Privacy Policy
Last updated: September 12, 2026
Introduction
This Privacy Policy explains how Penny Finance LLC ("Penny," "we," "our," or "us") collects, uses, shares, and protects personal information when you use our app, website, and related services, including our waitlist. Our Terms of Service describe the rules for using Penny.
Information We Collect
Information You Provide or Authorize
- Account and Social-Login Information: When you create an account, we collect your name, email address, and, if you use password sign-in, a password stored in hashed form. If you use Sign in with Apple or Google sign-in, we receive authentication information, including your provider account identifier and, when available, your name and email address. This may include an Apple private relay email address.
- Connected Financial Data: With your permission, we retrieve account details, balances, and transaction history through providers such as Plaid. If you connect eligible Apple Wallet accounts through Apple's FinanceKit, Penny reads the account information, balances, and transactions you authorize on your device and uploads them to Penny's servers for syncing, storage, and use in your household. This can include account and institution names, account identifiers, credit limits, transaction amounts and dates, descriptions, merchant information, and transaction status.
- Manual Entries and Attachments: We collect accounts, balances, transactions, and recurring entries you enter manually, along with categories, tags, notes, receipt images, and other images or details you add to your financial records.
- Purchase and Subscription Records: We receive information about your Penny purchases and subscriptions through the App Store and RevenueCat, including user and transaction identifiers, purchased products, subscription status, and renewal or expiration information.
- Household Invitations: When you invite someone to a household, we collect the invitee's email address and invitation details, such as the household and assigned role, to send and manage the invitation. We may receive your email address from another Penny user who invites you, even if you do not yet have an account.
- Waitlist Information: If you join our waitlist, we collect your email address and signup record to manage the waitlist and send a confirmation email.
- Profile and Preferences: Profile pictures, household details, currency and time zone settings, onboarding choices, and other preferences you provide.
- Support Communications: Your contact details and the messages, attachments, and other information you send when you contact us.
- API Access: If you create a personal API token, we store its name, permissions, a hashed version of the token, and records of its creation, expiration, revocation, and most recent use.
Information Collected Automatically
- Service and Diagnostic Records: We record account activity, financial-record changes, sync results, and errors to operate and troubleshoot Penny. When enabled, our error-monitoring provider receives filtered diagnostic reports as described on our Service providers page.
- Technical Information: Penny and its providers process IP addresses, request times, and browser, app, or device information in connection with delivering the service, securing access, and managing subscriptions.
- Cookies and Local Storage: We use cookies for web sign-in and security. Our website and app also use local device storage for settings and cached data that support their features. You can clear browser storage or block cookies through your browser settings, but doing so may affect sign-in and saved settings.
Financial Account Connections
Connecting an account authorizes Penny to import the financial information you choose to share through Plaid or FinanceKit. These connections provide financial records for tracking and analysis; they do not authorize Penny to move money or make payments from your connected accounts. Penny does not receive your bank password through these connections.
To revoke a Plaid bank connection, disconnect Penny from the relevant accounts in Plaid Portal, following Plaid's disconnection instructions. You can also use your bank's third-party access controls, where available. For FinanceKit, use Apple's Wallet financial-data sharing controls on your device to change or revoke Penny's access. See Apple's explanation of sharing account activity.
Revoking access stops future retrieval through that connection. It does not delete records already imported into Penny or remove them from a shared household.
How We Use Your Information
We use the information we collect to:
- Provide, maintain, and improve our services
- Organize and analyze your financial records to show balances, spending, income, cash flow, and other financial summaries
- Validate Penny subscription purchases and manage access to paid features through the App Store and RevenueCat; payment for App Store purchases is processed by Apple
- Send household invitations and waitlist confirmations
- Send you technical notices, updates, and support messages
- Respond to your comments, questions, and customer service requests
- Understand service usage and diagnose reliability issues
- Protect accounts, prevent abuse and unauthorized access, and enforce our Terms of Service
- Personalize and improve your experience
- Meet legal obligations and respond to lawful requests
Monthly Financial-Summary Emails
If your email address is verified and you have enabled marketing emails, we use financial records from your selected household (or an available household if none is selected) to prepare monthly summary emails. These can include the household name, net worth and changes in net worth, income, spending, cash flow, and spending by category. The summaries can include financial information shared by other household participants. We send your email address and the email content, including these financial summaries, to Resend for delivery. You can stop these emails using the unsubscribe link included in each monthly email. Unsubscribing does not stop account verification, password reset, or other service emails needed to operate your account.
Household Data Sharing
Accounts and financial information added to a household are shared with everyone in that household, including account balances, transactions, notes, receipt images, and related activity. Participants can also see membership information, such as names, email addresses, and roles. By adding financial information to a household, you consent to this sharing. The owner and anyone with the Member role can edit and delete shared accounts and transactions, including those added by someone else. Viewers have read-only access.
Leaving or being removed from a household ends your access to that household. It does not remove the accounts, transactions, or other financial information you added, or revoke their bank connections. Remaining household participants retain access according to their roles, and connected accounts may continue to receive new data. Owners cannot leave while they own the household: they must first transfer ownership to another participant, or delete the household. Contact us for help transferring ownership.
Before leaving, revoke any bank connections you want to stop sharing using the controls described above. If you also want to remove imported accounts and transactions from normal household views, use Delete Account in the account's edit screen while you still have access. A Viewer must ask the owner or a Member to do this. Deleting an account does not immediately erase its records: the owner or a Member can restore the account and its transactions while those records are retained. Deleting an account in Penny also does not immediately revoke bank access. For requests to delete personal information, contact privacy@penny.finance.
Participants may retain copies they have downloaded or received by email after access ends or records are deleted. If you give another application a Penny API token, that application can access household data within the token's permissions and your household role. You can revoke the token to stop further API access.
Images and Download Links
Transaction attachments, including receipts, and household export archives are stored privately and delivered using temporary download links. Anyone with a valid link can access the file until the link expires. Custom profile, household, account, and merchant images are served through public image URLs and can be viewed by anyone who has the URL. Avoid using sensitive documents as these display images.
Data Security
We use safeguards such as encrypted connections, hashed passwords, encrypted bank connection tokens, and authentication and household access controls to protect personal information. Authorized personnel may access information as needed to operate the service, provide support, investigate issues, or meet legal obligations. No method of transmission or storage is completely secure.
Data Sharing
We do not sell your personal information. We may share your information in the following circumstances:
- Service Providers and Connected Services: With providers that host Penny, store files, deliver emails, monitor errors, support sign-in, connect financial accounts, or manage subscriptions
- Household Participants and Authorized Applications: As described above, when you share a household or authorize API access
- Legal Requirements: When required by law or to respond to legal process
- Business Transfers: In connection with a merger, acquisition, or sale of assets
- With Your Consent: When you have given us permission to share your information
See our Service providers page for the providers we use, their purposes, and the types of information they process. Connected services such as Apple, Google, and Plaid also handle information under their own privacy policies. Our providers may process information in countries other than the one where you live.
Your Rights
You can contact privacy@penny.finance to request access to, correction of, or deletion of personal information. Depending on where you live and the law that applies, you may also have rights to receive a portable copy, object to or restrict processing, withdraw consent, or complain to a privacy regulator. We may need to verify your identity before acting on a request and will respond as required by applicable law.
You can update profile information in Penny, revoke financial connections as described above, and unsubscribe from marketing and monthly summary emails. Household owners can request an export of household records, including after subscription access expires. The export does not include receipt images; save those separately. Contact us if you need help accessing your personal information or cannot use an in-app control.
Deleting Your Penny Account
Use Settings → Delete Account to delete your Penny login and profile. This is different from deleting a financial account within a household. If you own a household with other participants, you must first transfer ownership or delete that household before deleting your Penny account. Contact us for help transferring ownership.
Deleting your Penny account removes your memberships and deletes households you still own and their associated records. It does not delete shared financial records in households owned by someone else. File cleanup and bank-connection revocation can take additional time after deletion; use the connection controls above to revoke access directly. Deleting a Penny account does not cancel an App Store subscription. See Subscriptions and Billing.
Data Retention
We retain account and financial records while they are needed to provide Penny, including records shared with an active household. Financial accounts and transactions removed from normal views may remain stored for restoration and history; hiding or deleting them from those views is not a request to erase all copies. Use account deletion or contact us to request deletion of personal information, subject to the household-sharing limits above.
Completed export archives expire after seven days and are scheduled for cleanup. Other retention periods depend on the record's purpose, whether it remains part of a shared household, and legal, security, or dispute-resolution needs. Deletion from active systems may not immediately remove copies in backups, delivery systems, or records held by connected services under their own policies. Contact us with questions about a particular record, including a waitlist entry or invitation.
Children's Privacy
Penny is intended for people aged 18 and older. We do not knowingly collect personal information from children under 18. If you believe a child has provided personal information, contact us so we can investigate and address it.
Changes to This Policy
We may update this policy and will post the revised version here with an updated date. We will provide any additional notice or seek consent required by applicable law for material changes.
Contact Us
For privacy questions or requests, email privacy@penny.finance.
