Privacy policy
The short version: We connect to your bank read-only to show you your own data. We never store your banking credentials. We don't sell your data to anyone. You can delete your account and all associated data at any time.
1. Who we are
Savvy ("we", "us", "our") is a financial management application developed and operated by Savvy. Our registered contact address is vikkie@savvyagent.app.
For data protection purposes, Savvy is the data controller of the personal data described in this policy.
2. Data we collect
2.1 Account data
When you create a Savvy account, we collect:
- Email address
- Full name (optional)
- Password (stored as a bcrypt hash — we cannot read it)
- Date of account creation
- Preferred language
2.2 Bank and transaction data
When you connect a bank account via open banking (powered by Qwist or similar PSD2-regulated providers), we receive and store:
- Account name, type, and IBAN (masked)
- Account balance history
- Transaction history including amount, merchant name, date, and category
- Account holder name as returned by your bank
We do not store your banking username, password, PIN, or any credential used to access your bank. Access is established via OAuth tokens issued by PSD2-regulated third parties and can be revoked at any time.
2.3 App usage data
- Features used and screens viewed (anonymised)
- Error logs
- Session timestamps
- Device OS version and app version
2.4 Communications data
- Messages sent to our support team
- Email address used to join the waiting list
- In-app feedback submitted voluntarily
3. How we use your data
| Purpose | Data used |
|---|---|
| Providing the Savvy service (categorisation, Payday Plan, AI insights, Savings Pots) | Transaction data, account data |
| Powering Ask Savvy AI responses | Transaction history, spending patterns — processed via AWS Bedrock (EU regions only) for real-time inference, not stored |
| Generating Monthly Reports | Transaction data, account data |
| Sending you service notifications (payday detected, anomaly spotted) | Email address, account data |
| Improving the product (feature usage analytics) | Anonymised usage data |
| Responding to support requests | Email address, issue description |
| Complying with legal obligations | Account data |
4. Legal basis for processing
Under GDPR, we rely on the following legal bases:
- Contract performance (Art. 6(1)(b)): Processing necessary to provide you the Savvy service you signed up for.
- Consent (Art. 6(1)(a)): Where you have given explicit consent — such as connecting a bank account or enabling optional analytics.
- Legitimate interest (Art. 6(1)(f)): Fraud prevention, service security, and product improvement where your interests are not overridden.
- Legal obligation (Art. 6(1)(c)): Where we must comply with a legal requirement.
5. Bank and open banking data
Savvy uses PSD2-regulated open banking providers (currently Qwist) to connect to your bank. These providers are licensed by relevant financial authorities and operate under strict data protection rules.
Connecting a bank account grants Savvy read-only (AIS) access — we can see your account and transaction data, but this connection alone cannot move money, initiate payments, or modify your account in any way.
Separately, if you choose to enable Payday Plan automation or approve a transfer suggested by Savvy, you'll be asked to grant an additional, explicit payment initiation (PIS) consent. Only with this separate consent in place can Savvy initiate a bank transfer — and every individual transfer still requires you to authenticate directly with your own bank (Strong Customer Authentication) before it goes through. Savvy never has standing access to move money without your bank confirming each transfer with you.
You can revoke either the read-only bank connection or the payment initiation consent at any time in the Savvy app. Revoking access immediately ends our ability to fetch new data or initiate payments. Previously fetched transaction data is retained unless you delete your account.
6. Data sharing and third parties
We never sell your data to third parties. We share data only with the following categories of processors, under data processing agreements:
- Supabase (infrastructure and database) — EU data residency
- Qwist (open banking data access and payment initiation) — regulated EU entity
- AWS Bedrock (runs Anthropic's Claude model for Ask Savvy, EU regions only) — Anthropic does not receive or access this data directly; used for real-time inference only, never stored or used to train any model
- Apple (App Store distribution, push notifications)
- Google Analytics / Microsoft Clarity (anonymised website analytics — no financial data)
We may share data if required by a court order or other legal obligation. We will inform you where legally permitted.
7. Data storage and security
All data is stored on Supabase infrastructure hosted in the EU (Frankfurt). We apply:
- AES-256 encryption at rest for all user data
- TLS 1.3 in transit for all API and app communication
- Row-level security (RLS) enforcing that users can only access their own data
- Passwords hashed with bcrypt (never stored in plaintext)
- No banking credentials ever stored
We retain your data for as long as your account is active plus 30 days after deletion, to allow for error recovery. After 30 days, all data is permanently deleted from our systems.
8. Your rights under GDPR
You have the following rights regarding your personal data:
- Access: Request a copy of all data we hold about you.
- Rectification: Correct inaccurate or incomplete data.
- Erasure: Delete your account and all associated data. Available directly in the app under Settings.
- Restriction: Request we limit processing of your data in certain circumstances.
- Portability: Receive your data in a machine-readable format.
- Objection: Object to processing based on legitimate interest.
- Withdrawal of consent: Withdraw any consent given at any time without affecting prior processing.
To exercise any right, email vikkie@savvyagent.app. We respond within 30 days.
9. Cookies
The Savvy mobile app does not use cookies. Our website (savvyagent.app) uses:
- Essential cookies: Required for the site to function (session state, theme preference). No consent required.
- Analytics cookies: Google Analytics and Microsoft Clarity, used to understand aggregate traffic and how visitors use the site. These do not load until you explicitly accept them in the cookie banner shown on your first visit. You can change your choice at any time via the "Cookie preferences" link in the site footer, which withdraws or grants consent immediately.
10. Children
Savvy is not directed at anyone under 18. We do not knowingly collect personal data from children. If you believe a minor has created an account, please contact us immediately at vikkie@savvyagent.app.
11. Changes to this policy
We may update this policy as our product evolves or regulations change. Material changes will be notified via email to registered users at least 14 days before taking effect. The "last updated" date at the top always reflects the current version.
12. Contact and complaints
For any privacy questions or requests: vikkie@savvyagent.app
You have the right to lodge a complaint with your national data protection authority. In Germany, this is the Bundesbeauftragte für den Datenschutz (BfDI).