Privacy Policy

Last updated: 27 September 2026


The short version

Your expenses live on your phone. We can't see them.

If you turn on family sharing, the expenses you mark shared are stored on our server so your household can see them too. Everything else stays local.

When you scan a receipt, your phone reads the words on it and sends that text to Google to be sorted into items and prices. When the phone cannot read it, the photo is sent instead. If you use Ask, the one sentence you type goes the same way. None of it is stored anywhere afterwards, and the app asks your permission before any of it ever leaves your phone — you can say no and keep using everything else.

We don't sell your data. We don't run ads. We don't track you across other apps.


What we collect, and why

Stays on your phone only

Unless you turn on family sharing, all of this is on your device and nowhere else:

We have no way to read any of it.

Receipt photos never leave your phone. They are not uploaded to your household, and they are not written into an export file either — an export you save to a cloud drive carries the figures, never the pictures. You can see how much space they use, and delete them, at Settings → Scanning & data.

Only if you create an account

You only need an account to share a household. Then we store:

What Why
Email address To sign you in and recover your account
Password Stored hashed — never in a readable form, not even to us
The name you enter So the other people in your household see a name beside a shared expense instead of an anonymous row. You choose it when you sign up, you can change it at any time at Settings → Family → Your name, and the only people who ever see it are the members of a household you joined
Household membership, role and permissions To know whose data you may see, and what the household owner has allowed you to change
Expenses you marked shared So your household can see them
Budgets and shopping list for the household So they stay in step across phones

Expenses you mark private are never uploaded.

Scanning a receipt

Reading a receipt takes two steps, and they happen in different places.

Step one — the words come off the paper, on your phone. In English, Spanish, French, German, Portuguese, Turkish and Indonesian, your phone does this itself, using the text recognition built into iOS and Android. Nothing is sent, and the photo stays where it is.

Step two — the words are sorted into items and prices. That part goes to Google's Gemini API, through our server, because working out that a line reading GV WHL MLK 1GAL 3.48 is a gallon of milk at $3.48 is the thing the model is for.

So what is actually sent depends on what your phone managed:

What leaves your phone
Your phone read the receipt The text only. The photo never leaves
Your phone could not read it, or your language is not one of the seven above The photo, as a fallback, so the scan still works

Either way:

The photo you took is saved on your phone, and only on your phone, so you can open the original receipt again later. See Stays on your phone only above.

If you would rather nothing left your phone at all, you can add every receipt by hand and use the whole app without ever scanning one.

Ask

Ask lets you type one sentence — “add milk to my list”, “how much is left this month” — instead of tapping through the app. That sentence is sent to Google's Gemini API, through the same server the receipt photo uses, to work out what you meant by it.

Permission before anything leaves your phone

The first time you scan a receipt, and the first time you use Ask, the app stops and asks. The request names Google, says that the receipt's text or its photo is what gets sent, and says what is kept. Allow or Not now.

Barcodes

If you scan a product barcode to add it to your shopping list, the barcode number — and nothing else — is sent to Open Food Facts, a non-profit open food database, to look up the product name.

Barcode scanning is optional. Typing an item name never touches the network — suggestions come from your own history and a list built into the app.

Help clips

The step-by-step guides in Settings → How it works are short animations kept on our website rather than inside the app, so the app stays small. The first time you play one it downloads and is then cached on your phone; after that it plays offline and sends nothing.

What we never collect


Who else can see your data

Nobody, except:

We do not sell your data. We do not share it for advertising. We have never received a government request for user data; if that changes, we will say so here.


Your rights

You can take your data out at any time. Settings → Export gives you everything in a readable file, with no account required.

You can delete everything, yourself, in the app.

If you would rather we did it, email support@pennyroost.com and we will action it within 30 days.

If you are in California (CCPA) or the EU/UK (GDPR) you have rights to access, correct, delete and port your data, and to object to processing. Everything above is how you exercise them; email us if you would like it done another way. You may also complain to your data protection authority.

We keep server data while your account exists. After deletion it is removed from live systems immediately and from backups within 30 days.


Security

No system is perfect. If you find a security problem, email support@pennyroost.com and we will respond.


Children

The app is not directed at children under 13 and we do not knowingly collect their data. A parent may add a child to a household; in that case the parent provides the account and the child's expenses marked private stay private from other members. If you believe a child under 13 created their own account, contact us and we will remove it.


Changes

If this policy changes in a way that affects you, we will tell you in the app before it takes effect. The date at the top always reflects the current version.

Contact

InfraSpatial Solutions LLC — support@pennyroost.com