SPARSOMPERSÓNUVERND

Persónuvernd, í stuttu máli.

Síðan er í tveimur hlutum. Fyrst biðlistinn á sparsom.ai, eina vinnslan sem fer fram í dag. Síðan persónuverndarstefna Sparsom-appsins, orðrétt.

HLUTI 1

Biðlistinn á sparsom.ai

Þessi síða er biðlisti, ekki appið. Því er lítið að geyma og enn minna að deila. Allt hér lýsir því sem raunverulega gerist í dag.

ÁBYRGÐARAÐILI

Ábyrgðaraðili er Sparsom AS, norskt fyrirtækjanúmer 837 185 882. Um vinnsluna gildir norskur réttur.

Fyrirspurnir um vinnsluna sendist á contact@sparsom.ai.

HVAÐ VIÐ GEYMUM

Þrír reitir, allir úr eyðublaðinu sem þú fylltir út:

Netfangið þitt, geymt með litlum stöfum. Tungumálið sem þú last síðuna á (nb, sv, da, fi, is eða en). Tíminn þegar þú skráðir þig. Hver færsla fær auk þess tæknilegt auðkenni.

Það er allt. Við geymum ekki nöfn, símanúmer, heimilisföng, IP-tölur, bankaupplýsingar eða færslur. Appið er ekki til enn, og þessi síða snertir engin bankagögn.

IP-talan þín er lesin á því augnabliki sem þú sendir eyðublaðið, og er einungis notuð til að telja tilraunir á mínútu. Hún er í minni netþjónsins og er aldrei skrifuð í gagnagrunninn.

Eyðublaðið hefur einnig falinn reit sem aðeins sjálfvirk forrit fylla út. Sé hann útfylltur er ekkert geymt.

HVERS VEGNA

Netfangið: til að láta vita þegar röðin kemur að þér. Það er eina notkunin.

Tungumálið: svo skilaboðin berist á því tungumáli sem þú last síðuna á.

Tíminn: til að vita röðina í biðröðinni.

IP-talan: til að hindra að einhver skrái þúsund netföng á mínútu.

LAGAGRUNDVÖLLUR

Samþykki, sbr. persónuverndarreglugerðina (GDPR) 6. gr. 1. mgr. a-lið.

Þú veitir samþykki með því að senda eyðublaðið, og þú getur afturkallað það hvenær sem er. Þá er færslunni eytt.

HVER SÉR ÞAÐ

Þrír vinnsluaðilar, og engir aðrir. Engin auglýsinganet, engin rakning, engin endursala.

Supabase: gagnagrunnurinn þar sem biðlistinn er.

Resend: sending tölvupósts, svæði eu-west-1 (ESB).

Vercel: hýsing síðunnar sjálfrar. Vercel Analytics og Speed Insights eru ekki uppsett; síðan mælir ekkert um þig.

HVE LENGI

Fram að útgáfu. Þegar biðlistinn hefur gert sitt gagn og öllum hefur verið boðið inn er honum eytt í heild.

Biðjir þú um eyðingu fyrr gerist það strax.

VEFKÖKUR

Þessi síða setur engar vefkökur. Engar.

Hún geymir heldur ekkert í localStorage eða sessionStorage, og sækir engar skriftur, letur eða myndir af öðrum lénum. Leturgerðirnar eru sóttar við byggingu og bornar fram af okkar eigin léni.

Þess vegna er hér heldur ekkert samþykkisborð. Það er ekkert til að samþykkja.

RÉTTINDI ÞÍN

Þú átt rétt á aðgangi að því sem við geymum um þig, leiðréttingu villna, eyðingu, og flytjanleika gagna, að fá upplýsingarnar á véllæsilegu sniði.

Þú getur einnig afturkallað samþykki hvenær sem er, án þess að gefa ástæðu.

Sendu tölvupóst á contact@sparsom.ai. Þú færð svar innan 30 daga, sem er fresturinn í persónuverndarreglugerðinni. Í reynd fyrr, þar sem listinn er stuttur.

ÖRYGGI

Síðan er einungis borin fram yfir HTTPS, og sendir HSTS-hausinn sem biður vafrann um að reyna aldrei http aftur.

Vafrinn fær sex öryggishausa: Content-Security-Policy, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy og Strict-Transport-Security.

Netfangið er staðfest áður en það er geymt, og netföngum með stýritáknum eða HTML er hafnað.

Skrif í gagnagrunninn eiga sér stað frá netþjóninum með lykli sem er aldrei sendur í vafrann. Sérstakt hlið í byggingarkeðjunni skannar byggingarafurðina fyrir lyklum fyrir hverja útgáfu.

Eyðublaðið tekur við fimm tilraunum á mínútu fyrir hverja IP-tölu.

KVÖRTUN

Teljir þú að við vinnum rangt með upplýsingar um þig geturðu kvartað til norsku persónuverndarstofnunarinnar.

Datatilsynet, www.datatilsynet.no

BREYTINGAR

Við uppfærum þessa síðu þegar vinnslan breytist, til dæmis þegar appið fær bankatengingu. Þá verður henni lýst hér áður en hún er tekin í notkun, ekki eftir á.

Síðast uppfært:

HLUTI 2

Stefnan fyrir Sparsom-appið

Þetta er persónuverndarstefna Sparsom-appsins, orðrétt úr skjalinu. Hún lýsir appinu, ekki biðlistanum hér að ofan, og engri setningu í henni hefur verið breytt.

Stefnan er til á norsku og ensku. Á hinum fjórum tungumálum síðunnar birtist enski textinn, því vélþýdd persónuverndarstefna er ekki skjal sem neinn hefur undirritað.

Sparsom Privacy Policy

Last updated: 16 August 2026

Reference translation of the Norwegian original («Personvernerklæring for Sparsom»). In case of any discrepancy, the Norwegian version prevails.

This Privacy Policy explains how Sparsom AS collects, uses and protects your personal data when you use the Sparsom app and the website sparsom.ai (together, the "Service"). We process personal data in accordance with the Norwegian Personal Data Act and the EU General Data Protection Regulation (GDPR).

1. Data controller

Sparsom AS (org. no. 837 185 882) is the data controller for personal data processed in the Service.

Contact: contact@sparsom.ai

2. What data we collect

2.1 Data you provide

  • Account information: email address and login details when you create an account.
  • Messages you send to the AI assistant in the app.
  • Corrections you make to transaction categories.

2.2 Bank data via open banking (PSD2)

When you connect your bank, we retrieve account information via Neonomics AS, a licensed third-party provider (AISP) under the Payment Services Directive (PSD2), supervised by the Financial Supervisory Authority of Norway (Finanstilsynet). This includes:

  • Account name, account number and balance.
  • Transaction history: amount, date, merchant/counterparty and transaction description.

The connection is made with your explicit consent through your bank’s own authentication (e.g. BankID). Sparsom never has access to your bank login credentials or BankID. Consent must be renewed periodically in accordance with PSD2 requirements, and you can withdraw it at any time in the app.

2.3 Data collected automatically

  • Technical information: device type, operating system, app version and language setting.
  • Usage analytics: anonymised events about how the app is used (e.g. which screens are opened). Financial data is never included in analytics.
  • Error reports: technical crash reports without personally identifiable content. Financial data is automatically scrubbed before reports are sent.

3. How we use your data

  • Providing the Service: showing balances, transactions, categorisation, alerts, Sparsom Score and monthly summaries. Legal basis: contract (GDPR Art. 6(1)(b)).
  • AI categorisation and AI assistant: transactions are categorised automatically, and the AI assistant answers questions about your finances. Legal basis: contract (Art. 6(1)(b)).
  • Bank connection: retrieving account data via Neonomics. Legal basis: your explicit consent (Art. 6(1)(a)).
  • Improving the Service: anonymised usage analytics and error reports. Legal basis: legitimate interest (Art. 6(1)(f)).
  • Communication: important messages about your account, changes to terms or the Service. Legal basis: contract and legitimate interest.

We never sell your personal data, and we do not use it for third-party marketing.

4. Automated processing and AI

Sparsom uses artificial intelligence (AI models from Anthropic) to categorise transactions and power the AI assistant in the app. This means that transaction data and messages you send to the assistant are processed by the AI model to provide you with answers and insights.

  • The AI provider does not use your data to train its models.
  • AI responses are informational insights based on your data, not financial advice.
  • No decisions with legal effect or similarly significant effect on you are made in a fully automated manner.

5. Data processors and third parties

We only share data with providers that are necessary to deliver the Service and that are bound by data processing agreements:

  • Neonomics AS (Norway): licensed open banking provider. Retrieves account data from your bank with your consent.
  • Anthropic (USA): AI models for categorisation and the AI assistant. Transfers to the USA are safeguarded through the EU-U.S. Data Privacy Framework and/or the EU Standard Contractual Clauses (SCC).
  • PostHog (EU Cloud): usage analytics. Data is stored in the EU. Financial data is never collected, and screen recording (Session Replay) is disabled.
  • Sentry (EU): error and crash reporting. Data is stored in the EU. Collection of personally identifiable information is disabled, and financial data is automatically scrubbed.
  • Apple App Store / Google Play: process subscription payments. Sparsom never receives your payment card details. See Apple’s and Google’s own privacy policies.

6. Data retention

  • Transaction data: stored in raw form for up to 13 months (12 complete calendar months plus the current month). Raw data is then deleted and replaced by monthly category aggregates linked to your account. The aggregates cannot be traced back to individual transactions, but they are pseudonymised personal data and are deleted when you delete your account.
  • Account information: stored for as long as you have an active account.
  • Upon account deletion: your personal data is deleted or anonymised without undue delay, unless statutory retention obligations (e.g. the Norwegian Bookkeeping Act) require otherwise.
  • Usage analytics and error reports: stored in anonymised form.

7. Your rights

Under the GDPR you have the right to:

  • Access the data we hold about you.
  • Rectification of inaccurate data.
  • Erasure ("the right to be forgotten").
  • Restriction of processing.
  • Data portability – receiving your data in a machine-readable format.
  • Object to processing based on legitimate interest.
  • Withdraw consent at any time, without affecting the lawfulness of processing already carried out.

To exercise your rights, contact us at contact@sparsom.ai. We respond within 30 days at the latest.

You also have the right to lodge a complaint with the Norwegian Data Protection Authority (Datatilsynet, www.datatilsynet.no) if you believe our processing violates data protection law.

8. Security

We take the security of your financial data seriously. Measures include encryption of data in transit and at rest, access controls, and bank connections exclusively via licensed PSD2 infrastructure. Sparsom never stores your bank login credentials.

9. Age limit

The Service is intended for persons over 18 years of age. We do not knowingly collect data about persons under 18.

10. Changes to this policy

We may update this Privacy Policy as needed. In the event of material changes, we will notify you in the app or by email. The current version is always available at sparsom.ai.

11. Contact

Sparsom AS, org. no. 837 185 882

Email: contact@sparsom.ai

Skilmálarcontact@sparsom.ai← Til baka á forsíðuna