Section 1

Who We Are

SapphireCore is a personal finance and AI assistant application. PDG & Associates LLC ("we," "our," or "us"), a company organized under the laws of Florida doing business as SapphireCore, is responsible for the personal information processed through the Service. Our principal place of business is:

PDG & Associates LLC d/b/a SapphireCore
3900 Alton Rd, Apt 206
Miami Beach, FL 33140
United States

Email: support@sapphirecore.net

Section 2

Scope of This Policy

This Privacy Policy explains how SapphireCore collects, uses, retains, and shares personal information when you use our iOS mobile application and related services (collectively, the "Service"). It applies to all users, including users of both the Personal and Business workspace features.

This Policy does not apply to third-party services we connect to — those services have their own privacy policies, which we link to throughout this document. It also does not apply to information Apple collects directly through the App Store.

This Policy should be read together with our Terms of Service, which govern your use of SapphireCore. Subscription pricing, automatic-renewal, and cancellation terms are presented in the app before you purchase and are also governed by Apple's App Store terms. Account deletion is described in Section 14 of this Policy.

Section 3

Information We Collect

3.1 Information You Provide Directly

  • Account credentials: Your name, email address, and password. SapphireCore does not store your plaintext password.
  • Profile information: Your display name and, if you choose to upload one, a profile photo.
  • Financial settings: Budget amounts, savings goals, monthly income targets, your self-reported credit score (optional), and other planning values you enter manually.
  • Profile photo: If you upload a profile photo, it is stored on SapphireCore's servers (Supabase cloud storage). The photo is selected from your device's camera or photo library using the iOS system picker.
  • Tax documents: When you use the Tax Center (CPA) feature, you capture or select documents (receipts, invoices, statements) from your device and upload them to your own connected cloud storage account (Google Drive or another provider you choose). Raw document files are stored in your own cloud account — not on SapphireCore's servers. The document image is temporarily transmitted to SapphireCore's server and forwarded to Anthropic's API for AI extraction; it is not stored on SapphireCore's servers after processing. SapphireCore stores only the document metadata and AI-extracted fields described in Section 8.
  • Accountant contact information: If you add an accountant or CPA, we store their name, email address, and firm name.
  • AI conversations: The text of your messages to the SapphireCore AI assistant, including any financial details you type or share within a conversation.

3.2 Information Collected from Third Parties

  • Bank and financial data via Plaid: When you link a bank account, Plaid provides us with account names, account number masks (last four digits), institution names, account balances, transaction history, credit card liability data, and investment holdings. See Section 5.
  • Apple subscription data: When you purchase a subscription or in-app item, Apple sends us cryptographically signed notifications containing a pseudonymous transaction identifier, product identifier, and purchase status.

3.3 Information Collected Automatically

  • AI-extracted memory: Short factual summaries that the AI extracts automatically from your conversations after it replies (for example, "User is saving for a down payment") to personalize future responses within your session and across sessions. These memory facts are stored with your account and deleted when you delete your account.
  • Push notification token: A device identifier provided by Apple and routed via Expo to deliver push notifications.
  • App usage information: Feature usage timestamps, chat thread history, and notification records.
  • Connection audit data: When you connect a bank account, we record a one-way hash (SHA-256) of your IP address — not the raw IP address — along with your device's user agent string, the institution identifier, and the connection outcome. We use this for security and rate-limiting.
  • Email engagement events: Delivery status and, when emails are opened, the IP address and mail client information reported by our email provider, Resend. We use this data to manage email deliverability and honor unsubscribes.

3.4 Information Processed On-Device Only

  • Voice input: If you dictate messages using voice-to-text, audio is processed by Apple's Speech Recognition framework (SFSpeechRecognizer) and is never transmitted to SapphireCore's servers. Depending on device model, locale, and iOS settings, Apple's framework may route speech to Apple's own servers for processing; this is governed by Apple's privacy policy, not SapphireCore's. You can require on-device-only recognition by disabling "Improve Siri & Dictation" in iOS Settings > Privacy & Security > Analytics & Improvements.
  • Google OAuth token: If you connect Google Drive, your Google OAuth access token is stored only on your device in iOS Secure Storage (Keychain). It is never transmitted to or stored on SapphireCore's servers.

3.5 Anonymous Learning Signals (Opt-In)

You may choose to contribute anonymous merchant classification signals to SapphireCore's shared learning system. This is off by default. If you enable it in Settings > Privacy Settings, we record a contribution identified only by a pseudonymous HMAC-SHA256 hash — your user ID and any personal identifiers are not included. No financial amounts are included. You can withdraw your participation at any time. See Section 20.

Section 4

How We Use Your Information

PurposeData UsedBasis
Provide and operate the ServiceAll categories in §3Contract performance
Process in-app purchases and manage subscriptionsApple transaction identifiersContract performance
Deliver AI financial insights using Anthropic's APIFinancial summary, conversation, AI memoryContract performance
Send transactional emails (verification, OTP, security)Email address, nameContract performance
Send lifecycle and informational emails as permitted by law (opt-out available)Email address, name, planLegitimate interest
Send annual subscription renewal remindersEmail address, name, plan, renewal dateLegal obligation (Cal. B&P §17602(h))
Deliver push notificationsPush token, balance and reminder dataContract performance
California ARL compliance recordkeepingApple transaction ID, pseudonymized email hash, purchase dateLegal obligation (Cal. B&P §17602)
Security, fraud prevention, and rate limitingIP hash, user agent, login patternsLegitimate interest
Track AI usage costs for service healthToken counts, model — no contentLegitimate interest
Anonymous merchant classification (opt-in)Pseudonymous signal — no personal dataConsent

We do not use your personal information for advertising or for sale to third parties.

Section 5

Bank & Financial Account Data (Plaid)

SapphireCore uses Plaid Inc. to connect your bank, credit card, and investment accounts. When you link an account:

  • You authenticate directly with your financial institution through Plaid's secure interface. Your bank username and password are entered only into Plaid's interface and are never seen by or transmitted to SapphireCore.
  • Plaid provides SapphireCore with read-only access to your account data: account names, masked account numbers (last four digits), institution name, current balances, transaction history, credit card liability details, and investment holdings.
  • SapphireCore cannot initiate transactions, move funds, or make payments on your behalf.
  • Plaid's access credential (allowing ongoing data retrieval) is stored securely on our servers in a restricted server-side database column. It is not accessible to authenticated users or client applications, is never included in API responses, and is never logged. All data in our database, including this credential, is protected by AES-256 encryption applied at the storage layer by our database infrastructure provider.
  • When you disconnect a bank account or delete your SapphireCore account, we call Plaid's API to revoke access, ending Plaid's authorization to share your data with us.
  • You can also review the connections Plaid maintains on your behalf, disconnect them, and request deletion of data stored in Plaid's own systems through the Plaid Portal at my.plaid.com.

Our use of Plaid is covered by an active Master Services Agreement between SapphireCore and Plaid. Plaid's privacy practices for end users are described in Plaid's End User Privacy Policy at plaid.com/legal/#end-user-privacy-policy.

Plaid Products We use Plaid's Transactions product for transaction history, the Liabilities product for credit card data (with your explicit consent at connection time), and the Investments product for investment portfolio data.
Section 6

Artificial Intelligence Features (Anthropic)

The AI assistant and document analysis features in SapphireCore are powered by Anthropic PBC's Claude API. Anthropic processes data as our service provider under Anthropic's commercial API terms.

6.1 What We Send to Anthropic

When you use AI features, we send Anthropic a prompt that may include:

  • Your first name
  • A summary of your linked accounts: account and card names with the last four digits (masked), account type and subtype, current and available balances, credit limits and utilization, upcoming payment due dates, minimum payments, and autopay status
  • Transaction context: merchant names and transaction descriptions, amounts, dates, spending categories, and detected recurring subscriptions. A summary of recent activity accompanies your chat request; when your question requires it, the assistant may retrieve matching transactions from the current and previous calendar year
  • Your self-reported credit score and monthly income, if you have provided them (Personal workspace only)
  • Your savings goals and budget context
  • Your AI memory facts (short summaries like "User is saving for a house")
  • Your chat message and recent conversation history for the current session, including the assistant's earlier replies
  • Your device time zone
  • For document processing: the document image or PDF you submitted for AI extraction
  • Images or photos you attach to an AI chat conversation for vision-based analysis, and the file name of a PDF you attach
  • For Tax Center and CPA features: merchant names and amounts of business transactions, for AI-assisted tax categorization and preparation of CPA export packages
  • The public product name of a credit card, to look up its published reward rates

This information is provided to Anthropic only in connection with an AI request you make — for example, sending a chat message, uploading a receipt, or generating a tax report. Additional transaction history is retrieved only when needed to answer your question.

We do not send Anthropic your: Supabase user ID, bank account numbers, bank access credentials, email address, phone number, or government-issued identifiers.

6.2 Anthropic's Data Use and Retention

Under Anthropic's Commercial Terms of Service, Anthropic does not train its AI models on content submitted via the commercial API. This is distinct from Anthropic's consumer product terms.

Under Anthropic's commercial terms and Data Processing Addendum, Anthropic acts as our processor and processes your data to provide the API service and for trust-and-safety monitoring. Anthropic states that API inputs and outputs are deleted from its systems within 30 days by default, except where longer retention is required to enforce its usage policies or by law. Anthropic is contractually required under its Commercial Terms and Data Processing Addendum to process this data only as our service provider and on our instructions, to safeguard it with security measures including encryption at rest and in transit, access controls, breach notification and deletion commitments, and to protect it to a level that is the same as or equivalent to the protections described in this Privacy Policy and required by applicable App Store privacy requirements.

Anthropic's privacy information is available at anthropic.com/legal/privacy, and its commercial terms at anthropic.com/legal/commercial-terms.

6.4 No Use of Your Data to Train Language Models

SapphireCore does not use your personal information to train, fine-tune, or improve any large language model, and does not sell or share it for that purpose. As described above, Anthropic does not train its models on content submitted through the commercial API.

6.3 AI Usage Records

We maintain records of AI API usage for service health and cost management. These records contain only token counts, model identifiers, and cost data — no conversation content. When you delete your account, your identifier is removed from these records immediately; the remaining anonymized usage record is automatically deleted 90 days later. See Section 13.

Section 7

Apple Services & In-App Purchases

7.1 In-App Purchases

All subscription and in-app purchases are processed by Apple Inc. through the App Store. SapphireCore does not collect or store your payment card information. We receive from Apple only: a pseudonymous transaction identifier, the product purchased, the purchase date, and subscription status changes via Apple's App Store Server Notifications (ASSN).

7.2 Apple App Store Server Notifications

Apple sends us cryptographically signed notifications when your subscription status changes (new subscription, renewal, cancellation, refund). We verify these notifications using Apple's published certificate chain — all verification happens locally. We store only a subset of notification data for compliance purposes. See Section 16.

SapphireCore operates under Apple's standard Paid Application and Free Application agreements, which govern Apple's role in processing transactions on our behalf.

7.3 iOS Speech Recognition

If you use voice dictation in SapphireCore, audio is processed by Apple's Speech Recognition framework (SFSpeechRecognizer) and is never transmitted to SapphireCore's servers. Depending on device model, locale, and iOS settings, Apple's framework may route speech to Apple's own servers for processing; this is governed by Apple's privacy policy, not SapphireCore's.

Section 8

Cloud Document Storage

8.1 Architecture: Your Files Stay in Your Cloud

SapphireCore's Tax Center feature stores your documents in your own cloud storage account — not on SapphireCore's servers. When you connect a cloud provider and capture or select a document:

  1. The document is uploaded from your device directly to your connected cloud account (Google Drive, iCloud, Dropbox, or OneDrive).
  2. SapphireCore reads the document back temporarily to perform AI extraction.
  3. The document image is sent to Anthropic's API for OCR and field extraction (merchant, amount, date, category).
  4. The AI-extracted metadata is saved to your SapphireCore account; the raw document file remains only in your cloud account.

SapphireCore stores in its database only: a reference to the file in your cloud (the cloud provider's file ID), a link to open the file in your cloud provider's app, and AI-extracted fields (merchant name, amount, date, tax category, document type, a short OCR excerpt). No raw document file is stored on SapphireCore's servers.

8.2 Google Drive Integration

If you connect Google Drive as your document cloud:

  • We request the drive.file OAuth scope. This limits access to files and folders that SapphireCore creates on your behalf in your Google Drive — we cannot access your broader Google Drive content.
  • Documents are saved into a SapphireCore/CPA [year]/[folder]/ directory in your Google Drive.
  • We also request your Google account email and profile for display purposes only (shown in the connected account UI).
  • Your Google OAuth token is stored only on your device in iOS Secure Storage (Keychain). It is never transmitted to or stored on SapphireCore's servers.
  • When you delete your SapphireCore account, the app revokes your Google OAuth token with Google before completing deletion.

Google's privacy practices are described at policies.google.com/privacy.

8.3 CPA Export Reports

When you generate a business tax export (CSV and PDF), the generated report files are temporarily stored in SapphireCore's secure cloud storage to allow you to download or share them. These export files contain transaction data (merchant names, amounts, dates, tax categories) but not raw bank credentials or account numbers. They are associated with your account and deleted when your account is deleted.

iCloud, Dropbox, OneDrive Support for iCloud Drive, Dropbox, and OneDrive as document storage providers is planned. The same privacy architecture applies to all supported providers — raw files live in your own cloud account, not on SapphireCore's servers.
Section 9

Email Communications

We use Resend Inc. to deliver emails on our behalf.

9.1 Transactional Emails

We send emails required for account operation: account verification, one-time passwords, password reset, security alerts, and email address change confirmations. These cannot be unsubscribed from while you have an active account.

9.2 Lifecycle and Informational Emails

We may send lifecycle emails (such as onboarding tips or re-engagement messages) as permitted by applicable law. You may opt out at any time by clicking the one-click unsubscribe link included in any such email, or by emailing support@sapphirecore.net. Opting out through the unsubscribe link removes you from all lifecycle and marketing communications immediately; requests sent by email are honored promptly. The transactional and service emails described in Section 9.1 are not affected.

9.3 Annual Renewal Reminders

If you have an active annual subscription, California law (B&P Code §17602(h)) requires us to send you a renewal reminder before your annual renewal date. This email contains your plan name, renewal date, and cancellation instructions. It is transactional in nature and required while you have an active annual subscription.

9.4 Email Engagement Data

Resend reports delivery and engagement events (delivered, opened, clicked, bounced) to us. Open events may include the IP address and mail client reported to Resend at open time. We use this only to manage email deliverability and suppress future emails to addresses that have bounced or unsubscribed.

Section 10

Push Notifications

We use Expo's push notification infrastructure, which routes through Apple Push Notification service (APNs). When push notifications are enabled, your device push token is stored in our database and used to deliver financial alerts, payment reminders, and goal notifications. Push notification content may include balance amounts or reminder text.

We do not share push tokens with advertisers or use them for cross-app tracking. Push tokens are deleted when you delete your account. You can disable push notifications at any time in iOS Settings > Notifications > SapphireCore.

Section 11

Market Data Services

For market news and investment data, SapphireCore calls the APIs of Finnhub, Financial Modeling Prep, and MarketAux. We send only ticker symbols or general market data requests — no personal identifiers, account data, or financial details about you are transmitted to these services. Market data is cached and served to all users from that cache.

Section 12

How We Share Your Information

12.1 Service Providers

We share your information with the following providers who process data on our behalf:

ProviderPurposeData Shared
Anthropic PBC AI API for the assistant chat, receipt/document extraction, tax categorization, and CPA export classification First name, financial account and transaction summary, conversation text, AI memory facts, document images — no email or user ID (see Section 6)
Plaid Inc. Bank connectivity and financial data retrieval A pseudonymous user UUID (client_user_id); bank credentials entered directly into Plaid's interface
Supabase Inc. Database, authentication, file storage, and serverless functions All data stored in the Service (excluding raw document files, which go to your cloud)
Resend Inc. Email delivery Email address, name, email content
Expo (Expo Inc.) Push notification delivery via APNs Push notification token, notification title and body (may include balance amounts)
Sentry (Functional Software Inc.) Client-side error and performance monitoring Scrubbed error state — email addresses, numeric sequences, and dollar amounts are removed before transmission; the user is represented by a pseudonymous UUID (no name, email, or financial data is included)

12.2 What We Do Not Do

  • We do not sell your personal information.
  • We do not share your personal information with advertising networks or data brokers.
  • We do not share financial account data or transaction history for purposes other than delivering the Service.

12.3 Anonymous Learning Signals

If you opt in (Section 3.5), we contribute pseudonymized merchant classification signals to our internal learning system. These signals are identified only by an HMAC-SHA256 hash — they are not associated with your name, email, or user ID. These signals are not shared externally.

12.4 Legal Disclosures

We may disclose information if required by law, court order, or government authority, or if we believe disclosure is necessary to protect the safety, rights, or property of SapphireCore, our users, or the public.

12.5 Business Transfers

If SapphireCore is involved in a merger, acquisition, or sale of assets, your information may be transferred. We will provide notice before your information becomes subject to a different privacy policy.

Section 13

Data Retention

We retain your personal information for as long as your account is active, plus the periods described below.

Data CategoryRetentionBasis
Account, profile, financial, and AI data (bank accounts, transactions, chat history, goals, subscriptions, settings, export reports) Deleted as part of the account-deletion process User request / contract end
AI usage records (token counts, cost — no conversation content) Your identifier is removed on account deletion; the anonymized record is deleted 90 days later by an automated daily job Legitimate interest (service health)
Merchant correction audit log (normalized merchant key, action type — no personal information) Your identifier is removed on account deletion; the anonymized, immutable record is retained indefinitely as a system integrity log Legitimate interest
Subscription consent records — contains Apple's pseudonymous transaction identifier, purchase date, and a cryptographic hash of the Apple-signed transaction. No raw personal information. Later of: 3 years from original purchase date, or 1 year after subscription termination Legal obligation — Cal. B&P §17602(a)(6)
Annual reminder delivery records — contains a one-way hash of your email address. No raw email stored. 3 years from the date sent Legal obligation — Cal. B&P §17602(h)
Apple notification log (Apple-assigned event identifiers — no user account data) Retained for operational integrity Legitimate interest
Anonymous merchant signals (pseudonymous HMAC hash only) 25 months from contribution date Legitimate interest
Raw tax documents Stored in your own cloud account (Google Drive, etc.) — SapphireCore has no custody; deletion is governed by your cloud provider and your own files User-controlled
Compliance Records Are Pseudonymized The records retained after account deletion for legal compliance purposes (subscription consent log and annual reminder log) use Apple's pseudonymous transaction identifier and a one-way hash of your email address. These are pseudonymized identifiers — no name, address, or raw email is stored in these records.
Section 14

Account Deletion

You may delete your account at any time from Settings > Account > Delete Account. The deletion process includes the following steps, in order:

  1. Your Google OAuth authorization (if connected) is revoked with Google.
  2. Your Plaid bank connections are revoked with Plaid, ending their authorization to share your data with us.
  3. All personal financial data is deleted from our database, including bank accounts, transactions, subscriptions, chat history, AI memory, tax document metadata, goals, reminders, notifications, settings, and workspace data.
  4. Your user profile, email preferences, and authentication account are deleted.
  5. SapphireCore-hosted export files (CPA reports) are deleted from our cloud storage.

After deletion, only the anonymized and legally-required records described in Section 13 remain. Account deletion cannot be reversed.

Your raw tax documents stored in your Google Drive or other connected cloud account are not affected by SapphireCore account deletion — those files remain in your cloud account under your control.

Subscription Must Be Cancelled Separately Deleting your SapphireCore account does not cancel your App Store subscription. To stop future charges, cancel your subscription in iOS Settings > Apple ID > Subscriptions before or after deleting your account.
Section 15

U.S. Privacy Rights

We voluntarily provide the following privacy request options to all U.S. users. Where applicable state law grants you additional rights and requires us to honor them, we will do so. If your state's privacy law imposes specific obligations on businesses of our size and data practices, we will comply with those requirements.

15.1 Access

You may request information about the personal information we hold about you. Contact us at support@sapphirecore.net.

15.2 Deletion

You may delete your account and most associated personal information using the in-app deletion feature (Settings > Account > Delete Account). For requests beyond what the in-app feature covers, email us at support@sapphirecore.net. Some information may be retained as described in Section 13 where required by law or legitimate interest.

15.3 Correction

You may correct your profile, financial settings, and most personal information directly in the app. For corrections we cannot support in-app, contact us by email.

15.4 No Sale of Personal Information

We do not sell your personal information. We do not share your personal information for cross-context behavioral advertising. We have not sold or shared personal information in the preceding 12 months.

We do not track you across third-party websites or apps over time, we do not permit third parties to collect information about your activity across other websites or apps through the Service, and we do not use cross-site tracking for advertising. Because we do not engage in such tracking, we do not respond to browser "Do Not Track" signals.

15.5 Opt Out of Sharing (Anonymous Signals)

If you have enabled the opt-in anonymous merchant signal contribution, you may withdraw at any time in Settings > Privacy Settings. See Section 3.5.

15.6 Non-Discrimination

We will not discriminate against you for exercising any privacy right described in this Policy.

15.7 How to Submit a Request

Email support@sapphirecore.net with "Privacy Request" in the subject line. We will respond within 45 days. We may need to verify your identity before processing your request.

Section 16

California Automatic Renewal Law (ARL) Disclosures

SapphireCore's automatically renewing subscriptions are subject to California Business & Professions Code §17602 (as amended by AB 2863, effective July 1, 2025).

16.1 Consent Records

For each subscription purchase, we maintain a consent record as required by §17602(a)(6). This record contains: Apple's pseudonymous transaction identifier, the purchase date, and a cryptographic hash (SHA-256) of Apple's signed transaction document (JWS), which allows an auditor to verify the record against Apple's authoritative transaction history. No raw personal information (name, email, address) is stored in these records. Records are retained for the legally-required period — see Section 13.

16.2 Annual Renewal Reminders

If you have an active annual subscription, we send a renewal reminder 25–35 days before your renewal date as required by §17602(h). The email contains your plan name, renewal date, and cancellation instructions. We retain pseudonymized delivery evidence (a one-way hash of your email address) to demonstrate compliance — the raw email address is not stored in compliance records.

16.3 Cancellation

Cancel at any time through iOS Settings > Apple ID > Subscriptions, or through Settings > Subscription in the SapphireCore app.

Section 17

Sensitive Personal Information

The following categories of information we process may be considered sensitive under applicable privacy laws:

  • Financial account data: Bank account names, balances, and transaction history accessed via Plaid. We use this data solely to operate the Service.
  • Login credentials: Email address and password. Passwords are not stored in plaintext.

We do not collect: Social Security Numbers, government-issued ID numbers, biometric identifiers, health information, precise geolocation, or racial or ethnic origin data.

We do not use sensitive personal information for advertising or to make inferences about characteristics unrelated to delivering the Service.

Section 18

Children's Privacy

SapphireCore is for users 18 years of age and older. We do not knowingly collect personal information from individuals under 18. If you are under 18, please do not use the Service.

If we learn that we have collected personal information from a person under 18, we will delete it promptly. If you believe we may have done so, contact us at support@sapphirecore.net.

Section 19

Security

We implement technical and organizational measures to protect your personal information, including:

  • Password handling: SapphireCore does not store your plaintext password. Authentication is managed through Supabase's authentication infrastructure, which handles credential security on our behalf.
  • One-time passwords: OTP codes are stored only as one-way hashes — they cannot be recovered from our database in plaintext.
  • Bank access credentials: Plaid's access token is stored server-side in a restricted database column that client applications cannot access. It is never returned to the client application and is never logged. Our database storage is protected by AES-256 encryption at rest.
  • IP address privacy: IP addresses associated with bank connection events are stored only as non-reversible SHA-256 hashes. Raw IP addresses are not stored.
  • Database access controls: Row-level security (RLS) is enforced on all user data tables. Server-side code authenticates your identity from a verified token — never from values you supply in the request body.
  • Error reporting: Client-side errors reported to our error monitoring service (Sentry) are scrubbed to remove email addresses, long numeric sequences, and dollar amounts before transmission. Identifiers in error reports do not allow re-identification.
  • Google OAuth token: Stored only on your device in iOS Secure Storage (Keychain). Never transmitted to SapphireCore's servers.
  • Apple notification verification: All Apple App Store Server Notifications are cryptographically verified against Apple's published certificate chain before processing.

No security system is fully impenetrable. We cannot guarantee the security of data in transit over the internet. You are responsible for keeping your account credentials confidential.

Section 20

Your Privacy Choices

ChoiceHow to Exercise
Delete your account and most personal dataSettings > Account > Delete Account (in-app), or email us
Opt out of lifecycle / informational emailsOne-click unsubscribe in any lifecycle email, or email support@sapphirecore.net
Opt in / out of anonymous merchant learning signalsSettings > Privacy Settings (in-app) — off by default
Disable push notificationsiOS Settings > Notifications > SapphireCore
Disconnect a bank accountAccounts screen > Disconnect (in-app)
Disconnect Google DriveDocuments screen > Connected Accounts > Disconnect (in-app)
Cancel subscriptioniOS Settings > Apple ID > Subscriptions
Access, correct, or request a copy of your dataEmail support@sapphirecore.net
Section 21

Contact & Privacy Requests

For questions about this Privacy Policy, to exercise your privacy rights, or to report a privacy concern:

PDG & Associates LLC d/b/a SapphireCore
3900 Alton Rd, Apt 206
Miami Beach, FL 33140
United States
Email: support@sapphirecore.net

We will respond to verifiable requests within 45 days. If we need additional time (up to 90 days total), we will notify you within the initial period.

Section 22

Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, the Service, or applicable law. When we make material changes, we will update the effective date at the top of this document and provide notice within the SapphireCore application. For changes that materially affect how we handle your personal information, we will provide advance notice before the changes take effect where required by applicable law or where appropriate given the nature of the change.

Prior versions are available upon request by emailing support@sapphirecore.net.

Section 23

Definitions

  • Personal information — any information that identifies or is reasonably capable of identifying you as an individual.
  • Pseudonymized — data that has been processed so it can no longer be attributed to a specific individual without additional information (such as a key or algorithm). Unlike anonymization, pseudonymization may be reversible by someone who holds the linking information.
  • Service — the SapphireCore iOS application and related features and services.
  • Service provider / processor — a company that processes personal information on our behalf, under our instructions, and subject to appropriate data protection safeguards.
  • Plaid — Plaid Inc., our bank connectivity provider.
  • Anthropic — Anthropic PBC, the provider of the Claude AI API that powers SapphireCore's AI features.
  • Apple ASSN — Apple App Store Server Notifications: Apple's system for sending cryptographically signed subscription status events to SapphireCore.