Sprout Automation Group LLC
Privacy Policy
Last updated: August 3, 2026
This policy explains what information we collect, why we collect it, who processes it on our behalf, and how you get it back or get it deleted. It covers this website, getthesprout.com, and both of our products — SproutRT and CardSprout AI.
1. Who we are
Sprout Automation Group LLC (“Sprout,” “we,” “us,” or “our”) is a Texas limited liability company based in San Antonio, Texas. We build and operate two software products:
- SproutRT— referral-territory intelligence for home-care agencies. It helps a marketing rep find the facilities worth visiting, prepare for the visit, and see which relationships actually produce referrals.
- CardSprout AI — business-card capture and follow-up. It turns a photo of a business card into a contact record and helps the user send timely follow-up email from their own account.
We are the controller of the personal information described in this policy that we collect for our own purposes — for example, account and billing information. For the working data our customers put into the products, we act as a service provider or processor on that customer’s behalf and follow their instructions.
For any privacy question or request, write to hello@getthesprout.com.
2. What data we collect
Visitors to this marketing site
getthesprout.com sets no tracking or advertising cookies and runs no third-party analytics script. We do not build a profile of you, we do not fingerprint your browser, and we do not share your visit with an ad network. Two ordinary things do happen:
- Our hosting provider generates standard server request logs (such as IP address, user agent, requested URL, and timestamp) as part of delivering and protecting the site.
- If you email us, the message, your email address, and anything you choose to tell us live in our business email account until we no longer need them.
The product demo videos on this site are click-to-play. Nothing loads from the video host until you press play; if you do, the host’s embedded player is loaded in a frame and may set its own cookies and record a view under its own privacy policy. Simply reading the page never contacts it.
SproutRT customers
SproutRT is used by an agency and its marketing staff. The data in an account falls into four buckets:
- Account data— the agency name, each user’s name, work email, role, and authentication credentials, plus support correspondence and billing records.
- Public business information about healthcare facilities — facility name, address, phone number, website, hours, ratings, and publicly listed staff names and titles taken from the facility’s own public website (for example, an admissions director or activities director). These are business contacts at businesses, not patients.
- Agency-authored content — notes, check-ins, visit history, and voice recordings and their transcripts, created by the agency’s own marketing staff about their own visits.
- Pseudonymized referral attribution — imported read-only from the customer’s own AxisCare account, with every client and lead name reduced to a six-character handle before it is stored. See section 7.
Location. SproutRT can show a marketer how far away a facility is. That distance is computed on the device. Raw GPS coordinates are not transmitted to our servers, and we do not keep a location history or a breadcrumb trail of where a marketer has been.
CardSprout AI customers
- Account data— name, email, authentication credentials, support correspondence, and billing records.
- Business-card images — the photographs of business cards you take in the app.
- Extracted contact details — the name, title, company, phone, email, and address read out of the card image, plus any corrections you make.
- Notes and follow-up content — what you write about the conversation, and the follow-up emails drafted for you and sent by you.
- Gmail authorization — if, and only if, you grant it through Google’s consent screen, the OAuth token that lets CardSprout AI send follow-ups from your own Gmail account and recognize replies to those messages. See section 9.
Business-card data describes the person on the card. If you photograph someone’s card, you are responsible for having the right to store and use their details and for honoring their requests about them.
3. How we use it
- To run the product — store your records, show your territory and contacts, generate visit briefs, scores, summaries, and drafted follow-ups, transcribe voice notes, and map facilities.
- To send what you send — deliver follow-up email from your connected account and mark a contact as having replied.
- To support you— answer questions, reproduce and fix bugs, and restore data after a mistake.
- To bill you— manage subscriptions, invoices, and tax records.
- To keep it safe — detect and prevent abuse, fraud, and security incidents, and enforce our Terms of Service.
- To improve the product — understand which features are used and where they break, using aggregate and operational information rather than reading customer content for product research.
- To comply with the law — respond to lawful requests and meet our record-keeping obligations.
4. What we do not do
- We do not sell or rent personal information. Not to data brokers, not to advertisers, not to anyone.
- We do not share personal information for cross-context behavioral advertising and we run no ad pixels on this site.
- We do not use customer data to train AI models — not our own, and not a third party’s. When a feature needs an AI vendor, we send the minimum necessary content through that vendor’s commercial API under terms that do not permit training on our submissions.
- We do not mine one customer’s data to benefit another customer. Each agency’s notes, contacts, and attribution stay inside that agency’s account.
5. Purposes and legal bases
We process personal information for these purposes and on these bases:
- Performance of a contract — creating and maintaining your account, delivering the features you subscribed to, and billing.
- Consent— connecting your Gmail account, recording a voice note, and any optional integration you switch on. You may withdraw consent at any time by disconnecting the integration.
- Legitimate interests — securing the service, preventing abuse, understanding aggregate usage, and communicating with customers about their account.
- Legal obligation — tax and accounting records and responses to lawful requests.
- At our customer’s direction — for the facility, contact, note, and attribution data inside an account, we act on behalf of the customer who put it there.
6. Subprocessors
We are a small company and we build on infrastructure rather than running our own. These are the providers that may process data on our behalf, and what each one is for:
- Vercel— hosting for this website and our applications, including CDN delivery and server request logs.
- Supabase— database, file storage (including business-card images and voice recordings), authentication, and serverless functions.
- Anthropic— AI text generation, including visit briefs, summaries, and drafted follow-up emails.
- OpenAI— audio transcription (Whisper) for voice notes recorded in SproutRT.
- Google— Places and Maps APIs for facility information and mapping, and the Gmail API for CardSprout AI sending and reply detection where you have granted consent.
- Firecrawl— extraction of public web pages, such as a facility’s own website or public event calendar.
- Perplexity— research against public web sources, such as competitor profiles and community events.
- Synthesia— production and hosting of the marketing videos on this website only, streamed through its embedded player when a visitor presses play. No customer data is provided to Synthesia.
This list is current as of the date at the top of this page. We update it when a provider changes. We also use ordinary business tools for email and payments; those receive only what is necessary for correspondence and billing.
7. The AxisCare pseudonymization commitment
SproutRT can connect read-only to a customer’s AxisCare account to answer one question: which facilities are actually sending referrals. That question does not require anyone’s name, so we do not keep one.
- Before anything is written to our database, every client and lead name is reduced to a six-character handle — the first three letters of the first name plus the first three letters of the last name. “Nancy Wilch” becomes “NanWil.”
- Full names never reach our database, our logs, or the prompts we send to AI vendors.
- We do not import or store dates of birth, Social Security numbers, addresses, insurance or member identifiers, diagnoses, medications, care plans, or clinical notes. What we keep is the referral source, the count, the date, and whether the referral converted.
- Re-identification is possible only inside the customer’s own AxisCare account, which we do not control and cannot write back into. A rep sees “NanWil → 3 referrals” in SproutRT and opens AxisCare if they need the person.
- Records that hold pseudonymized handles are flagged in our schema so they can be exported or wiped as a set.
This is a product commitment, not a setting. It is enforced in the import code before storage, and it applies to every SproutRT account.
8. HIPAA posture
Our products are sales and relationship tools, and they are deliberately designed to avoid receiving protected health information (PHI). SproutRT tracks facilities, business contacts, visits, and pseudonymized referral counts. CardSprout AI tracks business cards and follow-up email. Neither is a clinical system, and neither needs patient information to do its job.
Customers must not enter PHI into our services. That includes patient or client names and contact details, dates of birth, Social Security numbers, insurance or member identifiers, diagnoses, medications, care plans, and clinical or care notes — in any field, note, voice recording, uploaded file, or card image.
We do not currently offer or sign Business Associate Agreements, and you should not treat our services as HIPAA-compliant systems of record or as a place to store patient information. We would rather say that plainly than imply a compliance posture we have not undertaken.
If you believe PHI has been entered into an account, tell us at hello@getthesprout.com and we will work with you to remove it promptly. For clarity, the pseudonymized handles described in section 7 and the publicly listed facility staff described in section 2 are deliberately outside the category of patient information.
9. Google API Services user-data disclosure (CardSprout AI)
CardSprout AI can send follow-up email from your own Gmail account and detect when someone replies. This requires Gmail access, which you grant through Google’s own consent screen and can revoke at any time.
Sprout Automation Group’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy (opens in a new tab), including the Limited Use requirements.
In practical terms, that means:
- We use Gmail access only to provide the features you asked for — sending follow-ups you approve, from your account, and recognizing replies to those messages so the contact’s status updates.
- We do not use Gmail data for advertising, and we do not sell or transfer it to data brokers, information resellers, or any other third party for their own purposes.
- We do not use Gmail data to develop, improve, or train generalized or general-purpose AI or machine-learning models.
- No human at Sprout reads your Gmail data, except with your explicit consent (for example, when you ask us to investigate a problem), where necessary for security purposes such as investigating abuse, to comply with applicable law, or where the data has been aggregated and anonymized.
- We request the narrowest scopes that make the feature work, and we store the resulting token encrypted and scoped to your account.
You can disconnect Gmail from inside CardSprout AI, or revoke access at any time from your Google Account permissions page (opens in a new tab). Revoking access stops sending and reply detection; contacts and notes already in your account remain until you delete them.
10. Data retention and deletion
- While you are a customer — we keep your account data and working data for as long as the account is active, because that is the product.
- After cancellation — we keep the account for 30 days so you can reactivate or export, then delete it. Tell us sooner and we will delete sooner.
- On request— email hello@getthesprout.com from the address on the account and ask for an export or a deletion. We verify that the request really comes from the account owner and then complete it within 30 days of verification. Exports are provided in a machine-readable format.
- What deletion removes — records in our production database and files in our storage buckets, including business-card images, voice recordings, notes, and pseudonymized attribution. Residual copies inside our infrastructure providers’ encrypted backups age out on those providers’ rolling backup schedules.
- What we may keep — billing and tax records we are legally required to retain, and security logs, for the period required. These do not include your working data.
11. Security
- Data is encrypted in transit (HTTPS/TLS on every request) and at rest by our infrastructure providers.
- Every account’s data is isolated at the database layer with row-level access rules, so one customer’s query cannot reach another customer’s rows.
- Access to production data is limited to the operator of the company, on a need-to-troubleshoot basis, and we prefer to reproduce problems without looking at customer content when we can.
- API keys, tokens, and other secrets are held server-side in the platform’s encrypted environment store. They are never bundled into client-side code shipped to your browser.
- Authentication is handled by our platform provider, with hashed credentials and scoped session tokens.
No system is perfectly secure. If a breach affects your data, we will notify you promptly and describe what happened, what was affected, and what we are doing about it, consistent with applicable law.
13. Children’s privacy
Our services are business tools sold to businesses. They are not directed to children, and we do not knowingly collect personal information from anyone under 18. If you believe a minor has provided us information, contact hello@getthesprout.com and we will delete it.
14. Where we operate and store data
We are based in San Antonio, Texas, and we operate in the United States for United States customers. Our database and file storage are hosted in United States regions. Some providers — for example a CDN, or an AI API — operate globally distributed infrastructure, so a request may be routed through equipment outside your state while it is being served.
Our services are not offered to or directed at individuals in the European Economic Area, the United Kingdom, or Switzerland, and we do not currently maintain a representative in those regions.
15. Your choices and rights
Whatever state you are in, you may ask us to give you a copy of the personal information we hold about you, correct it, or delete it, and you may ask what we have shared and with whom. Texas residents have these rights under the Texas Data Privacy and Security Act; we extend the same handling to everyone rather than sorting requests by state.
- Send requests to hello@getthesprout.com. We will verify the request, respond within 30 days of verification, and will not charge you or degrade your service for asking.
- We do not sell personal information and do not share it for targeted advertising, so there is no opt-out to exercise on those points.
- If your information sits inside a customer’s account — for example, you are a facility staff member listed in an agency’s territory, or a contact on a card someone scanned — that customer decides what happens to it. Write to us and we will route your request to them and help them honor it.
- You can withdraw an integration’s consent at any time by disconnecting it in the app, and you can close your account by emailing us.
- If we deny a request, we will tell you why and how to appeal by replying to the same address.
16. Changes to this policy
We update this policy when the products change or a provider changes. The effective date at the top always reflects the current version. If a change materially affects how we handle personal information, we will notify account owners by email or in-app notice before it takes effect. Continuing to use the services after a change takes effect means the updated policy applies to you.
17. How to contact us
Sprout Automation Group LLC
San Antonio, Texas, United States
hello@getthesprout.com
One address handles all of it — privacy questions, export requests, deletion requests, security reports, and complaints. A real person reads it.
See also our Terms of Service.
