Who We Are
SapphireCore is a personal finance and AI assistant application. PDG & Associates LLC ("we," "our," or "us"), a company organized under the laws of Florida doing business as SapphireCore, is responsible for the personal information processed through the Service. Our principal place of business is:
PDG & Associates LLC d/b/a SapphireCore
3900 Alton Rd, Apt 206
Miami Beach, FL 33140
United States
Email: support@sapphirecore.net
Scope of This Policy
This Privacy Policy explains how SapphireCore collects, uses, retains, and shares personal information when you use our iOS mobile application and related services (collectively, the "Service"). It applies to all users, including users of both the Personal and Business workspace features.
This Policy does not apply to third-party services we connect to — those services have their own privacy policies, which we link to throughout this document. It also does not apply to information Apple collects directly through the App Store.
This Policy should be read together with our Terms of Service, which govern your use of SapphireCore. Subscription pricing, automatic-renewal, and cancellation terms are presented in the app before you purchase and are also governed by Apple's App Store terms. Account deletion is described in Section 14 of this Policy.
Information We Collect
3.1 Information You Provide Directly
- Account credentials: Your name, email address, and password. SapphireCore does not store your plaintext password.
- Profile information: Your display name and, if you choose to upload one, a profile photo.
- Financial settings: Budget amounts, savings goals, monthly income targets, your self-reported credit score (optional), and other planning values you enter manually.
- Profile photo: If you upload a profile photo, it is stored on SapphireCore's servers (Supabase cloud storage). The photo is selected from your device's camera or photo library using the iOS system picker.
- Tax documents: When you use the Tax Center (CPA) feature, you capture or select documents (receipts, invoices, statements) from your device and upload them to your own connected cloud storage account (Google Drive or another provider you choose). Raw document files are stored in your own cloud account — not on SapphireCore's servers. The document image is temporarily transmitted to SapphireCore's server and forwarded to Anthropic's API for AI extraction; it is not stored on SapphireCore's servers after processing. SapphireCore stores only the document metadata and AI-extracted fields described in Section 8.
- Accountant contact information: If you add an accountant or CPA, we store their name, email address, and firm name.
- AI conversations: The text of your messages to the SapphireCore AI assistant, including any financial details you type or share within a conversation.
3.2 Information Collected from Third Parties
- Bank and financial data via Plaid: When you link a bank account, Plaid provides us with account names, account number masks (last four digits), institution names, account balances, transaction history, credit card liability data, and investment holdings. See Section 5.
- Apple subscription data: When you purchase a subscription or in-app item, Apple sends us cryptographically signed notifications containing a pseudonymous transaction identifier, product identifier, and purchase status.
3.3 Information Collected Automatically
- AI-extracted memory: Short factual summaries that the AI extracts automatically from your conversations after it replies (for example, "User is saving for a down payment") to personalize future responses within your session and across sessions. These memory facts are stored with your account and deleted when you delete your account.
- Push notification token: A device identifier provided by Apple and routed via Expo to deliver push notifications.
- App usage information: Feature usage timestamps, chat thread history, and notification records.
- Connection audit data: When you connect a bank account, we record a one-way hash (SHA-256) of your IP address — not the raw IP address — along with your device's user agent string, the institution identifier, and the connection outcome. We use this for security and rate-limiting.
- Email engagement events: Delivery status and, when emails are opened, the IP address and mail client information reported by our email provider, Resend. We use this data to manage email deliverability and honor unsubscribes.
3.4 Information Processed On-Device Only
- Voice input: If you dictate messages using voice-to-text, audio is processed by Apple's Speech Recognition framework (SFSpeechRecognizer) and is never transmitted to SapphireCore's servers. Depending on device model, locale, and iOS settings, Apple's framework may route speech to Apple's own servers for processing; this is governed by Apple's privacy policy, not SapphireCore's. You can require on-device-only recognition by disabling "Improve Siri & Dictation" in iOS Settings > Privacy & Security > Analytics & Improvements.
- Google OAuth token: If you connect Google Drive, your Google OAuth access token is stored only on your device in iOS Secure Storage (Keychain). It is never transmitted to or stored on SapphireCore's servers.
3.5 Anonymous Learning Signals (Opt-In)
You may choose to contribute anonymous merchant classification signals to SapphireCore's shared learning system. This is off by default. If you enable it in Settings > Privacy Settings, we record a contribution identified only by a pseudonymous HMAC-SHA256 hash — your user ID and any personal identifiers are not included. No financial amounts are included. You can withdraw your participation at any time. See Section 20.
How We Use Your Information
| Purpose | Data Used | Basis |
|---|---|---|
| Provide and operate the Service | All categories in §3 | Contract performance |
| Process in-app purchases and manage subscriptions | Apple transaction identifiers | Contract performance |
| Deliver AI financial insights using Anthropic's API | Financial summary, conversation, AI memory | Contract performance |
| Send transactional emails (verification, OTP, security) | Email address, name | Contract performance |
| Send lifecycle and informational emails as permitted by law (opt-out available) | Email address, name, plan | Legitimate interest |
| Send annual subscription renewal reminders | Email address, name, plan, renewal date | Legal obligation (Cal. B&P §17602(h)) |
| Deliver push notifications | Push token, balance and reminder data | Contract performance |
| California ARL compliance recordkeeping | Apple transaction ID, pseudonymized email hash, purchase date | Legal obligation (Cal. B&P §17602) |
| Security, fraud prevention, and rate limiting | IP hash, user agent, login patterns | Legitimate interest |
| Track AI usage costs for service health | Token counts, model — no content | Legitimate interest |
| Anonymous merchant classification (opt-in) | Pseudonymous signal — no personal data | Consent |
We do not use your personal information for advertising or for sale to third parties.
Bank & Financial Account Data (Plaid)
SapphireCore uses Plaid Inc. to connect your bank, credit card, and investment accounts. When you link an account:
- You authenticate directly with your financial institution through Plaid's secure interface. Your bank username and password are entered only into Plaid's interface and are never seen by or transmitted to SapphireCore.
- Plaid provides SapphireCore with read-only access to your account data: account names, masked account numbers (last four digits), institution name, current balances, transaction history, credit card liability details, and investment holdings.
- SapphireCore cannot initiate transactions, move funds, or make payments on your behalf.
- Plaid's access credential (allowing ongoing data retrieval) is stored securely on our servers in a restricted server-side database column. It is not accessible to authenticated users or client applications, is never included in API responses, and is never logged. All data in our database, including this credential, is protected by AES-256 encryption applied at the storage layer by our database infrastructure provider.
- When you disconnect a bank account or delete your SapphireCore account, we call Plaid's API to revoke access, ending Plaid's authorization to share your data with us.
- You can also review the connections Plaid maintains on your behalf, disconnect them, and request deletion of data stored in Plaid's own systems through the Plaid Portal at my.plaid.com.
Our use of Plaid is covered by an active Master Services Agreement between SapphireCore and Plaid. Plaid's privacy practices for end users are described in Plaid's End User Privacy Policy at plaid.com/legal/#end-user-privacy-policy.
Artificial Intelligence Features (Anthropic)
The AI assistant and document analysis features in SapphireCore are powered by Anthropic PBC's Claude API. Anthropic processes data as our service provider under Anthropic's commercial API terms.
6.1 What We Send to Anthropic
When you use AI features, we send Anthropic a prompt that may include:
- Your first name
- A summary of your linked accounts: account and card names with the last four digits (masked), account type and subtype, current and available balances, credit limits and utilization, upcoming payment due dates, minimum payments, and autopay status
- Transaction context: merchant names and transaction descriptions, amounts, dates, spending categories, and detected recurring subscriptions. A summary of recent activity accompanies your chat request; when your question requires it, the assistant may retrieve matching transactions from the current and previous calendar year
- Your self-reported credit score and monthly income, if you have provided them (Personal workspace only)
- Your savings goals and budget context
- Your AI memory facts (short summaries like "User is saving for a house")
- Your chat message and recent conversation history for the current session, including the assistant's earlier replies
- Your device time zone
- For document processing: the document image or PDF you submitted for AI extraction
- Images or photos you attach to an AI chat conversation for vision-based analysis, and the file name of a PDF you attach
- For Tax Center and CPA features: merchant names and amounts of business transactions, for AI-assisted tax categorization and preparation of CPA export packages
- The public product name of a credit card, to look up its published reward rates
This information is provided to Anthropic only in connection with an AI request you make — for example, sending a chat message, uploading a receipt, or generating a tax report. Additional transaction history is retrieved only when needed to answer your question.
We do not send Anthropic your: Supabase user ID, bank account numbers, bank access credentials, email address, phone number, or government-issued identifiers.
6.2 Anthropic's Data Use and Retention
Under Anthropic's Commercial Terms of Service, Anthropic does not train its AI models on content submitted via the commercial API. This is distinct from Anthropic's consumer product terms.
Under Anthropic's commercial terms and Data Processing Addendum, Anthropic acts as our processor and processes your data to provide the API service and for trust-and-safety monitoring. Anthropic states that API inputs and outputs are deleted from its systems within 30 days by default, except where longer retention is required to enforce its usage policies or by law. Anthropic is contractually required under its Commercial Terms and Data Processing Addendum to process this data only as our service provider and on our instructions, to safeguard it with security measures including encryption at rest and in transit, access controls, breach notification and deletion commitments, and to protect it to a level that is the same as or equivalent to the protections described in this Privacy Policy and required by applicable App Store privacy requirements.
Anthropic's privacy information is available at anthropic.com/legal/privacy, and its commercial terms at anthropic.com/legal/commercial-terms.
6.4 No Use of Your Data to Train Language Models
SapphireCore does not use your personal information to train, fine-tune, or improve any large language model, and does not sell or share it for that purpose. As described above, Anthropic does not train its models on content submitted through the commercial API.
6.3 AI Usage Records
We maintain records of AI API usage for service health and cost management. These records contain only token counts, model identifiers, and cost data — no conversation content. When you delete your account, your identifier is removed from these records immediately; the remaining anonymized usage record is automatically deleted 90 days later. See Section 13.
Apple Services & In-App Purchases
7.1 In-App Purchases
All subscription and in-app purchases are processed by Apple Inc. through the App Store. SapphireCore does not collect or store your payment card information. We receive from Apple only: a pseudonymous transaction identifier, the product purchased, the purchase date, and subscription status changes via Apple's App Store Server Notifications (ASSN).
7.2 Apple App Store Server Notifications
Apple sends us cryptographically signed notifications when your subscription status changes (new subscription, renewal, cancellation, refund). We verify these notifications using Apple's published certificate chain — all verification happens locally. We store only a subset of notification data for compliance purposes. See Section 16.
SapphireCore operates under Apple's standard Paid Application and Free Application agreements, which govern Apple's role in processing transactions on our behalf.
7.3 iOS Speech Recognition
If you use voice dictation in SapphireCore, audio is processed by Apple's Speech Recognition framework (SFSpeechRecognizer) and is never transmitted to SapphireCore's servers. Depending on device model, locale, and iOS settings, Apple's framework may route speech to Apple's own servers for processing; this is governed by Apple's privacy policy, not SapphireCore's.
Cloud Document Storage
8.1 Architecture: Your Files Stay in Your Cloud
SapphireCore's Tax Center feature stores your documents in your own cloud storage account — not on SapphireCore's servers. When you connect a cloud provider and capture or select a document:
- The document is uploaded from your device directly to your connected cloud account (Google Drive, iCloud, Dropbox, or OneDrive).
- SapphireCore reads the document back temporarily to perform AI extraction.
- The document image is sent to Anthropic's API for OCR and field extraction (merchant, amount, date, category).
- The AI-extracted metadata is saved to your SapphireCore account; the raw document file remains only in your cloud account.
SapphireCore stores in its database only: a reference to the file in your cloud (the cloud provider's file ID), a link to open the file in your cloud provider's app, and AI-extracted fields (merchant name, amount, date, tax category, document type, a short OCR excerpt). No raw document file is stored on SapphireCore's servers.
8.2 Google Drive Integration
If you connect Google Drive as your document cloud:
- We request the
drive.fileOAuth scope. This limits access to files and folders that SapphireCore creates on your behalf in your Google Drive — we cannot access your broader Google Drive content. - Documents are saved into a
SapphireCore/CPA [year]/[folder]/directory in your Google Drive. - We also request your Google account
emailandprofilefor display purposes only (shown in the connected account UI). - Your Google OAuth token is stored only on your device in iOS Secure Storage (Keychain). It is never transmitted to or stored on SapphireCore's servers.
- When you delete your SapphireCore account, the app revokes your Google OAuth token with Google before completing deletion.
Google's privacy practices are described at policies.google.com/privacy.
8.3 CPA Export Reports
When you generate a business tax export (CSV and PDF), the generated report files are temporarily stored in SapphireCore's secure cloud storage to allow you to download or share them. These export files contain transaction data (merchant names, amounts, dates, tax categories) but not raw bank credentials or account numbers. They are associated with your account and deleted when your account is deleted.
Email Communications
We use Resend Inc. to deliver emails on our behalf.
9.1 Transactional Emails
We send emails required for account operation: account verification, one-time passwords, password reset, security alerts, and email address change confirmations. These cannot be unsubscribed from while you have an active account.
9.2 Lifecycle and Informational Emails
We may send lifecycle emails (such as onboarding tips or re-engagement messages) as permitted by applicable law. You may opt out at any time by clicking the one-click unsubscribe link included in any such email, or by emailing support@sapphirecore.net. Opting out through the unsubscribe link removes you from all lifecycle and marketing communications immediately; requests sent by email are honored promptly. The transactional and service emails described in Section 9.1 are not affected.
9.3 Annual Renewal Reminders
If you have an active annual subscription, California law (B&P Code §17602(h)) requires us to send you a renewal reminder before your annual renewal date. This email contains your plan name, renewal date, and cancellation instructions. It is transactional in nature and required while you have an active annual subscription.
9.4 Email Engagement Data
Resend reports delivery and engagement events (delivered, opened, clicked, bounced) to us. Open events may include the IP address and mail client reported to Resend at open time. We use this only to manage email deliverability and suppress future emails to addresses that have bounced or unsubscribed.
Push Notifications
We use Expo's push notification infrastructure, which routes through Apple Push Notification service (APNs). When push notifications are enabled, your device push token is stored in our database and used to deliver financial alerts, payment reminders, and goal notifications. Push notification content may include balance amounts or reminder text.
We do not share push tokens with advertisers or use them for cross-app tracking. Push tokens are deleted when you delete your account. You can disable push notifications at any time in iOS Settings > Notifications > SapphireCore.
Market Data Services
For market news and investment data, SapphireCore calls the APIs of Finnhub, Financial Modeling Prep, and MarketAux. We send only ticker symbols or general market data requests — no personal identifiers, account data, or financial details about you are transmitted to these services. Market data is cached and served to all users from that cache.
How We Share Your Information
12.1 Service Providers
We share your information with the following providers who process data on our behalf:
| Provider | Purpose | Data Shared |
|---|---|---|
| Anthropic PBC | AI API for the assistant chat, receipt/document extraction, tax categorization, and CPA export classification | First name, financial account and transaction summary, conversation text, AI memory facts, document images — no email or user ID (see Section 6) |
| Plaid Inc. | Bank connectivity and financial data retrieval | A pseudonymous user UUID (client_user_id); bank credentials entered directly into Plaid's interface |
| Supabase Inc. | Database, authentication, file storage, and serverless functions | All data stored in the Service (excluding raw document files, which go to your cloud) |
| Resend Inc. | Email delivery | Email address, name, email content |
| Expo (Expo Inc.) | Push notification delivery via APNs | Push notification token, notification title and body (may include balance amounts) |
| Sentry (Functional Software Inc.) | Client-side error and performance monitoring | Scrubbed error state — email addresses, numeric sequences, and dollar amounts are removed before transmission; the user is represented by a pseudonymous UUID (no name, email, or financial data is included) |
12.2 What We Do Not Do
- We do not sell your personal information.
- We do not share your personal information with advertising networks or data brokers.
- We do not share financial account data or transaction history for purposes other than delivering the Service.
12.3 Anonymous Learning Signals
If you opt in (Section 3.5), we contribute pseudonymized merchant classification signals to our internal learning system. These signals are identified only by an HMAC-SHA256 hash — they are not associated with your name, email, or user ID. These signals are not shared externally.
12.4 Legal Disclosures
We may disclose information if required by law, court order, or government authority, or if we believe disclosure is necessary to protect the safety, rights, or property of SapphireCore, our users, or the public.
12.5 Business Transfers
If SapphireCore is involved in a merger, acquisition, or sale of assets, your information may be transferred. We will provide notice before your information becomes subject to a different privacy policy.
Data Retention
We retain your personal information for as long as your account is active, plus the periods described below.
| Data Category | Retention | Basis |
|---|---|---|
| Account, profile, financial, and AI data (bank accounts, transactions, chat history, goals, subscriptions, settings, export reports) | Deleted as part of the account-deletion process | User request / contract end |
| AI usage records (token counts, cost — no conversation content) | Your identifier is removed on account deletion; the anonymized record is deleted 90 days later by an automated daily job | Legitimate interest (service health) |
| Merchant correction audit log (normalized merchant key, action type — no personal information) | Your identifier is removed on account deletion; the anonymized, immutable record is retained indefinitely as a system integrity log | Legitimate interest |
| Subscription consent records — contains Apple's pseudonymous transaction identifier, purchase date, and a cryptographic hash of the Apple-signed transaction. No raw personal information. | Later of: 3 years from original purchase date, or 1 year after subscription termination | Legal obligation — Cal. B&P §17602(a)(6) |
| Annual reminder delivery records — contains a one-way hash of your email address. No raw email stored. | 3 years from the date sent | Legal obligation — Cal. B&P §17602(h) |
| Apple notification log (Apple-assigned event identifiers — no user account data) | Retained for operational integrity | Legitimate interest |
| Anonymous merchant signals (pseudonymous HMAC hash only) | 25 months from contribution date | Legitimate interest |
| Raw tax documents | Stored in your own cloud account (Google Drive, etc.) — SapphireCore has no custody; deletion is governed by your cloud provider and your own files | User-controlled |
Account Deletion
You may delete your account at any time from Settings > Account > Delete Account. The deletion process includes the following steps, in order:
- Your Google OAuth authorization (if connected) is revoked with Google.
- Your Plaid bank connections are revoked with Plaid, ending their authorization to share your data with us.
- All personal financial data is deleted from our database, including bank accounts, transactions, subscriptions, chat history, AI memory, tax document metadata, goals, reminders, notifications, settings, and workspace data.
- Your user profile, email preferences, and authentication account are deleted.
- SapphireCore-hosted export files (CPA reports) are deleted from our cloud storage.
After deletion, only the anonymized and legally-required records described in Section 13 remain. Account deletion cannot be reversed.
Your raw tax documents stored in your Google Drive or other connected cloud account are not affected by SapphireCore account deletion — those files remain in your cloud account under your control.
U.S. Privacy Rights
We voluntarily provide the following privacy request options to all U.S. users. Where applicable state law grants you additional rights and requires us to honor them, we will do so. If your state's privacy law imposes specific obligations on businesses of our size and data practices, we will comply with those requirements.
15.1 Access
You may request information about the personal information we hold about you. Contact us at support@sapphirecore.net.
15.2 Deletion
You may delete your account and most associated personal information using the in-app deletion feature (Settings > Account > Delete Account). For requests beyond what the in-app feature covers, email us at support@sapphirecore.net. Some information may be retained as described in Section 13 where required by law or legitimate interest.
15.3 Correction
You may correct your profile, financial settings, and most personal information directly in the app. For corrections we cannot support in-app, contact us by email.
15.4 No Sale of Personal Information
We do not sell your personal information. We do not share your personal information for cross-context behavioral advertising. We have not sold or shared personal information in the preceding 12 months.
We do not track you across third-party websites or apps over time, we do not permit third parties to collect information about your activity across other websites or apps through the Service, and we do not use cross-site tracking for advertising. Because we do not engage in such tracking, we do not respond to browser "Do Not Track" signals.
15.5 Opt Out of Sharing (Anonymous Signals)
If you have enabled the opt-in anonymous merchant signal contribution, you may withdraw at any time in Settings > Privacy Settings. See Section 3.5.
15.6 Non-Discrimination
We will not discriminate against you for exercising any privacy right described in this Policy.
15.7 How to Submit a Request
Email support@sapphirecore.net with "Privacy Request" in the subject line. We will respond within 45 days. We may need to verify your identity before processing your request.
California Automatic Renewal Law (ARL) Disclosures
SapphireCore's automatically renewing subscriptions are subject to California Business & Professions Code §17602 (as amended by AB 2863, effective July 1, 2025).
16.1 Consent Records
For each subscription purchase, we maintain a consent record as required by §17602(a)(6). This record contains: Apple's pseudonymous transaction identifier, the purchase date, and a cryptographic hash (SHA-256) of Apple's signed transaction document (JWS), which allows an auditor to verify the record against Apple's authoritative transaction history. No raw personal information (name, email, address) is stored in these records. Records are retained for the legally-required period — see Section 13.
16.2 Annual Renewal Reminders
If you have an active annual subscription, we send a renewal reminder 25–35 days before your renewal date as required by §17602(h). The email contains your plan name, renewal date, and cancellation instructions. We retain pseudonymized delivery evidence (a one-way hash of your email address) to demonstrate compliance — the raw email address is not stored in compliance records.
16.3 Cancellation
Cancel at any time through iOS Settings > Apple ID > Subscriptions, or through Settings > Subscription in the SapphireCore app.
Sensitive Personal Information
The following categories of information we process may be considered sensitive under applicable privacy laws:
- Financial account data: Bank account names, balances, and transaction history accessed via Plaid. We use this data solely to operate the Service.
- Login credentials: Email address and password. Passwords are not stored in plaintext.
We do not collect: Social Security Numbers, government-issued ID numbers, biometric identifiers, health information, precise geolocation, or racial or ethnic origin data.
We do not use sensitive personal information for advertising or to make inferences about characteristics unrelated to delivering the Service.
Children's Privacy
SapphireCore is for users 18 years of age and older. We do not knowingly collect personal information from individuals under 18. If you are under 18, please do not use the Service.
If we learn that we have collected personal information from a person under 18, we will delete it promptly. If you believe we may have done so, contact us at support@sapphirecore.net.
Security
We implement technical and organizational measures to protect your personal information, including:
- Password handling: SapphireCore does not store your plaintext password. Authentication is managed through Supabase's authentication infrastructure, which handles credential security on our behalf.
- One-time passwords: OTP codes are stored only as one-way hashes — they cannot be recovered from our database in plaintext.
- Bank access credentials: Plaid's access token is stored server-side in a restricted database column that client applications cannot access. It is never returned to the client application and is never logged. Our database storage is protected by AES-256 encryption at rest.
- IP address privacy: IP addresses associated with bank connection events are stored only as non-reversible SHA-256 hashes. Raw IP addresses are not stored.
- Database access controls: Row-level security (RLS) is enforced on all user data tables. Server-side code authenticates your identity from a verified token — never from values you supply in the request body.
- Error reporting: Client-side errors reported to our error monitoring service (Sentry) are scrubbed to remove email addresses, long numeric sequences, and dollar amounts before transmission. Identifiers in error reports do not allow re-identification.
- Google OAuth token: Stored only on your device in iOS Secure Storage (Keychain). Never transmitted to SapphireCore's servers.
- Apple notification verification: All Apple App Store Server Notifications are cryptographically verified against Apple's published certificate chain before processing.
No security system is fully impenetrable. We cannot guarantee the security of data in transit over the internet. You are responsible for keeping your account credentials confidential.
Your Privacy Choices
| Choice | How to Exercise |
|---|---|
| Delete your account and most personal data | Settings > Account > Delete Account (in-app), or email us |
| Opt out of lifecycle / informational emails | One-click unsubscribe in any lifecycle email, or email support@sapphirecore.net |
| Opt in / out of anonymous merchant learning signals | Settings > Privacy Settings (in-app) — off by default |
| Disable push notifications | iOS Settings > Notifications > SapphireCore |
| Disconnect a bank account | Accounts screen > Disconnect (in-app) |
| Disconnect Google Drive | Documents screen > Connected Accounts > Disconnect (in-app) |
| Cancel subscription | iOS Settings > Apple ID > Subscriptions |
| Access, correct, or request a copy of your data | Email support@sapphirecore.net |
Contact & Privacy Requests
For questions about this Privacy Policy, to exercise your privacy rights, or to report a privacy concern:
PDG & Associates LLC d/b/a SapphireCore
3900 Alton Rd, Apt 206
Miami Beach, FL 33140
United States
Email: support@sapphirecore.net
We will respond to verifiable requests within 45 days. If we need additional time (up to 90 days total), we will notify you within the initial period.
Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, the Service, or applicable law. When we make material changes, we will update the effective date at the top of this document and provide notice within the SapphireCore application. For changes that materially affect how we handle your personal information, we will provide advance notice before the changes take effect where required by applicable law or where appropriate given the nature of the change.
Prior versions are available upon request by emailing support@sapphirecore.net.
Definitions
- Personal information — any information that identifies or is reasonably capable of identifying you as an individual.
- Pseudonymized — data that has been processed so it can no longer be attributed to a specific individual without additional information (such as a key or algorithm). Unlike anonymization, pseudonymization may be reversible by someone who holds the linking information.
- Service — the SapphireCore iOS application and related features and services.
- Service provider / processor — a company that processes personal information on our behalf, under our instructions, and subject to appropriate data protection safeguards.
- Plaid — Plaid Inc., our bank connectivity provider.
- Anthropic — Anthropic PBC, the provider of the Claude AI API that powers SapphireCore's AI features.
- Apple ASSN — Apple App Store Server Notifications: Apple's system for sending cryptographically signed subscription status events to SapphireCore.