Privacy Policy
The short version: We connect to your bank read-only to show you your own data. We never store your banking credentials. We don't sell your data to anyone. You can delete your account and all associated data at any time.
1. Who we are
Savvy ("we", "us", "our") is a financial management application developed and operated by Savvy. Our registered contact address is privacy@savvyagent.app.
For data protection purposes, Savvy is the data controller of the personal data described in this policy.
2. Data we collect
2.1 Account data
When you create a Savvy account, we collect:
- Email address
- Full name (optional)
- Password (stored as a bcrypt hash — we cannot read it)
- Date of account creation
- Preferred language
2.2 Bank and transaction data
When you connect a bank account via open banking (powered by Tink or similar PSD2-regulated providers), we receive and store:
- Account name, type, and IBAN (masked)
- Account balance history
- Transaction history including amount, merchant name, date, and category
- Account holder name as returned by your bank
We do not store your banking username, password, PIN, or any credential used to access your bank. Access is established via OAuth tokens issued by PSD2-regulated third parties and can be revoked at any time.
2.3 App usage data
- Features used and screens viewed (anonymised)
- Error logs
- Session timestamps
- Device OS version and app version
2.4 Communications data
- Messages sent to our support team
- Email address used to join the waiting list
- In-app feedback submitted voluntarily
3. How we use your data
| Purpose | Data used |
|---|---|
| Providing the Savvy service (categorisation, Payday Plan, AI insights, Savings Pots) | Transaction data, account data |
| Powering Ask Savvy AI responses | Transaction history, spending patterns — sent to AI provider for inference only, not stored |
| Generating Monthly Reports | Transaction data, account data |
| Sending you service notifications (payday detected, anomaly spotted) | Email address, account data |
| Improving the product (feature usage analytics) | Anonymised usage data |
| Responding to support requests | Email address, issue description |
| Complying with legal obligations | Account data |
4. Legal basis for processing
Under GDPR, we rely on the following legal bases:
- Contract performance (Art. 6(1)(b)): Processing necessary to provide you the Savvy service you signed up for.
- Consent (Art. 6(1)(a)): Where you have given explicit consent — such as connecting a bank account or enabling optional analytics.
- Legitimate interest (Art. 6(1)(f)): Fraud prevention, service security, and product improvement where your interests are not overridden.
- Legal obligation (Art. 6(1)(c)): Where we must comply with a legal requirement.
5. Bank and open banking data
Savvy uses PSD2-regulated open banking providers (currently Tink, a Visa company) to connect to your bank. These providers are licensed by relevant financial authorities and operate under strict data protection rules.
The connection is read-only. Savvy cannot initiate payments, move money, or modify your bank account in any way through this connection.
You can revoke the bank connection at any time in the Savvy app. Revoking access immediately ends our ability to fetch new data from your bank. Previously fetched transaction data is retained unless you delete your account.
6. Data sharing and third parties
We never sell your data to third parties. We share data only with the following categories of processors, under data processing agreements:
- Supabase (infrastructure and database) — EU data residency
- Tink / Visa (open banking data access) — regulated EU entity
- Anthropic (AI inference for Ask Savvy) — data sent for real-time inference only, not stored by Anthropic for training under our API agreement
- Apple (App Store distribution, push notifications)
- Google Analytics / Microsoft Clarity (anonymised website analytics — no financial data)
We may share data if required by a court order or other legal obligation. We will inform you where legally permitted.
7. Data storage and security
All data is stored on Supabase infrastructure hosted in the EU (Frankfurt). We apply:
- AES-256 encryption at rest for all user data
- TLS 1.3 in transit for all API and app communication
- Row-level security (RLS) enforcing that users can only access their own data
- Passwords hashed with bcrypt (never stored in plaintext)
- No banking credentials ever stored
We retain your data for as long as your account is active plus 30 days after deletion, to allow for error recovery. After 30 days, all data is permanently deleted from our systems.
8. Your rights under GDPR
You have the following rights regarding your personal data:
- Access: Request a copy of all data we hold about you.
- Rectification: Correct inaccurate or incomplete data.
- Erasure: Delete your account and all associated data. Available directly in the app under Settings.
- Restriction: Request we limit processing of your data in certain circumstances.
- Portability: Receive your data in a machine-readable format.
- Objection: Object to processing based on legitimate interest.
- Withdrawal of consent: Withdraw any consent given at any time without affecting prior processing.
To exercise any right, email privacy@savvyagent.app. We respond within 30 days.
9. Cookies
The Savvy mobile app does not use cookies. Our website (savvyagent.app) uses:
- Essential cookies: Required for the site to function (session state, theme preference). No consent required.
- Analytics cookies: Google Analytics and Microsoft Clarity, used to understand aggregate traffic. These use anonymised data only. You can opt out via your browser's Do Not Track setting or by disabling cookies.
10. Children
Savvy is not directed at anyone under 18. We do not knowingly collect personal data from children. If you believe a minor has created an account, please contact us immediately at privacy@savvyagent.app.
11. Changes to this policy
We may update this policy as our product evolves or regulations change. Material changes will be notified via email to registered users at least 14 days before taking effect. The "last updated" date at the top always reflects the current version.
12. Contact and complaints
For any privacy questions or requests: privacy@savvyagent.app
You have the right to lodge a complaint with your national data protection authority. In Germany, this is the Bundesbeauftragte für den Datenschutz (BfDI).