Data Retention and Disposal Policy
Effective date: July 24, 2026 · Last updated: August 23, 2026
This policy describes how long Sprig Finance ("Sprig," "we," "us," or "our"), operated by CoreForge LLC, retains information in connection with the Sprig application, and how that information is disposed of. It supplements our Privacy Policy, which governs our overall handling of information.
1. Design principle
Sprig is built so that almost nothing needs to be retained or deleted on our end in the first place. Financial data (transactions, balances, and investment holdings) is retrieved from your financial institution through Plaid and delivered directly to your device. It is never written to a database or disk on any server we operate, so there is no financial data at rest on our systems to retain or dispose of. Copies of your data are kept on your own device and in your own iCloud account. Those copies are yours, they sit under your own Apple Account rather than ours, and only you can remove them. Section 4 explains how.
2. What we retain, and for how long
| Data | Where it lives | Retention period |
|---|---|---|
| Bank connection credential (Plaid access token) | Your device only, in the iOS Keychain. It is handed to your device when you link the institution, and your device sends it with each request. We do not store it on our backend in any form, encrypted or otherwise | Until you disconnect the institution or delete the app |
| Connection identifier (the Plaid item ID for a linked institution) | Our backend, inside short-lived operational records: a note of when your bank last responded, and a log of when Plaid last contacted us about that connection | Expires automatically, at most 30 days, and is deleted when you disconnect the institution |
| Notification address, if you turn on notifications | Our backend. Used only to send your device a content-free signal to check for updates. It cannot be used to read or access anything | Until you disconnect the institution, turn off notifications, or delete the app |
| Institution-wide service status (whether a bank is having a known outage) | Our backend, cached briefly and shared across everyone using Sprig. It describes the bank, not you | 30 minutes |
| Anonymous device identifier | Your device, in the iOS Keychain. It is sent with each request so our host can apply basic rate limiting, and is not stored on our backend. It is not tied to your identity, your bank, or any data | Stays in your device's Keychain, which can outlive the app itself. Removed when you erase the device or reset its Keychain |
| Transactions, balances, holdings, and any manual entries or customizations | Your device and your own iCloud account. Never on any server we operate | Until you remove it yourself, see Section 4 |
We do not retain transaction history, account balances, or investment holdings on any server at any point. That data passes through our backend relay only for the length of a single request needed to deliver it to your device.
3. Disposal triggers
Your notification address is deleted from our systems immediately when any of the following occurs. The short-lived operational records described above are not rewritten after a disconnect, and expire on their own within 30 days at the latest.
- You disconnect a linked financial institution from within the app
- You delete your account or data from within the app
- A connection is no longer valid and is not reauthorized
Disconnecting or deleting also instructs Plaid to release that connection on their end, which stops any further access to that account through Sprig.
4. Your own copies, and how to remove them
The data that makes up your actual financial picture in Sprig, including transaction history, balances, holdings, and any notes or edits you have made, is kept on your device and in your own iCloud account. Both belong to you, and neither is on a server we operate.
Deleting the app does not delete everything. It removes the copy on your device. It does not remove the copy in your own iCloud account. To remove all of your Sprig data, delete the app from your device, then open Settings, tap your name, tap iCloud, then Manage Account Storage, find Sprig in the list, and delete its data there.
5. Compromise response
Because we do not hold your bank connection credential, a breach of our systems would not expose it. If we ever suspect that a connection credential has been compromised, our incident response process requires immediate invalidation of the affected Plaid access token and rotation of our Plaid client secret. This bounds how long any exposure could last, independent of when it is discovered.
6. Review
We review this policy whenever our data handling practices change, and at minimum once a year, as part of our information security program.
7. Contact
Questions about this policy can be directed to us through our Contact page, or by mail:
CoreForge LLC
30 N Gould St #N
Sheridan, WY 82801