← Back to Fledge

Fledge Privacy Policy (Draft)

This is a draft document for review and is not final legal advice or a final production policy. It should not be shown to actual users until a proper compliance review is completed.

1) What data we may collect

We may collect and process the following personal and financial information when you use the app:

This app handles financial transaction data and therefore falls within the type of personal information that requires careful handling under POPIA.

2) Why we collect it

We collect this information to:

We do not use your data to provide regulated financial advice.

3) Data storage and cross-border hosting

Fledge runs on Render (the app and its server) and stores data in a PostgreSQL database with Neon. Both are located in Frankfurt, Germany, which is outside South Africa. Sign-in emails are sent through an email delivery provider.

If AI category suggestions are switched on and you choose to use them, only your payee names (for example "CHECKERS SIXTY60") and your own category names are sent to Anthropic, in the United States, to suggest a category for each payee. Amounts, dates, balances and account details are never sent. Nothing is changed until you review and apply the suggestions.

Because the app may process South African users' financial data on infrastructure outside South Africa, this draft disclosure is intended to cover the POPIA cross-border transfer issue explicitly. Before real launch, a proper compliance review should confirm the final terms and hosting arrangement and ensure the user consent language matches the final architecture.

4) How long data is kept

We may keep account and transaction data for as long as the account remains active or as required to operate the service, maintain records, and comply with legal or operational obligations.

Where possible, we aim to keep data only for the period needed to provide the service. If you close your account or request deletion, we will aim to delete your personal information and related transaction records promptly, subject to any legal or technical limits.

5) Security

We will apply reasonable technical and organisational safeguards, including:

This is a baseline draft; a real production deployment should include a formal security review before wider launch.

6) Your rights and deletion requests

You may request access to, correction of, or deletion of your personal information by contacting the service operator using the contact details in the final production version of this policy.

A deletion request will typically mean:

Some data may need to be retained to satisfy legal, security, or operational requirements, but we will aim to delete the data that is not required for those purposes.

7) Important draft note

This draft is not a final legal document and needs a real compliance review before real users see it. It should be treated as an internal working draft only.