Scope of this policy
This policy applies specifically to the Cornerstone Spark Chrome extension. The broader Cornerstone platform remains covered by the general privacy policy. Spark does not collect browsing history or the contents of websites you visit.
Information Spark handles
- Account information used for Firebase email authentication, including your email address, Cornerstone user identifier, authentication state, and authentication tokens. Your password is sent to Firebase for authentication and is not stored in Spark application data.
- Profile and workspace metadata needed to show the personal and shared workspaces available to your account.
- Spark content you create or edit, saved revisions, the workspace you select, and navigation state used to restore your place.
- Limited technical request information processed by Firebase and Cornerstone services to authenticate, operate, secure, and diagnose the extension.
Local data on your device
Spark may keep authentication state, small interface preferences, and templates in extension-local browser storage. Spark also supports an optional offline snapshot. When you deliberately save one, that snapshot can contain Spark content and navigation state and remains on the device until you remove it, clear the extension's data, or uninstall the extension.
Network access and Chrome permissions
Spark requests no Chrome API permissions. It does not request tabs, scripting, storage, or access to arbitrary websites. Its host access is restricted to the Firebase Identity Toolkit and Secure Token endpoints used for sign-in and token refresh, plus the configured Cornerstone workspace and Spark data API endpoints.
- https://identitytoolkit.googleapis.com/*
- https://securetoken.googleapis.com/*
- Configured Cornerstone workspace and feature-data HTTPS origins
How information is used and shared
Information is used only to sign you in, show authorised workspaces, load and save Spark content, maintain revisions and navigation state, support optional offline work, protect the service, and respond to support or legal obligations. It is processed by Cornerstone and Google Firebase for those purposes. We do not sell extension data, use it for advertising, run analytics inside the extension, or use private Spark content to train AI models.
Security, retention, and your choices
Spark transmits account and workspace information over encrypted HTTPS connections. Cloud information is retained while needed to provide the Cornerstone service, maintain security and records, resolve disputes, or meet legal obligations. Local data remains under the extension's browser storage until it is removed or the extension is uninstalled.
You may request access, correction, or deletion of personal information held by Cornerstone, or make a privacy complaint, by emailing philip.ronald.hultgren@gmail.com. We may need to verify your identity and may retain records required by law.
Overseas processing and changes
Google Firebase and related infrastructure may process information in the United States and other regions. If Spark's data practices change, this policy will be updated and material changes will be disclosed as required before the new handling begins.
Read the general Cornerstone privacy policy for more information about company-wide privacy management, complaints, and data incidents.