Privacy Policy
Last updated: July 12, 2026
This Privacy Policy explains how Ivy-F ("Ivy-F", "we", "us") collects, uses, shares, and protects your information when you use our applications and websites, including ivy-f.app (the Ivy-F app) and ivy-f.net (this website) (together, the "Services"). By using the Services you agree to this Policy.
1. Who we are
The Services are operated by Ivy [Ivy]. For any privacy questions or requests, contact us at support.ivyf@gmail.com.
2. Information we collect
Information you provide
- Account information — when you sign in (including via Google Sign-In), we receive your email address and basic profile identifiers used to create and key your single Ivy-F account across the app and site.
- Financial inputs you enter — figures you type into the app such as age, net worth, income, expenses, budgets, goals, and routine transactions. Much of this is stored locally on your device; some may be synced to your account.
- Assistant ("Billie") content — messages you send to the in-app AI assistant and its responses, which may be stored to provide and improve the feature. To generate a reply, your chat messages (and any images you attach) are sent to our large-language-model providers — Anthropic (Claude), Google (Gemini), and NVIDIA (NIM) — which process them under their API data-use terms to produce the response. We do not use your chats to train models of our own. If you flag an AI response using the in-app Report button, that response and your report are shared with our support team for review.
- Support communications — information you send us by email or in-app support.
Information collected automatically
- Usage analytics and session recordings — we use PostHog to understand how the Services are used. This may include events, pages/screens viewed, and session replays (recordings of on-screen interactions, with sensitive inputs masked where configured). On mobile devices, analytics and session replay are off by default and only run if you turn them on ("Allow PostHog Analytics" on the landing panel or in Settings → Privacy); you can turn them off again the same way at any time.
- Device and technical data — IP address, device/browser type, operating system, identifiers, and approximate location derived from IP. When you sign in, we also record the device model, browser, screen resolution, ISP, and approximate city for that device — these power the Device Management list in Settings and the cross-device login approval prompts, so you can recognize and unlink devices on your account. Approximate location is resolved on our own servers using MaxMind's GeoLite2 database (your IP is not sent to a geolocation provider in the normal case); only if that local lookup is unavailable do we query a fallback lookup service (IPinfo or ipapi.co) with your IP. This product includes GeoLite2 Data created by MaxMind, available from https://www.maxmind.com.
- Local storage and cookies — we use cookies and browser/local storage to keep you signed in, remember preferences, and operate analytics.
Payment information
Subscriptions (Pro/Select) are processed by our payment providers (e.g., Stripe, and, in the mobile apps, Apple App Store / Google Play billing). We do not store full card numbers; payment processors handle card data under their own privacy terms.
3. How we use your information
- Provide, maintain, and secure the Services and your account.
- Generate your projections, plans, and assistant responses.
- Process subscriptions and prevent fraud and abuse.
- Analyze and improve features, performance, and reliability.
- Communicate with you about support, updates, and changes.
- Comply with legal obligations and enforce our Terms.
4. Legal bases (EEA/UK users)
Where applicable, we rely on: performance of a contract (to provide the Services), legitimate interests (to secure and improve the Services), consent (for non-essential analytics/cookies, where required), and legal obligation.
5. How we share information
We do not sell your personal information. We share it only with:
| Recipient | Purpose |
|---|---|
| Google (Sign-In) | Authentication / login |
| Stripe; Apple / Google billing | Payment processing |
| PostHog | Analytics & session replay (off by default on mobile; opt-in) |
| Anthropic, Google, NVIDIA (AI model providers) | Generating assistant ("Billie") responses — your chat messages are sent to the provider serving your tier to produce the reply |
| Email & hosting providers | Operating the Services (support email, hosting) |
| IPinfo / ipapi.co (fallback only) | Approximate location from IP for the Device Management list — queried only when our local GeoLite2 lookup is unavailable |
You can opt out of PostHog at any time inside ivy-f.app (Settings → Privacy → Opt-Out → select and opt out of PostHog). On mobile, PostHog is off unless you've tapped "Allow PostHog Analytics".
We may also disclose information to comply with law, protect rights and safety, or in connection with a merger, acquisition, or sale of assets.
6. Data retention
We keep personal information for as long as your account is active or as needed to provide the Services, then delete or anonymize it within a reasonable period, unless a longer period is required by law.
7. Your rights and choices
- Access, correct, or delete your data, and delete your account — from within the app (Settings) or by emailing support.ivyf@gmail.com. Step-by-step instructions: Delete your account.
- Clear local data stored on your device from the app's privacy settings.
- Opt out of analytics and manage cookies where offered.
- EEA/UK and California residents have additional rights (e.g., portability, objection, and the right to lodge a complaint with a regulator).
8. Children and teens
Ivy-F is an educational tool intended for teenagers and adults. We do not direct the Services to, or knowingly create accounts for, children under 13. Because we are based in South Africa and our users may be under 18, we treat anyone under 18 as a child under POPIA: if you are under 18, your account runs in Protected mode: certain features are restricted, analytics stay off, chats use a stricter safety profile, and a visible session timer shows time online (see "Error 2000" on this site's Errors pages for the full list). A parent or legal guardian can review and manage these protections through the in-app Guardian Management flow: the guardian creates their own Ivy-F account in Management mode, requests a sync to the child's account by email address, the child must accept the request in their own app, and the guardian then verifies their identity by submitting a photo of their government ID held next to their unique sync code. ID photos are used solely for that review, go directly to our support team, and are never stored — they are deleted once the decision is made. Every restriction change made by a verified guardian is logged as the record of parental consent, and revoking the link instantly restores full protection. A parent or guardian may also review, request deletion of, or withdraw consent for their child's data at any time by emailing support.ivyf@gmail.com.
9. Security
We use reasonable technical and organizational measures to protect your information. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
10. International transfers
Your information may be processed in countries other than your own. Where required, we use appropriate safeguards for such transfers.
11. Changes to this Policy
We may update this Policy from time to time. Material changes will be posted here with an updated date, and where required we will notify you.
12. Contact us
Questions or requests: support.ivyf@gmail.com.