SPARSOMPRIVACY

Privacy, briefly.

This page has two parts. First the waiting list on sparsom.ai, which is the only processing that happens today. Then the privacy policy for the Sparsom app, reproduced word for word.

PART 1

The waiting list on sparsom.ai

This site is a waiting list, not the app. So there is little to store, and even less to share. Everything here describes what actually happens today.

DATA CONTROLLER

The data controller is Sparsom AS, Norwegian organisation number 837 185 882. The processing is governed by Norwegian law.

Enquiries about the processing go to contact@sparsom.ai.

WHAT WE STORE

Three fields, all of them from the form you just filled in:

Your email address, stored in lowercase. The language you read the page in (nb, sv, da, fi, is or en). The time you signed up. Each row also gets a technical id.

That is all. We do not store names, phone numbers, addresses, IP addresses, bank details or transactions. The app does not exist yet, and this site touches no banking data.

Your IP address is read the moment you submit the form, and is used only to count attempts per minute. It lives in server memory and is never written to the database.

The form also has a hidden field that only automated bots fill in. If it is filled in, nothing is stored at all.

WHY

The email address: to tell you when it is your turn. That is the only use.

The language: so the message arrives in the language you actually read the page in.

The timestamp: to know the order of the queue.

The IP address: to stop anyone signing up a thousand addresses a minute.

LEGAL BASIS

Consent, under GDPR Article 6(1)(a).

You give consent by submitting the form, and you can withdraw it at any time. The row is then deleted.

WHO SEES IT

Three processors, and no one else. No ad networks, no tracking, no resale.

Supabase: the database holding the waiting list.

Resend: email delivery, region eu-west-1 (EU).

Vercel: hosting for the site itself. Vercel Analytics and Speed Insights are not installed; the site measures nothing about you.

HOW LONG

Until launch. Once the waiting list has done its job and everyone has been invited in, it is deleted in full.

Ask for deletion before that and it happens immediately.

COOKIES

This site sets no cookies. None.

It stores nothing in localStorage or sessionStorage either, and it loads no scripts, fonts or images from other domains. The fonts are downloaded at build time and served from our own domain.

That is also why there is no consent banner here. There is nothing to consent to.

YOUR RIGHTS

You have the right to access what we hold about you, to have errors corrected, to erasure, and to data portability, receiving your data in a machine-readable format.

You may also withdraw consent at any time, without giving a reason.

Send an email to contact@sparsom.ai. You will have a reply within 30 days, the deadline set by the GDPR. In practice sooner, since the list is short.

SECURITY

The site is served over HTTPS only, and sends the HSTS header asking browsers never to try http again.

The browser receives six security headers: Content-Security-Policy, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy and Strict-Transport-Security.

Email addresses are validated before storage, and addresses containing control characters or HTML are rejected.

Writes to the database happen from the server with a key that is never sent to the browser. A dedicated gate in the build chain scans the build artefact for keys before every deploy.

The form accepts five attempts per minute per IP address.

COMPLAINTS

If you believe we are handling your data incorrectly, you can complain to the Norwegian Data Protection Authority.

Datatilsynet, www.datatilsynet.no

CHANGES

We update this page when the processing changes, for example when the app gains bank integration. That will be described here before it is put to use, not afterwards.

Last updated:

PART 2

The policy for the Sparsom app

This is the privacy policy for the Sparsom app, reproduced word for word from the document. It describes the app, not the waiting list above, and not one sentence in it has been rewritten.

The policy exists in Norwegian and English. The four other languages on this site show the English text, because a machine-translated privacy policy is not a document anyone has signed.

Sparsom Privacy Policy

Last updated: 16 August 2026

Reference translation of the Norwegian original («Personvernerklæring for Sparsom»). In case of any discrepancy, the Norwegian version prevails.

This Privacy Policy explains how Sparsom AS collects, uses and protects your personal data when you use the Sparsom app and the website sparsom.ai (together, the "Service"). We process personal data in accordance with the Norwegian Personal Data Act and the EU General Data Protection Regulation (GDPR).

1. Data controller

Sparsom AS (org. no. 837 185 882) is the data controller for personal data processed in the Service.

Contact: contact@sparsom.ai

2. What data we collect

2.1 Data you provide

  • Account information: email address and login details when you create an account.
  • Messages you send to the AI assistant in the app.
  • Corrections you make to transaction categories.

2.2 Bank data via open banking (PSD2)

When you connect your bank, we retrieve account information via Neonomics AS, a licensed third-party provider (AISP) under the Payment Services Directive (PSD2), supervised by the Financial Supervisory Authority of Norway (Finanstilsynet). This includes:

  • Account name, account number and balance.
  • Transaction history: amount, date, merchant/counterparty and transaction description.

The connection is made with your explicit consent through your bank’s own authentication (e.g. BankID). Sparsom never has access to your bank login credentials or BankID. Consent must be renewed periodically in accordance with PSD2 requirements, and you can withdraw it at any time in the app.

2.3 Data collected automatically

  • Technical information: device type, operating system, app version and language setting.
  • Usage analytics: anonymised events about how the app is used (e.g. which screens are opened). Financial data is never included in analytics.
  • Error reports: technical crash reports without personally identifiable content. Financial data is automatically scrubbed before reports are sent.

3. How we use your data

  • Providing the Service: showing balances, transactions, categorisation, alerts, Sparsom Score and monthly summaries. Legal basis: contract (GDPR Art. 6(1)(b)).
  • AI categorisation and AI assistant: transactions are categorised automatically, and the AI assistant answers questions about your finances. Legal basis: contract (Art. 6(1)(b)).
  • Bank connection: retrieving account data via Neonomics. Legal basis: your explicit consent (Art. 6(1)(a)).
  • Improving the Service: anonymised usage analytics and error reports. Legal basis: legitimate interest (Art. 6(1)(f)).
  • Communication: important messages about your account, changes to terms or the Service. Legal basis: contract and legitimate interest.

We never sell your personal data, and we do not use it for third-party marketing.

4. Automated processing and AI

Sparsom uses artificial intelligence (AI models from Anthropic) to categorise transactions and power the AI assistant in the app. This means that transaction data and messages you send to the assistant are processed by the AI model to provide you with answers and insights.

  • The AI provider does not use your data to train its models.
  • AI responses are informational insights based on your data, not financial advice.
  • No decisions with legal effect or similarly significant effect on you are made in a fully automated manner.

5. Data processors and third parties

We only share data with providers that are necessary to deliver the Service and that are bound by data processing agreements:

  • Neonomics AS (Norway): licensed open banking provider. Retrieves account data from your bank with your consent.
  • Anthropic (USA): AI models for categorisation and the AI assistant. Transfers to the USA are safeguarded through the EU-U.S. Data Privacy Framework and/or the EU Standard Contractual Clauses (SCC).
  • PostHog (EU Cloud): usage analytics. Data is stored in the EU. Financial data is never collected, and screen recording (Session Replay) is disabled.
  • Sentry (EU): error and crash reporting. Data is stored in the EU. Collection of personally identifiable information is disabled, and financial data is automatically scrubbed.
  • Apple App Store / Google Play: process subscription payments. Sparsom never receives your payment card details. See Apple’s and Google’s own privacy policies.

6. Data retention

  • Transaction data: stored in raw form for up to 13 months (12 complete calendar months plus the current month). Raw data is then deleted and replaced by monthly category aggregates linked to your account. The aggregates cannot be traced back to individual transactions, but they are pseudonymised personal data and are deleted when you delete your account.
  • Account information: stored for as long as you have an active account.
  • Upon account deletion: your personal data is deleted or anonymised without undue delay, unless statutory retention obligations (e.g. the Norwegian Bookkeeping Act) require otherwise.
  • Usage analytics and error reports: stored in anonymised form.

7. Your rights

Under the GDPR you have the right to:

  • Access the data we hold about you.
  • Rectification of inaccurate data.
  • Erasure ("the right to be forgotten").
  • Restriction of processing.
  • Data portability – receiving your data in a machine-readable format.
  • Object to processing based on legitimate interest.
  • Withdraw consent at any time, without affecting the lawfulness of processing already carried out.

To exercise your rights, contact us at contact@sparsom.ai. We respond within 30 days at the latest.

You also have the right to lodge a complaint with the Norwegian Data Protection Authority (Datatilsynet, www.datatilsynet.no) if you believe our processing violates data protection law.

8. Security

We take the security of your financial data seriously. Measures include encryption of data in transit and at rest, access controls, and bank connections exclusively via licensed PSD2 infrastructure. Sparsom never stores your bank login credentials.

9. Age limit

The Service is intended for persons over 18 years of age. We do not knowingly collect data about persons under 18.

10. Changes to this policy

We may update this Privacy Policy as needed. In the event of material changes, we will notify you in the app or by email. The current version is always available at sparsom.ai.

11. Contact

Sparsom AS, org. no. 837 185 882

Email: contact@sparsom.ai

Termscontact@sparsom.ai← Back to the front page