Privacy Policy
Last updated 28 September 2026
PennyWise is a personal expense tracker. Your ledger belongs to you: we do not sell it, we do not share it with advertisers, and we do not use it to market loans or financial products to you. Most of what the app does happens on your phone.
Who we are
PennyWise is built and operated by Aditya Jain, an independent developer. For anything in this policy, write to aditya.official824@gmail.com.
What we collect
What you put in. The transactions you log — amount, merchant, date, category, payment method, and any note or tag you add. Alongside them, the figures you enter during setup: your name, monthly income, rent, EMIs and savings goal, plus any goals, bills and budgets you create.
Your account. PennyWise needs an account. Until you sign in, the app works under a temporary anonymous id, and what you log carries over when you do. We keep your email address, and your password if you set one (stored by our sign-in service, never by us in readable form). If you sign in with Google, Google sends us your email address, your name and your profile picture; we never see your Google password. We email you only to confirm your address and to reset your password.
A short list of product events. To understand whether the app is actually useful, we record a fixed set of named events — things like “the app was opened”, “a transaction was logged” and how it was logged, and “a day was closed”. There is no third-party analytics SDK, no advertising identifier, and no device fingerprinting. These events never contain free text, merchant names or amounts.
Feedback you choose to send from the app is stored with your account, your account email, the app version and the platform, so we can reproduce the problem and reply. It contains only what you typed; your ledger is not attached.
Coach questions. We do not keep the questions you ask the Coach or its answers. For the AI Coach on Plus we store one number: how many AI requests your account has made this month, so the monthly limit can work.
We do not collect your contacts or your browsing, and your location never reaches our servers. If you allow it, your location goes to OpenStreetMap’s services to find shops nearby or a place you asked about, and nowhere else (below). Second Thought, if you turn it on, checks which app is in front of you on your phone; what it saves is described under “Second Thought”. We have no connection to your bank and cannot move money.
What never leaves your phone
Payment notifications. If you turn on notification capture, the app reads your notifications on your device to find completed payments. That text is parsed on the phone and is never uploaded. A payment or incoming credit reported by your bank’s app, a UPI app, or your bank’s SMS (from a registered bank sender) is added to your ledger automatically, marked “Auto”, and PennyWise tells you with a notification you can undo. A message from a chat app or a person waits for you to confirm it. What is saved to your account is the entry itself: the amount, the payee, the date, whether money went out or came in, and the bank’s reference number. You can turn automatic logging off in Profile → More → Settings.
The capture log. So you can see why a payment was or was not picked up, the app keeps a record of the last 200 notifications it looked at, on the phone. For anything that looked like a payment it keeps the text and what it decided. For everything else, one-time codes included, it keeps only which app sent it and what happened, never the words. It is never uploaded, it is deleted when you delete your account, and you can clear it any time from “See what Penny read” in the auto-capture settings. Sharing an entry, if you ever want to send us one, is something only you can do.
Receipt photos. When you scan a receipt, the image is read on your device using Google ML Kit’s on-device text recognition. The photo is not uploaded to us, and we do not keep it. Only the expense you confirm is saved.
The Coach
On Free, the Coach works entirely on your phone. It answers from your own numbers with fixed rules, and what you ask it is not sent anywhere. (A question about ordering groceries can look up shops nearby, if you allow location; see “Shops nearby”.)
On Plus, the Coach can answer with an AI model. When it does, the phone sends, through PennyWise’s own server: your question, the last few messages of the chat, a summary of your numbers (your first name, currency, income, rent, EMIs and savings goal, monthly and category totals for recent months, and your goals, bills and budgets by name and amount — about what Home shows), and, if the question needs them, the matching entries from your ledger (date, merchant, amount, category and payment method). It never sends your email address, your account id, your notes, or your location. Before your first AI answer, the app shows you this and asks you to continue.
The model is provided by Sarvam AI, whose service is hosted in India. We have set our Sarvam account so that what the Coach sends is not used to train their models and is not retained after the answer. PennyWise’s server passes the request on and stores only the monthly count described above; it never logs what you or the Coach wrote. If we ever change the AI provider, we will tell you in the app first.
The Coach answers questions about your money and about PennyWise. Anything else — and any request to pick a stock, fund or app — is answered on your phone with a fixed reply and is never sent to the AI. If you report an answer, the question and that answer are sent to us with the reason you chose, so we can check it.
Travel and shop questions. If you ask whether a cheaper ride exists or a shop is nearby, and you allow location, the app looks the place up on OpenStreetMap: the destination you named and the area around you go to its Nominatim service, and your coordinates go to its Overpass service to find shops. The AI model is never given your coordinates. A local fare you teach the Coach is kept on your phone only.
A question you ask Penny out loud is handled the same way as a typed one, once your phone has turned it into text (see “Voice logging” below).
Second Thought (optional, Android)
Cap an app — a food-delivery or quick-commerce app, say — and PennyWise can show a card the moment you open it, with what you have spent there this month. To do that it needs two permissions you grant in Android Settings, never in a pop-up: Usage access, so it can tell which app just came to the front, and Display over other apps, so the card can appear on top. Both are off until you turn them on, and the card is never drawn over a payment app.
Which app is in front is checked on your phone and compared against the caps you set; what else you do in other apps is never recorded. The list of apps you can pick from is read from your phone when you open the picker and is not stored. The apps you choose for a cap are saved with that cap in your account. When a card appears, we save which capped app it was, when, and whether you went on or backed out, with your caps, so the app can show how often it helped (the last 100 of these).
Shops nearby (optional)
If you allow location, the app can tell you how many grocery shops are within a short walk when you open a quick-commerce app you have capped, or when you ask the Coach about ordering groceries or a ride. To do that it sends your coordinates — one latitude and longitude — to the OpenStreetMap Overpass service (overpass-api.de, or its independent mirror overpass.kumi.systems when the first is down), which returns the shops on its map nearby; for a ride question, the area around you also goes to OpenStreetMap’s Nominatim service to find the place you named. These are the only places your location goes. It is never sent to PennyWise’s own servers or to the AI model, never stored by us, and never used for anything else. The app makes no claim about what a shop charges; it only says what the delivery app adds on top.
Voice logging, stated plainly
PennyWise can listen for “Hey Penny” while the app is open in front of you. That listening happens entirely on your phone, using a small speech model built into the app that recognises only that phrase. No audio leaves your phone for the wake word, and none of it is recorded or kept. It pauses while you are typing.
It stops when you leave the app. PennyWise does not listen in the background, and you can switch listening off entirely in Profile.
When you start a voice session — by saying “Hey Penny” or holding the Penny button — PennyWise uses your phone’s speech recognition to turn that speech into text. On most Android devices that service is provided by Google, and that audio may be sent to Google to be transcribed, under Google’s privacy policy. We do not receive or store the audio — only the text it produces, and only if you save the expense.
If you would rather no audio ever left your phone, switch voice off in Profile. Every feature is reachable by typing.
Exports and the home-screen widget
When you export your data — a CSV on any plan, and on Plus a formatted Excel file or a PDF report, including custom reports for a period, categories or payment methods you choose — the file is created on your phone and saved to its Downloads folder under PennyWise. We do not receive a copy. Where it goes after that is up to you. On Plus, the settings of each custom report you make (its format, file name, filters and number of entries, the last 50) and your “every month” choice are saved to your account so you can make it again; the files themselves never are.
If you add the PennyWise widget to your home screen, it shows today’s spending and what is left this month to anyone who can see your screen. Remove the widget to stop that.
Crash reports
When the app fails, PennyWise records what went wrong so the fault can be found and fixed: the error message, the technical stack trace, the version of the app and the kind of device. It is stored in the same private database as the rest of your account and is readable only by us.
It never includes anything from your ledger — no merchants, no amounts, no categories, no voice transcripts. Nothing is sent to a third-party crash-reporting service, because there isn’t one: the reports go to the same place your own data already does.
Where your data is stored
Your ledger is kept on your device and synced to our database so it survives a lost or replaced phone. That database is hosted by Supabase in Singapore. Access is enforced per row: a signed-in account can read and write only its own data, and this is enforced by the database itself rather than by the app.
Data is encrypted in transit and at rest, and the app keeps your sign-in token in Android’s secure Keystore. To lock PennyWise behind your fingerprint, face or passcode, use your phone’s own app lock in system settings; PennyWise no longer carries a lock of its own.
Who else can see it
Nobody, other than the services needed to run the app: Supabase (database, sign-in and the Coach’s server), Sarvam AI (the AI Coach on Plus, as described above), OpenStreetMap (place and shop lookups, only if you allow location), Google (if you use Google sign-in; for speech recognition as described above; and Gmail, which sends our account emails), Google Play (distribution, crash reporting, and payment if you subscribe to Plus), RevenueCat (subscription receipts), and open.er-api.com (exchange rates, fetched when you change currency; it receives only a normal web request, nothing from your ledger). If you buy Plus, RevenueCat receives your account id, Google Play’s purchase token, your device and system version, and a country worked out from your connection, so the subscription can be matched to your account; we keep the purchase events it sends us (product, price, dates) with your account. It never receives anything from your ledger, and no card details pass through PennyWise or RevenueCat — Google Play handles the payment.
We do not sell your data. We do not share it with advertisers, data brokers, credit bureaus or lenders. PennyWise does not show ads and does not refer you to loans or financial products.
Permissions, and why each exists
- Microphone — voice logging, and listening for “Hey Penny” while the app is open. Never in the background, and never off your phone unless you start a voice session.
- Camera and photos — photographing or choosing a receipt to scan.
- Notification access — optional, off unless you turn it on, so payment notifications can be read on-device.
- Notifications — reminders you choose to switch on.
- Location — optional, off unless you turn it on, so the app can list shops within a walk of you. See “Shops nearby” above for exactly where it goes.
- Usage access and Display over other apps — optional, granted in Android Settings, for Second Thought only. See above. The app never lists or reports what you do in other apps.
Every one of these is optional and the app works without it.
Deleting your data
Profile → More → Settings → Delete account and all data erases everything we hold about you: every transaction, goal, bill, budget and profile field, your product events, feedback, crash reports, subscription receipts and Coach usage count, then the account itself, and clears what the app kept on the phone. It is immediate and cannot be undone. It does not cancel a Plus subscription: cancel that in Google Play, which bills it.
Two records are kept by others: RevenueCat keeps a record of a purchase under an anonymous id, and Google Play keeps its own order history. Cannot reach the app? Email us from your account’s address and we will delete the account within 30 days. You can export your data at any time from Profile.
How long we keep it
Your ledger is kept for as long as your account exists, because that is the point of it. Delete your account and it is gone. Product events, crash reports, purchase events and the Coach usage count are kept while your account exists and are deleted with it.
On your phone only
Some things never leave your phone at all: your accessibility and theme settings, the list of notifications PennyWise sent you, local fares you teach the Coach, and the audio used for “Hey Penny”.
The website
PennyWise’s website is hosted by Vercel, which keeps standard server logs and gives us page-view and speed statistics without cookies or advertising identifiers. If you join a waitlist there, we keep the email address you give until you ask us to remove it.
Why we use your data
We use your ledger and account to provide the app you signed up for. Notification access, location, the microphone, usage access and display over other apps are used only because you turned them on, and you can turn any of them off in Android Settings. Crash reports and product events are used, in our legitimate interest, to find faults and to see whether features help.
Where it is processed
Your data is stored in Singapore (Supabase) and, for AI Coach answers, processed in India (Sarvam AI). Subscription records pass through the United States (RevenueCat, Google). Wherever it goes, it is handled as this policy describes.
Your rights
Wherever you live, you can see, correct, export and delete your data from the app, and you can withdraw a permission at any time. To ask for anything the app does not do, or to complain, email aditya.official824@gmail.com; we reply within 30 days.
- India (Digital Personal Data Protection Act): the address above is our grievance contact. You may nominate someone to exercise your rights if you cannot, and you can complain to the Data Protection Board of India.
- EU and UK: you have the rights of access, correction, erasure, portability, restriction and objection, and you can complain to your data protection authority.
- California: we do not sell or share your personal information, and you will not be treated differently for using your rights.
- UAE, Singapore, Canada and Australia: the same access, correction and deletion apply under your local privacy laws.
Children
PennyWise is for people 13 and over. If you are under 18, use it with a parent or guardian's consent; they can ask us to see or delete your data at any time. We do not knowingly collect data from children under 13, and we delete it if we learn we have.
Changes
If this policy changes in a way that affects you, we will say so in the app before the change takes effect. The date at the top always reflects the current version.