Last Updated: June 27, 2026
1. Introduction
Welcome to Penny Sense ("we," "our," or "us"). We are committed to protecting your privacy and ensuring the security of your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our financial management, bookkeeping, and receipt processing services, including — when you choose to connect a financial account — the bank and credit-card account data we access on your behalf (see "Bank Account Connections").
2. Information We Collect
2.1 Personal Information
We collect the following types of personal information:
- Account Information: Name, email address, and password when you create an account
- Phone Numbers: Mobile phone numbers for SMS receipt processing (optional feature)
- Financial Data: Receipt images, transaction details, vendor names, amounts, dates, and categories
- Payment Information: Credit card statements, bank account information for reconciliation (stored securely and encrypted)
- Bank Connection Data: When you link a bank or credit-card account, the account details, balances, and transactions we access through our data provider (see "Bank Account Connections")
2.2 Automatically Collected Information
- Device information (browser type, operating system)
- IP address and location data
- Usage data (pages visited, features used, time spent)
- Cookies and similar tracking technologies
2.3 SMS-Specific Data
When you opt into SMS receipt processing:
- Phone number (verified via 6-digit code)
- MMS message content (receipt images)
- Message timestamps and frequency
- SMS delivery status
3. How We Use Your Information
We use your information for the following purposes:
- Service Provision: Process receipts, categorize expenses, generate financial reports
- Bookkeeping & Reconciliation: Import, categorize, and reconcile transactions from connected financial accounts against your accounting records
- SMS Processing: Receive receipt images via text message and send processing confirmations
- AI Analysis: Use artificial intelligence to extract data from receipts and categorize transactions
- Account Management: Create and maintain your account, authenticate users
- Communication: Send service updates, verification codes, and processing confirmations
- Improvement: Analyze usage patterns to improve our services
- Security: Detect and prevent fraud, abuse, and security incidents
- Legal Compliance: Comply with applicable laws and regulations
4. SMS Terms and Conditions
By providing your phone number and verifying it, you consent to receive SMS messages from Penny Sense for receipt processing purposes.
- Message Frequency: Message frequency varies based on your usage. You will receive confirmations for each receipt you text to us.
- Message & Data Rates: Standard message and data rates may apply from your mobile carrier.
- Opt-Out: You may opt out at any time by texting STOP to our number or by removing your phone number in Settings.
- Help: For help, text HELP to our number or contact support at support@penny-sense.com
- Carriers: Supported carriers include AT&T, T-Mobile, Verizon, Sprint, and other major US carriers.
5. How We Share Your Information
We do not sell your personal information. We may share your information in the following circumstances:
- Service Providers: Third-party vendors who help us operate our service (hosting, AI processing, SMS delivery via Telnyx, bank-data access via our financial data provider)
- Legal Requirements: When required by law, court order, or governmental authority
- Business Transfers: In connection with a merger, acquisition, or sale of assets
- With Your Consent: When you explicitly authorize us to share your information
6. Third-Party Services
We use the following third-party services:
- Stripe: For payment processing and, when you connect a bank account, financial account data access via Stripe Financial Connections. We may use other data aggregation providers (such as Plaid) for bank connections in the future.
- Anthropic Claude AI: For receipt data extraction and transaction categorization
- OpenAI: For text embeddings used to power memory and search across your messages, and as an alternate AI provider for receipt extraction and categorization when our primary provider is unavailable
- Google AI (Gemini): For AI image generation when you request it
- Telnyx: For SMS message delivery and receipt processing
- Vercel: For hosting and database services
- Firebase: For authentication services
- Mailjet: For transactional email delivery and inbound receipt-by-email parsing
- Google Analytics (GA4): For product usage analytics (page-view metadata and IP address)
- Sentry: For application error monitoring and diagnostics
7. Bank Account Connections
You may choose to connect a bank or credit-card account so Penny Sense can keep your books up to date automatically. This feature is optional. When you connect an account, you authorize us to access certain financial account data through a third-party data aggregation provider (currently Stripe Financial Connections; we may use other providers such as Plaid in the future).
7.1 Data we access (with your authorization)
- Account details: the financial institution name, account type, and a masked account number (last four digits)
- Balances: current and available account balances
- Transactions: posted and pending transactions, including dates, amounts, descriptions, and merchant names
7.2 What we do not collect
We never receive or store your online banking username or password. You authenticate directly with your financial institution through our data provider, and we receive only the data described above via a secure access token.
7.3 How we use this data
We use connected-account data solely to import your transactions into your accounting records, categorize them, reconcile them against your books, and display account balances. We do not use it for advertising, and we do not sell it.
7.4 Storage and sharing
This data is encrypted in transit and at rest and is stored only in the United States. We share it only with service providers that process it on our behalf under contract (for example, our AI provider for transaction categorization) and as required by law. We do not share it with unrelated third parties.
7.5 Disconnecting and retention
You can disconnect a linked account at any time from the bank-connections screen in the app, which revokes our ongoing access to that account through the provider. Transactions already imported into your books are retained as part of your accounting records (see "Data Retention"); you may request their deletion as described in "Your Rights."
7.6 Provider policies
Our access to your financial account data is also governed by our data provider's terms. For more information, see Stripe's Privacy Center and, where Plaid is used, Plaid's End User Privacy Policy.
8. Data Security
We implement industry-standard security measures to protect your information:
- Encryption in transit (HTTPS/TLS) and at rest
- Envelope encryption of sensitive credentials and access tokens
- Secure authentication with Firebase
- Regular security audits and monitoring
- Access controls and per-organization data isolation
- Webhook signature verification for inbound integrations
However, no method of transmission over the Internet is 100% secure. While we strive to protect your data, we cannot guarantee absolute security.
9. Data Retention
We retain your information for as long as:
- Your account is active
- Needed to provide you services
- Required for legal, tax, or accounting purposes
You may request deletion of your data at any time through your account settings or by contacting us.
10. Your Rights
Depending on your location, you may have the following rights:
- Access: Request a copy of your personal information
- Correction: Request correction of inaccurate data
- Deletion: Request deletion of your data (available in Settings)
- Disconnect: Disconnect any linked bank account at any time, revoking our access
- Opt-Out: Unsubscribe from SMS messages at any time
- Data Portability: Request your data in a portable format
- Object: Object to certain processing of your data
To exercise these rights, contact us at privacy@penny-sense.com or use the data management tools in your account settings.
11. Children's Privacy
Our service is not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13. If you believe we have collected information from a child under 13, please contact us immediately.
12. International Data Transfers
Your information may be transferred to and processed in countries other than your own. We ensure appropriate safeguards are in place to protect your information in accordance with this Privacy Policy. Financial account data obtained through bank connections (see "Bank Account Connections") is stored only in the United States.
13. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new Privacy Policy on this page and updating the "Last Updated" date. Your continued use of our service after changes constitutes acceptance of the updated policy.
14. Contact Us
If you have questions about this Privacy Policy or our privacy practices, contact us:
- Email: privacy@penny-sense.com
- Support: support@penny-sense.com
- Website: https://penny-sense.com/support
California Privacy Rights
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):
- Right to know what personal information is collected, used, shared, or sold
- Right to delete personal information
- Right to opt-out of the sale of personal information (we do not sell your information)
- Right to non-discrimination for exercising your CCPA rights
To exercise these rights, email privacy@penny-sense.com with "CCPA Request" in the subject line.