Security & Privacy

POPIA-minded by design.

We handle sensitive financial data carefully. This page explains our approach in plain language.

What we do

  • Process then delete uploads: statements are parsed to transactions, then the raw files are removed.
  • Mask identifiers: account references are displayed in masked form where possible.
  • Least data necessary: we store what is needed to give insights, not unnecessary sensitive detail.
  • Secure access: we support strong sign-in and 2FA (where enabled in the app).

What we don’t do

  • We don’t sell your data.
  • We don’t share your data with advertisers.
  • We don’t keep raw statement uploads longer than needed to parse them.
Note: This website is informational. The exact controls will depend on how you deploy (local app vs cloud).

POPIA note

If you use a hosted version of GrapeFinance, the platform will be designed with POPIA principles in mind: transparency, purpose limitation, security safeguards, and user control.