Privacy Policy

Last updated: March 2026

Our approach to privacy

PennyPath is built with privacy at its core. We believe you should be able to manage your money without handing over personal information. We store the absolute minimum data needed to make the app work, and we never sell, share, or monetise your data.

What we store

When you create an account, we store:

  • A unique identifier from your authentication provider (Firebase UID)
  • Your preferred currency (GBP, USD, or EUR)
  • Your preferred theme (light, dark, or system)
  • Your financial data: income sources, bills, debts, budgets, expenses, savings goals, emergency fund, and mortgage details

What we do not store

  • Your name or email address
  • Bank account numbers or sort codes
  • Credit card details
  • Any form of personally identifiable information (PII)

Your email address is held by Firebase Authentication (operated by Google) and is never stored in our database.

Authentication

We use Firebase Authentication for account management. When you sign in, Firebase verifies your identity and issues a token. We create a secure, HTTP-only session cookie that expires after 14 days. We do not access or store your password.

No bank connections

PennyPath does not connect to your bank accounts. All financial data is entered manually by you. We never have access to your bank credentials or transaction history from your bank.

Data storage and security

Your data is stored in a secure database hosted on Google Cloud Platform. All connections are encrypted in transit using TLS. The application runs on Google Cloud Run with access restricted by authentication at every API endpoint.

Cookies

We use a single HTTP-only session cookie for authentication. We do not use tracking cookies, analytics cookies, or any third-party cookies. Your theme preference is stored in your browser's local storage.

Third-party services

  • Firebase Authentication (Google) -- handles sign-in and account security
  • Google Cloud Platform -- hosts the application and database
  • Google Fonts -- serves the Inter typeface

We do not use any analytics, advertising, or tracking services.

Data export and deletion

You can export all your financial data at any time from the Settings page in CSV or PDF format. You can delete your account and all associated data from the Settings page. Deletion is permanent and cannot be undone.

Changes to this policy

If we make changes to this privacy policy, we will update the date at the top of this page. We encourage you to review this page periodically.