Spongle Privacy Policy

Last updated October 5, 2026·Version 1.20.2

Last updated: 5 October 2026

Spongle is currently operating in a pre-launch and testing phase. Some functionality described in this Privacy Policy may not yet be commercially available. We are already processing personal data where people create accounts, manage profiles, use available features, contact us or otherwise interact with Spongle. At a glance We collect only the personal data we need to operate Spongle and provide the features available to you. We do not sell your personal data. Where payment features are enabled, payment processing is handled through Stripe. Additional information may be processed when optional or commercial features, such as payments or AI tools, are enabled and used. You retain your data protection rights, including rights to access, delete, export or restrict the use of your personal data where applicable. Certain records may need to be retained for longer periods where required by law.

Spongle is currently operating in a pre-launch and testing phase. Although some marketplace features are not yet commercially available, we are already processing personal data where users: visit the Service; create an account; build or manage a profile; contact us; participate in testing; or otherwise interact with Spongle. During the pre-launch period, we may process account information, profile information, communications, technical information and diagnostic information where reasonably necessary to: operate the Service; keep the Service secure; test functionality; identify and troubleshoot problems; and improve Spongle. This processing is carried out as described elsewhere in this Privacy Policy. Features that are not yet active Certain processing activities described in this Privacy Policy relate to functionality that may not yet be commercially available or enabled for all users. For example, processing associated with: paid campaigns; payment transactions; creator payouts; Boost purchases; and other commercial marketplace functionality will only take place when the relevant feature has been enabled and is actually used. References in this Privacy Policy to future or commercially activated features do not mean that Spongle is currently carrying out all of the processing described. The relevant processing will apply only when the corresponding feature or service is enabled and used. Changes during pre-launch As Spongle develops, we may introduce new features, change existing features or remove functionality. Where a new or changed feature materially affects how or why we process personal data, we will update this Privacy Policy as appropriate. Where required by applicable data protection law, we will also provide any additional information, notices, choices or consent mechanisms before the relevant processing begins. Your rights during pre-launch The fact that Spongle is operating in a pre-launch or testing phase does not reduce your data protection rights. Personal data collected during this period will be handled in accordance with: this Privacy Policy; and applicable data protection law. We will only retain personal data for as long as necessary for the purposes described in this Privacy Policy, or where retention is otherwise required by applicable law.

As Spongle moves from its pre-launch and testing phase into commercial operation, we may update this Privacy Policy to reflect newly activated functionality. This may include personal data processing associated with: marketplace transactions; payments; creator payouts; paid campaigns; Boost purchases; and other commercial features. Existing users Where we make material changes to this Privacy Policy, we will take appropriate steps to bring those changes to the attention of existing users before, or when, the relevant processing begins. Where applicable data protection law requires additional notice, choice or consent for a particular type of processing, we will provide this before carrying out that processing. Existing users may also be asked to acknowledge that an updated Privacy Policy has been made available to them. An acknowledgement that a Privacy Policy has been provided does not replace any consent that may be separately required under applicable data protection law. Privacy Summary Your privacy matters to us. We collect only the information reasonably necessary to operate your account and provide Spongle's available features. We do not sell your personal data. Where payment functionality is enabled, payment processing is handled through Stripe. Your data protection rights continue to apply throughout Spongle's pre-launch and commercial operation. Certain payment, contractual, signature, tax or compliance records may need to be retained for longer periods where required by law. Collecting a Creator's tax details for the reporting the law requires of Spongle does not make Spongle that Creator's employer. Creators remain responsible for their own tax.

Your privacy matters to us. We collect only the information reasonably necessary to operate your account and provide Spongle's available features. We do not sell your personal data. Where payment functionality is enabled, payment processing is handled through Stripe. Your data protection rights continue to apply throughout Spongle's pre-launch and commercial operation. Certain payment, contractual, signature, tax or compliance records may need to be retained for longer periods where required by law. Collecting a Creator's tax details for the reporting the law requires of Spongle does not make Spongle that Creator's employer. Creators remain responsible for their own tax.

Spongle Limited ("Spongle", "we", "our", or "us") is a private company limited by shares, incorporated and registered in the Republic of Ireland under the Companies Act 2014. We help creators and brands collaborate on campaign-based partnerships. Detail Information Business Name Spongle Limited (trading as "Spongle") Legal Structure Private Company Limited by Shares, incorporated under the Companies Act 2014 Company Registration Number 815169 (Companies Registration Office, Ireland) VAT Number IE4749783DH (Revenue Commissioners, Ireland) Date of Incorporation 11 May 2026 Trademark Status Spongle® is a registered trade mark in Ireland and the United Kingdom Contact Emails: privacy@spongle.co (privacy and data-protection enquiries and requests) legal@spongle.co (legal notices, and notices of illegal content and our point of contact under the EU Digital Services Act) support@spongle.co (general support) security@spongle.co (security vulnerability disclosure) report@spongle.co (abuse, safety, and conduct reports) info@spongle.co (general enquiries) notifications@spongle.co (automated notifications, outbound only) Registered Address: Spongle Limited, 77 Camden Street Lower, Dublin 2, D02 XE80, Ireland. EU establishment (GDPR Article 27). Spongle Limited is established in the European Union (Ireland) and is therefore directly subject to the EU GDPR. Article 27 of the EU GDPR applies only to controllers established outside the EU and does not apply to Spongle. EU users can contact us directly using the details above and may lodge a complaint with their national supervisory authority or with our lead authority, the Data Protection Commission (Ireland). Users in the United Kingdom. Spongle Limited is established in Ireland and has no establishment in the United Kingdom. Users in the United Kingdom may contact us directly at privacy@spongle.co, and may lodge a complaint with the Information Commissioner's Office (https://ico.org.uk). Where we appoint a representative in the United Kingdom, their details will be published in this section.

Account Information Email address, username, password (stored only as a secure hash by our authentication provider) User role (creator or brand), account creation timestamps Country of residence (ISO country code) Country of the bank that issued the payment card used (two-letter country code only), retained as evidence of your location for VAT purposes and to help detect fraudulent payments. We do not store your card number or any part of it. Date of birth (collected to verify that you are at least 18 and, for Creators, used to pre-fill and check the tax details form described below; never shown to other members) Gender (optional; kept private) Profile preferences, notification settings Creator Data Content niche, audience size estimates Portfolio uploads, social media links Campaign participation history Performance metrics and analytics Brand Data Company name, industry sector Campaign briefs, budgets, requirements Representative contact information Brand guidelines and asset uploads Content and Communications Uploaded media files (images, videos, documents) Pitch submissions and proposals In-app chat messages and threads, including messages held back by our automated message screening and the reason they were held Contract documents and agreements Reports you make about other members' content or behaviour, and reports or notices made about yours (the reason chosen, any details given, and the record of what we decided and why) Dispute information. If you open or answer a dispute about a campaign, what you write (the reason, what you expected and your account of what happened) and any files you upload as evidence (images, video, PDFs or documents). The other party to that campaign and Spongle staff can see what you submit. We also keep the outcome, the reasons for it, and the notes our staff make while reviewing it Delivery records used in a dispute. When a dispute is opened we automatically attach a record of what was agreed in the contract and what was delivered, taken from the post checks described in Section 4 Other People in Your Content Pitch videos, Deliverables, and other content you upload may show or name people other than you -- a friend, a family member, or someone appearing in a review, for example. We process their image, voice, and name only as part of hosting and displaying your content, in reliance on your confirmation in the Terms (Section 5.1A) that they have agreed to appear. If you appear in a member's content and are not a Spongle member, you can contact privacy@spongle.co to exercise the rights in Section 11. Delivery Details (Shipped-Product Campaigns Only) Some campaigns involve a brand sending you a physical product. Where that is the case, and only after the contract for that campaign is active, you may choose to submit delivery details so the brand can post it to you. We collect: Recipient name Address line 1, and address line 2 where you provide one City or town Postcode or Eircode, where your country uses one Country We do not collect a telephone number for delivery. We do not collect delivery details for any other kind of campaign, and we never collect them before a contract is active. Providing delivery details is your choice. If you would rather not give an address through Spongle, you do not have to — but the brand will not be able to send you the product, and you should raise that with the brand before pitching on a campaign that depends on it. Location Details (On-Location Campaigns Only) Some campaigns ask you to work at the brand's own location. Where that is the case, the brand tells us the city or town and the full address when it creates the campaign. We show the city to creators browsing the campaign, so you know where the work is before you pitch. We do not show the full address to anyone until you and the brand have both signed the contract and the brand has paid for the campaign — at that point it is shown to you and written into your signed agreement. If the brand never pays, the contract expires and the full address is never shown to you. The address comes from the brand, not from you. Where a brand runs its business from home, that address may be personal data, and we handle it accordingly. Unlike delivery details, an on-location address is not wiped at the end of the campaign. It forms part of a signed contract, so we keep it with that contract for as long as we keep the contract itself — see the retention table below. Contract and Legal Data Contract PDFs and signed agreements Electronic signature evidence (see Section 10) Signature integrity hashes (SHA-256) that bind each signature to the contract content shown at signing Contract audit trails and access logs Payment terms and agreement amounts Campaign deliverables and obligations Governing law and jurisdiction selections Financial Data Stripe Connect account IDs Payment transaction records Earnings, payouts, and revenue data Tax compliance information Subscription billing records (where a paid plan is offered, it is purchased on the web and processed via Stripe; none is offered at launch) Campaign Boost purchases (where Spongle offers Boosts): the Campaign boosted, the price and currency, any VAT charged (rate, amount and country), the start and end of the Boost and, if the payment was refunded or reversed, when and why. For a Boost bought on the website: the Stripe checkout and payment references, any VAT number you gave and the result of checking it with the EU VIES service, and the country of the bank that issued your card (your IP address and browser details are recorded as for any other card payment; see Section 9). For a Boost bought in the app: the Apple transaction ID or the Google Play order ID (or, if Google does not give us an order ID, the Google purchase token), the product, and whether it was a live or test purchase. We also record that you asked for the Boost to start straight away, the wording you agreed to, and the time. If we refuse an in-app Boost, we record that refusal For a limited number of legacy subscribers, app store transaction identifiers and purchase tokens (for subscriptions previously bought through the Apple App Store or Google Play Store) Tax Reporting Information (Creators) Spongle is required by applicable platform-reporting legislation to collect, verify and report specified information about certain Creators who carry out reportable activities or receive or are credited with consideration through the Platform (see Section 7, "Tax Authorities"). That legislation is Council Directive (EU) 2021/514 ("DAC7") as implemented in Irish law and, for Creators resident for tax purposes in a partner jurisdiction outside the European Union (currently, the United Kingdom), the OECD Model Rules for Reporting by Platform Operators with respect to Sellers in the Sharing and Gig Economy ("MRDP"). We ask for this information before you enter into your first Contract, and you cannot sign a Contract until it has been provided and accepted. We do not ask for it when you sign up. Spongle collects this information itself, through the tax details form in the Payments area of your Account (or the tax details step shown before signing); it is not collected by Stripe. Where your Stripe connected account already holds your name and address, we may pre-fill the form with them, and with the date of birth you gave us when you signed up, for you to check and confirm. A Creator may be an individual or an entity (for example, a company or a creative agency). The information the law requires depends on which of these the Creator is, on the Creator's country of tax residence and on the reporting regime that applies. The tax details form currently collects the information required for Creators who are individuals. A Creator that is an entity must contact support@spongle.co before submitting a Pitch, We will tell you how we will collect the information the applicable rules require for that entity (such as its legal name, business address, tax identification number and business registration number). We will keep it confidential and secure, use it only for the purposes described in this section, and keep it for the period set out in Section 9. For a Creator who is an individual, we collect and hold: your first and last legal name; your primary (home) address; your date of birth; the country in which you are resident for tax purposes; your tax identification number and the country that issued it (in Ireland, your Personal Public Service Number (PPSN); in the United Kingdom, your National Insurance number; elsewhere, the tax identification number issued by your country of tax residence); your place of birth, only where you tell us that no tax identification number has been issued to you; your VAT number, if you have one (optional); the identifier of your Stripe connected account (and of any earlier connected account), so that the details can be matched to the payments made to you; a record that you confirmed that the tax identification number is your own and that the details are correct, and when you did so; a keyed fingerprint of your tax identification number (see below); and the results of the checks described below, including the result of any check of your VAT number with the EU VIES service. Your tax identification number is encrypted as soon as it is saved. The app and the website show only its last four characters. It is decrypted only by our server: when a tax report is prepared for filing with the Revenue Commissioners and, where a record saved before we introduced the keyed fingerprint described below does not yet have one, once when you next save your details, to create it. Every tax report, and every download of it, is logged. We also keep a record of each request and reminder we send you about this information, and of each step we take under our Terms and Conditions if the information is missing. How we check your tax details. The law requires us to take reasonable steps to check that the information is correct. The checks depend on the type of information, on whether the Creator is an individual or an entity, and on the country concerned. For the tax details form, before we accept your details, our systems: check that your tax identification number has the format and check digit used by the country that issued it, and is not an example or placeholder number; check that it is not already held on another Spongle account; compare the date of birth you give us with the date of birth you gave Stripe for your connected account (if they differ, we cannot accept your details), and compare the legal name you give us with the name held by Stripe (if they differ, your details are saved but flagged for a member of our team to review). For these checks we read your date of birth, your name and the status of Stripe's verification of your identity from Stripe, and we use them for this purpose only; and, if you give a VAT number, check it with the European Commission's VAT Information Exchange System (VIES). VIES can confirm only VAT numbers issued by EU Member States, so a VAT number issued outside the EU cannot be confirmed through it; if VIES cannot be reached when you save your details, the VAT number is accepted on a format check alone. We may also compare your details with other information available to us and ask you to correct them. To check for duplicates without storing your number in readable form more than once, we store a keyed fingerprint of it: a one-way code made from the issuing country and the number using a secret key held only on our server. The fingerprint cannot be turned back into your number, is never shown in the app or on the website, and is used only for this check. We use these checks, and keep their results, because the law requires it (GDPR Article 6(1)(c); see Section 5). Your tax details are stored in our EU database (Supabase; see Section 7). The requests and reminders, and the yearly copy of what we reported about you (Section 7, "Tax Authorities"), are sent to you by email through our email provider (Resend; see Section 7). A copy of each yearly statement is also kept in Spongle's private storage for the retention period in Section 9. What collecting your tax details does not mean. We collect and report this information to meet Spongle's own legal duty as a platform operator. We do not use it to operate payroll, or to calculate or pay your tax on your behalf. Collecting it does not make you an employee or worker of Spongle. You remain solely responsible for your own tax affairs (see Sections 5.4 and 8.12 of our Terms of Service). Technical Data IP addresses, device information The IP address our servers observe when you begin a card payment, together with your browser or app user-agent string and the payment channel used. This is recorded for card payments only. It is not recorded for bank transfers, nor for automatic renewal or retry charges taken when you are not present. It is used to defend card chargebacks — see Section 7 (Payment Disputes and Chargeback Defence) and Section 9 (Data Retention) Operating system, app version Your time zone and language setting. When you sign up, sign in or open the app, we read the time zone and the language and region setting from your device or browser and save them to your account. We use them only to show dates, times, numbers, prices and addresses the way you are used to reading them, and to send reminders at a sensible time where you are. We read these from your device's settings. We do not use GPS, your IP address or your precise location to work them out. They are updated whenever you use Spongle on a device with different settings, and are kept with the rest of your account details Error logs and performance data Cookie preferences and tracking data A device signature, on the website only. When you sign up or sign in on spongle.co we combine characteristics your browser reports -- user-agent, language, screen size and colour depth, timezone, and how your browser renders a small test image -- into a single short code. It is not a cookie and nothing is stored on your device. We use it only to spot bots and repeat abusive sign-ups, which is our legitimate interest in keeping the platform safe (Article 6(1)(f)); we do not use it for advertising, tracking you across other websites, or building a profile of you. It is recorded against sign-up and sign-in attempts, including failed ones, and kept for 90 days Social Media Integration Data Connected platform profile information Follower counts and engagement metrics Content performance statistics Account verification status Performance figures for a campaign post you publish, read from the moment you submit its link to us and refreshed for the duration of that campaign (Section 4) AI and Analytics Data SpongleAI chat prompts and responses Content analysis results Automated insights and recommendations Product-usage events (only with your analytics consent): key actions such as creating an account, publishing a campaign, submitting or accepting a pitch, signing a contract, and completing a payment -- recorded against your account ID and account type (brand or creator) only; never message content, pitch content, or payment amounts Technical error and crash reports (only with your analytics consent): where part of the Platform fails on your device, we record the technical details of that failure -- the error type and message, the generalised page you were on, and basic device and browser information -- so that we can identify and repair faults. These reports are generated automatically by the application and are not read by us as a record of what you were doing; they are used to fix defects. We do not collect message content, pitch content, or payment amounts in these reports Special Category Data We do not solicit, request, or knowingly process special-category personal data as defined in Article 9 GDPR (data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade-union membership, genetic data, biometric data used for identification, health data, or data concerning sex life or sexual orientation). Please do not include this kind of information in campaign briefs, pitch videos, messages, or other uploads. If you believe special-category data has been submitted inadvertently, contact privacy@spongle.co and we will remove it. Biometric authentication at contract signing. Where you sign a Contract using Face ID, Touch ID, a fingerprint, or another biometric method, that check is carried out entirely by your device's operating system within its secure hardware. Spongle does not receive, collect, store, or process your biometric data (such as a face or fingerprint template); we record only whether a biometric or device-passcode authentication succeeded, as part of the signature evidence described in Section 10. Spongle therefore does not carry out biometric identification within the meaning of Article 9 GDPR. Where Your Data Comes From We gather personal data from three places: From you -- the details you enter when you register, set up a profile, submit a pitch, build a campaign, sign a contract, or contact our team. From your use of Spongle -- information created automatically as you use the app and website, such as device, log, and usage data. From selected third parties, namely: the social platforms you link by OAuth, which return your public profile and engagement figures (Section 4); and Stripe, which generates identity, verification, and payout information during Connect onboarding and payment (including the name and address we may use to pre-fill a Creator's tax details form, and the date of birth, name and identity-verification status we compare with those a Creator gives on that form), and tells us when a card payment is disputed with the card issuer or flagged by the issuer as possibly fraudulent. We never purchase personal data from list brokers, data resellers, or enrichment services. We do not use any outside service to look up your social media profile, and your username is never passed to a third party for that purpose.

Spongle AI Services Our AI features use third-party AI providers: OpenAI (assistant chat, drafting, and analysis), Google Gemini (AI image generation for niche and marketing imagery), and Cloudflare Workers AI (internal and admin features only, including a suggestion for our staff when they confirm the outcome of a dispute that a Brand has referred to us under Section 15.3 of our Terms; it is given the agreed contract scope and the reason given for rejecting the content, with email addresses, IP addresses, phone numbers and account and payment identifiers removed). The applicable providers are listed in the sub-processor table in Section 7. Content suggestions, campaign drafting, and recommendations Automated content analysis and insights We limit the data sent to AI providers to what is needed to provide the feature. When you use Spongle AI, this means your chat messages and information from your own account — such as your profile, campaigns, and pitches — are sent to our AI assistant provider (OpenAI) so it can answer you; we never send another user's private data. These providers' API terms exclude data sent through their APIs from being used to train their models by default. Google Gemini is used only to generate illustrative imagery from a category description and does not receive your personal data. For our AI providers we rely on their published API terms, and we do not authorise the use of your data to train their models. Automated Sign-Up Protection We use Cloudflare Turnstile to detect and block automated bots during sign-up Important: Our AI features are not 100% accurate. They provide estimates and suggestions based on available data patterns. We recommend treating these insights as guidance rather than definitive assessments. Human review is always recommended for important decisions. Data Processing for AI Social media metrics and engagement patterns Content performance and interaction data Account creation dates and activity patterns Cross-platform behaviour analysis What actually reaches the AI provider. When you use the Spongle AI assistant, the information it needs to answer you is sent to OpenAI as part of your question. Depending on what you ask, that can include your profile details, your campaigns and pitches, your contracts and their terms and amounts, your payment history, and the contents of your Spongle messages, including the other party's display name. It is read using your own permissions, so the assistant can only ever see what you can already see in the app yourself. We do not send it your password, your card details, or anything held by Stripe. Our image generation is different: the prompts sent to Google Gemini are written by Spongle and fixed. No personal data and no content of yours is sent to Gemini at any point. If you would rather not have your information processed this way, you do not have to use the AI assistant -- the rest of Spongle works exactly the same without it.

We support OAuth and API integrations with the following platforms so creators can verify their social media connections. Supported Platforms (6 Total) Instagram (Business Login for Instagram — professional accounts) TikTok YouTube (via Google) Facebook Pages Threads Pinterest LinkedIn and Snapchat are not currently offered. Neither platform lets us read the audience or engagement figures a Brand relies on. Since 20 September 2026 they cannot be connected, the small number of earlier connections was removed, and we hold no LinkedIn or Snapchat account data. If either platform later makes those figures available, we will update this Policy before offering it again. How Connections Work OAuth-Verified Connections: Full OAuth 2.0 authorisation flow with PKCE where supported Direct API access to the figures each platform reports, refreshed on the schedule set out under "Data Sync Frequency" below OAuth tokens stored server-side only (never on your device) Access and refresh tokens are held server-side and encrypted at rest using AES-256-GCM Marked as "verified" with a platform badge Automatic daily metric sync What We Access via OAuth Public profile information (username, display name, avatar, bio) Follower and following counts Post and video counts Engagement metrics (likes, comments, views, shares) Engagement rate calculations, worked out from the like, comment and share counts on your most recent posts (typically the last 20 to 25). We read those counts only; we do not read, store or analyse the content of those posts Account verification status (platform blue tick) Performance figures for a campaign post you have published and submitted to us, as set out immediately below Campaign Post Metrics When you accept a campaign and publish the agreed content to your own account, you submit the link to that post to us. From that point, and for the duration of that campaign, we read how that specific post is performing and make those figures visible to the Brand that commissioned it. For campaign reporting we read figures for that post only. The only other posts we touch are the recent-post counts used for your engagement rate, described above. We do not collect demographic information about your followers or your audience. What we are able to read depends entirely on what each platform permits. Some of these figures are publicly visible on the post itself. Others are insights that the platform ordinarily shows only to you as the account holder. Both are set out below so that you can see precisely what a Brand will be shown. Platform Publicly visible on the post Insights ordinarily visible only to you Instagram Likes, comments, and views on a reel Reach, saves, shares, average watch time, skip rate, total interactions TikTok Views, likes, comments, shares None available to us YouTube Views, likes, comments Watch time, average view duration, average percentage viewed, shares, subscribers gained and lost, playlist saves Pinterest None available to us Impressions, saves, save rate, pin clicks, outbound clicks, comments, reactions Threads Views, likes, replies, reposts, quotes Shares Facebook Likes, comments, shares None available to us Where a platform does not measure a figure, we record nothing for it. We do not substitute a zero, and a Brand is shown only what was actually measured. What We Store On Your Device: Nothing. OAuth tokens never leave our servers. Server-Side: Username, metrics, profile URL, sync timestamps Server-Side (Encrypted): Access and refresh tokens, scope, expiry Pitch Snapshots: Frozen metrics at pitch submission for brand review What We Do Not Do Post anything to your account. We never post on your behalf, and a Brand can never trigger a post to your account. If we later offer a way for you to publish an approved campaign post through Spongle yourself, we will update this Policy before it is available Access private messages or DMs Store login credentials on your device Share your OAuth tokens with third parties Access content beyond what is needed for metrics Modify or delete any of your social media content Read the content of your posts. For a campaign post you have submitted, we read its performance figures; for your engagement rate, we read only the like, comment and share counts on your recent posts Collect demographic information about your followers or your audience Give a Brand any ability to act on, change, or post to your account Data Sync Frequency OAuth-verified accounts: daily automatic sync via secure cloud functions Campaign post metrics: refreshed approximately every six hours while the campaign is running On-demand refresh available in app settings Metrics frozen at pitch submission for brand review Revoking Access You can disconnect social accounts at any time in Settings OAuth tokens are deleted immediately when you disconnect For Facebook, YouTube and TikTok we also ask the platform, at the same moment, to withdraw Spongle's authorisation, so Spongle no longer appears among the apps connected to your account. Instagram, Threads and Pinterest do not offer us that call, so for those platforms you can remove Spongle in the platform's own settings if you wish Historical metrics are kept for pitch snapshots (legal basis: contract performance) You can also revoke access directly on the social platform's own settings page

This section explains specifically how Spongle accesses, uses, stores, and shares Google user data, in line with the Google API Services User Data Policy and the Google APIs Terms of Service. It applies in two situations: when you choose to sign in with your Google account, and when a Creator chooses to connect their YouTube channel. If you never use either feature, Spongle does not access any Google user data about you. Data We Access Sign in with Google. When you sign in or register using your Google account, we receive — through Google's OpenID Connect sign-in (scopes openid, profile, email) — your name, email address, profile picture, and your Google account identifier. YouTube channel connection (Creators only). If a Creator connects their YouTube channel, we access read-only data through the YouTube Data API and YouTube Analytics API (scopes youtube.readonly, yt-analytics.readonly): your public channel profile (channel name, channel ID, handle, avatar, and description), subscriber count, video count, public view counts, and aggregate engagement and analytics metrics (such as views, likes, and comments). Read-only access only. We request read-only scopes. We do not request or obtain access to upload, edit, publish, or delete any content; to private messages; or to any other Google service, including Gmail, Google Drive, Google Calendar, or your Google contacts. How We Use Google User Data Sign in with Google data is used solely to authenticate you, to create and maintain your Spongle account, and to pre-fill your name, email address, and profile picture. YouTube data is used solely to verify your channel connection and display a verified badge, to show accurate audience and engagement metrics on your Spongle profile and in the pitches you submit to Brands, to record a snapshot of those metrics at the moment you pitch, and to keep your metrics current through an automatic daily sync. We do not use Google user data for advertising, we do not sell it, and we do not use it to train artificial-intelligence or machine-learning models. Spongle's use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. How We Store Google User Data OAuth access and refresh tokens are stored on our servers only, never on your device, and are encrypted at rest using AES-256-GCM. They are retained only for as long as your Google sign-in or YouTube channel remains connected. Channel metrics are stored in our EU-based database (Supabase, Dublin region). We keep only the current figures, refreshed by the daily sync; we do not keep a day-by-day history. They are deleted when you disconnect the channel, except for the metric snapshot frozen at the point of a pitch, which is retained on the basis of contract performance so that Brands have a stable record of the figures they relied upon (see Section 4, "Revoking Access"). You can disconnect at any time in Settings, which deletes the stored OAuth tokens immediately, and you can additionally revoke Spongle's access directly in your Google account at myaccount.google.com/permissions. How We Share Google User Data We do not sell Google user data and we do not share it for advertising or for any purpose unrelated to providing or improving the features described above. Because Spongle exists to connect Creators and Brands, the public YouTube profile and metrics you choose to connect are shown to other Spongle members as part of your profile and your pitches. That is the purpose of connecting a channel, and it happens only for channels you connect yourself. We do not disclose Google user data to any other third party except: (a) the infrastructure sub-processor that hosts it on our behalf under a data-processing contract (Supabase — EU database, authentication, and storage; see Section 7); and (b) where we are required to do so by law. Your OAuth tokens are never shared with any third party. Limited Use Affirmation Spongle's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Consent (Article 6(1)(a)) Optional cookies and tracking Marketing communications Linking a social media account (optional — your choice) Analytics and personalisation Contract Performance (Article 6(1)(b)) Account creation and management Hosting, displaying, and delivering the content you upload (profiles, Pitches, Deliverables, messages) Campaign participation Campaign product fulfilment — passing your delivery details to the brand you have a contract with, so it can send you the product that campaign requires Payment processing Platform functionality Subscription management (where a paid plan is offered, it is purchased on the web via Stripe; legacy In-App Purchase and Google Play Billing transactions apply only to existing subscribers) Selling and providing Campaign Boosts, checking in-app Boost purchases with Apple or Google, and ending a Boost if its payment is refunded or reversed Setting your default currency (euro or pounds sterling) from the country on your Account Showing dates, times and amounts in your local format, and timing reminders to your time zone Campaign discovery personalisation (country-based content relevance) Measuring how a campaign post you have published is performing, and reporting those figures to the Brand that commissioned it, for the duration of that campaign Legal Obligation (Article 6(1)(c)) Tax reporting and compliance Collecting, verifying, retaining and reporting Creator tax information where required under the applicable DAC7 or MRDP rules: carrying out the due-diligence checks described in Section 2 (such as checking the format of a tax identification number, checking for duplicates by means of a keyed fingerprint, comparing an individual Creator's date of birth with the one held by Stripe, and checking any VAT number given with VIES); keeping records of the procedures applied and the information relied upon; sending the requests and reminders the rules require where information is missing, and applying the measures the rules require; filing the report with the Revenue Commissioners; and sending each reportable Creator a copy of what we report about them (section 891I of the Taxes Consolidation Act 1997 and S.I. No. 705 of 2022, which give effect in Ireland to Council Directive (EU) 2021/514 ("DAC7"), and, for Creators resident for tax purposes in a partner jurisdiction outside the European Union such as the United Kingdom, the MRDP) Identity and KYC verification (carried out by our payment provider, Stripe Connect, as part of its onboarding and anti-money-laundering obligations) Regulatory audit requirements Handling notices of illegal content, giving statements of reasons for moderation decisions, handling appeals, and keeping records of them (EU Digital Services Act, Regulation (EU) 2022/2065) Legitimate Interest (Article 6(1)(f)) Fraud prevention and security Service improvement and development Customer support and troubleshooting Bot detection and platform integrity Verifying connected social accounts and keeping their metrics accurate Screening in-app messages for contact details and off-platform links, reviewing reports about members and content, and enforcing our Terms and Code of Conduct Hosting content that shows or names people other than the member who uploaded it (see Section 2) Keeping a record of your request that a Campaign Boost start straight away, and of any refund or reversal, so we can show what was agreed and respond to refund claims and chargebacks What Happens If You Hold Back Certain Data Parts of Spongle cannot run without certain information. Where data is required to provide the service you have signed up for under our Terms and Conditions (Article 6(1)(b)), or to satisfy a legal duty (Article 6(1)(c)), declining to provide it limits what we can do for you: no email and password means no account can be created or kept secure; no date of birth means we cannot confirm you are 18 or over, so registration cannot proceed; no linked Stripe Connect account means a Creator cannot pitch or be paid, and a Brand cannot fund a campaign or pay a Creator; where the tax and identification information required for seller due diligence (Section 2, "Tax Reporting Information (Creators)") has not been provided and accepted, a Creator cannot sign a contract until it has been. If details we already hold turn out to be missing or incorrect after a contract has been signed, we ask for them and send two written reminders; if they are still missing 60 days after the second reminder, the Creator's payments are held, the account is suspended from new work, and no new account can be opened, until they are provided. If they are still missing 24 months after that, the held payments are paid out and the account is closed and cannot be reopened until they are provided. Where a Creator is a reportable seller, we report the payments to the Revenue Commissioners as the law requires, including, where the tax identification number has not been provided, the fact that it has not been provided; no social-connection details means we cannot show verified metrics or a verified badge on your profile. no delivery details means a brand cannot post you the product on a campaign that involves sending one; everything else about the campaign is unaffected. Anything we describe as optional -- gender, or extra profile details, for instance -- is genuinely optional, and leaving it out changes nothing about your access to the core service. Where we ask for consent (marketing email or optional analytics, for example), you may decline it or withdraw it later and keep full use of Spongle.

Core Platform Operations Account creation and authentication Profile customisation and preferences Campaign matching and recommendations Content upload and management Setting your default currency (euro or pounds sterling) from your country Showing dates, times, numbers and prices in your local format, and sending reminders at a sensible local time Campaign discovery relevance (country-level, not precise location) Communication and Collaboration In-app messaging and notifications Campaign updates and status changes Payment alerts and confirmations Customer support interactions Three Kinds of Message, Handled Differently Not every message from Spongle works the same way: Essential account and service messages keep the platform running and record what you have agreed to -- sign-in codes and security alerts; payments, payouts and refunds, and Spongle's VAT invoices for its own fees; contracts and signature copies; breach and dispute notices and their deadlines; changes to our terms or this policy; and confirmations of account deletion or a data request. These form part of providing the service you signed up for under our Terms and Conditions (Article 6(1)(b)), or are required of us by law (Article 6(1)(c)). They are sent from notifications@spongle.co and cannot be switched off while your account is open -- the service depends on them, and some of them we are obliged to send you. Optional updates tell you about activity you would probably like to know about but would not be harmed by missing -- a creator pitching your campaign, a pitch being accepted, declined or expiring, a campaign finishing, deliverables being approved automatically, and the welcome note when you join. Every one of these carries an Unsubscribe link. Turning them off costs you nothing you cannot recover: the same news still reaches you by push notification and in your in-app activity feed, neither of which this setting touches. You can switch them back on at any time under Settings, Notifications. Marketing messages -- newsletters, product news, tips, and offers -- reach you only if you have opted in (Article 6(1)(a)). You control this under Privacy & Data, you can turn it off whenever you wish, and every marketing email carries its own unsubscribe link. What the Unsubscribe link does. Using it stops optional updates and withdraws your marketing consent, in a single action -- we would rather over-honour "stop emailing me" than under-honour it. It never affects the essential messages above. Coming back is deliberately not symmetrical: optional updates are restored by a switch under Settings, Notifications, but marketing consent can only be restored by you, under Privacy & Data, as a fresh choice recorded with its own timestamp. Nothing else on Spongle turns marketing back on for you. AI-Powered Features Content suggestions and optimisation Automated insights and analytics Personalised recommendations Trust, Safety and Content Moderation Screening in-app messages automatically for email addresses, phone numbers, postal addresses, external links, social-media handles, and requests to move off the platform; a message that matches may be blocked at the moment it is sent and placed in a queue for our team to review (Terms, Sections 11, 13.2 and 16.2) Monitoring published campaign posts automatically against the approved content record Reviewing reports and notices of illegal content, deciding on enforcement action, and handling appeals -- always with a person making the decision Telling the person who reported, and the member whose content was affected, what we decided and why Financial Operations Payment processing and tracking Earnings calculations and reporting Tax compliance and documentation Dispute resolution and chargebacks Subscription billing and renewal management Platform Improvement Usage analytics and performance monitoring Feature development and testing Security enhancements and fraud prevention User experience improvements

What Is Visible to Other Members Because Spongle exists to connect Brands and Creators, some of your information is shown to other members by design: Your public profile, seen by other signed-in members, carries your username, name, and avatar and -- depending on whether you are a Creator or a Brand -- your business name and logo, bio, broad location (city and country), niches or industry, website, verified status, and any social accounts you have linked. It never shows your email address, date of birth, or gender. Inside a campaign, the Brand running it sees your pitch video, the fee you propose, and the social figures recorded at the moment you pitched; matching Creators see the brief and what the campaign asks for; and once matched, both sides can message through in-app chat. Delivery details you submit for a shipped-product campaign are shown to one party only: the brand you have an active contract with for that campaign. No other brand, no other creator, and no one browsing the platform can see them. Spongle staff can access them only where genuinely necessary — for example to resolve a delivery dispute or to meet a legal obligation. The brand receives them so it can post the product to you, and must not use them for anything else (see our Terms, Section 11.1A). Kept private throughout: your contact details, login credentials, date of birth, gender, and payment and payout information — with the single exception of delivery details on a shipped-product campaign, which go to the contracted brand as described above, and only then. Direct messages stay between you and the other party, reachable by Spongle staff only where genuinely necessary -- for instance to resolve a dispute or meet a legal obligation. With Your Explicit Consent Accepted campaign pitches and collaborations Public profile information display Social media cross-posting (if enabled) With Trusted Service Providers Provider Location Purpose Safeguard Stripe USA Payment processing, holding campaign payments until release, payouts, and KYC; subscription billing (web) Standard Contractual Clauses / EU-US Data Privacy Framework Supabase EU Database, authentication, storage, and hosting of platform data EU data centres European Commission (VIES) EU Checking a VAT number you give us (Campaign Boost purchases and Creator tax details) Within the EU PostHog EU Consent-based product analytics -- key usage events, generalised page views (the type of page, not its exact address) and the moment you leave a page, together with technical error and crash reports, recorded against your account ID and account type (brand or creator) EU data centres Cloudflare Global edge network Web app hosting (Cloudflare Pages), hosting for Spongle's internal admin console (Cloudflare Workers, staff-only), DNS, edge cache, bot-challenge (Turnstile -- receives your IP address), and internal/admin AI features (Workers AI) Standard Contractual Clauses OpenAI USA AI assistant chat, drafting, and analysis Standard Contractual Clauses Google (Gemini) USA AI image generation (niche category and marketing imagery) from fixed prompts written by Spongle. No personal data and no user content is sent to Gemini Standard Contractual Clauses Resend USA / EU All Spongle email -- essential account, payment and service notifications, optional updates, legal-change notices, and any marketing email Standard Contractual Clauses Apple USA Sign in with Apple; push notification delivery (APNs — device identifiers and notification content); in-app purchases of Campaign Boosts, where offered (Apple processes the payment as the seller under its own privacy policy; we give Apple the Campaign's identifier with the purchase and check the purchase with Apple); billing for legacy in-app-purchase subscribers Standard Contractual Clauses Google USA Google sign-in; push notification delivery to Android devices via Firebase Cloud Messaging (device tokens transmitted to Google); in-app purchases of Campaign Boosts, where offered (Google processes the payment as the seller under its own privacy policy; we give Google the Campaign's identifier with the purchase, check the purchase and any refund with Google, and may ask Google to refund a purchase we refuse); billing for legacy Google Play subscribers Standard Contractual Clauses Social platforms (Instagram, Facebook and Threads (Meta); TikTok; YouTube (Google); Pinterest) Global OAuth connection and read-only retrieval of profile and engagement metrics Standard Contractual Clauses Our accountants and professional advisers Ireland Reviewing our annual tax report to the Revenue Commissioners before it is filed (including Creator tax details), and advising us on our tax obligations Professional duty of confidentiality and written terms requiring confidentiality and security Reports, Notices and Enforcement When you report content or a member, your report (the reason and any details you give) goes to our support team together with the record concerned. We do not tell the member you reported who reported them unless the law requires it or it is strictly necessary to explain our decision to them, and we never do so where you have reported anonymously. When we tell a member why their content was removed or their account restricted, we say whether a report or notice prompted the action. We may disclose reports, notices, and enforcement records to Coimisiún na Meán (the Digital Services Coordinator for Ireland), other competent authorities, or law enforcement where the law requires it. Legal Requirements Court orders and legal proceedings Regulatory investigations Tax authority requests Law enforcement compliance Tax Authorities Spongle is required under applicable platform-reporting legislation to report information about Creators who are reportable sellers, whether they are individuals or entities. Where a Creator is reportable, we report to the Revenue Commissioners in Ireland once a year, by 31 January, for the previous calendar year. Depending on the reporting regime and the Creator's country of tax residence, the Revenue Commissioners pass the information to the tax authority of that country: to the tax authority of another EU Member State under Council Directive (EU) 2021/514 ("DAC7"), or to the tax authority of a partner jurisdiction outside the European Union (for example, HM Revenue & Customs in the United Kingdom) under the MRDP. Spongle does not choose which foreign tax authority receives the information. We report the tax details you gave us (Section 2, "Tax Reporting Information (Creators)"), including your tax identification number, together with the total consideration paid or credited to you in each quarter of the calendar year, the number of relevant activities (Campaigns) involved, the fees, commissions and taxes we charged or withheld, and any other information the applicable rules require. By 31 January each year, we send each reportable Creator a copy of the information we reported about them for the previous year. Our accountants and professional advisers may see this information when they review the report for us before it is filed. They are bound by a professional duty of confidentiality and by written terms requiring them to keep it confidential and secure. This is a legal obligation under GDPR Article 6(1)(c), not something you consent to. We cannot opt you out of it. Automatic Payout Holds and Pitch Pauses for Missing Tax Details Refusing to let a Creator sign a contract until tax details have been provided and pass the checks in Section 2 is applied automatically by our systems, without a person deciding each case. Where we hold a Creator's payouts or pause new pitches because tax details are missing (Section 5, "What Happens If You Hold Back Certain Data"), that is also applied automatically; pausing new pitches is the suspension from new work described in Section 5. They depend only on whether the required details have been provided and pass those checks; they involve no assessment of you. The hold and the pause apply only where the platform-reporting rules require Spongle to apply them, and only after our request, two written reminders and a further 60 days, as those rules require. Closing an account for missing tax details is decided by a person. You can end the refusal, the hold and the pause at any time by adding valid tax details (or, for an entity, by providing them to support@spongle.co), and any held funds are then released. If you think a hold or pause has been applied to you in error, you can ask for a person to review it, give us your view and contest it by writing to support@spongle.co or privacy@spongle.co (GDPR Article 22(3)). Payment Disputes and Chargeback Defence We may share your personal data with: (a) payment processors and card networks (Stripe, Visa, Mastercard) for the purpose of processing payments and defending disputes you raise or are involved in; (b) your card issuer or our card acquirer for the purpose of providing chargeback evidence; (c) our legal advisers for the purpose of dispute defence. The lawful basis is Article 6(1)(f) UK/EU GDPR (legitimate interest in defending against fraudulent or unfounded payment disputes). Card network rules allow a business to contest an unfounded "friendly fraud" chargeback by demonstrating a consistent history of undisputed payments by the same cardholder — for example Visa Compelling Evidence 3.0. So that we are able to rely on those rules, we record the IP address our servers observe when a card payment is started, together with the user-agent string and the payment channel used. Where a chargeback is raised, we may submit that information — both for the disputed payment and for earlier undisputed payments made with the same card — to Stripe, the relevant card network, and the card issuer, alongside the email address and account identifier associated with those payments. We record this information for card payments only, and only where you are present and start the payment yourself. The lawful basis is Article 6(1)(f) UK/EU GDPR (legitimate interest in defending against fraudulent or unfounded payment disputes). Where you (Creator) are involved in a dispute initiated by a Brand against Spongle or its payment processor, we may share your personal data to the extent necessary to evidence your delivery of the contracted service. Wherever possible we evidence service delivery using your professional service records (signed contract, deliverable post URL, content hash, monitoring log) rather than your personal contact data. When a Brand disputes a card payment with its bank, the evidence we give Stripe and the card issuer can include the Brand's name, email address and billing address, the IP address recorded when the payment was started, the campaign's post links and performance figures, and the in-app messages the Brand and the Creator exchanged about that campaign. This means a Creator's messages in that conversation can be shared with Stripe and the card issuer, for the sole purpose of showing that the work was agreed and delivered. We do this under our legitimate interest in defending payments that were properly made (Article 6(1)(f)). When we compile a dispute-evidence bundle, the information shared is limited to what is necessary to evidence the transaction and service delivery and to defend the dispute. We disclose evidence only to Spongle, our payment processor (Stripe) and — where strictly necessary — the relevant card network, card issuer, and our legal advisers; the technical and contact details included are those the chargeback process requires. We do not disclose dispute evidence to any other third party. Evidence bundles compiled for dispute defence are stored in private, access-restricted storage and are retained for the duration of the dispute resolution process and, where they form part of our financial records, for up to seven (7) years in line with our retention schedule (Section 9). Any recipient of an externally shared evidence bundle is expected to process it solely to defend the disputed transaction, not to retain it beyond the dispute resolution period, not to disclose it onward without authorisation from Spongle Limited, and to honour any data-subject-rights request. Where a Campaign deal becomes the subject of a payment dispute, chargeback, or referred dispute, the stored preview video, the approved content record (the "Approved Bundle"), the published post URL and content hash, and our post monitoring records together constitute the evidence of what was agreed and what was delivered. These records are retained for the periods set out in Section 9 notwithstanding any earlier scheduled deletion, in reliance on Article 6(1)(f) GDPR (defence of legal claims) and, where deletion has been requested, Article 17(3)(e) GDPR. You can contact our data protection team at privacy@spongle.co to: Request a copy of evidence shared about you in a dispute Object to the processing under Article 21 UK/EU GDPR (subject to our overriding legitimate interest) Request rectification or erasure of any evidence retained beyond the dispute resolution period Business Transfers and Insolvency If Spongle is involved in a merger, acquisition or sale of assets, your personal data may be transferred to the successor entity, which will remain bound by this Privacy Policy (or a privacy policy that is at least as protective). We will notify you of any such change before it takes effect. If Spongle stops operating, personal data we are not legally required to keep will be securely deleted. Records we are legally obliged to retain -- for example, financial and tax records -- will be kept by our liquidator or an appointed custodian only for as long as the law requires (6 years), and then securely destroyed. Any funds held on your behalf will be released in line with our Terms and Conditions. We Never Sell your personal data to third parties Share data for marketing purposes without consent Give advertisers access to raw user data

Data Storage Locations Primary: Supabase (PostgreSQL, EU region) Backups: EU data centres only Processing: Ireland (EU region) Third-Party Transfers Stripe (USA): Standard Contractual Clauses / EU-US Data Privacy Framework OpenAI (USA): SCCs for the Spongle AI assistant Google (USA): SCCs for AI image generation Cloudflare (global edge network): SCCs for web hosting, hosting of Spongle's internal admin console, DNS, edge security and bot-challenge, and internal/admin AI features Apple and Google (USA): SCCs for sign-in, push notification delivery, in-app Campaign Boost purchases, and legacy subscription transaction data Tax authorities: Spongle files the tax information it reports with the Revenue Commissioners in Ireland. Where you are resident for tax purposes outside Ireland, the Revenue Commissioners, not Spongle, may pass it to the tax authority of your country under the applicable tax-information-exchange arrangements: another EU Member State under DAC7, or a partner jurisdiction outside the European Union (for example, HM Revenue & Customs in the United Kingdom) under the MRDP. Spongle does not choose which foreign tax authority receives it (Section 7, "Tax Authorities") Transfer Safeguards EU Commission-approved Standard Contractual Clauses Review of our processors' transfer safeguards Data minimisation for international processing Encryption in transit and at rest

Active Accounts The periods below describe how long we keep each type of data while your account is active. We may keep specific records longer where the law requires it (for example payment, contract, and tax records — see the table further down), or delete data sooner where we no longer need it. Data Type Retention Period Account data Duration of account, then deleted after the 30-day grace period (except data we must keep by law) Campaign and pitch data Kept while your account is active. When your account is deleted, your campaigns and pitches are unlinked from you (your identifier is removed); records that form part of a contract, payment, or dispute are kept where we must for legal or tax reasons (see below) Messages Kept for the life of the conversation. Automatic system messages you have read are deleted the next time you open the app once 3 days have passed since you read them. Other messages, including messages blocked by our filters, are not deleted on a fixed schedule while your account is open; they are deleted when your account is permanently deleted (see below). The record of why a message was blocked is kept as set out in the "Reports, notices, blocked-message records" row below. If a campaign, contract or dispute still needs your messages when you ask to delete your account, permanent deletion is deferred until it is resolved (see "After 30 Days" below) Delivery details (shipped-product campaigns) Kept only while needed to get the product to you. Once the brand marks the product as posted, the address fields are blanked 14 days later; if it was never posted, they are blanked as soon as the contract ends. Once blanked they cannot be recovered — we keep only the destination country and the delivery status, for audit. Deleted in full if you delete your account. We keep no delivery details for campaigns that do not involve sending a product Location details (on-location campaigns) The city is part of the campaign record. The full address is provided by the brand and, once both parties sign, forms part of the signed contract — so it is kept with that contract for the contract and financial retention periods above, and is not wiped at the end of the campaign Spongle AI chat history Conversations are deleted automatically after 30 days of inactivity. Aggregate AI usage metering records (counts, not chat content) are kept for up to 13 months Analytics data Discovery-feed usage analytics are collected only with your consent and used to improve the Platform. Usage events recorded in our own database are kept for 2 years and then deleted automatically. You can withdraw consent at any time, after which we stop recording new activity, and your profile and events held by our analytics provider are deleted when you delete your account Preview / draft content media 120 days from submission, then purged (chargeback window) Unsuccessful pitch videos Deleted around 30 days after a pitch is rejected, withdrawn, or expires. We send a 7-day warning first so you can download a copy; the pitch record itself is kept. Pitch videos (all other pitches) Removed 120 days after the Campaign finishes (the later of the Campaign end date and the last verified delivery). We send a 7-day warning first so you can download a copy; the pitch record itself is kept. Post monitoring records (verification checks and engagement snapshots) Kept for as long as your account is open, because they are the record of what was actually delivered under a contract. Once your account is deleted they are unlinked from you and kept with the contract and payment record for 6 years, or 7 years where they form part of a chargeback, breach, or dispute record (see the legal-compliance table below) Payment IP records (the IP address, user-agent string and payment channel observed when a card payment is started) 36 months from the date of the payment, then deleted automatically. This period covers the maximum window in which a card dispute may still be raised, together with the period during which an earlier payment may still be needed as supporting evidence Reports, notices, blocked-message records, statements of reasons, and appeal decisions Kept while the matter is open and afterwards as an enforcement record needed to apply our repeat-infringer and misuse rules and to demonstrate compliance with the Digital Services Act. Personal data in these records is removed or anonymised when it is no longer needed for those purposes, and kept longer only where it forms part of a dispute, legal-hold, or law-enforcement matter. Scheduled deletion of a reported pitch video is paused while a report about it is open Financial records (payments, payouts, invoices, platform fees) 6 years (Irish Companies Act and tax law) Deleted Accounts (30-Day Grace Period) When you request account deletion, your account enters a 30-day soft deletion period. During the Grace Period (Days 1--30): Your account is marked as "pending deletion" and deactivated Your profile is hidden from other users You cannot access any platform features All active campaigns and contracts are suspended Your data stays intact but inaccessible You can restore your account during the grace period: log back in and you'll be asked whether to restore your account or continue with deletion If you restore it, you'll get a "Welcome Back" confirmation Campaign media is the one exception. Images and files uploaded to a campaign -- covers, brand assets and the campaign's own media -- are attached to the campaign rather than to you, and the other party to that contract still relies on them as part of the record of what was agreed. They are therefore not removed when you close your account. Everything uploaded to your own profile -- avatar, portfolio, business logo, pitch videos and data exports -- is deleted. After 30 Days (Permanent Deletion): If an open dispute, a payment still clearing, a payout in transit, or a legal hold still affects your account, permanent deletion is deferred until that matter is resolved. Where we can, we tell you this before you confirm closure. We also email you once to explain the delay and to confirm that you may complain to the Data Protection Commission. Your account stays closed and deactivated throughout, and the deletion completes automatically once the matter clears. The following data is permanently deleted or anonymised so that it no longer identifies you (records we must keep by law — see below — are retained but unlinked from your profile): Profile information (display name, bio, avatar) Portfolio content and uploaded media Campaign preferences and saved items Draft contracts and unsigned agreements Chat messages and notification history Social media connection data and OAuth tokens Analytics preferences and dashboard settings Delivery details submitted for shipped-product campaigns Data Retained for Legal Compliance (GDPR Article 6(1)(c)) Even after the 30-day grace period, we are legally required to keep certain data: Data Type Retention Period Legal Basis Payment transaction records 6 years Irish Companies Act and tax law (Revenue Commissioners requirements) Signed contracts (PDFs) 6 years Statute of Limitations Act 1957 (Ireland) Electronic signature evidence Kept with the signed contract record (6 years) Establishing and defending legal claims about the signed contract (Statute of Limitations 1957 (Ireland)) Tax compliance information (Spongle's own tax and VAT records) 6 years Irish tax and VAT law (Taxes Consolidation Act 1997 and Value-Added Tax Consolidation Act 2010) and the Companies Act 2014 Creator seller-due-diligence and platform-tax-reporting records, for individual and entity Creators: the tax details and other information relied upon, the keyed fingerprint of the tax identification number, the Creator's confirmation that the details are correct, the results of the checks we carried out, the requests and reminders we sent, the measures we took where information was missing (holding payments, suspending or closing an account), and the DAC7 and MRDP reports filed 6 years from the end of the calendar year in which the relevant procedures were applied or the information was relied upon, including after the Account is deleted Section 891I Taxes Consolidation Act 1997 and S.I. No. 705 of 2022 (Revenue Commissioners), and the applicable MRDP reporting obligations Chargeback, breach, and dispute records 7 years Dispute-resolution evidence and legal limitation periods (and anti-money-laundering rules where applicable) Platform fee records 6 years VAT compliance and Revenue Commissioners App store transaction records (legacy subscribers) 6 years Tax compliance for legacy IAP subscription transactions Campaign Boost purchase records, including your request that the Boost start straight away At least 6 years from the purchase. If you delete your account, the link to your account is removed but the record is kept Irish Companies Act 2014 and tax law; evidence of what was agreed (Article 6(1)(f)) Legal Holds If your account is subject to legal proceedings, regulatory investigation, or a law enforcement request, deletion may be paused until the matter is resolved. We will notify you unless prohibited by law. The same applies at the level of an individual Campaign deal: where a payment dispute, chargeback, referred dispute, open content report, or fraud investigation relating to a specific deal remains unresolved, the scheduled removal of that deal's media (pitch video and preview content) is paused until the matter is resolved. The pause applies only to the affected deal — media belonging to other deals continues to be removed on its normal schedule. Under GDPR Article 17(3)(e), we may retain data that would otherwise be deleted — including following an account deletion request — where and for as long as retention is necessary for the establishment, exercise or defence of legal claims. Contract-Specific Retention Data Type Retention Period Signed Contracts (PDFs) 6 years Unsigned or Draft Contracts Expired automatically when not signed, then removed in line with our retention schedule Signature Evidence Kept with the contract record (6 years) Document Hashes Kept with the contract record (6 years) Contract Storage Backups 6 years

Legal Basis for Processing Contract Performance (GDPR Article 6(1)(b)): Signature evidence is needed to create legally binding contracts between creators and brands. Legitimate Interest (GDPR Article 6(1)(f)): Our legitimate interest, and that of the other party to the contract, in being able to show who signed the contract, when, and what they signed, and in establishing or defending legal claims if the contract is disputed. Data Collected When You Sign a Contract When you electronically sign a contract on Spongle, we automatically collect the following evidence package to support the legal validity and admissibility of the signature under electronic-signature regulations: 1. IP Address: Your public IP address at the exact moment of signature Used to verify your location and identity Stored in INET format (e.g. "192.168.1.1" or IPv6) Supports attribution of an electronic signature to the person who signed 2. User Agent String: Your browser and device identification string Used to identify the device and software used to sign Helps detect fraudulent signatures from unusual devices 3. Timestamp: Exact date and time of signature in UTC ISO 8601 format (e.g. "2025-01-29T14:23:45.123Z") Millisecond precision for audit accuracy Used to establish the chronological order of signatures 4. Device Information (Optional): Device platform identifier (e.g. the browser platform string) Screen resolution Browser language and timezone settings 5. Signature Hash: A SHA-256 hash that binds your signature to the exact contract content shown at signing (computed over the contract content together with your signing timestamp, IP address and device string) 64-character hexadecimal string Uniquely identifies the exact contract version you signed Used to detect any change to the contract after signing 6. Consent Confirmations: A record that you confirmed the required consents before signing (that you have read the agreement, consent to signing electronically, and agree to be legally bound) A record that you scrolled through the full agreement before signing was enabled 7. Authentication Result: A record that a device authentication step was completed at the moment of signing -- a biometric method (such as Face ID, Touch ID, or fingerprint) where available, or your device passcode This is a pass/fail result only. The biometric check is performed by your device's operating system in secure hardware; Spongle does not receive, collect, or store any biometric data (see the "Special Category Data" description in Section 2) 8. Document Fingerprint: A SHA-256 fingerprint of the exact agreement text, stored with the Contract so that any later alteration of the agreed terms can be detected Legal Recognition of Electronic Signatures Electronic signatures are recognised in law in the places where Spongle operates. We collect the evidence described above so that, if a signature is ever questioned, we can show who signed, when, and what they signed. The laws that recognise electronic signatures include: EU -- eIDAS Regulation (EU) No 910/2014: Article 25: Electronic signatures shall not be denied legal effect solely because they are in electronic form Recital 49: Electronic signatures should not be denied legal effect solely because they are electronic Ireland -- Electronic Commerce Act 2000: Section 13: Electronic signatures Section 19: Formation and validity of contracts made electronically UK -- Electronic Communications Act 2000: Section 7: Electronic signatures and related certificates How We Use Signature Evidence Contract Authentication: Verify the identity of the signatory Prove intent to sign and be bound by the contract Establish that the signature was created by the claimed individual Legal Protection: Evidence package provided in case of contract disputes Designed to support the signature's validity and admissibility under Irish, UK and EU electronic-signature law Aligned with the electronic-signature laws listed above Supports contract enforcement actions Fraud Prevention: Detect suspicious signing patterns (e.g. rapid signatures from different locations) Identify account takeovers or unauthorised access Flag contracts signed from unusual devices or locations Audit Trail: Complete chronological record of the contract lifecycle Chain of custody from creation to signing to storage Proves when each party signed and from where Your Rights Regarding Signature Evidence Right of Access: You can request a copy of your signature evidence package This includes all collected data (IP, device info, timestamp, hash) Provided within one calendar month of request (extendable by up to two further months for complex requests) Right to Rectification: Incorrect data (e.g. wrong timestamp) can be corrected You must provide proof of inaccuracy Original evidence preserved for legal audit trail Right to Erasure (Limited): Signature evidence for signed contracts is kept with the contract for 6 years, because we may need it to establish or defend a legal claim (GDPR Article 17(3)(e)) Signature evidence for unsigned or draft contracts is removed in line with our draft-contract retention schedule We cannot delete evidence for active or completed contracts (contract performance basis) Right to Object: You can object to the collection of optional data (device details) If you object to our use of the required data (IP address, timestamp, hash), we will continue to keep it where we need it to establish, exercise or defend legal claims about the contract (GDPR Article 21(1)) Data Security for Signature Evidence Encrypted at rest and stored in our EU-based database Access is restricted by database row-level security to the contract parties (brand and creator) Authorised Spongle personnel may access signature evidence only where necessary — for example, to resolve a dispute, provide support, or comply with a legal request — and access to it is restricted to authorised personnel under our internal access controls HTTPS/TLS encryption for all data transmission Signature evidence is not transmitted to third parties except as described in this policy (for example, where strictly necessary to defend a payment dispute or to comply with a legal request)

Right of Access (Article 15) Request a copy of your personal data Information about processing activities Details of third-party sharing Creators' tax details and the requests and reminders we sent about them are included; the tax identification number is shown by its last four characters, for security. If you need us to confirm the full number we hold, write to privacy@spongle.co Right to Rectification (Article 16) Correct inaccurate personal data Complete incomplete information Update outdated records Creators can update their tax details at any time in the Payments area of their Account (an entity Creator writes to support@spongle.co); the updated details are used for future tax reports Right to Erasure (Article 17) -- "Right to Be Forgotten" Request deletion of your account and personal data 30-day grace period: log back in during this window and choose to restore your account Personal data permanently deleted once the grace period ends Your product-usage analytics profile and events held by our analytics provider (PostHog, EU) are deleted as part of account erasure Some data kept for legal compliance (see Section 9) Legal basis data (payments, contracts, signatures) retained for up to 6 years; dispute records up to 7 years Creator tax details and tax-reporting records, whether they relate to an individual or an entity, retained for 6 years from the end of the calendar year in which the relevant procedures were applied or the information was relied upon, because the law requires it. Deleting your account does not override that obligation, but the rest of your data is still deleted or anonymised on the schedule in Section 9 You will receive email confirmation of your deletion request and grace period details Right to Restrict Processing (Article 18) Limit how we process your data Temporary suspension of processing Block automated decision-making Right to Data Portability (Article 20) Export your data in machine-readable format (JSON and CSV) Transfer data to another service Receive a structured data export Right to Object (Article 21) Object to processing based on legitimate interests Opt out of direct marketing Stop automated profiling Right to Withdraw Consent (Article 7) Remove consent for specific processing Opt out of cookies and tracking Unsubscribe from marketing To exercise your rights, contact: privacy@spongle.co We respond to data-subject requests within one calendar month, extendable by up to two further months for complex or numerous requests. We may need to verify your identity first. There is no self-service download in the app. Requests under this section are handled by our team; your rights under Articles 15 and 20 are unaffected.

Technical Safeguards HTTPS/TLS encryption for all data transmission AES-256-GCM encryption for sensitive data at rest (OAuth tokens and Creator tax identification numbers; user session tokens are held in platform secure storage) Database row-level security on all tables Server-side PKCE for OAuth authentication flows Distributed API rate limiting on authentication, payment, OAuth, and other sensitive endpoints Webhook signature verification (Stripe, Apple, email providers) Regular security audits covering database policies, API endpoints, and access controls Operational Security Data-protection practices for anyone with access to personal data Access controls and permission management Incident response procedures Automated managed database backups (EU region) Third-Party Security Stripe PCI-DSS Level 1 compliance Apple App Store and Google Play Store security standards for legacy IAP transactions Use of vetted, established service providers Contractual security requirements Server-Side Audit Trail In order to satisfy our obligations under GDPR Article 5(2) (accountability), Article 7(1) (demonstrable consent) and Article 32 (security of processing), the following audit categories are recorded on the Spongle server and are not stored solely on your device: Security events — we keep server-side records of account security activity, including sign-ins, sign-in attempts, new-device sign-ins and password resets. Records of successful sign-ins and password resets are held in tamper-resistant logs that you cannot modify or delete. You may request a copy of the security records we hold about you under Article 15 (Right of Access) via the contact details in Section 18. Consent and GDPR-action records — changes to your consent settings, and GDPR-related actions such as data-export requests and account deletion, restoration or legal-hold actions, are logged server-side with the action taken and a timestamp, so that we can demonstrate how your consents and requests have been handled. Cookie consent records — for users who hold a Spongle account, your cookie preferences are recorded against your account on the Spongle server as the canonical record, in addition to being held on your device for in-session use. For visitors without an account, cookie preferences are held on your device only until you create an account, at which point the preferences are synchronised to your account record. Cookie-consent records held against your account follow the retention described in Section 9. Retention differs by log category. Records of data-processing actions (such as data-export requests) are kept for two (2) years from the date each entry is recorded, then automatically and permanently deleted. Authentication and session logs are deleted after ninety (90) days as part of our data-minimisation cleanup. Sign-in and security-event records (sign-ins, sign-in attempts, and new-device sign-ins) are kept while your account is open as part of our security monitoring; when your account is permanently erased, these records are unlinked from your identity so that they no longer identify you. Records of your consent choices, and of GDPR actions taken on your account (such as account deletion, restoration, or legal-hold actions), are kept for as long as we need them to demonstrate that our processing was lawful under GDPR Articles 5(2) and 7(1); this can be longer than two years, and they are not deleted simply because you close your account, because they are our evidence of how your consents and requests were handled — a separate basis from the account-data retention in Section 9. Where a longer period is required by law (for example, chargeback, breach, and dispute records retained for seven (7) years under Article 6(1)(c)), that longer period applies.

We use a small number of essential cookies and similar on-device storage to keep you signed in, keep the Platform secure, and remember your preferences. With your consent, our analytics provider also uses on-device storage (not advertising cookies) to support the usage analytics described below. We do not use advertising cookies or advertising pixels. Full detail is set out in our Cookie Policy. We do not use advertising analytics, advertising pixels, or cross-site tracking. Two kinds of analytics form part of how the Platform works. First, the in-app Analytics dashboard shows you performance information about your own campaigns, pitches and account; this is part of the service you have signed up for and does not depend on cookie consent. Second, with your consent we record key product-usage events, which pages you visit and when you leave them -- for example, publishing a campaign, submitting a pitch, or opening a campaign page -- so that we can understand how the Platform is used and improve it. Recording the moment you leave a page allows us to measure how long pages are viewed and how often visitors leave without going further; it does not record what you did on the page. With your consent we also receive automatic technical reports when part of the Platform fails on your device, so that we can find and repair faults. Page records are generalised before they leave your device: we record the type of page rather than its exact address, so a reference to a particular campaign, pitch or profile is replaced with a placeholder, and anything following the address, such as a query string, is discarded. This means we can see that a campaign page was viewed, but not which campaign it was. This consent-based usage analytics is controlled by the Analytics category in our cookie banner and your privacy settings, is off by default, and is processed on our behalf by PostHog, an analytics provider whose servers are located in the EU (see Section 7 for the full list of our service providers). Events are recorded against your account ID and account type only -- never message content, pitch content, or payment amounts -- and are deleted when your account is erased. You can turn this analytics off again at any time from the cookie banner or your privacy settings. Neither kind of analytics is used for advertising, and your analytics data is never sold. For users who hold a Spongle account, your cookie preferences are recorded against your account on the Spongle server as the canonical record, in addition to being held on your device for in-session use. See Section 12 (Server-Side Audit Trail) for further detail.

To create a Spongle account or use any of our services, you must: Be at least 18 years of age (or the age of majority in your country of residence, if higher). Have the legal capacity to enter into binding contracts under applicable law. Agree to comply with our Terms and Conditions and this Privacy Policy. By registering for or using Spongle, you confirm that you meet these eligibility requirements. Important: If you are under 18, you are not permitted to register for an account, submit content, take part in campaigns, receive or make payments, or use any feature of the Spongle platform. Data Protection for Minors: Spongle does not knowingly collect or process personal data from anyone under 18 If we become aware that such information has been submitted, we will promptly delete the account and associated data Age verification may be carried out at any time, including through our payment provider (Stripe Connect) Accounts found to be in breach of this requirement may be suspended or terminated

Incident Response 72-hour notification to the Data Protection Commission (Ireland) Immediate notification to affected users if the risk is high UK ICO notification for UK-specific incidents Detailed incident reporting and remediation Breach Types Covered Unauthorised access to personal data Accidental data disclosure System security failures Third-party data breaches affecting users User Notification Email alerts for significant breaches In-app notifications and updates Clear guidance on what you should do to protect yourself

AI Transparency When you interact directly with Spongle AI or another AI feature, we make clear that you are dealing with an automated assistant, and we identify AI-assisted features within the Platform. Spongle AI can make mistakes, so treat its output as guidance and check anything important (see also Section 3). Certain illustrative imagery on the Platform, such as content-category images, is generated by artificial intelligence and carries machine-readable markings identifying it as artificially generated. This reflects our obligations under the EU AI Act (Regulation (EU) 2024/1689, as amended by Regulation (EU) 2026/1744). AI-Powered Features Content recommendations and suggestions Campaign matching and optimisation Automated insights and analytics Human Oversight Most decisions that affect you involve a person. Four decisions are automated. First, if a published post is removed or materially altered during a Campaign and is not restored within the cure period set out in the Terms, the Creator's fee is automatically refunded to the Brand. Second, if a Brand cancels a signed and funded Contract, the Creator's fee is automatically divided between the Creator and the Brand according to how far the Campaign had progressed, using the fixed percentages set out in the Terms. Third, if a Creator cancels a signed and funded Contract, the Creator's fee is automatically refunded to the Brand in full. Fourth, if a Campaign's end date passes with no verified delivery, the Creator's fee is automatically refunded to the Brand. We apply all four automatically so that the same rule is applied consistently to everyone, rather than at our discretion. None of them involves any assessment of the quality of a Creator's work. In each case you may ask for a person to review the outcome, put your case, and contest it. Creators may also appeal a detected breach before the cure period ends, which pauses the process while the appeal is considered. Refusing a contract signature, holding payouts and pausing pitches when tax details are missing are also applied automatically; see Section 7, "Automatic Payout Holds and Pitch Pauses for Missing Tax Details", including how to ask for a person to review them. One further automated step affects messages only: our message screening can block a message at the moment you send it if it contains contact details or off-platform links that breach the Terms. It does not use profiling and has no legal or similarly significant effect on you -- you are told why, you can rephrase and resend, and you can ask a person to review any blocked message by contacting support@spongle.co. Human review for account suspensions or bans. Manual verification for payment disputes. Where a Brand refers a dispute to us under Section 15.3 of our Terms, a member of our staff confirms the outcome by applying the pre-agreed rules to the verified facts; Spongle does not act as a mediator or arbitrator between the Brand and the Creator. Automated delivery records and AI suggestions only inform that confirmation; they never make it. Appeal processes for automated decisions. Your Rights Request human review of automated decisions Access information about automated processing Challenge automated decision outcomes Object to profiling based on legitimate interests

Notification Methods Email notifications for significant changes In-app announcements and banners Website updates and version tracking Change Types Minor updates: Clarifications and corrections Major updates: New features or legal requirements Emergency updates: Security or compliance issues User Consent Continued use counts as acceptance of minor changes Active consent required for material changes that require it

Data Protection Contacts For all privacy, data protection, and subject access requests, contact: Privacy & data protection: privacy@spongle.co General Enquiries: info@spongle.co Please use the subject line "Privacy Request" for data protection enquiries. We respond to data-subject requests within one calendar month, extendable by up to two further months for complex or numerous requests. For general enquiries, we reply as soon as we reasonably can. Supervisory Authorities Ireland: Data Protection Commission -- dataprotection.ie UK: Information Commissioner's Office -- ico.org.uk EU: Your local data protection authority

This Privacy Policy is governed by: EU General Data Protection Regulation (GDPR) Irish Data Protection Act 2018 Irish and UK contract law Dispute Resolution and Complaints If you are unhappy with how we handle your personal data, please contact privacy@spongle.co first so that we can try to put it right. You have the right to lodge a complaint with the Data Protection Commission (Ireland), our lead supervisory authority, or with the supervisory authority of the EU Member State where you live or work, or with the Information Commissioner's Office if you are in the UK (Section 18). You also have the right to an effective judicial remedy against a supervisory authority or against Spongle (GDPR Articles 78 and 79). Proceedings against Spongle may be brought in the courts of Ireland or, if you live in another EU Member State, in the courts of that Member State. We do not impose arbitration on anyone for data-protection matters. Disputes between Brands and Creators about a campaign are handled under Section 15 of the Terms and Conditions and are not data-protection matters. Document Reference: SPONGLE-PP-2026 Jurisdiction: Republic of Ireland Language: British English Last Updated: 30 September 2026 © 2026 Spongle Limited. All rights reserved.

For privacy and data-protection enquiries, contact privacy@spongle.co

© 2026 Spongle Limited. All rights reserved.