Fledge Privacy Policy (Draft)
This is a draft document for review and is not final legal advice or a final production policy. It should not be shown to actual users until a proper compliance review is completed.
1) What data we may collect
We may collect and process the following personal and financial information when you use the app:
- email address used for sign-in (we email you a one-time sign-in code and link; there is no password)
- account profile information needed to manage your user account
- categories, budgets, and manually entered transaction data
- CSV import data and imported transaction records
- bank statement PDFs are read on your own device; if a PDF is password-protected, the password is used only on your device and is never sent to us or stored
- bank account connection details, bank tokens, and related credential metadata where enabled
- app usage data needed to operate the service and prevent abuse
- any information you provide in support or account-recovery requests
This app handles financial transaction data and therefore falls within the type of personal information that requires careful handling under POPIA.
2) Why we collect it
We collect this information to:
- create and maintain your account
- save and sync your budget, categories, and transactions
- allow you to import or review your spending data
- provide account-linking or statement-import features
- maintain the service, troubleshoot issues, and prevent misuse
- meet our operational and security obligations
We do not use your data to provide regulated financial advice.
3) Data storage and cross-border hosting
Fledge runs on Render (the app and its server) and stores data in a PostgreSQL database with Neon. Both are located in Frankfurt, Germany, which is outside South Africa. Sign-in emails are sent through an email delivery provider.
If AI category suggestions are switched on and you choose to use them, only your payee names (for example "CHECKERS SIXTY60") and your own category names are sent to Anthropic, in the United States, to suggest a category for each payee. Amounts, dates, balances and account details are never sent. Nothing is changed until you review and apply the suggestions.
Because the app may process South African users' financial data on infrastructure outside South Africa, this draft disclosure is intended to cover the POPIA cross-border transfer issue explicitly. Before real launch, a proper compliance review should confirm the final terms and hosting arrangement and ensure the user consent language matches the final architecture.
4) How long data is kept
We may keep account and transaction data for as long as the account remains active or as required to operate the service, maintain records, and comply with legal or operational obligations.
Where possible, we aim to keep data only for the period needed to provide the service. If you close your account or request deletion, we will aim to delete your personal information and related transaction records promptly, subject to any legal or technical limits.
5) Security
We will apply reasonable technical and organisational safeguards, including:
- access controls to limit who can view data
- encrypted storage for sensitive tokens and credentials where possible
- HTTPS for browser traffic
- no unnecessary logging of sensitive financial data
- least-privilege access for system administrators
This is a baseline draft; a real production deployment should include a formal security review before wider launch.
6) Your rights and deletion requests
You may request access to, correction of, or deletion of your personal information by contacting the service operator using the contact details in the final production version of this policy.
A deletion request will typically mean:
- removing your account profile
- removing your stored categories, budgets, and transactions
- deleting stored connection credentials or tokens associated with your account where applicable
- removing any associated import history or account metadata
Some data may need to be retained to satisfy legal, security, or operational requirements, but we will aim to delete the data that is not required for those purposes.
7) Important draft note
This draft is not a final legal document and needs a real compliance review before real users see it. It should be treated as an internal working draft only.