Home Vault ("we", "us", or "our") is committed to protecting your personal information in accordance with the Protection of Personal Information Act (POPIA) of the Republic of South Africa. This policy explains what data we collect, how we use it, and your rights.
1. What data we collect
- Account information: Your email address and name, collected when you create an account.
- Financial data: Transactions, budgets, savings goals, and any other financial information you enter into the app. This data is stored on your behalf and never shared with third parties for marketing purposes.
- Usage data: Information about how you interact with the app (e.g. which features you use, API call frequency) to help us improve the service.
2. How we use your data
- To provide the service: Your data is used to display your financial overview, budgets, goals, and insights within the app.
- AI-powered insights: When you use AI features (such as "Should I Buy?", budget analysis, or spending suggestions), relevant financial data is sent to OpenAI to generate responses. No data is used to train OpenAI models under our API agreement.
- Payments: Subscription billing is handled by LemonSqueezy. We pass your user ID to LemonSqueezy at checkout to link your subscription to your account, but we do not store your card details.
3. Third-party services
- Supabase — Provides our database and authentication infrastructure. Your data is stored in Supabase's secure, encrypted database.
- OpenAI — Powers AI features. Financial data sent to OpenAI is subject to OpenAI's API data usage policy.
- LemonSqueezy — Processes subscription payments. Payment information is handled entirely by LemonSqueezy and never stored by us.
- Vercel — Hosts the application. Vercel may process request metadata (e.g. IP addresses) as part of hosting the service.
4. Data retention
We retain your data for as long as your account is active. If you request account deletion, we will delete your personal data and financial records within 30 days, except where we are required by law to retain certain records.
5. Your rights under POPIA
As a data subject under POPIA, you have the right to:
- Access: Request a copy of the personal information we hold about you.
- Correction: Request that we correct inaccurate or incomplete information.
- Deletion: Request that we delete your personal information, subject to legal retention requirements.
- Objection: Object to the processing of your personal information in certain circumstances.
To exercise any of these rights, please contact us at pnel53@gmail.com.
6. Security
All data is encrypted in transit using TLS and encrypted at rest via Supabase's infrastructure. We apply row-level security policies so that each user can only access their own data. Despite these measures, no system is completely secure — please use a strong, unique password.
7. Contact
If you have questions or concerns about this policy or how we handle your data, please email us at pnel53@gmail.com.