PennyPilot ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our mobile application, PennyPilot: Expense & Budget. By using the App, you agree to the terms of this Privacy Policy.
By default, PennyPilot is designed to operate as a completely localized application.
On-Device Processing: All financial transactions, budgets, financial goals, and net worth calculations are processed and stored strictly on your local device.
No Mandatory Transmission: If you use the App in its default offline mode, no personal or financial data is transmitted to us or any third-party servers.
If you explicitly choose to enable our Cloud Sync and Authentication features, the App will securely collect and transmit the following data to provide these services:
Account Credentials: Your email address, password, or authentication tokens (if signing in via Google) to create and secure your user account.
Financial Data: Your logged expenses, income, budgets, goals, and net worth records. This data is transmitted strictly to synchronize your account across multiple devices or provide secure backups. You can turn off the cloud sync anytime to stop this transmission. Cloud sync is a pro feature and is turned off by default.
Notification Access & Auto-Logging (PennyPilot Pro) :
What we collect: If you choose to enable the "Auto Log Contactless" feature, you must explicitly grant PennyPilot the "Notification Access" permission. When enabled, PennyPilot temporarily reads the content of incoming notifications generated by supported digital wallet applications on your device to extract transaction details (merchant name and amount).
How it is used: This data is used strictly for the automated creation of expense entries within your PennyPilot ledger.
Data Storage and Transmission: We do not transmit, sell, or share your notification data. All notification parsing and data extraction occurs locally on your device. The extracted transaction data is saved directly to your local device database. No notification contents or resulting transaction data are uploaded to our servers or shared with any third parties.
User Control: You may revoke Notification Access at any time via your device’s system settings, or toggle the feature off within the PennyPilot application.
For European Union residents and global users who opt into Cloud Sync, we ensure strict compliance with the General Data Protection Regulation (GDPR):
Server Location: All synchronized cloud data is physically stored and processed on secure Google Firebase servers located in Stockholm, Sweden (europe-north2 region), entirely within the European Union.
Encryption: Data is encrypted both in transit (using HTTPS/TLS) and at rest on Google's cloud infrastructure.
We partner with third-party service providers to provide core infrastructural services and application monetization. These services only access your data to perform specific tasks on our behalf:
Firebase Authentication (Google LLC): Used to securely handle user logins and account creation for users who opt into cloud features.
Cloud Firestore (Google LLC): Used to host, store, and sync encrypted financial data across devices for users who opt into cloud features.
Google AdMob (Google LLC): Used to display rewarded video advertisements that unlock temporary Premium features. By choosing to watch an ad, you consent to Google AdMob's data practices, which may include the collection of your Advertising ID (Google Ad ID), device information, app usage data, and personalized ad serving.
If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, we use the Google User Messaging Platform (UMP) SDK to request your explicit consent before collecting advertising data via Google AdMob. You may withdraw or manage your advertising consent at any time through the App's Settings screen.
We believe you should have absolute ownership of your financial data. Regardless of your location, you have the following rights:
Opt-In/Opt-Out: Cloud synchronization is 100% voluntary. You can disable cloud features at any time and revert to local storage. Notification Access & Auto-Logging is also 100% voluntary
Data Deletion (Right to be Forgotten): You can permanently delete your cloud account and all associated financial records directly through the App's settings menu. Upon execution, your Firebase Authentication record and Firestore data documents are permanently erased from our servers.
We comply with state-level privacy laws, including the California Consumer Privacy Act. We do not sell, trade, or rent your personal financial data to third parties. Your financial data is used strictly to provide the core application functionality.
However, please note that interacting with our rewarded advertisements allows our advertising partner (Google AdMob) to collect and share your Advertising ID for personalized advertising purposes, which may be classified as "sharing" or "selling" identifiers under California law. You can opt out of personalized ads at any time via your Android system settings: Settings → Google → Ads → Opt out of Ads Personalization.
PennyPilot does not knowingly collect or solicit personal data from anyone under the age of 13. If you believe a child has provided us with personal data, please contact us immediately to have it deleted.
If you have any questions, concerns, or data deletion requests regarding this Privacy Policy, please contact us at:
Customer Support Email: support@pennypilotfinance.com
Account Deletion Without the App: To request the permanent deletion of your PennyPilot cloud account and all associated financial data without using the app, please email us at the address above with the subject line "Account Deletion". We will erase your data within 7 days.