Privacy Policy
Last updated: 27 September 2026
The short version
Your expenses live on your phone. We can't see them.
If you turn on family sharing, the expenses you mark shared are stored on our server so your household can see them too. Everything else stays local.
When you scan a receipt, your phone reads the words on it and sends that text to Google to be sorted into items and prices. When the phone cannot read it, the photo is sent instead. If you use Ask, the one sentence you type goes the same way. None of it is stored anywhere afterwards, and the app asks your permission before any of it ever leaves your phone — you can say no and keep using everything else.
We don't sell your data. We don't run ads. We don't track you across other apps.
What we collect, and why
Stays on your phone only
Unless you turn on family sharing, all of this is on your device and nowhere else:
- Your expenses, and the individual items on each receipt
- The photo of every receipt you scan, so you can look at the original later
- Your budgets and category limits
- Your shopping list
- Your recurring bills
- Corrections you make to item names, and the names the app learns from them
We have no way to read any of it.
Receipt photos never leave your phone. They are not uploaded to your household, and they are not written into an export file either — an export you save to a cloud drive carries the figures, never the pictures. You can see how much space they use, and delete them, at Settings → Scanning & data.
Only if you create an account
You only need an account to share a household. Then we store:
| What | Why |
|---|---|
| Email address | To sign you in and recover your account |
| Password | Stored hashed — never in a readable form, not even to us |
| The name you enter | So the other people in your household see a name beside a shared expense instead of an anonymous row. You choose it when you sign up, you can change it at any time at Settings → Family → Your name, and the only people who ever see it are the members of a household you joined |
| Household membership, role and permissions | To know whose data you may see, and what the household owner has allowed you to change |
| Expenses you marked shared | So your household can see them |
| Budgets and shopping list for the household | So they stay in step across phones |
Expenses you mark private are never uploaded.
Scanning a receipt
Reading a receipt takes two steps, and they happen in different places.
Step one — the words come off the paper, on your phone. In English, Spanish, French, German, Portuguese, Turkish and Indonesian, your phone does this itself, using the text recognition built into iOS and Android. Nothing is sent, and the photo stays where it is.
Step two — the words are sorted into items and prices. That part goes to
Google's Gemini API, through our server, because working out that a line
reading GV WHL MLK 1GAL 3.48 is a gallon of milk at $3.48 is the thing the
model is for.
So what is actually sent depends on what your phone managed:
| What leaves your phone | |
|---|---|
| Your phone read the receipt | The text only. The photo never leaves |
| Your phone could not read it, or your language is not one of the seven above | The photo, as a fallback, so the scan still works |
Either way:
- Nothing is saved on our server, and nothing is written to any log — not the photo, not the text
- What comes back is the items and prices, and they are kept on your phone
- Google's handling is governed by their own terms: https://ai.google.dev/gemini-api/terms
The photo you took is saved on your phone, and only on your phone, so you can open the original receipt again later. See Stays on your phone only above.
If you would rather nothing left your phone at all, you can add every receipt by hand and use the whole app without ever scanning one.
Ask
Ask lets you type one sentence — “add milk to my list”, “how much is left this month” — instead of tapping through the app. That sentence is sent to Google's Gemini API, through the same server the receipt photo uses, to work out what you meant by it.
- Nothing of yours goes with it. Not your expenses, totals, budgets, merchants, history, account or any device identifier. The request contains the sentence and the app's fixed list of category names — the same list for every user, whoever they are.
- The model decides what you meant; your phone does the rest. When Ask answers “$142 left this month”, that figure was worked out on your phone from data Google never received. The model only ever returns an intent.
- The sentence is not saved on our server and not written to any log.
- Ask is optional, and it is a shortcut rather than a feature of its own — everything it can do can also be done by tapping, with no network at all. If Ask cannot reach the network, or you have not given permission, a parser built into the app handles the common sentences on the phone.
Permission before anything leaves your phone
The first time you scan a receipt, and the first time you use Ask, the app stops and asks. The request names Google, says that the receipt's text or its photo is what gets sent, and says what is kept. Allow or Not now.
- Saying no is a supported answer, not a broken app. Typing receipts in by hand, budgets, category limits, your shopping list, recurring bills, history, search and Price Watch are all local and all keep working.
- You can change your mind either way at Settings → Legal → Reading receipts with AI.
- Nothing is sent while that permission is off.
Barcodes
If you scan a product barcode to add it to your shopping list, the barcode number — and nothing else — is sent to Open Food Facts, a non-profit open food database, to look up the product name.
- The camera reads the barcode on your phone. No image is uploaded.
- No account, no device ID and no other information goes with the request. Open Food Facts has no way to know who asked, or what else is on your list.
- The answer is stored on your phone, so scanning the same product again works offline and sends nothing at all.
- Their privacy policy: https://world.openfoodfacts.org/privacy
- Product data is used under the Open Database Licence and is credited in the app.
Barcode scanning is optional. Typing an item name never touches the network — suggestions come from your own history and a list built into the app.
Help clips
The step-by-step guides in Settings → How it works are short animations kept on our website rather than inside the app, so the app stays small. The first time you play one it downloads and is then cached on your phone; after that it plays offline and sends nothing.
- The request asks for a clip by name. It carries no account, no expense data and no device identifier.
- Like any web server, ours records the ordinary request details — an IP address and a timestamp. We do not connect those to your account or to anything in your ledger, and we do not use them for analytics.
What we never collect
- Bank logins or card numbers — we never ask for bank access at all
- Location
- Contacts
- Advertising identifiers
- Analytics on how you use the app
Who else can see your data
Nobody, except:
- Members of a household you joined — the expenses you marked shared, and the name you chose
- Our infrastructure providers, who process data on our behalf:
- Supabase — database and accounts, if you create one
- Vercel — our server: it relays receipt text (or the photo) and Ask sentences on their way to Google, and hosts the help clips
- Google — sorts the receipt into items and prices, and works out what an Ask sentence means. Their handling is governed by their own terms: https://ai.google.dev/gemini-api/terms
- Open Food Facts — receives a barcode number when you scan one, nothing else
- Stripe — payments. Not active in this version: nothing is for sale, so no payment data exists yet. Listed here because it applies the moment it is.
We do not sell your data. We do not share it for advertising. We have never received a government request for user data; if that changes, we will say so here.
Your rights
You can take your data out at any time. Settings → Export gives you everything in a readable file, with no account required.
You can delete everything, yourself, in the app.
- Settings → Reset all data wipes this device.
- Settings → Account → Delete account permanently removes your account and every piece of data synced to it. No email, no waiting on us. If you were the owner of a household with other people in it, ownership passes to another adult so your family does not lose their own records.
If you would rather we did it, email support@pennyroost.com and we will action it within 30 days.
If you are in California (CCPA) or the EU/UK (GDPR) you have rights to access, correct, delete and port your data, and to object to processing. Everything above is how you exercise them; email us if you would like it done another way. You may also complain to your data protection authority.
We keep server data while your account exists. After deletion it is removed from live systems immediately and from backups within 30 days.
Security
- Everything travels over HTTPS
- Passwords are hashed by our authentication provider
- Sign-in tokens are held in your phone's Keychain / Keystore
- Household data is isolated at the database level, so one household's rows cannot be returned to another even if our app code has a bug
- Receipt photos, their contents and Ask sentences are never written to logs
No system is perfect. If you find a security problem, email support@pennyroost.com and we will respond.
Children
The app is not directed at children under 13 and we do not knowingly collect their data. A parent may add a child to a household; in that case the parent provides the account and the child's expenses marked private stay private from other members. If you believe a child under 13 created their own account, contact us and we will remove it.
Changes
If this policy changes in a way that affects you, we will tell you in the app before it takes effect. The date at the top always reflects the current version.
Contact
InfraSpatial Solutions LLC — support@pennyroost.com