Sovereign collects only what you give us and what's needed to run the app.
| Category | What specifically | Why |
|---|---|---|
| Account | Email address | Authentication (magic link or OAuth). We don't store passwords. |
| Holdings & activity | Metals trades (gold, silver, platinum, palladium), cryptocurrency holdings, spending entries, future income projections, tracked account balances | Stored under Supabase Row-Level Security and at-rest encryption. |
| Net worth snapshots | Periodic captures of total assets, debts, net worth, year change, notes, account values, and spending breakdowns | Optionally end-to-end encrypted on your device before upload (see Section 2). |
| Profile | Display name (optional), birth year (optional), Pro subscription status, anonymous user ID, encryption salt (if E2EE enabled) | Personalisation, feature access, and account management. |
| Usage | None. We don't run analytics or collect behavioural telemetry. | โ |
All financial data is stored locally in your browser by default. Cloud sync (via Supabase) is opt-in โ you choose to enable it when you create an account.
Local storage (default). Without an account, all your data lives in your browser's localStorage. It never leaves your device. Clearing your browser storage or uninstalling the app permanently deletes it.
Cloud sync. When you create a Sovereign account, your data is automatically synced to Supabase, a US-based database service, so you can access it across devices. Your metals trade history, cryptocurrency holdings, spending entries, future income projections, and account profile (email, plan, encryption salt) are stored in your account's row under Supabase's at-rest encryption and Row-Level Security policies that ensure only you can read your data via the API. Data is encrypted in transit (TLS).
End-to-end encryption (optional). AES-256 You can additionally enable E2EE for your net worth snapshots from the Account tab. When enabled, the values inside each snapshot โ total assets, total debt, net worth, year change, notes, account values, and spending breakdowns โ are encrypted on your device using AES-GCM-256. The encryption key is derived from a passphrase you set at enrollment using PBKDF2-SHA256 with 600,000 iterations and a per-user salt. Your passphrase and key never leave your device; Sovereign's servers store only ciphertext for those snapshot fields and cannot read them โ even if compelled.
Scope of E2EE. End-to-end encryption applies only to net worth snapshot fields. Your metals trade history, spending rows, future income entries, and profile data (email, plan tier, encryption salt) are not end-to-end encrypted; they are protected by Supabase's at-rest encryption and Row-Level Security as described above. We are working to expand E2EE coverage to additional tables in a future release.
Supabase servers are located in the United States (AWS us-east-1).
| We never | Details |
|---|---|
| Sell your data | Your data is never sold, rented, or traded to any third party. |
| Use advertising trackers | No Google Analytics, Meta Pixel, or any other behavioural ad platform. |
| Track you across apps | No advertising IDs, fingerprinting, or cross-app tracking. On iOS, we request App Tracking Transparency and default to no tracking. |
| Access your contacts | The app has no access to your address book or contact list. |
| Access your camera or microphone | We don't request or use camera, microphone, or location permissions. |
| Store passwords | Authentication is passwordless โ we use magic links and OAuth only. |
The following third parties process data on Sovereign's behalf. Each is limited to the purpose listed.
Export your data. Use the PDF / Export tab inside the app to download all your snapshots and trade history as CSV or JSON at any time.
Delete your account. Go to Account โ Danger Zone โ Delete My Account & All Data. You'll be asked to type DELETE to confirm. On confirmation, our delete-account Supabase Edge Function permanently removes, in one server-side transaction, your auth identity (so the same Apple ID / email can sign up fresh) and every row of cloud data we hold for you: snapshots, metal trades, spending rows, profile, alerts, and any shared links. Local browser data is not affected โ clear your browser storage (or delete the app on iOS) to remove that. No support request needed.
Correct or update your data. You can edit any entry directly inside the app. Email address changes are made through Supabase Auth settings โ contact us if you need help.
Data portability. Your exported CSV and JSON files are in open, standard formats โ no vendor lock-in.
If you're in the EU/EEA, you have additional rights under GDPR including the right to object to processing, restrict processing, and lodge a complaint with your local supervisory authority. Contact us at the address below to exercise any of these rights.
We keep your data for as long as your account is active. If you delete your account, cloud data is removed immediately and the auth user record is destroyed in the same operation โ there is no soft-delete or recovery period. Backups may retain data for up to 30 days before they're cycled out, which is standard Supabase infrastructure behaviour and outside the application layer.
If you stop using the app without deleting your account, your data remains stored until you choose to delete it or contact us to do so.
Sovereign is not directed at children under 13. We don't knowingly collect personal information from children. If you believe a child under 13 has created an account, please contact us and we'll delete it promptly.
If we make a material change โ for example, adding a new data category or a new third-party processor โ we'll post the updated policy here and update the "Last updated" date above. For significant changes, we'll also notify signed-in users by email.
The version number (currently v1.0) increments on material changes, not minor wording edits.
For privacy questions, data requests, or to exercise your rights:
We aim to respond to all privacy requests within 5 business days.