Privacy Policy

Last updated: July 5, 2026

The short version

Your financial data is stored on your device, not our servers. We never sell your data. We don't serve ads. The only data we collect is what's described below, and we collect as little as possible.

Who we are

SparkFi is operated by [ENTITY NAME], a [STATE] limited liability company ("SparkFi," "we," "us," or "our"). Our registered address is [ADDRESS]. For privacy enquiries, contact us at sparkteam@catchthesparkfi.com.

Note: entity details will be updated upon LLC formation.

What data we collect and why

On this website

When you sign up for the waitlist we collect your email address and, optionally, your first name. We also collect basic page-view analytics (pages visited, referral source, approximate country). Your IP address is hashed with SHA-256 and a per-request salt for rate-limiting purposes only — the raw IP address is never stored and the hash is discarded after the request completes.

Legal basis (GDPR): Waitlist registration is processed on the basis of your consent (Art. 6(1)(a) GDPR). Page-view analytics are processed on the basis of our legitimate interest in understanding site traffic (Art. 6(1)(f) GDPR), which we have balanced against your right to privacy given the minimal data collected and the absence of raw IP storage.

In the SparkFi app

Financial data. SparkFi connects to your bank and brokerage accounts via Teller (bank sync) and SnapTrade (investment sync). All transaction data, account balances, and financial records are stored locally on your Mac or iPhone. If you enable iCloud sync, Apple encrypts that data end-to-end. We never receive, transmit, or store your financial transactions on our servers.

Legal basis (GDPR): Local financial data processing is performed solely on your device under your control. We act as a data processor in respect of any data that passes through our backend services (e.g. Plaid link-token proxy), on the basis of contract (Art. 6(1)(b) GDPR).

We do not collect identity information. At no time does SparkFi request your Social Security Number (SSN), Social Insurance Number (SIN), home address, legal name, or other personally identifiable fields — whether through connecting a bank or brokerage account (automatic syncing via Plaid or SnapTrade) or through any feature that captures a photo or document, such as scanning a paystub. Our bank and brokerage sync only requests transaction and balance data; we do not use Plaid's optional "Identity" product, which is the only mechanism by which that kind of information could otherwise reach us. If any such field is ever incidentally present in data captured through automatic syncing or document/photo capture, it is not stored on our servers and is never shared with any third party.

Document scanning (paystub photos). SparkFi's Income Creation Assistant can fill out an income source from a photo of your paystub. That image is processed entirely on your device using Apple's on-device Foundation Models — the photo, and any data read from it, is never transmitted to SparkFi or to any third party, regardless of your subscription plan. We do not read your Social Security Number, Social Insurance Number, your home address, your legal name, or your employer's Employer Identification Number (EIN) from a scanned paystub or any other document, even though paystubs typically show several of these — our on-device extraction process is built to disregard those fields entirely rather than capture and discard them. If a future version of SparkFi needs to compare one of these values on-device (for example, to recognize a duplicate scan), only an irreversibly masked or hashed form would ever be stored — never the original value — and it would never leave your device.

Analytics. The app sends lightweight usage events to help us understand how SparkFi is used and where to focus development. Each event contains:

No financial data, no personally identifiable information, and no device identifiers are included in analytics events. Your IP address is used only to enforce a per-minute rate limit and is not stored. Events are retained for 12 months then deleted.

Legal basis (GDPR): App analytics are processed on the basis of our legitimate interest in improving the product (Art. 6(1)(f) GDPR). You can opt out at any time in Settings → System Settings → Privacy → Share Analytics.

Payments and subscriptions. If you subscribe to SparkFi Basic, payment is processed entirely by Apple through the App Store. We do not receive or store your payment card details, billing address, or any payment instrument data. Apple provides us with a subscription status token only. See Apple's Privacy Policy for how your payment data is handled.

Third-party services

The following sub-processors may receive data as part of delivering the service. All are bound by data processing agreements.

Teller — bank account connection and transaction sync. Teller's access token is stored in your device's secure Keychain and is never transmitted to SparkFi servers. See Teller's Privacy Policy.

SnapTrade — brokerage account connection. SnapTrade credentials are stored in your device's secure Keychain. See SnapTrade's Privacy Policy.

Plaid — bank account linking (used in some connection flows). See Plaid's Privacy Policy.

Finnhub — real-time stock quotes for manually entered investment holdings. Only ticker symbols are sent; no personal or financial data is transmitted. See Finnhub's Privacy Policy.

Apple iCloud — optional encrypted sync of your SparkFi data across your devices. Governed by Apple's Privacy Policy.

Anthropic — powers SparkFi's optional AI features (Spending Insights, Transaction Categorizer, Financial Coach), available on qualifying subscription tiers. When you use these features, relevant transaction descriptions, amounts, categories, and/or an account summary are sent to Anthropic's Claude API through our backend proxy to generate a response. This data is not used by us for any purpose other than generating the AI response you requested. See Anthropic's Privacy Policy.

How we use your data

Your email address is used to send waitlist updates, your invite, and — if you become a customer — account and billing emails. We do not share it with third parties except the sub-processors listed above.

App analytics are used solely to understand feature usage and improve the product. They are never sold, shared with advertisers, or used for profiling.

International data transfers

SparkFi is operated from the United States. If you access the service from the European Economic Area (EEA), the United Kingdom, or Canada, your data (specifically: waitlist email address and app analytics events) will be transferred to and processed in the United States. We rely on Standard Contractual Clauses (SCCs) approved by the European Commission as the transfer mechanism for EEA personal data. UK users benefit from the equivalent International Data Transfer Agreement (IDTA). Canadian users' data is handled in accordance with PIPEDA (see the Canadian Residents section below).

Data retention

Waitlist email addresses are retained until you unsubscribe or request deletion. App analytics events are retained for 12 months. Website page-view analytics are retained for 12 months. No raw IP addresses are retained at any point.

Your rights

Depending on where you live, you may have the following rights regarding your personal data:

To exercise any right, email sparkteam@catchthesparkfi.com. We will respond within 30 days (45 days for California requests if additional time is needed, with notice).

Your financial data stored locally in the SparkFi app is entirely under your control — delete the app to remove it from your device.

California residents (CCPA / CPRA)

If you are a California resident, you have the following rights under the California Consumer Privacy Act as amended by the California Privacy Rights Act:

Categories of personal information collected: Identifiers (email address); Internet or other electronic network activity (analytics events, page views); Financial information (processed and stored locally on your device; if you use an optional AI feature, the relevant transaction or account data is sent to our backend proxy and Anthropic solely to generate that response — see "Third-party services" above — and is not otherwise collected or retained by us).

To exercise your California rights, email sparkteam@catchthesparkfi.com with "California Privacy Request" in the subject line. We will not discriminate against you for exercising these rights.

Canadian residents (PIPEDA)

If you are a Canadian resident, your personal information is collected, used, and disclosed in accordance with the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy legislation, including Quebec's Act respecting the protection of personal information in the private sector (Law 25).

We collect only the information necessary for the purposes described in this policy, with your knowledge and consent. You may withdraw consent at any time, subject to legal or contractual restrictions. You have the right to access your personal information and to challenge its accuracy. To exercise these rights or to make a complaint, contact our privacy officer at sparkteam@catchthesparkfi.com.

Cookies

This website uses a single session cookie for CSRF protection and referral tracking. No advertising cookies, no tracking pixels, and no third-party analytics scripts are used.

Children

SparkFi is a financial management application intended for adults (17+). It is not directed at children under 13. We do not knowingly collect personal information from anyone under 13. If you believe a child under 13 has provided us with personal information, please contact us at sparkteam@catchthesparkfi.com and we will delete it promptly.

Changes to this policy

We will post changes here and update the "Last updated" date. For material changes, we will send an email to waitlist and active subscribers at least 30 days before the change takes effect, giving you time to review and, where applicable, withdraw consent.

Contact

Questions or requests? Email sparkteam@catchthesparkfi.com.

If you are in the EEA and are unsatisfied with our response, you have the right to lodge a complaint with your local data protection authority. For UK residents, the relevant authority is the Information Commissioner's Office (ICO).