Privacy Policy
Last Updated: July 1, 2026
This Privacy Policy explains how Penny - AI Money Manager ("we", "our", or "us")
collects, uses, discloses, and safeguards your information when you use our mobile application
(the "App"). Please read this policy carefully. By using the App, you consent to the practices
described in this policy.
Contact Us: If you have any questions about this Privacy Policy, please contact us at
viduapps1@gmail.com.
1. Information We Collect
1.1 Information You Provide Directly
- Account Information: When you sign up, we collect your email address and display name. If you use Sign in with Apple, we receive the email and name you authorize Apple to share.
- Financial Data: You may manually enter or scan receipts to record financial transactions, including amounts, merchant names, categories, dates, and optional notes.
- Receipt Images: When you use the receipt scanning feature, the App processes images on-device using Apple Vision (iOS) or Google ML Kit (Android) for text recognition. The raw image may be transmitted to our backend server for AI-powered parsing to extract transaction details. We do not permanently store receipt images unless required for debugging with your consent.
- AI Chat Queries: When you use the AI Chat feature, your messages and relevant financial context (transaction summaries, category breakdowns) are sent to our backend server, which forwards them to a third-party AI LLM provider for processing.
- Budget & Category Preferences: You can set custom spending categories and monthly budget targets, which are stored locally and in our cloud backend if you enable sync.
1.2 Information Collected Automatically
- Device Information: We may collect device model, operating system version, and app version to diagnose issues and optimize performance.
- Usage Data: Anonymous usage statistics (feature interactions, screen views) may be collected to improve the App experience.
- Crash Logs: If the App crashes, anonymized diagnostic data may be sent to help us fix bugs.
1.3 Information from Third-Party Services
- Firebase Authentication: When you sign in with email/password or Sign in with Apple, Firebase Auth manages the authentication flow. We receive only the Firebase User ID, email, and display name.
- Apple App Store (In-App Purchases): When you purchase a premium subscription, Apple's StoreKit handles the transaction. We receive a purchase receipt token to validate and activate your subscription. We do not see your payment card details.
2. How We Use Your Information
We use the collected information for the following purposes:
- To provide and maintain the App: Process transactions, generate financial insights, manage budgets, and deliver AI chat responses.
- To authenticate your identity: Verify login credentials and manage account access.
- To process premium subscriptions: Validate in-app purchase receipts with Apple and unlock premium features based on entitlement status.
- To enable cloud sync: Synchronize your transaction data across devices via our self-hosted backend API server (
iptvstarshare.com) when you enable the cloud sync feature (premium feature).
- To improve our services: Analyze usage patterns to improve features, fix bugs, and optimize performance.
- To communicate with you: Send transactional emails (e.g., subscription confirmation, account deletion confirmation) and critical service updates.
- To comply with legal obligations: Respond to lawful requests from authorities and enforce our Terms of Service.
3. Data Storage and Security
3.1 Where Your Data is Stored
- Local Storage (Your Device): Your financial transactions are stored locally on your device using encrypted Hive databases. Your authentication tokens are stored in the platform secure keystore (iOS Keychain / Android EncryptedSharedPreferences).
- Cloud Storage (Backend Server): If you enable cloud sync (premium feature), your transaction data, categories, budgets, and settings are synced to our self-hosted backend API server at
iptvstarshare.com and stored in an encrypted SQLite database on the server.
- Account & Subscription Data: Your user ID, subscription status, premium expiry dates, and purchase receipt tokens are stored in a separate SQLite database on the same backend server to validate ongoing entitlement.
3.2 Data Security Measures
- All network communication between the App and our backend is encrypted using TLS 1.3 with certificate pinning to prevent man-in-the-middle attacks.
- Authentication tokens are stored in platform-specific secure storage (iOS Keychain, Android EncryptedSharedPreferences).
- Receipt images are processed and discarded — they are not permanently retained on our servers.
- Backend API endpoints enforce per-user data isolation — every request is authenticated via Firebase ID token verification, and all database queries are scoped to the authenticated user's ID.
- Our backend enforces request binding (nonce-based), rate limiting, and Firebase ID token verification to prevent unauthorized access.
4. Data Sharing and Third-Party Services
We do not sell your personal information. We share data only with the following third-party services necessary for the App's operation:
- Google Firebase (Firebase Auth, Crashlytics): Used for user authentication and crash reporting. Firebase Privacy Policy
- Third-Party AI LLM Provider: Used to process AI Chat queries and receipt parsing. Chat messages and transaction context may be sent to a third-party AI language model provider for response generation. The provider is contractually obligated not to use your data for model training.
- Apple Inc. (App Store, StoreKit, Sign in with Apple): Used for app distribution, in-app purchase processing, and authentication. Apple Privacy Policy
- Apple Vision / Google ML Kit: On-device text recognition from receipt images. The App uses Apple Vision on iOS and Google ML Kit on Android — both operate entirely on-device with no image data transmitted to third-party servers for OCR.
- Codemagic (CI/CD): Used for building and distributing the App. Build artifacts may include anonymized metadata. Codemagic Privacy Policy
5. Data Retention and Deletion
- Account Data: We retain your account data and associated transaction records for as long as your account is active. You may delete your account at any time from the App Settings → Delete Account.
- Account Deletion: When you delete your account, the following occurs:
- Your Firebase Authentication account is deleted.
- All transaction records associated with your user ID are permanently removed from our backend database.
- Your local data on the device remains until you manually clear it or uninstall the App.
- Cloud data on the backend server associated with your user ID is deleted.
- Backup Data: Regular database backups of our backend server are retained for up to 30 days for disaster recovery purposes. After account deletion, your data will be removed from the next scheduled backup rotation.
- Receipt Images: We do not permanently store receipt images. They are processed temporarily for OCR and AI parsing, then discarded.
- AI Chat Logs: Chat message history may be retained temporarily for context continuity within a session. We do not maintain long-term archives of chat conversations.
6. Your Rights and Choices
6.1 Access and Portability
You can export all your transaction data at any time from App Settings → Export All Data (premium feature) or by using the Backup & Restore feature to export a JSON backup of all your data.
6.2 Correction and Deletion
- You can edit or delete individual transactions directly in the App.
- You can clear all local data from App Settings → Clear All Data.
- You can delete your entire account and all associated data from App Settings → Delete Account. This triggers server-side deletion of all your records.
6.3 Opt-Out of Cloud Sync
Cloud sync is an optional premium feature. You can disable it at any time from App Settings → Cloud Sync. Your local data remains intact and functional.
6.4 GDPR Rights (EEA Users)
If you are located in the European Economic Area, you have the following additional rights:
- Right to Access: Request a copy of the personal data we hold about you.
- Right to Rectification: Request correction of inaccurate data.
- Right to Erasure ("Right to be Forgotten"): Request deletion of your data (this can be done via the Delete Account feature).
- Right to Restrict Processing: Request limitation on how we use your data.
- Right to Data Portability: Request your data in a structured, machine-readable format.
- Right to Object: Object to processing of your personal data.
To exercise any of these rights, contact us at viduapps1@gmail.com. We will respond within 30 days.
7. Children's Privacy
The App is not intended for children under the age of 13 (or 16 in the EEA). We do not knowingly collect personal information from children. If we become aware that a child has provided us with personal data, we will take steps to delete it. If you believe a child has provided us with personal information, please contact us immediately.
8. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by:
- Updating the "Last Updated" date at the top of this policy.
- Sending an in-app notification or email for significant changes.
- Prompting you to review the updated policy on your next app launch for material changes.
Your continued use of the App after any changes constitutes your acceptance of the updated policy. We encourage you to review this policy periodically.
9. Data Controller and Contact Information
Data Controller: Suraj Bhosale
Contact Email: viduapps1@gmail.com
If you have any questions, concerns, or complaints regarding this Privacy Policy or our data practices, please contact us at the email above. We will investigate and resolve your concern promptly.
For EEA Users: If you are unsatisfied with our response, you have the right to lodge a complaint with your local data protection authority (DPA).