This Privacy Policy explains how Sprout ("Sprout", "we", "us", or "our") collects, uses, and protects your personal information when you use our mobile application (the "App"). Sprout is designed to help separated and co-parenting families track and share children's expenses.
We comply with the Protection of Personal Information Act, 2013 (Act No. 4 of 2013) of South Africa ("POPIA"). If you are a resident of another jurisdiction, additional protections under your local law may apply; please contact us for further information.
1. Who we are (Responsible Party)
Sprout is operated by Sprout Technologies, a company registered in the Republic of South Africa with the Companies and Intellectual Property Commission (CIPC).
- General & support: [email protected]
- Privacy queries / Information Officer: [email protected]
- Website: https://sproutapp.co.za
Sprout Technologies is registered with the Information Regulator of South Africa as required by the POPIA Regulations.
2. Information we collect
2.1 Information you give us directly
- Account information: your email address and a password (stored as a salted hash, never as plaintext).
- Profile information: your display name and the email address of the co-parent you choose to invoice.
- Family information: the first names you enter for your children, and the labels and names you assign to co-parents.
- Expense information: the date, description, category, amount, notes, payment status, and co-parent share of each expense you log.
- Fixed-expense and maintenance configuration: the recurring amounts, schedules, splits, and inflation history you set up.
- Receipt and proof files (optional): photos or PDFs of receipts you attach to expenses, and receipts you submit to the AI receipt scanner.
- Agreement documents (optional): the PDF parenting agreements and court orders you upload for AI-assisted searching.
- Support correspondence: the contents of any emails or messages you send us.
2.2 Information collected automatically
- Device and app information: operating system version, app version, device language, and crash logs.
- Authentication metadata: the timestamps of your sign-in events.
- Subscription state: whether your account holds an active entitlement and the platform that granted it.
2.3 What we do NOT collect
3. Why we collect it (lawful basis under POPIA)
Under section 11 of POPIA, we process your personal information on the following lawful bases:
| Purpose | Lawful basis |
|---|---|
| Creating and securing your Sprout account | Performance of a contract with you |
| Storing and syncing your expenses, family data, receipts, and agreements | Performance of a contract with you |
| Running AI receipt scanning and agreement chat features when you trigger them | Performance of a contract with you (you initiate each call) |
| Processing in-app subscription payments | Performance of a contract; legitimate interest |
| Sending essential service emails (sign-in links, billing receipts) | Performance of a contract; legal obligation |
| Diagnosing crashes and improving the App | Our legitimate interest in maintaining a working service |
| Responding to your support requests | Performance of a contract |
| Complying with a court order, tax law, or other legal obligation | Legal obligation |
4. Where your information is stored
4.1 On your device
By default, all the data you enter into Sprout is stored on your device, using a combination of encrypted iOS/Android system storage and the App's local database (SQLite). Receipts and proof-of-expense files are stored as binary blobs in your device's app sandbox.
4.2 In the cloud
When cloud sync is enabled, the following data is also stored on our servers so you can access it across multiple devices:
- Your account (email and authentication tokens)
- Your settings, children, arrangements, fixed expenses, and variable expenses
- Your subscription entitlement state
Cloud storage is provided by Supabase Inc. (Postgres database + Auth), hosted in their eu-central-1 (Frankfurt, Germany) region. All data in transit is encrypted via TLS 1.2+, and all data at rest is encrypted using AES-256.
Receipt blobs and agreement PDFs are not currently synced to the cloud — they remain on the device where they were uploaded. We will notify you in-app before any change to this behaviour.
Cross-border transfer to the EU is permitted under section 72 of POPIA on the basis that the EU has data-protection laws providing an adequate level of protection (section 72(1)(a)).
Some of our processors are based in the United States, which does not have an adequacy determination from South Africa. Transfers to these processors (Anthropic, Apple, Google, and Expo — see section 6) are made on the basis that we have entered into written agreements with each that impose data-protection obligations equivalent to those required by POPIA, as contemplated by section 72(1)(c) of POPIA.
5. AI features: how your data is used
Sprout offers two AI-powered features. Both run only when you explicitly trigger them.
5.1 Receipt scanning
When you take a photo of a receipt and tap "Scan", the image is sent to our secure server (a Supabase Edge Function) which forwards it to Anthropic PBC's Claude API for line-item extraction. The Anthropic API key is held server-side; it is never embedded in the App.
We send the receipt image only. We do not send your name, email, family information, or any expense history. Anthropic states that data submitted to its API is not used to train its models and is retained for up to 30 days for abuse-detection purposes only. See anthropic.com/legal/privacy.
5.2 Agreement chat
When you upload a parenting agreement or court order PDF and ask a question, the App sends the extracted text of the document(s) and your question to the same Edge Function, which forwards them to Anthropic's Claude API. Documents are not persisted in our cloud beyond the duration of the API call.
If you do not wish to use these features, simply do not tap the scan or chat buttons. The rest of the App functions normally without them.
6. Third-party processors
We share your personal information only with the following operators, each bound by a written agreement to process your data only on our instructions.
| Provider | Purpose | Country |
|---|---|---|
| Supabase Inc. | Authentication, cloud database, serverless functions | USA (entity) / Germany (data) |
| Anthropic PBC | AI receipt scanning and agreement chat (on demand) | USA |
| Apple Inc. | iOS App Store distribution | USA |
| Google LLC | Google Play distribution | USA |
| Expo Inc. | App build infrastructure | USA |
7. How long we keep your information
| Category | Retention |
|---|---|
| On-device data | Until you delete the App or sign out and clear local storage |
| Cloud data | While your account exists and for 30 days after deletion |
| Authentication logs | 90 days (Supabase default) |
| Receipt image submitted to AI | Up to 30 days at Anthropic (abuse-detection only); not retained on our servers after the API call |
| Support emails | 24 months after the matter is resolved |
| Records required by tax or other law | As required by law (typically 5 years) |
If you delete your account, we will permanently remove your cloud-stored personal information within 30 days, except where we are legally required to keep it.
8. Your rights under POPIA
You have the following rights in respect of your personal information:
- Right to be notified that your personal information is being collected (this Policy fulfils that obligation).
- Right of access: request a copy of the personal information we hold about you.
- Right to correction or deletion: request that we correct inaccurate information, or delete information that is no longer needed.
- Right to object: object to the processing of your personal information for any reason.
- Right to lodge a complaint: complain to the Information Regulator of South Africa if you believe we have not handled your information lawfully.
To exercise any of these rights, email [email protected]. We will respond within 30 days.
You can also delete most of your data directly from within the App: go to Setup → Account → Delete account. If you no longer have the app installed, see our Delete Account & Data page for an email-based request option.
Information Regulator (South Africa): inforegulator.org.za · [email protected] · JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001
9. Children
Sprout is designed for adult parents and guardians. It is not directed at children under 13. We do not knowingly collect personal information directly from children. The first names of your children that you enter into Sprout are processed under your authority as their parent or guardian, as permitted under section 35 of POPIA.
10. Security
We take reasonable, appropriate technical and organisational measures to safeguard your personal information, including TLS 1.2+ encryption for all data in transit, AES-256 encryption for all data at rest, row-level security policies that prevent any user from reading another user's rows, and server-side storage of all AI API keys.
In the event of a security compromise involving your personal information, we will notify you and the Information Regulator of South Africa as required by section 22 of POPIA, as soon as reasonably possible after becoming aware of the compromise.
If you believe your account has been compromised, email [email protected] immediately.
11. Changes to this Policy
We may update this Policy from time to time. If we make a material change, we will notify you through the App or by email at least 14 days before the change takes effect. The current version is always available at sproutapp.co.za/privacy.html.
12. PAIA manual
In terms of section 51 of the Promotion of Access to Information Act, 2000 ("PAIA"), Sprout has compiled a PAIA manual. A copy is available on request by emailing [email protected].
13. Contact
- General support: [email protected]
- Privacy queries: [email protected]
- Security incidents: [email protected]
This Policy is provided in plain English. The English version prevails in the event of any conflict.