Security & Privacy
POPIA-minded by design.
We handle sensitive financial data carefully. This page explains our approach in plain language.
What we do
- Process then delete uploads: statements are parsed to transactions, then the raw files are removed.
- Mask identifiers: account references are displayed in masked form where possible.
- Least data necessary: we store what is needed to give insights, not unnecessary sensitive detail.
- Secure access: we support strong sign-in and 2FA (where enabled in the app).
What we don’t do
- We don’t sell your data.
- We don’t share your data with advertisers.
- We don’t keep raw statement uploads longer than needed to parse them.
Note: This website is informational. The exact controls will depend on how you deploy (local app vs cloud).
POPIA note
If you use a hosted version of GrapeFinance, the platform will be designed with POPIA principles in mind: transparency, purpose limitation, security safeguards, and user control.