Privacy Policy
Last updated: 7 June 2026
This Privacy Policy explains how Sprigly (“the app”, “we”, “us”) handles your information. In short: your budgeting data stays on your own device. To sign you in and manage your subscription, we also process a small amount of account data, described in sections 4–5.
1. Who is responsible (Data Controller)
For the purposes of the EU General Data Protection Regulation (GDPR):
- Name: Konstantin Siegel
- Address: Keimstraße 6, 4020 Linz, Austria
- Email: hello@spriglyapp.com
2. Summary
- Your budget, transactions, accounts, and envelopes are stored locally on your device. They are not sent to us or any third party (see section 3).
- To use Sprigly you sign in with your email (a one-time code — no password) and unlock the app with a subscription. For that we process your email, subscription status, and a device identifier (see sections 4–5).
- The app uses no analytics, advertising, tracking, or crash-reporting tools. (Our marketing website uses cookieless analytics — see section 12.)
- We never see or store your card or payment details — your payment is handled entirely by Google Play (see section 5).
- We do not sell your personal information, and we never use it for anything unrelated to running Sprigly.
3. Budgeting data (stays on your device)
When you use Sprigly, you create and store data such as transactions, amounts, dates, notes, budget envelopes, categories, accounts, transfers, a display name you choose, and app settings.
This budgeting data stays on your device in the app’s local database. We have no access to it, cannot read it, and do not transmit, sell, or share it. Uninstalling the app or clearing its data deletes this information from your device.
Device backups (e.g. Google’s own backup) are controlled by your device settings and Google’s policies, not by us.
4. Account, login, and subscription data
To give you an account and a paid subscription, a small amount of data does leave your device. We keep it to the minimum needed. Here is exactly what we process, why, and our legal basis under the GDPR:
- Email address — collected when you sign up; used as your account identity, to log you in, to manage your subscription, and to contact you for support. Legal basis: performance of our contract with you (Art. 6(1)(b) GDPR).
- One-time login codes — generated each time you sign in and sent to your email instead of a password; they expire within about an hour. Legal basis: performance of a contract (Art. 6(1)(b) GDPR).
- Session tokens — stored on your device to keep you signed in. Legal basis: performance of a contract (Art. 6(1)(b) GDPR).
- Sign-in metadata — your IP address, device/browser information, and timestamps from each sign-in, kept in our authentication logs to keep your account secure and prevent abuse. Legal basis: our legitimate interest in security (Art. 6(1)(f) GDPR).
- Subscription status — the product, status, expiry, store, and purchase/renewal events for your subscription, used to unlock the app and manage your plan. Legal basis: performance of a contract (Art. 6(1)(b) GDPR).
- Account identifier — a random ID that links your purchase to your account so your subscription can be restored across devices. Legal basis: performance of a contract (Art. 6(1)(b) GDPR).
- Device identifier — a per-install identifier (app-scoped; it resets if you reinstall) used to limit how many devices share one account and to prevent account sharing. Legal basis: our legitimate interest in preventing abuse (Art. 6(1)(f) GDPR).
- Payment details — your card and billing information are handled only by Google. We never see or store them.
5. Who else processes your data
We use the following service providers to run the account and subscription features. Each receives only the data it needs for its task. Where a provider is located outside the EEA, we rely on appropriate safeguards for that transfer (see section 11).
- Supabase (Supabase Inc.) — our processor for authentication and database. It stores your email, your sign-in/security logs (including IP), your subscription record, and your device entries. Hosted in the EU (Ireland). See supabase.com/privacy.
- Maileroo — our processor for transactional email; it delivers your one-time login codes and receives your email address and the code. See maileroo.com/privacy-policy.
- RevenueCat (RevenueCat, Inc.) — our processor for subscription management. It receives your account identifier, purchase tokens, product IDs, subscription status and history, platform, country, and device/IP. Located in the USA. See revenuecat.com/privacy.
- Google (Google Play Billing) — the seller of the subscription and your payment processor. Google receives your Google account, payment details, and purchase records, and acts as an independent controller under its own terms. See policies.google.com/privacy.
We protect this data with encryption in transit (HTTPS), strict database access controls so each user can reach only their own records, passwordless login (we store no passwords), and secret keys that live only on the server, never in the app.
Separate providers run our marketing website (section 12) and the optional launch waitlist (section 13).
6. What the app does NOT do
The Sprigly app does not:
- Upload, sell, or share your budgeting data — it stays on your device
- Use analytics, telemetry, or usage tracking
- Use advertising or marketing trackers
- Use third-party crash-reporting services
- Link to your bank accounts or use open-banking / PSD2 connections
- Receive or store your card or payment details
- Load remote fonts, scripts, or other third-party web resources
7. App permissions
Sprigly requests only the permissions needed to function. It needs internet access to sign you in and check your subscription. We do not access your contacts, location, photos, microphone, or camera.
8. Data retention
- Budgeting data: kept on your device until you delete it or uninstall the app — controlled entirely by you.
- Email / account: kept until you delete your account.
- Subscription records: kept for the life of your subscription plus any period required by law (most billing records are held by Google as the seller).
- Device entries: kept until removed by the device limit or until your account is deleted.
- One-time login codes: expire within about an hour, then become invalid.
- Sign-in / security logs: kept for a limited period under our provider’s log-retention settings.
9. Your rights
EU / EEA / UK (GDPR / UK GDPR)
You have rights to access, rectification, erasure, restriction, portability, and objection. For your budgeting data, you exercise these directly by editing or deleting data in the app. For your account and subscription data, contact us at hello@spriglyapp.com, or follow the Delete Your Data page to delete your account. You also have the right to lodge a complaint with your local data protection supervisory authority.
California (CCPA / CPRA)
You have rights to know, delete, and correct, and to opt out of “sale” or “sharing.” We collect the limited personal information described in sections 4–5 to provide the app. We do not sell or share your personal information, and we do not use it for cross-context behavioural advertising.
Everywhere else
Contact us with any questions or requests at hello@spriglyapp.com.
10. Children and minors
Sprigly is intended for users aged 16 and over. It is not directed to children, and we do not knowingly create accounts for or collect personal information from anyone under 16.
11. International data transfers
Your budgeting data stays on your device and is not transferred anywhere. Your account data is hosted in the EU (Ireland) by Supabase. Running your subscription, however, involves processing some data outside the EEA — by RevenueCat (USA) and Google (global). Where data is transferred outside the EEA, we rely on appropriate safeguards for that transfer, such as the European Commission’s Standard Contractual Clauses, together with the receiving provider’s own terms.
12. The website (spriglyapp.com)
Sections 1–11 concern the Sprigly app, which contains no analytics. This section covers our marketing website, spriglyapp.com. The data controller is the same as in section 1.
Hosting
The website is hosted by Vercel Inc. as our processor. To deliver the site, Vercel processes connection data such as your IP address and browser user-agent in server logs. We rely on our legitimate interest (Art. 6(1)(f) GDPR) in operating a secure, functioning website.
Cookieless analytics
We use PostHog (EU-hosted) as our processor for privacy-preserving, cookieless website analytics. PostHog sets no cookies and stores nothing in your browser, so no consent prompt is required to access your device.
To count unique visitors, your IP address and user-agent are processed transiently on the server to compute a one-way hash with a salt that rotates daily and is then deleted; the raw IP and user-agent are not stored, and the result is not designed to identify you and is not linked to your app data. We do not track you across other websites. Our legal basis is our legitimate interest (Art. 6(1)(f) GDPR) in understanding website usage. See PostHog’s privacy information at posthog.com/privacy.
13. The early-access waitlist
If you choose to join our launch waitlist (on the /waitlist page), we process the personal data you give us there. This is optional and separate from your in-app account.
- What we collect: your email address and the date and time you signed up. Nothing else.
- Why: to send you email about Sprigly — news of the launch and, from time to time, product updates and other news about the app. We do not sell or share your address, and we do not use it for anything unrelated to Sprigly.
- Legal basis: your consent (Art. 6(1)(a) GDPR), which you give by submitting the form. You can withdraw it at any time — every email we send includes an unsubscribe link, or you can email hello@spriglyapp.com and we will remove you.
- Retention: we keep your address until you unsubscribe or ask us to delete it (whichever you choose) — you can do either at any time.
We use the following processors for the waitlist, each under their standard data processing terms (and, where they are outside the EEA, the safeguards described in section 11):
- Supabase — stores the waitlist (see supabase.com/privacy).
- Resend — delivers our emails (see resend.com/legal/privacy-policy).
- Cloudflare Turnstile — protects the form from bots. It is privacy-preserving and sets no tracking cookies (see cloudflare.com/privacypolicy).
14. Changes to this policy
We may update this policy as Sprigly evolves. We will update the “Last updated” date and, for significant changes, notify you in the app.
15. Contact
- Email: hello@spriglyapp.com
- Postal: Keimstraße 6, 4020 Linz, Austria