Privacy Policy
Last updated: July 2026
We never sell your personal or financial data to third parties. Period.
This Privacy Policy describes how SapphireCore ("we", "us", or "our") collects, uses, and protects information when you use the SapphireCore mobile application ("App"). By using the App, you agree to the practices described in this policy.
1. Information We Collect
SapphireCore collects information you provide directly, including your name, email address, financial goals, income estimates, and credit score range. If you connect bank accounts through Plaid, we receive read-only access to your transaction history, account balances, and account names. We do not store your bank login credentials.
- Account information: name, email address, and password (hashed) provided at registration.
- Financial data: bank account details, transaction history, account balances, and investment holdings — retrieved via Plaid with your explicit authorization.
- Usage data: app interactions, feature usage, and session information for improving the App.
- Device information: device type, operating system, and app version for technical support.
2. How We Use Your Information
We use your information to provide personalized financial insights and AI-powered chat responses. Your financial data is used solely to improve the accuracy of SapphireCore's recommendations. We do NOT sell your personal information to third parties.
- To provide and operate the App and its financial management features.
- To display your bank accounts, transactions, and investment portfolio within the App.
- To generate AI-powered financial insights and personalized recommendations.
- To send reminders and notifications you configure within the App.
- To improve the App and diagnose technical issues.
3. AI Learning and Anonymous Signals
SapphireCore includes an optional AI Learning feature that improves subscription detection accuracy for all users. When enabled (the default), corrections you make — such as marking a payment as "not a subscription" — are contributed as anonymous signals.
What we do to protect your privacy:
- Your user identity is never stored with the signal. We use a one-way cryptographic hash (SHA-256) solely to enforce a daily rate limit.
- Signals are bucketed by ISO calendar week (e.g. "2026-W27"), not by day or time, so individual activity cannot be identified.
- Signals are only used in aggregate once at least 20 signals from at least 5 different weeks are collected for a merchant — preventing any individual from influencing results.
You can disable this feature at any time in Settings → Privacy → "Improve AI for everyone". Your personal corrections continue to work for your account regardless of this setting.
4. Data Retention
We retain different categories of data for different periods:
- Account and financial data: retained while your account is active, deleted immediately upon account deletion.
- AI correction audit log: events are retained for record-keeping, but your personal identity (user ID) is permanently removed from the log when you delete your account.
- Rate-limiting records: pseudonymous (hashed) rate-limit records are automatically deleted after 90 days.
- Anonymous AI signals: retained as part of the aggregate learning dataset. Because no personal identifier is stored, these cannot be linked back to you and therefore fall outside the scope of individual deletion rights.
5. Data Storage and Security
Your data is stored securely using Supabase infrastructure with row-level security, ensuring each user can only access their own data. Sensitive credentials are stored using device-level encryption. You may delete your account and all associated personal data at any time from Settings → Security → Delete Account.
- All data in transit is encrypted using TLS 1.2 or higher.
- All data at rest is encrypted using AES-256 via Supabase.
- Plaid access tokens are stored server-side only and never transmitted to or stored on your device.
- We enforce row-level security — each user can only access their own data.
- Access to production systems is protected by multi-factor authentication.
6. Microphone and Voice
SapphireCore may request access to your microphone to enable voice input in the chat. Voice audio is processed locally on your device for speech-to-text conversion and is not recorded or stored on our servers. You can deny microphone access and use text input instead.
7. Camera and Photos
SapphireCore may request access to your camera or photo library to allow you to attach images to your messages. Photos are sent directly to our AI for analysis and are not stored permanently on our servers.
8. Email Access (CPA Feature)
If you choose to connect your email account (Gmail, iCloud Mail, or other providers), SapphireCore scans your inbox for financial documents such as receipts, invoices, and bank statements to assist with expense tracking. We only read emails that match financial patterns. We do not read, store, or share personal emails. Email access requires your explicit authorization and can be revoked at any time from Settings.
9. Third-Party Services
SapphireCore uses the following third-party services to operate the App:
- Plaid Technologies, Inc. — used to securely connect your bank and investment accounts. Plaid's access tokens are stored server-side only and never accessible to client devices.
- Anthropic Claude API — used to power AI financial insights and chat responses. Only anonymized financial summaries are sent; no raw account numbers or personally identifiable information is transmitted.
- Supabase — our cloud database and backend provider. All data is stored encrypted at rest (AES-256) in Supabase infrastructure located in the United States.
- Resend — used for transactional email delivery (account verification, alerts).
- Google (Gmail integration) — used for the optional CPA email feature. We do not access your Google Drive or non-financial Gmail data without your explicit consent.
- Sentry — used for error monitoring and crash reporting. Personal and financial data is scrubbed before any information is sent to Sentry.
Each service operates under its own privacy policy.
10. California Residents — Your CCPA Rights
If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA):
- Right to Know: You may request a copy of the personal information we have collected about you and how we use it.
- Right to Delete: You may request that we delete your personal information. You can do this directly from Settings → Security → Delete Account. This permanently removes all personal data linked to your account, including financial data, preferences, and AI correction history.
- Right to Opt-Out of Sale: We do not sell your personal information to third parties. You do not need to opt-out because we never sell your data.
- Right to Non-Discrimination: We will not discriminate against you for exercising any of your CCPA rights.
To exercise your rights, contact us at: support@sapphirecore.net
11. Your Privacy Rights (GDPR)
If you are located in the European Economic Area, United Kingdom, or Switzerland, you have the following rights under GDPR:
- Right of Access: Request a copy of the personal data we hold about you.
- Right to Rectification: Request correction of inaccurate personal data.
- Right to Erasure ("Right to be Forgotten"): Delete your account from Settings → Security → Delete Account. This removes all personal identifiers from our systems. Note: anonymous signals contributed to the AI learning dataset cannot be individually identified or removed, as no personal identifier was stored with them.
- Right to Restriction and Portability: Contact us at support@sapphirecore.net.
- Right to Object: You may opt out of anonymous AI signal contribution at any time in Settings → Privacy.
12. Children's Privacy
SapphireCore is not intended for users under the age of 18. We do not knowingly collect personal information from minors. If you believe a minor has provided us with personal data, please contact us immediately.
13. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes via the App or by email. Continued use of the App after changes constitutes acceptance of the updated policy.
14. Contact Us
For privacy questions or data deletion requests, contact us:
Pavel Govorushko
Founder, SapphireCore
Email: support@sapphirecore.net
Last updated: July 2026