Sprig Finance

Data Retention and Disposal Policy

Effective date: July 24, 2026  ·  Last updated: August 23, 2026

This policy describes how long Sprig Finance ("Sprig," "we," "us," or "our"), operated by CoreForge LLC, retains information in connection with the Sprig application, and how that information is disposed of. It supplements our Privacy Policy, which governs our overall handling of information.

1. Design principle

Sprig is built so that almost nothing needs to be retained or deleted on our end in the first place. Financial data (transactions, balances, and investment holdings) is retrieved from your financial institution through Plaid and delivered directly to your device. It is never written to a database or disk on any server we operate, so there is no financial data at rest on our systems to retain or dispose of. Copies of your data are kept on your own device and in your own iCloud account. Those copies are yours, they sit under your own Apple Account rather than ours, and only you can remove them. Section 4 explains how.

2. What we retain, and for how long

Data Where it lives Retention period
Bank connection credential (Plaid access token) Your device only, in the iOS Keychain. It is handed to your device when you link the institution, and your device sends it with each request. We do not store it on our backend in any form, encrypted or otherwise Until you disconnect the institution or delete the app
Connection identifier (the Plaid item ID for a linked institution) Our backend, inside short-lived operational records: a note of when your bank last responded, and a log of when Plaid last contacted us about that connection Expires automatically, at most 30 days, and is deleted when you disconnect the institution
Notification address, if you turn on notifications Our backend. Used only to send your device a content-free signal to check for updates. It cannot be used to read or access anything Until you disconnect the institution, turn off notifications, or delete the app
Institution-wide service status (whether a bank is having a known outage) Our backend, cached briefly and shared across everyone using Sprig. It describes the bank, not you 30 minutes
Anonymous device identifier Your device, in the iOS Keychain. It is sent with each request so our host can apply basic rate limiting, and is not stored on our backend. It is not tied to your identity, your bank, or any data Stays in your device's Keychain, which can outlive the app itself. Removed when you erase the device or reset its Keychain
Transactions, balances, holdings, and any manual entries or customizations Your device and your own iCloud account. Never on any server we operate Until you remove it yourself, see Section 4

We do not retain transaction history, account balances, or investment holdings on any server at any point. That data passes through our backend relay only for the length of a single request needed to deliver it to your device.

3. Disposal triggers

Your notification address is deleted from our systems immediately when any of the following occurs. The short-lived operational records described above are not rewritten after a disconnect, and expire on their own within 30 days at the latest.

Disconnecting or deleting also instructs Plaid to release that connection on their end, which stops any further access to that account through Sprig.

4. Your own copies, and how to remove them

The data that makes up your actual financial picture in Sprig, including transaction history, balances, holdings, and any notes or edits you have made, is kept on your device and in your own iCloud account. Both belong to you, and neither is on a server we operate.

Deleting the app does not delete everything. It removes the copy on your device. It does not remove the copy in your own iCloud account. To remove all of your Sprig data, delete the app from your device, then open Settings, tap your name, tap iCloud, then Manage Account Storage, find Sprig in the list, and delete its data there.

5. Compromise response

Because we do not hold your bank connection credential, a breach of our systems would not expose it. If we ever suspect that a connection credential has been compromised, our incident response process requires immediate invalidation of the affected Plaid access token and rotation of our Plaid client secret. This bounds how long any exposure could last, independent of when it is discovered.

6. Review

We review this policy whenever our data handling practices change, and at minimum once a year, as part of our information security program.

7. Contact

Questions about this policy can be directed to us through our Contact page, or by mail:

CoreForge LLC
30 N Gould St #N
Sheridan, WY 82801