Privacy Policy
Last updated: June 25, 2026
This Privacy Policy explains how [LEGAL ENTITY NAME — e.g., Sweetwater Labs LLC] ("Company," "we," "us") collects, uses, and shares information when you use Sprout (the "Service"), a text-message-based personal-spending assistant. Sprout links a bank card once through Plaid and texts you a summary of your spending each morning, and lets you ask questions about your own spending by text.
Sprout is available only to residents of the United States who are 18 or older, with a U.S. mobile number and a U.S. financial account. By using the Service you agree to this Policy.
1. Information you provide
When you sign up and use the Service, you provide:
- Your mobile phone number, which is your primary account identifier.
- Your time zone (so your daily text arrives at your local morning time).
- Onboarding answers, which may include self-reported information about your money goals, what you find frustrating about tracking money, how often you are paid, the spending category you most want to watch, your money style, and — if you choose to tell us — your monthly income and a monthly savings target.
- The text messages you send us, including the free-text questions you ask the assistant. We store the content of inbound and outbound messages.
You are never required to share your income or savings target; the assistant simply works better if you do.
2. Financial account information (via Plaid)
To deliver the Service, you authorize a connection to your financial account through Plaid. You enter your bank login directly with Plaid (or sign in at your bank). Sprout never sees or receives your bank username or password.
From this connection we receive and store: the name of your financial institution; for each linked account, its name, type (for example checking or credit card), and the last four digits; and your transaction history, including each transaction's amount, date, description and merchant name, status (pending or posted), and a spending category we assign. We also retain the raw transaction record we receive from Plaid so we can re-categorize transactions without re-querying your bank.
We do not receive or store your full card or account numbers (only the last four digits), your bank login credentials, or your account balances. To keep your connection active, Plaid issues us an access token for your linked institution, which we store encrypted at rest; we reference your linked accounts by Plaid's account identifiers.
3. Information collected automatically
When you visit our website or use the Service, we automatically collect:
- Cookies and a randomly generated device identifier used to run our landing-page A/B test and to attribute sign-ups to a referral code (see the Cookies section).
- Basic web analytics for our marketing pages (page views and aggregate visitor metrics), via Vercel Analytics, which does not use cookies.
- On our marketing landing pages we record anonymous events (a page view or a tap on the call-to-action), tied to the device identifier above, along with the page path and browser user-agent string.
- Operational logs and metrics tied to your account identifier (such as which command you sent, timing, error information, and usage and cost counts). These logs do not contain the body of your messages.
4. What we do not collect
We do not collect your full card or bank account numbers, your bank login credentials, your account balances, your Social Security number, a government ID, your email address, or your precise geolocation. The Service is U.S.-only and accepts U.S. mobile numbers only.
5. How we use your information
- To deliver the Service: send your daily spending text, answer the questions you ask by text, and categorize your transactions.
- To run the conversational onboarding and remember your preferences and goals.
- To process your subscription, free trial, and payments through Stripe.
- To provide support, prevent fraud and abuse, secure the Service, and comply with law.
- To improve the Service, including measuring which marketing pages perform better and attributing sign-ups to referral codes.
We do not sell your personal information, and we do not share it for cross-context behavioral advertising.
6. Automated processing and artificial intelligence
Sprout uses an automated AI model (Anthropic's Claude) in two ways. First, to assign a spending category to your transactions, we send the model only a normalized merchant name (for example, "starbucks"). We do not send transaction amounts, dates, or any information that identifies you for this step.
Second, the conversational assistant uses the model to understand your onboarding answers and your questions and to draft replies. The assistant is sent your messages and the spending figures relevant to your question. It is not sent your name, phone number, or account identifier — your identity is supplied only inside our own systems, never to the model. A short, rolling window of your recent conversation (the last few exchanges) is retained to give the assistant context.
The assistant is automated and may occasionally be wrong or incomplete. Any dollar figure it states is checked against your actual data before it is sent; if a figure cannot be verified, the assistant declines rather than guess. The assistant provides information about your own spending and is not financial, tax, or investment advice.
7. How we share information (service providers)
We share information with the service providers that operate the Service, only as needed to provide it:
- Supabase — our database host, where your account and spending data are stored.
- Stripe — payment processing and subscription billing. Stripe receives your phone number and your payment-card details (which you enter with Stripe), and our internal account and referral identifiers.
- Plaid — the bank-data connection described above. You enter your bank login with Plaid during the one-time linking; Plaid provides us your account and transaction data.
- Sendblue — our primary messaging provider, which sends and receives your texts (including iMessage and SMS). It receives your phone number and the full content of the messages we exchange with you.
- Twilio — a backup SMS provider used if Sendblue is unavailable; it receives the same phone number and message content for those messages.
- Anthropic — the AI provider described in the section above.
- Vercel — our website and application hosting provider, and our cookieless web-analytics provider.
- GitHub Actions — runs our scheduled jobs, including the job that sends your daily text; that job handles your phone number and the text to be sent.
- An external QR-code image service (api.qrserver.com) — on desktop, our landing page asks this service to render a QR code containing our public sign-up number. Your visit to our page results in a request to that service.
- A log-management provider (Axiom) where configured, used for operational diagnostics.
We may also disclose information if required by law or legal process, to enforce our Terms, or to protect the rights, safety, or property of our users, the public, or the Company; and in connection with a merger, acquisition, or sale of assets, subject to this Policy.
8. Cookies
We use the following first-party cookies. We do not use third-party advertising or analytics cookies.
- st_session — keeps you logged in to the web dashboard (lasts 30 days).
- st_device — a random identifier that buckets you into our landing-page A/B test and ties anonymous landing analytics to your browser (lasts 365 days).
- st_ref — remembers a referral/campaign code from a link you followed so we can attribute your sign-up (lasts 90 days).
- st_variant — remembers a manually forced test variant, used for quality assurance (lasts 365 days).
- st_admin — used only for our internal staff console, not set for ordinary users (lasts 8 hours).
Our marketing analytics (Vercel Analytics) is cookieless. You can block or delete cookies in your browser settings, though some site features may not work as intended.
9. Text messages and your consent
You begin receiving texts only after you opt in — typically by texting our keyword to our number, or by signing up on the web. By opting in you consent to receive recurring automated texts from Sprout, including your daily spending summary and replies to messages you send. Message frequency varies. Message and data rates may apply.
You can opt out at any time by replying STOP (or UNSUBSCRIBE, QUIT, or END); we will stop sending texts and send a single confirmation. Reply HELP for help, or START to resume. Opting out stops messages but does not, by itself, cancel a paid subscription or delete your stored data.
10. Data retention and deletion
We keep your information for as long as your account exists and as needed to provide the Service, resolve disputes, and meet legal obligations. Transaction records, message history, and operational logs are retained on this basis. The assistant's short-term conversation memory is limited to your most recent exchanges, although the underlying record persists until it is overwritten.
Opting out of texts or canceling your subscription does not automatically delete the data we have already stored. To request deletion of your account and personal information, contact us using the details below (and you may disconnect your bank link at any time). When you delete your account, we revoke our connection to your financial institution through Plaid (which invalidates the stored access token) and delete the personal information we hold, except where we are required or permitted by law to retain it. We periodically review this retention and deletion practice. Some records in backups or logs may persist for a limited period after deletion.
11. Your choices and rights
You can: stop texts (reply STOP); pause your daily texts (reply PAUSE); cancel your subscription (reply CANCEL or use the billing portal); disconnect your bank; and request access to, correction of, or deletion of your personal information by contacting us.
Depending on where you live (for example, California under the CCPA/CPRA), you may have additional rights, including to know what personal information we collect, to delete it, to correct it, and to not be discriminated against for exercising these rights. We do not sell your personal information or share it for cross-context behavioral advertising. To exercise any right, contact us using the details below; we may need to verify your identity, which for this Service is tied to control of your mobile number.
12. Security
We take reasonable measures to protect your information. All access to our database is server-side and restricted; our database enforces deny-by-default access controls, and your browser never queries it directly. We never receive your bank login credentials, and we store only the last four digits of any card or account; the access token Plaid issues for your connection is encrypted at rest (AES-256-GCM). Login codes are hashed, not stored in plain text. Incoming webhooks from our payment and messaging providers are verified using signing secrets. Traffic to our website and app is encrypted in transit.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
13. Children
The Service is not directed to and may not be used by anyone under 18. We do not knowingly collect personal information from anyone under 18. If you believe a minor has used the Service, contact us and we will delete the information.
14. Changes to this Policy
We may update this Policy from time to time. When we do, we will revise the date above, and material changes will be communicated as required by law. Your continued use of the Service after an update means you accept the revised Policy.
15. Contact us
Questions or requests about this Policy or your information: [contact email — e.g., privacy@getsprout.app]. [LEGAL ENTITY NAME — e.g., Sweetwater Labs LLC].