This Privacy Policy explains how Sprout ("Sprout", "we", "us", or "our") collects, uses, and protects your personal information when you use our mobile application (the "App"). Sprout is designed to help separated and co-parenting families track and share children's expenses.

We comply with the Protection of Personal Information Act, 2013 (Act No. 4 of 2013) of South Africa ("POPIA"). If you are a resident of another jurisdiction, additional protections under your local law may apply; please contact us for further information.

1. Who we are (Responsible Party)

Sprout is operated by Sprout Technologies, a company registered in the Republic of South Africa with the Companies and Intellectual Property Commission (CIPC).

Sprout Technologies is registered with the Information Regulator of South Africa as required by the POPIA Regulations.

2. Information we collect

2.1 Information you give us directly

2.2 Information collected automatically

2.3 What we do NOT collect

We do not collect your physical address, ID number, or date of birth. We do not access your contacts, calendar, location, or microphone. We do not include third-party advertising trackers or analytics SDKs. We do not sell or rent your personal information to anyone, ever.

3. Why we collect it (lawful basis under POPIA)

Under section 11 of POPIA, we process your personal information on the following lawful bases:

PurposeLawful basis
Creating and securing your Sprout accountPerformance of a contract with you
Storing and syncing your expenses, family data, receipts, and agreementsPerformance of a contract with you
Running AI receipt scanning and agreement chat features when you trigger themPerformance of a contract with you (you initiate each call)
Processing in-app subscription paymentsPerformance of a contract; legitimate interest
Sending essential service emails (sign-in links, billing receipts)Performance of a contract; legal obligation
Diagnosing crashes and improving the AppOur legitimate interest in maintaining a working service
Responding to your support requestsPerformance of a contract
Complying with a court order, tax law, or other legal obligationLegal obligation

4. Where your information is stored

4.1 On your device

By default, all the data you enter into Sprout is stored on your device, using a combination of encrypted iOS/Android system storage and the App's local database (SQLite). Receipts and proof-of-expense files are stored as binary blobs in your device's app sandbox.

4.2 In the cloud

When cloud sync is enabled, the following data is also stored on our servers so you can access it across multiple devices:

Cloud storage is provided by Supabase Inc. (Postgres database + Auth), hosted in their eu-central-1 (Frankfurt, Germany) region. All data in transit is encrypted via TLS 1.2+, and all data at rest is encrypted using AES-256.

Receipt blobs and agreement PDFs are not currently synced to the cloud — they remain on the device where they were uploaded. We will notify you in-app before any change to this behaviour.

Cross-border transfer to the EU is permitted under section 72 of POPIA on the basis that the EU has data-protection laws providing an adequate level of protection (section 72(1)(a)).

Some of our processors are based in the United States, which does not have an adequacy determination from South Africa. Transfers to these processors (Anthropic, Apple, Google, and Expo — see section 6) are made on the basis that we have entered into written agreements with each that impose data-protection obligations equivalent to those required by POPIA, as contemplated by section 72(1)(c) of POPIA.

5. AI features: how your data is used

Sprout offers two AI-powered features. Both run only when you explicitly trigger them.

5.1 Receipt scanning

When you take a photo of a receipt and tap "Scan", the image is sent to our secure server (a Supabase Edge Function) which forwards it to Anthropic PBC's Claude API for line-item extraction. The Anthropic API key is held server-side; it is never embedded in the App.

We send the receipt image only. We do not send your name, email, family information, or any expense history. Anthropic states that data submitted to its API is not used to train its models and is retained for up to 30 days for abuse-detection purposes only. See anthropic.com/legal/privacy.

5.2 Agreement chat

When you upload a parenting agreement or court order PDF and ask a question, the App sends the extracted text of the document(s) and your question to the same Edge Function, which forwards them to Anthropic's Claude API. Documents are not persisted in our cloud beyond the duration of the API call.

If you do not wish to use these features, simply do not tap the scan or chat buttons. The rest of the App functions normally without them.

6. Third-party processors

We share your personal information only with the following operators, each bound by a written agreement to process your data only on our instructions.

ProviderPurposeCountry
Supabase Inc.Authentication, cloud database, serverless functionsUSA (entity) / Germany (data)
Anthropic PBCAI receipt scanning and agreement chat (on demand)USA
Apple Inc.iOS App Store distributionUSA
Google LLCGoogle Play distributionUSA
Expo Inc.App build infrastructureUSA

7. How long we keep your information

CategoryRetention
On-device dataUntil you delete the App or sign out and clear local storage
Cloud dataWhile your account exists and for 30 days after deletion
Authentication logs90 days (Supabase default)
Receipt image submitted to AIUp to 30 days at Anthropic (abuse-detection only); not retained on our servers after the API call
Support emails24 months after the matter is resolved
Records required by tax or other lawAs required by law (typically 5 years)

If you delete your account, we will permanently remove your cloud-stored personal information within 30 days, except where we are legally required to keep it.

8. Your rights under POPIA

You have the following rights in respect of your personal information:

To exercise any of these rights, email [email protected]. We will respond within 30 days.

You can also delete most of your data directly from within the App: go to Setup → Account → Delete account. If you no longer have the app installed, see our Delete Account & Data page for an email-based request option.

Information Regulator (South Africa): inforegulator.org.za · [email protected] · JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001

9. Children

Sprout is designed for adult parents and guardians. It is not directed at children under 13. We do not knowingly collect personal information directly from children. The first names of your children that you enter into Sprout are processed under your authority as their parent or guardian, as permitted under section 35 of POPIA.

10. Security

We take reasonable, appropriate technical and organisational measures to safeguard your personal information, including TLS 1.2+ encryption for all data in transit, AES-256 encryption for all data at rest, row-level security policies that prevent any user from reading another user's rows, and server-side storage of all AI API keys.

In the event of a security compromise involving your personal information, we will notify you and the Information Regulator of South Africa as required by section 22 of POPIA, as soon as reasonably possible after becoming aware of the compromise.

If you believe your account has been compromised, email [email protected] immediately.

11. Changes to this Policy

We may update this Policy from time to time. If we make a material change, we will notify you through the App or by email at least 14 days before the change takes effect. The current version is always available at sproutapp.co.za/privacy.html.

12. PAIA manual

In terms of section 51 of the Promotion of Access to Information Act, 2000 ("PAIA"), Sprout has compiled a PAIA manual. A copy is available on request by emailing [email protected].

13. Contact

This Policy is provided in plain English. The English version prevails in the event of any conflict.