Privacy Policy

Pennywick: Budget & Receipts · Last updated August 24, 2026

Pennywick is designed to keep your financial information private. This policy explains exactly what data the app touches, and what — if anything — ever leaves your device.

Data stored on your device (and your own iCloud)

Your transactions, budgets, savings goals, categories, and receipt images are stored locally on your device using Apple's on-device data storage (SwiftData), and synced to your own iCloud account so your data is available across your devices. This sync uses Apple's private CloudKit database — your data is end-to-end encrypted and Pennywick's developer cannot access it. Nothing is uploaded to Pennywick's developer or to any analytics service, and there is no account system beyond your existing Apple ID / iCloud.

Household sharing (optional)

If you create a household, Pennywick uses Apple CloudKit Sharing so invited family members or roommates can see a shared ledger through their own Apple IDs. You choose who to invite, and you can stop sharing at any time. Shared data stays in Apple's CloudKit infrastructure — Pennywick does not operate a separate server and cannot read your shared household. Family mode may share the full ledger (including goals and recurring items); Roommates mode shares expenses only. People you invite can see the shared financial data you choose to include; do not invite anyone you do not trust with that information.

Camera and photo access

Pennywick uses your device's camera or photo library only to capture or import images of receipts and bills so you can log expenses. These images are processed entirely on your device to extract text and categorize it (optical character recognition and on-device Apple Intelligence). Receipt images are not sent to Pennywick or to any analytics service. When iCloud sync or household sharing is on, related ledger data syncs through your Apple iCloud account (and, for households, to people you invite) as described above.

Currency conversion lookup

If you enable “Convert foreign receipts automatically,” Pennywick sends only a currency pair and a date (for example, “USD to EUR, June 2026”) to a currency exchange-rate service to look up the historical rate. No amounts, receipt content, or any other data are included in this request, and it is not linked to your identity. You can turn this off at any time in Settings; the app will simply use the exchange rate you enter manually instead.

Optional: cloud receipt reading with your own AI key

Receipt categorization runs on-device by default, and that is what happens unless you deliberately change it. Pennywick never sends your receipts anywhere on its own initiative. There are two ways you can choose to change that — using your own API key, described here, or Pennywick's own cloud reading, described in the next section. Both are off until you turn them on.

You may optionally add your own API key from OpenAI or Google in Settings → Receipt scanning → Your AI key, to have receipts read by that provider's model instead. This is off until you turn it on, and turning it on takes two deliberate steps: adding the key, then accepting a prompt that names the company. After that, Pennywick sends only the extracted text of a receipt, capped in length — never the photo to that provider, using your key and billed to your account. The request goes straight from your device to them; it never passes through any Pennywick server, and Pennywick never sees your key, which is stored in your device's Keychain and is not backed up or synced to your other devices.

Remove the key at any time in the same screen and Pennywick immediately goes back to reading receipts on-device. Because you are the provider's customer in this arrangement, their terms govern what they do with the text: see OpenAI's policies and Google's Gemini API terms.

Optional: cloud receipt reading included in Pro

Pennywick Pro includes cloud receipt reading, where Pennywick runs the cloud model for you instead of you supplying an API key. This is the one feature that uses a server operated by Pennywick, and it is off until you turn it on in Settings → Receipt scanning → Cloud receipt reading and accept a prompt that names both recipients.

When it is on, Pennywick sends only the extracted text of a receipt, capped in length — never the photo to Pennywick's server, which passes it to OpenAI to sort it into fields and returns the result. The receipt text is not stored or logged by that server, and it is not used to train anything.

The server does keep one thing: a count of how many receipts you have read this month, so the monthly allowance included in Pro can be enforced. That counter is keyed by an irreversible hash of an Apple subscription identifier, not by a name, email, device, or account — there is still no Pennywick account, and the counter cannot be traced back to you. Nothing else about you is stored.

Turn it off at any time in the same screen and Pennywick immediately goes back to reading receipts on your device. Turning it off, or letting Pro lapse, stops it entirely.

What Pennywick does not do

Your data, your control

Because your data is stored locally and in your own iCloud, deleting the app and turning off iCloud sync removes Pennywick's data from your devices. If you used household sharing, leave or stop the share first so invited members lose access to the shared ledger. There is no separate Pennywick account to close and no developer-held copy to request deletion of.

Children's privacy

Pennywick is not directed at children and does not knowingly collect information from children.

Changes to this policy

If this policy changes, the “last updated” date above will be revised and the new policy will be posted at this same address.

Contact

Questions about this policy or your data? Use the contact form on the Support page.