions. It does not request tabs, scripting, storage, or access to arbitrary websites. Its host access is restricted to the Firebase Identity Toolkit and Secure Token endpoints used for sign-in and token refresh, plus the configured Cornerstone workspace and Spark data API endpoints.

  • https://identitytoolkit.googleapis.com/*
  • https://securetoken.googleapis.com/*
  • Configured Cornerstone workspace and feature-data HTTPS origins

How information is used and shared

Information is used only to sign you in, show authorised workspaces, load and save Spark content, maintain revisions and navigation state, support optional offline work, protect the service, and respond to support or legal obligations. It is processed by Cornerstone and Google Firebase for those purposes. We do not sell extension data, use it for advertising, run analytics inside the extension, or use private Spark content to train AI models.

Security, retention, and your choices

Spark transmits account and workspace information over encrypted HTTPS connections. Cloud information is retained while needed to provide the Cornerstone service, maintain security and records, resolve disputes, or meet legal obligations. Local data remains under the extension's browser storage until it is removed or the extension is uninstalled.

You may request access, correction, or deletion of personal information held by Cornerstone, or make a privacy complaint, by emailing philip.ronald.hultgren@gmail.com. We may need to verify your identity and may retain records required by law.

Overseas processing and changes

Google Firebase and related infrastructure may process information in the United States and other regions. If Spark's data practices change, this policy will be updated and material changes will be disclosed as required before the new handling begins.

Read the general Cornerstone privacy policy for more information about company-wide privacy management, complaints, and data incidents.