Data Retention and Disposal Policy
Effective date: July 24, 2026 · Last updated: July 24, 2026
This policy describes how long Sprig Finance ("Sprig," "we," "us," or "our"), operated by CoreForge LLC, retains information in connection with the Sprig application, and how that information is disposed of. It supplements our Privacy Policy, which governs our overall handling of information.
1. Design principle
Sprig is built so that almost nothing needs to be retained or deleted on our end in the first place. Financial data (transactions, balances, and investment holdings) is retrieved from your financial institution through Plaid and delivered directly to your device. It is never written to a database or disk on any server we operate, so there is no financial data at rest on our systems to retain or dispose of.
2. What we retain, and for how long
| Data | Where it lives | Retention period |
|---|---|---|
| Bank connection credential (Plaid access token) | Encrypted at rest on our backend (AES-256-GCM), key held separately in a write-only secrets store | Until the connection is disconnected or the account is deleted |
| Connection metadata (institution name, internal connection ID, sync cursor) | Our backend | Until the connection is disconnected or the account is deleted |
| Anonymous device identifier | Our backend, used only for basic rate limiting | Until the app is deleted or the account is deleted |
| Transactions, balances, holdings, and any manual entries or customizations | Your device only | Until you delete the app or remove the data yourself |
We do not retain transaction history, account balances, or investment holdings on any server at any point. That data passes through our backend relay only for the length of a single request needed to deliver it to your device.
3. Disposal triggers
The information described above is deleted from our systems immediately when any of the following occurs:
- You disconnect a linked financial institution from within the app
- You delete your account or data from within the app
- A connection is no longer valid and is not reauthorized
Disconnecting or deleting also instructs Plaid to release that connection on their end, which stops any further access to that account through Sprig.
4. On-device data
The data that makes up your actual financial picture in Sprig, including transaction history, balances, holdings, and any notes or edits you have made, exists only on your device. Deleting the app from your device removes all of it immediately and completely, since your device is the only place it was ever stored.
5. Compromise response
If we ever suspect that a connection credential has been compromised, our incident response process requires immediate invalidation of the affected Plaid access token and rotation of our Plaid client secret. This bounds how long any exposure could last, independent of when it is discovered.
6. Review
We review this policy whenever our data handling practices change, and at minimum once a year, as part of our information security program.
7. Contact
Questions about this policy can be directed to us by mail:
CoreForge LLC
30 N Gould St #N
Sheridan, WY 82801