Privacy Policy — The Savvy Friend
Publication status: CEO-approved copy, published at /privacy.
Operational retention, rights-workflow, effective-date and provider evidence
items remain tracked separately under TECH-CLAR-030.
Last updated: 2026-09-08
The Savvy Friend is operated by Astro Technology Solutions LLC (“Astro,” “we,” “us,” or “our”), 500 4th St NW Ste 102 PMB 3215, Albuquerque, NM 87102, United States. For privacy questions or rights requests, email privacy@thesavvyfriend.com. For general support, email info@thesavvyfriend.com.
Scope and age
This policy covers the public website, Journal, Free Financial Life Audit, Results, Results recovery, transactional email, optional marketing consent, and consent-gated analytics. The product is focused on people in the United States and is available online without geographic exclusion. We do not intentionally offer or target the service to people outside the United States; if that changes, this policy and our compliance program will be updated. The service is for adults 18 and older. Do not use it if you are under 18. If you believe a minor submitted information, contact us so we can assess and delete it where appropriate.
Information we collect
We collect only what the MVP needs:
- Audit answers, question/version identifiers, answer status and normalized values. Do not enter bank credentials, account numbers, government identifiers, or highly sensitive free text.
- Optional Q10 “Something else” text, encrypted in our database and excluded from Results, analytics, logs, and provider payloads.
- An email address when you request Results delivery or recovery. It is encrypted at rest; a separate HMAC lookup value is used to find records.
- Anonymous session, Results-session, and preference-center credentials as opaque tokens. We store only digests where designed; raw tokens are used transiently in cookies or links.
- Marketing preferences and consent evidence when you separately opt in.
- First-party attribution categories and limited UTM values captured at Audit start. We do not intentionally store full referrer URLs, IP addresses, or user-agent values in the Audit records.
- Analytics events and sanitized technical errors only after analytics consent. We do not send answers, financial values, email addresses, Q10 text, Results, tokens, or database identifiers to PostHog.
- Operational data generated by hosting, database, email, analytics, source-control, security, and support providers, subject to their roles, contracts, logs, and policies.
We collect information directly from you and from your browser/device during use. We do not buy personal data for the MVP.
How we use information
We use information to provide and secure the Audit and Results; validate, version, and preserve an immutable Result; deliver and recover Results by email; operate the preference center; honor marketing choices; prevent abuse; troubleshoot failures; improve the product using consent-gated, minimized analytics; maintain backups and business records; and comply with law.
For people in jurisdictions requiring a legal basis, the proposed bases are: performance of a requested service for the Audit, Results, recovery, and transactional email; consent for optional marketing and analytics; legitimate interests for security, abuse prevention, reliability, and limited operational records, balanced against user rights; and legal obligation where required. A human reviewer must confirm these bases for any EU/UK targeting before launch there.
Audit and Results
The Audit is educational and reflective. It is not financial, investment, tax, legal, accounting, medical, or other professional advice. It does not connect to a bank, make a score or ranking, recommend investments, create a budget, or guarantee an outcome. Results are generated from the answers supplied and may be incomplete or unsuitable for a particular situation.
The Audit starts an anonymous session. Retakes are separate executions. Results are immutable. A Results email contains a secure, expiring, single-use access link. The link is exchanged for a separate Results session and then removed from the visible URL. Recovery requests use generic responses so that a person cannot learn whether an email exists in our records.
Email and marketing
Results email is transactional only and is not a newsletter or promotional sequence. We will not add marketing content to it without revisiting the email and consent design. Optional marketing consent is separate, granular, unbundled, and can be withdrawn. Unsubscribing from marketing does not automatically delete Audit data; a separate deletion request is required. Newsletter, welcome sequence, and Early Access sending are outside the initial launch.
Analytics, local storage and cookies
The MVP uses necessary first-party cookies for anonymous Audit, Results, and preference sessions. It uses localStorage for temporary Audit recovery state and for the local analytics-consent preference. PostHog Cloud EU is initialized only after an affirmative analytics choice. Autocapture, session replay, heatmaps, and sensitive or identifying properties are disabled by contract/design. Analytics withdrawal stops future analytics initialization/events; it does not delete operational Audit records automatically.
Cookie Preferences is deferred for the initial U.S.-focused launch. We will not represent the current /preferences email center as a cookie center. If we intentionally target EU/EEA/UK users or add non-essential storage/access technologies, we must implement an appropriate consent surface before doing so.
Providers and transfers
Astro uses Vercel for hosting/deployment, Supabase/PostgreSQL for first-party persistence, Brevo for transactional email and future marketing synchronization, PostHog Cloud EU for consent-gated analytics, and GitHub for source control. They may process data as processors/service providers or as independent controllers for their own account, security, billing, or service-generated data. The exact plan, region, subprocessor list, DPA acceptance, transfer mechanism, and retention/deletion terms must be confirmed in our provider evidence register before launch. We do not claim that all data remains in the EU or that every provider acts only as our processor.
Where applicable, transfers from the EEA/UK/Switzerland will rely on an adequacy decision, Standard Contractual Clauses, UK Addendum/IDTA, or another valid mechanism. A provider’s DPA does not remove Astro’s responsibility for notices, consent, minimization, rights, and configuration.
Security
We use TLS in transit, provider encryption and access controls, application encryption for email and Q10 text, hashed opaque tokens, server-only database access, allowlisted analytics, generic anti-enumeration responses, and structured log sanitization. No system is guaranteed secure. Report suspected security or privacy incidents to privacy@thesavvyfriend.com.
Retention and deletion
The proposed operational schedule is in data-rights-and-retention-policy.md. It is a provisional compliance decision pending human legal review and provider confirmation, not a promise that every provider log or backup is deleted on the same day. We delete or anonymize identifiable data when the schedule expires or a valid request applies, subject to legal, security, fraud-prevention, dispute, and backup limitations. We retain deletion tombstones only as needed to prevent re-creation or prove a request was handled.
Your rights and requests
Email privacy@thesavvyfriend.com with the request type, the email used (if relevant), and enough context to locate the record. You may request access, correction, deletion, restriction, objection, portability where applicable, withdrawal of consent, or marketing unsubscribe. We may request proportionate verification and will not disclose data merely because someone knows an email address. We will acknowledge and respond without undue delay; our proposed operational target is 30 days for U.S. requests and one month for GDPR requests if applicable, subject to lawful extensions and exceptions. We do not discriminate for exercising rights.
If you are in the EU/EEA, you may complain to your local supervisory authority. If you are in the UK, you may complain to the ICO. A definitive EU/UK representative/DPO position is not claimed because the current product is U.S.-focused and not intentionally targeted there.
Children, changes, and governing context
The service is not for people under 18. We may update this policy as the product changes. The effective date and material-change notice method must be confirmed at publication. The company is organized in New Mexico; Terms contain the governing-law and dispute provisions, subject to mandatory consumer protections.
Remaining operational review
- Confirm publication/effective date and material-change mechanism.
- Confirm provider plan, regions, DPAs, subprocessors, and actual log/backup behavior.
- Confirm whether California thresholds are met and whether any other state law applies.
- Confirm the retention schedule, rights workflow, and any required EU/UK representative analysis.
- These operational items do not change the approved page copy and remain launch gates where required by TECH-CLAR-030.