Loading...

LOVSPARK Privacy Policy

Last Updated Date: July 16, 2026

Introduction

Welcome to the LOVSPARK Platform ("LOVSPARK", or the "Platform"), which includes the LOVSPARK website, web application, browser extension (Web Clipper), and any other features, functionalities, or services provided now or in the future (collectively the "Services"). The Services are offered by ARK TECHNOLOGY INTERNATIONAL LIMITED ("we", "us", or "our"), with its registered address at Unit 1302, 13/F, Witty Commercial Building, 1A–1L Tung Choi Street, Mong Kok, Kowloon, Hong Kong.

We value your privacy and are committed to protecting your personal data. This Privacy Policy ("Policy") explains how we collect, use, share, and safeguard your personal information when you access or use the Services, including any site, extension, or platform that links to this Policy.

This Policy describes:

  • The types of personal information we collect and how we collect it;
  • How we use your personal information and the legal bases for doing so;
  • How we share your information and with whom;
  • Your privacy rights under applicable laws, including the EU General Data Protection Regulation (GDPR), U.S. state privacy laws (such as CCPA/CPRA), and the People's Republic of China Personal Information Protection Law (PIPL);
  • How we protect your information and how long we retain it.

By accessing or using the Services, you acknowledge and agree to this Policy. If you do not agree, please do not use our Services. Please note that this Policy does not cover third-party products, services, websites, or content ("Third-Party Services"). These are subject to their own privacy policies, and we recommend reviewing their privacy statements before using them.


1. What Information We Collect

We may collect the following information from and about you, including information that you provide, automatically collected information, and information from other sources.

1.1 Information You Provide

When you interact with our Services, you may provide certain personal information voluntarily, including but not limited to:

  • Registration Information: When you register for an account, we may collect details such as your username, password, date of birth (where applicable), email address, and/or telephone number. If you register as a representative of an organization, we may also collect your name, business email address, phone number, country, physical address, and, if applicable, your organization's details.

  • User Content: We collect content you create, upload, generate, or otherwise make available through the Services. This may include:

    • Profile information (such as nickname and avatar);
    • Canvas projects (nodes, connections, comments, generated images, generated videos, and any other assets you place on the canvas);
    • AI generation inputs and outputs (prompts, reference images, model and Skill selections, generated images, generated videos);
    • Skill configurations and templates that you create or save as favorites;
    • Library contents (products in your Product Library, images in your Image Library, folder structures, custom tags, ratings, notes);
    • Public Content that you publish to the Community Library (visible to other LOVSPARK users);
    • Any other material you create, upload, or share using the Services.
  • Web Clipper Data: When you use the Web Clipper browser extension, we collect:

    • Source URLs of pages you clip;
    • Product or image data extracted from those pages (such as product name, price, SKU, brand, images, descriptions);
    • The target library you select (My / Curated nomination / Community publish);
    • Your tagging or note input at clip time.
  • Payment Information: When you purchase Paid Services or Credits packages (as defined in our Terms of Service), we use third-party payment processors to handle your payment transactions. These providers may collect your credit card details or other financial information. We do not store your full payment card details, but we may retain transaction confirmation or records required for compliance and accounting purposes.

  • Correspondence Information: When you contact us for support, feedback, or inquiries—whether by email, our Discord community, or other communication channels—we collect the information you choose to provide, including the content of your messages and any associated details.

  • Surveys and Promotions: With your consent, we may collect information when you participate in surveys, research studies, promotions, marketing campaigns, or events that we organize or sponsor.

1.2 Information We Collect Automatically

When you interact with our Services, including when you browse without creating an account, we automatically collect certain information about your device and usage patterns. This may include:

  • Technical and Device Information: Your IP address, browser type, user agent, mobile carrier, time zone, device identifiers (including identifiers used for advertising), device model, operating system, network type, and screen resolution.

  • Usage Information: We log information about your activity within the Services, including the pages or content you view, the duration of your interactions, access times, navigation paths, clicks, searches, the AI generation tasks you trigger (Skill, model, output count), Credits consumption events, and the referring URL (the website you visited before landing on our Services).

  • Affiliate Click and Conversion Data: When you click a purchase link on a Curated or Community Library product, we record the click event, the destination retailer, and (where available from the retailer or affiliate network) the conversion result, in order to support affiliate revenue attribution.

  • Location Information: We may infer the general geographic area (e.g., country, region, or city-level) from your device's IP address or similar network signals. We use this information to help protect your account (for example, by detecting unusual login activity), apply regional settings (such as language, time zone, or content availability), comply with geo-based legal requirements, and improve the relevance and quality of the responses and features you experience in the Services. With your permission, we may collect your precise location information for location-based functions.

  • Cookies and Similar Technologies: We use cookies, local storage, and similar technologies to operate and optimize the Services. Analytics storage is denied by default and enabled only when the existing cookie_consent value is explicitly granted. When storage is denied, our analytics providers may receive limited cookieless measurement requests, but we do not persist UTM attribution or send a signed-in User-ID. You can manage or disable cookies through your browser or device settings. For full details, please see our Cookie Policy.

1.3 Information From Other Sources

If you choose to register for or access the Platform using a third-party account (such as Apple, Google, or other supported identity providers), we may receive certain information from that third party, including your username, public profile details, email address, and any other information you authorize the third party to share with us. Similarly, we may share limited information with the third-party provider to enable authentication and account linkage, such as your app ID, access token, and referring URL.

If you connect a third-party content source to your Image Library, we will receive, with your explicit OAuth authorization, the data needed to perform the actions you request inside LOVSPARK. The connections we currently support and the specific permissions we request are as follows.

Google Drive. Account ID, folder lists, image files and metadata, and access tokens. We use this data only to import images you actively select.

Pinterest. When you authorize LOVSPARK to connect with your Pinterest account, we request the following read-only OAuth scopes. We do not request any write scope, meaning we cannot create, modify, or delete any board or pin on your Pinterest account.

Scope What it lets us do When we use it
boards:read View your public boards, including any group boards you participate in. When you browse and import pins from your boards into your LOVSPARK Image Library.
boards:read_secret View your secret (private) boards. Only requested if you choose to use your private boards with LOVSPARK; you may decline this scope and still use the connection with public boards only.

We use these scopes only to perform the read operations you explicitly request inside LOVSPARK (browsing your boards and importing the pin images you select). We do not access your Pinterest boards in the background, and we do not use Pinterest data to train any AI model. We retrieve from Pinterest only the data necessary for the import (account ID, board lists, pin images and metadata, access tokens). You can revoke LOVSPARK's access to your Pinterest account at any time from your Pinterest account settings → Apps or from your LOVSPARK account settings.


2. How We Use Your Information

We may use your information to operate, provide, support, and administer the Platform and Services, enable their features, secure your account, and to fulfill, enforce, and comply with our Terms of Service. In particular, we use personal information for the following purposes:

  • Eligibility and Age Verification to ensure you are legally permitted to use the Services.
  • Service Operation: Provide, operate, and maintain the Services, including core functionality, account features, AI generation, the Skill system, the Product and Image Libraries, the canvas workspace, the Web Clipper, and the Community Library.
  • Personalization and Recommendation: Personalize your home page, Skill discovery, and Library suggestions based on your usage and stated preferences.
  • AI Model Inference: Use the prompts, reference images, and other inputs you provide to generate Output via our own systems and trusted third-party AI providers. We do not use your private My Library content or your private canvas content to train our own foundation models without your separate, explicit consent.
  • Affiliate Revenue Attribution: Track click and conversion events on Curated and Community Library products to support our affiliate revenue model.
  • User-to-User Features: Display your Public Content (Community Library) and contributor attribution to other users in accordance with your settings.
  • Communication: Send you notices about changes to the Services, Terms, or policies; transactional emails (e.g., subscription receipts, account security alerts); and, with your consent, marketing emails.
  • Customer Support: Respond to questions, requests, complaints, and feedback received via email, our Discord community, or other channels.
  • Transactions: Process subscriptions, Credits purchases, refunds, and related sales support functions.
  • Platform Safety and Security: Safeguard security, defend our legal rights, property, commercial interests, and those of our affiliates, users, and the public.
  • Enforcement: Enforce our terms, conditions, and policies and meet legal and regulatory obligations.
  • Fraud and Abuse Prevention: Detect, investigate, and help prevent abuse, fraud, and illegal activity, including scanning, analyzing, and reviewing User Content and associated metadata for policy violations (including Community Library content moderation per our Terms of Service §5.4).
  • Internal Operations: Troubleshooting, data analysis, testing, research, statistics, surveys, and soliciting feedback to improve the Services.
  • Other Disclosed Purposes: Use your information for additional purposes that are disclosed at the time of collection, with your consent, or as otherwise permitted by applicable law.

Lawful Bases (GDPR / UK GDPR / Swiss FADP)

Where the GDPR or other equivalent data protection laws apply, we must identify a lawful basis before processing your personal information. Depending on the context, we process personal information under one or more of the bases below.

(a) Performance of a Contract. We process personal information as needed to enter into, perform, and administer our Terms of Service with you—this includes creating and managing your account, providing core Services and features, processing payments or subscriptions, delivering content you request, and responding to service-related inquiries.

(b) Consent. We rely on your consent where required by law or where we offer optional features. Examples include: subscribing to marketing emails; participating in surveys or beta programs; allowing us to access certain device data (e.g., precise location); enabling third-party Image Library connections (Google Drive, Pinterest); or using your inputs to train or improve our own AI models. You may withdraw your consent at any time using available settings or by contacting us (see Contact Us). Withdrawal will not affect processing that occurred before withdrawal.

(c) Legal Obligations. We process personal information to comply with laws and regulatory requirements—for example, tax and accounting rules, responding to lawful requests from public authorities, verifying identity where required (e.g., fraud, sanctions, or anti-money-laundering checks if applicable), or honoring data subject rights under privacy laws.

(d) Legitimate Interests. We process personal information where necessary to pursue our (or a third party's) legitimate interests, provided those interests are not overridden by your rights and freedoms. These interests include: securing and protecting the Platform; preventing fraud, abuse, or misuse; improving and developing the Services; measuring engagement; personalizing non-intrusive product experiences; supporting internal analytics and research; and operating affiliate revenue tracking. Where required, we apply appropriate safeguards or obtain consent.

(e) Protection of Vital Interests (Infrequent). In rare cases, we may process personal information to protect the vital interests of an individual—for example, responding to an urgent safety issue that involves risk of serious harm.

(f) Establishment, Exercise, or Defense of Legal Claims. We may process relevant personal information as needed to assert or defend legal claims, manage disputes, or protect our rights, users, affiliates, or the public.

(g) Other Permissible Grounds. If applicable local law provides additional lawful bases for processing, we will rely on those where appropriate and will identify them at the point of collection.

We may aggregate or de-identify personal information so that it can no longer reasonably identify you. We use such information for purposes described in this Policy, including analyzing usage trends, improving or adding features, and conducting research.

Lawful Bases (China PIPL)

If you are a user located in mainland China, in addition to the lawful bases above, our processing of your personal information is also governed by the Personal Information Protection Law of the People's Republic of China (PIPL). We process your personal information based on:

  • Your separate consent for sensitive personal information (e.g., precise location, biometric features in face / body images you may upload, payment information);
  • The necessity to perform our contract with you (account, subscription, AI generation);
  • Legal obligations under Chinese laws and regulations;
  • Reasonable use of personal information that you have publicly disclosed (e.g., Community Library content);
  • Other bases permitted by Chinese law.

We will obtain your separate consent before transferring your personal information outside mainland China, as required under PIPL Article 38, and provide you with the relevant information about overseas recipients.


3. How We Share Your Information

We do not sell your personal information. However, we may share it with third parties for the purposes described in this Policy and as permitted by law. This may include the following categories of recipients:

3.1 Service Providers and Business Partners

We engage trusted third-party vendors and partners to help us operate, improve, and support the Services. These may include:

  • Cloud and hosting providers that store and manage our infrastructure (e.g., AWS, Google Cloud, Cloudflare);
  • AI model providers that process the prompts and reference images you submit to generate Output (e.g., OpenAI, Anthropic, Google, Replicate, Fal, or other generative AI providers we may use from time to time);
  • Payment processors that handle transactions securely (e.g., Stripe, Apple App Store, Google Play);
  • Analytics and measurement providers to help us understand performance and usage (Google Analytics and, when enabled, Microsoft Clarity);
  • Affiliate networks and tracking partners to support affiliate revenue attribution (e.g., Skimlinks, Awin, Impact Radius, or similar);
  • Customer support and communication tools (e.g., Discord for community support, Sendgrid or Postmark for transactional email);
  • Content moderation and safety partners for screening Public Content;
  • Advertising and marketing partners, where allowed by law and in line with your preferences.

All such third parties are bound by strict contractual obligations to process data only on our behalf and in accordance with this Policy.

3.2 Other LOVSPARK Users

If you publish content to the Community Library, that content (including your contributor name and any contextual metadata you choose to share) will be visible to other LOVSPARK users. Other users may save your Public Content to their own libraries. See our Terms of Service §5.4 for the license terms governing Public Content.

3.3 Our Corporate Group

We may share your information with companies within our corporate group, including subsidiaries, parent entities, and affiliates under common ownership or control. Such sharing enables us to:

  • Operate and optimize the Services;
  • Improve products and features;
  • Conduct internal reporting and business planning.

Where applicable, these entities may be located outside your home country. In such cases, we implement appropriate safeguards for international data transfers (see §3.6 International Transfers below).

3.4 Legal and Compliance Obligations

We may disclose your information to law enforcement, regulators, courts, or other third parties when we believe in good faith that disclosure is necessary to:

  • Comply with applicable law, legal processes, or lawful requests;
  • Enforce our Terms of Service and other agreements, or investigate potential violations;
  • Detect, prevent, or address fraud, security, or technical issues;
  • Protect the rights, property, or safety of our company, users, or the public;
  • Establish, exercise, or defend legal claims.

3.5 Sale, Merger, or Reorganization

Your information may be shared or transferred in connection with a corporate transaction, such as:

  • A merger, acquisition, or sale of assets;
  • Financing, restructuring, or reorganization;
  • Bankruptcy, insolvency, or receivership.

If such a transaction occurs, we will require the recipient to honor this Privacy Policy or provide equivalent protection.

3.6 With Your Consent

We may share your information with third parties for other purposes if you consent or direct us to do so. Where required by law, we will obtain your explicit consent before sharing.

3.7 International Data Transfers

The personal information we collect may be stored and processed on servers located outside the country where you reside. Currently, we store data on secure servers in the United States (US-West region, e.g., AWS us-west-1 / us-west-2), but we may also engage affiliates and service providers in other countries to support our operations (for example, edge nodes operated by our content-delivery network and payment-processing facilities operated by Stripe).

When we transfer your personal information across borders for any purpose described in this Policy, we do so in compliance with applicable data protection laws and implement appropriate safeguards to protect your information.

  • EEA / UK / Switzerland: If you access the Services from these regions and your personal information is transferred to a country that has not been deemed to provide an adequate level of data protection, we implement appropriate safeguards as required by law. These include the European Commission's Standard Contractual Clauses (SCCs) (and the UK Addendum or other approved transfer tools, as applicable), supplemented by technical and organizational measures designed to protect your data.
  • Mainland China (PIPL): If you are located in mainland China, we transfer your personal information outside China only after meeting one of the legal bases under PIPL Article 38 (e.g., obtaining your separate consent, completing the security assessment by the Cyberspace Administration of China where required, or relying on Chinese standard contractual clauses).

4. Your Rights and Choices

You can view and update most of your profile information at any time by signing into your account. Additional privacy controls are available in Settings, where you can manage certain preferences and permissions. Depending on your location and applicable law, you may have the following rights regarding your personal information:

  • Access and Confirmation. You can request confirmation as to whether we process your personal information and obtain a copy of the data we hold about you.
  • Rectification. You have the right to request that we correct inaccurate or incomplete personal information.
  • Erasure ("Right to be Forgotten"). In certain circumstances, you can request that we delete your personal information, subject to legal or contractual obligations. Note that when you delete content within the Services, it is soft-deleted and retained for 30 days (see §6 Data Retention) — if you require immediate, irreversible deletion under PIPL or GDPR, please contact us using the information in §9 and we will process the request in accordance with applicable law.
  • Restriction of Processing. You may request that we limit the processing of your personal information in specific situations.
  • Data Portability. Where technically feasible, you can request a copy of your personal information in a structured, commonly used, and machine-readable format and ask us to transfer it to another controller.
  • Withdrawal of Consent. Where processing is based on your consent, you have the right to withdraw it at any time. This will not affect the lawfulness of processing before withdrawal.
  • Opt-Out of Sales and Targeted Advertising (U.S. Residents). If you are covered by U.S. state privacy laws such as the CCPA/CPRA, you may have the right to opt out of the sale or sharing of your personal information or its use for cross-context behavioral advertising. We do not sell your personal information, but we may engage in "sharing" for certain analytics purposes. The in-product Cookie Preference Center is not available in this release. You may use browser controls to block or delete cookies, or send a written request to [email protected] with the subject "CCPA/CPRA Opt-Out". We will honor your request within the timeframe required by applicable law.
  • Objection to Processing. In some cases, you may object to our processing of your personal information, including for direct marketing purposes.
  • Rights under PIPL (China users). In addition to the above, you have the right under PIPL to (i) request explanation of our personal information processing rules, (ii) request a copy of your personal information be transferred to a designated personal information processor, and (iii) deactivate your account; we provide convenient methods to deactivate accounts.
  • Complaints. You have the right to lodge a complaint with your local data protection authority if you believe your privacy rights have been violated.

If you have questions about these rights or how to exercise them, please contact us at [email protected]. We will respond to your request in accordance with applicable laws (typically within 15 business days, or as required by your local law).


5. Data Security

We take reasonable and appropriate technical and organizational measures to help protect personal data from unauthorized access, use, disclosure, alteration, and destruction. These measures include:

  • Encryption of data in transit (TLS) and at rest;
  • Access controls for employees and contractors, granted on a least-privilege, need-to-know basis;
  • Logging and audit trails of access to sensitive data;
  • Periodic security reviews of our infrastructure and code;
  • Vendor due diligence for all third-party data processors.

Unfortunately, the transmission of information via the internet is not completely secure, and we cannot guarantee the security of your information transmitted via the Services; any transmission is at your own risk.

To help us protect personal data, we request that you use a strong password, never share your password with anyone, never reuse passwords across sites, and enable two-factor authentication where available.


6. Data Retention

We generally retain your information for as long as it is necessary to serve the purpose(s) for which such information was collected, including to provide you with the Services. However, there are occasions where we are likely to keep this information longer in accordance with our legal obligations or where it is necessary for the establishment, exercise, or defense of legal claims.

Soft Delete (30 Days)

When you delete content within the Services — including canvas projects, library products, library images, and generated assets — the content is soft-deleted and retained on our servers for 30 days. During this period:

  • The content is invisible to you and other users;
  • The content does not count toward your storage quota;
  • We retain the content solely to support data integrity, customer recovery requests (where you ask our support team to restore accidentally deleted content), and legal compliance.

After 30 days, soft-deleted content is permanently removed from active systems and cannot be restored.

If you require immediate, irreversible deletion of specific content (for example, to exercise your "right to be forgotten" under GDPR or PIPL), please contact us using the methods in §9 and we will process such requests in accordance with applicable law, typically within 30 days.

Account Deletion

After you have terminated your use of our Services and requested account deletion, we may store your information in an aggregated and anonymized format. Notwithstanding the foregoing, we may also retain any information as reasonably necessary to comply with our legal obligations, to allow us to resolve and litigate disputes, and to enforce our agreements (e.g., transaction records may be retained for tax and accounting purposes for the period required by applicable law).

Affiliate and Transaction Records

Affiliate click logs, transaction records, and tax-relevant payment records are retained for the period required by applicable financial and tax laws (typically 5–10 years depending on jurisdiction).


7. Information Relating to Minors

The Services are not directed at children under the age of 13 (or the equivalent minimum age in the relevant jurisdiction; for example, 14 in mainland China and 16 in some EU member states). We do not knowingly collect personal information from children under the applicable minimum age. If you are a parent or guardian and believe that we have personal data about or collected from a child under the relevant age, please contact us at [email protected], and we will take steps to delete such information.


8. Privacy Policy Updates

We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other factors. When we make material changes, we will notify you by means of a notice within the Services or by other reasonable methods (such as email to your registered account address). The "Last Updated" date at the top of this Policy indicates when the changes take effect.

We encourage you to review this Policy periodically. By continuing to access or use the Services after the effective date of an updated Policy, you agree to the revised terms. If you do not agree with the updated Policy, you should discontinue using the Services.


9. Contact Us

If you have any questions or concerns about this Policy or our practices related to the protection of personal information, please feel free to contact us at:

  • Privacy / Data Protection inquiries: [email protected]
  • General support: [email protected]
  • Postal address: Unit 1302, 13/F, Witty Commercial Building, 1A–1L Tung Choi Street, Mong Kok, Kowloon, Hong Kong

We aim to respond to privacy requests within 15 business days after verifying your identity. For complex requests, we may require additional information to assist you effectively.

Please contact us first if you believe we have processed your personal information in a manner inconsistent with this Policy or applicable law. We will review and address your concern as promptly as we reasonably can. This does not affect your right to:

  • Lodge a complaint with your local data protection authority (for example, the relevant supervisory authority in the EEA, UK, or Switzerland; the Cyberspace Administration of China for mainland China users; or your State Attorney General for U.S. users).
  • Pursue other remedies available to you under applicable law or under the dispute resolution process described in our Terms of Service.

Data Protection Officer / EU Representative / UK Representative

[TODO: If you have appointed a DPO, EU Representative (under GDPR Article 27), or UK Representative, list their contact details here. Required if you offer Services to individuals in the EU/UK and meet the GDPR/UK GDPR threshold criteria.]