Privacy Policy for PenniBook & PenniBook Pro

Last Updated: August 2, 2026


PenniBook ("we," "our," or "us") is committed to protecting your privacy and ensuring you have a transparent, secure experience when using our mobile application (PenniBook & PenniBook Pro). This Privacy Policy explains what information we collect, how we process and protect it, and your rights regarding your personal and financial data.

By downloading, accessing, or using PenniBook, you agree to the terms described in this Privacy Policy.


1. INFORMATION WE COLLECT

A. Account & Profile Information

• Google Authentication Data: When you choose to sign in with Google, we collect your basic profile details, including your Display Name and Email Address provided by Google Firebase Authentication.

• Guest Mode Data: If you choose "Continue as Guest," no personal identity details (like email or Google account ID) are collected or stored on our cloud servers.

• User Custom Profile: In both Google Sign-In and Guest Mode, you provide a Display Name and Preferred Currency symbol to customize your local experience.

B. Financial, Ledger & Transaction Data

• Personal Transactions & Budgets: All personal financial entries, custom wallets, budgets, bills, and category logs are stored locally on your device using encrypted Room database storage.

• Collaborative Shared Account Data: When you create, join, or interact with a Shared Group Workspace, transactions, group names, balances, settlement calculations, and member attribution names ("You" vs. Member Name) are synchronized in real time via Cloud Firestore to enable live collaboration among group members.

C. Device & Technical Information

• Security Data: If enabled, biometric prompt credentials (fingerprint/face recognition) or PIN passcodes are processed entirely on your device via Android's local BiometricPrompt API. We never store, transmit, or have access to your biometric credentials or PIN.

• Device Properties: We may collect non-identifiable technical data, such as your device model, operating system version (e.g., Android 16/SDK 36), app version, and country code, for system optimization and troubleshooting.

D. Anonymous Analytics & Crash Reports

We utilize Google Analytics for Firebase and Firebase Crashlytics to collect aggregated, non-personally identifiable diagnostic data (e.g., crash stack traces, feature engagement rates, and performance metrics) to improve app stability and user experience. Learn more at: https://firebase.google.com/support/privacy.


2. HOW WE USE YOUR INFORMATION

We use the information we collect strictly to operate, maintain, and enhance PenniBook services, specifically to:

• Authenticate your account and maintain session continuity across app restarts.

• Synchronize collaborative shared account ledgers, invites (`pennibook://join`), dynamic creator member attribution, and automated debt settlement calculations in real time.

• Execute cloud database backups and data restoration procedures when requested.

• Render visual analytics charts, spending insights, and local notification reminders (e.g., bill/EMI alerts).

• Respond to support requests sent to our team.

We NEVER sell, rent, monetized trade, or share your personal information or financial ledger data with third-party advertisers or data brokers.


3. DATA ISOLATION & STORAGE ARCHITECTURE

• Strict Data Isolation: Personal transactions and shared group ledgers are strictly isolated from each other. Personal ledgers remain local and private to your device unless cloud sync is initiated by you.

• Real-time Delete Propagation: Actions performed within Shared Accounts (such as deleting shared entries or leaving group workspaces) propagate deletion rules across Cloud Firestore snapshot listeners automatically.

• Local Device Security: Offline files, local database schemas, CSV parses, and PDF exports rendered by the application remain secured within Android's local application sandboxing and encryption boundaries.


4. THIRD-PARTY SERVICES

PenniBook integrates trusted infrastructure providers to deliver cloud features:

• Firebase Authentication: For secure Google Sign-In identity management.

• Cloud Firestore: For real-time database synchronization and shared ledger hosting.

• Firebase Analytics & Crashlytics: For crash diagnostics and stability tracking.

These providers process data strictly in compliance with industry-standard privacy framework regulations.


5. YOUR DATA RIGHTS & CONTROL

• Exporting Data: You can export your transaction history at any time to PDF or CSV formats via the app's Data Management tools.

• Deleting Account & Data: You can clear local database storage at any time from the app Settings or uninstall the app to remove local entries. Leaving or deleting a Shared Group Workspace immediately detaches your profile from that group's real-time cloud snapshot listener.

• Unlinking Google Account: You can convert a Guest session to a Google account or unlink third-party credentials at any time within Settings.


6. DATA RETENTION AND DELETION POLICY

PenniBook gives you full control over your personal and financial data. You can delete or request the deletion of your data at any time through the following mechanisms:

A. Local Device Data Deletion

• Clear Local Data: You can immediately wipe all transactions, custom wallets, budgets, and settings stored on your device by going to App Settings > Data Management > Clear All Data, or by clearing the app data/cache in your Android System Settings.

• App Uninstallation: Uninstalling the PenniBook app instantly removes all local database files stored in your device's isolated storage sandbox.

B. Cloud Data Deletion (Google Accounts & Shared Workspaces)

• Leaving a Shared Group Workspace: When you leave or delete a Shared Account, your dynamic attribution and profile connection are instantly removed from the group's active Cloud Firestore snapshot listener.

• Complete Cloud Account & Data Erasure: If you signed in with Google and wish to permanently delete your cloud account, synced backups, and associated cloud profile records from our servers, you can:

  1. Use the "Delete Account & Cloud Data" option inside App Settings. or

  2. Send an email request directly to pennibook.support@gmail.com with the subject line "Request Data Deletion" from your registered Google email address. 

Upon receiving an email deletion request, all associated cloud backups, authentication records, and Firestore user profiles will be permanently deleted from our servers within 7 business days.


7. CHILDREN'S PRIVACY

PenniBook is not intended for use by children under the age of 13. We do not knowingly collect or solicit personal information from children under 13.


8. CHANGES TO THIS PRIVACY POLICY

We reserve the right to update or modify this Privacy Policy at any time. When changes are made, we will update the "Last Updated" date at the top of this policy. Your continued use of PenniBook after any changes indicates your acceptance of the updated terms.


9. CONTACT US

If you have any questions, concerns, or inquiries regarding this Privacy Policy or data security in PenniBook, please contact us at:


PenniBook Support Team

Email: pennibook.support@gmail.com