Privatliv, kort fortalt.
Siden har to dele. Først ventelisten på sparsom.ai, som er den eneste behandling, der sker i dag. Derefter privatlivspolitikken for Sparsom-appen, gengivet ordret.
DEL 1
Ventelisten på sparsom.ai
Denne side er en venteliste, ikke appen. Derfor er der lidt at gemme, og endnu mindre at dele. Alt her beskriver det, der faktisk sker i dag.
DATAANSVARLIG
Dataansvarlig er Sparsom AS, norsk organisationsnummer 837 185 882. Behandlingen sker efter norsk ret.
Henvendelser om behandlingen sendes til contact@sparsom.ai.
HVAD VI GEMMER
Tre felter, og de kommer alle fra formularen, du lige har udfyldt:
Din e-mailadresse, gemt med små bogstaver. Sproget du læste siden på (nb, sv, da, fi, is eller en). Tidspunktet du meldte dig til. Hver række får desuden et teknisk id.
Det er alt. Vi gemmer ikke navn, telefonnummer, adresse, IP-adresse, bankoplysninger eller transaktioner. Appen findes ikke endnu, og denne side rører ingen bankdata.
Din IP-adresse læses i det øjeblik du sender formularen, og bruges kun til at tælle antal forsøg per minut. Den ligger i serverens hukommelse og skrives aldrig til databasen.
Formularen har også et skjult felt, som kun automatiske robotter udfylder. Er det udfyldt, gemmes der ingenting overhovedet.
HVORFOR
E-mailadressen: for at sige til, når det er din tur. Det er den eneste brug.
Sproget: så beskeden kommer på det sprog, du faktisk læste siden på.
Tidspunktet: for at kende rækkefølgen i køen.
IP-adressen: for at forhindre at nogen tilmelder tusind adresser i minuttet.
RETSGRUNDLAG
Samtykke, jf. databeskyttelsesforordningen (GDPR) artikel 6, stk. 1, litra a.
Du giver samtykket ved at indsende formularen, og du kan trække det tilbage når som helst. Så slettes rækken.
HVEM DER SER DET
Tre databehandlere, og ingen andre. Ingen annoncenetværk, ingen sporing, intet videresalg.
Supabase: databasen hvor ventelisten ligger.
Resend: udsendelse af e-mail, region eu-west-1 (EU).
Vercel: hosting af selve hjemmesiden. Vercel Analytics og Speed Insights er ikke installeret; siden måler intet om dig.
HVOR LÆNGE
Til lancering. Når ventelisten har gjort sit arbejde, og alle er inviteret ind, slettes den i sin helhed.
Beder du om sletning inden da, sker det med det samme.
COOKIES
Denne side sætter ingen cookies. Ingen.
Den gemmer heller ikke noget i localStorage eller sessionStorage, og den henter ingen scripts, skrifttyper eller billeder fra andre domæner. Skrifttyperne hentes ved bygning og serveres fra vores eget domæne.
Derfor er der heller ingen samtykkebanner her. Der er ingenting at samtykke til.
DINE RETTIGHEDER
Du har ret til indsigt i hvad vi har gemt om dig, berigtigelse af fejl, sletning, og dataportabilitet, at få oplysningerne udleveret i et maskinlæsbart format.
Du kan også trække samtykket tilbage når som helst, uden at angive en grund.
Send en e-mail til contact@sparsom.ai. Du får svar inden for 30 dage, som er fristen i databeskyttelsesforordningen. I praksis hurtigere, da listen er kort.
SIKKERHED
Siden serveres kun over HTTPS og sender HSTS-headeren, der beder browseren aldrig forsøge http igen.
Browseren får seks sikkerhedsheadere: Content-Security-Policy, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy og Strict-Transport-Security.
E-mailadressen valideres, før den gemmes, og adresser med kontroltegn eller HTML afvises.
Skrivningen til databasen sker fra serveren med en nøgle, der aldrig sendes til browseren. En særskilt port i byggekæden scanner byggeartefakten for nøgler før hver udrulning.
Formularen tager imod fem forsøg i minuttet per IP-adresse.
KLAGE
Mener du, at vi behandler oplysninger om dig forkert, kan du klage til det norske Datatilsynet.
Datatilsynet, www.datatilsynet.no
ÆNDRINGER
Vi opdaterer denne side, når behandlingen ændrer sig, for eksempel når appen får bankintegration. Så beskrives den her, før den tages i brug, ikke bagefter.
Sidst opdateret:
DEL 2
Politikken for Sparsom-appen
Dette er privatlivspolitikken for Sparsom-appen, gengivet ordret fra dokumentet. Den beskriver appen, ikke ventelisten ovenfor, og ingen sætning i den er skrevet om.
Politikken findes på norsk og engelsk. På sidens fire øvrige sprog står den engelske tekst, fordi en maskinoversat privatlivspolitik ikke er et dokument, nogen har underskrevet.
Sparsom Privacy Policy
Last updated: 16 August 2026
Reference translation of the Norwegian original («Personvernerklæring for Sparsom»). In case of any discrepancy, the Norwegian version prevails.
This Privacy Policy explains how Sparsom AS collects, uses and protects your personal data when you use the Sparsom app and the website sparsom.ai (together, the "Service"). We process personal data in accordance with the Norwegian Personal Data Act and the EU General Data Protection Regulation (GDPR).
1. Data controller
Sparsom AS (org. no. 837 185 882) is the data controller for personal data processed in the Service.
Contact: contact@sparsom.ai
2. What data we collect
2.1 Data you provide
- Account information: email address and login details when you create an account.
- Messages you send to the AI assistant in the app.
- Corrections you make to transaction categories.
2.2 Bank data via open banking (PSD2)
When you connect your bank, we retrieve account information via Neonomics AS, a licensed third-party provider (AISP) under the Payment Services Directive (PSD2), supervised by the Financial Supervisory Authority of Norway (Finanstilsynet). This includes:
- Account name, account number and balance.
- Transaction history: amount, date, merchant/counterparty and transaction description.
The connection is made with your explicit consent through your bank’s own authentication (e.g. BankID). Sparsom never has access to your bank login credentials or BankID. Consent must be renewed periodically in accordance with PSD2 requirements, and you can withdraw it at any time in the app.
2.3 Data collected automatically
- Technical information: device type, operating system, app version and language setting.
- Usage analytics: anonymised events about how the app is used (e.g. which screens are opened). Financial data is never included in analytics.
- Error reports: technical crash reports without personally identifiable content. Financial data is automatically scrubbed before reports are sent.
3. How we use your data
- Providing the Service: showing balances, transactions, categorisation, alerts, Sparsom Score and monthly summaries. Legal basis: contract (GDPR Art. 6(1)(b)).
- AI categorisation and AI assistant: transactions are categorised automatically, and the AI assistant answers questions about your finances. Legal basis: contract (Art. 6(1)(b)).
- Bank connection: retrieving account data via Neonomics. Legal basis: your explicit consent (Art. 6(1)(a)).
- Improving the Service: anonymised usage analytics and error reports. Legal basis: legitimate interest (Art. 6(1)(f)).
- Communication: important messages about your account, changes to terms or the Service. Legal basis: contract and legitimate interest.
We never sell your personal data, and we do not use it for third-party marketing.
4. Automated processing and AI
Sparsom uses artificial intelligence (AI models from Anthropic) to categorise transactions and power the AI assistant in the app. This means that transaction data and messages you send to the assistant are processed by the AI model to provide you with answers and insights.
- The AI provider does not use your data to train its models.
- AI responses are informational insights based on your data, not financial advice.
- No decisions with legal effect or similarly significant effect on you are made in a fully automated manner.
5. Data processors and third parties
We only share data with providers that are necessary to deliver the Service and that are bound by data processing agreements:
- Neonomics AS (Norway): licensed open banking provider. Retrieves account data from your bank with your consent.
- Anthropic (USA): AI models for categorisation and the AI assistant. Transfers to the USA are safeguarded through the EU-U.S. Data Privacy Framework and/or the EU Standard Contractual Clauses (SCC).
- PostHog (EU Cloud): usage analytics. Data is stored in the EU. Financial data is never collected, and screen recording (Session Replay) is disabled.
- Sentry (EU): error and crash reporting. Data is stored in the EU. Collection of personally identifiable information is disabled, and financial data is automatically scrubbed.
- Apple App Store / Google Play: process subscription payments. Sparsom never receives your payment card details. See Apple’s and Google’s own privacy policies.
6. Data retention
- Transaction data: stored in raw form for up to 13 months (12 complete calendar months plus the current month). Raw data is then deleted and replaced by monthly category aggregates linked to your account. The aggregates cannot be traced back to individual transactions, but they are pseudonymised personal data and are deleted when you delete your account.
- Account information: stored for as long as you have an active account.
- Upon account deletion: your personal data is deleted or anonymised without undue delay, unless statutory retention obligations (e.g. the Norwegian Bookkeeping Act) require otherwise.
- Usage analytics and error reports: stored in anonymised form.
7. Your rights
Under the GDPR you have the right to:
- Access the data we hold about you.
- Rectification of inaccurate data.
- Erasure ("the right to be forgotten").
- Restriction of processing.
- Data portability – receiving your data in a machine-readable format.
- Object to processing based on legitimate interest.
- Withdraw consent at any time, without affecting the lawfulness of processing already carried out.
To exercise your rights, contact us at contact@sparsom.ai. We respond within 30 days at the latest.
You also have the right to lodge a complaint with the Norwegian Data Protection Authority (Datatilsynet, www.datatilsynet.no) if you believe our processing violates data protection law.
8. Security
We take the security of your financial data seriously. Measures include encryption of data in transit and at rest, access controls, and bank connections exclusively via licensed PSD2 infrastructure. Sparsom never stores your bank login credentials.
9. Age limit
The Service is intended for persons over 18 years of age. We do not knowingly collect data about persons under 18.
10. Changes to this policy
We may update this Privacy Policy as needed. In the event of material changes, we will notify you in the app or by email. The current version is always available at sparsom.ai.
11. Contact
Sparsom AS, org. no. 837 185 882
Email: contact@sparsom.ai