Privacy and security
What data Penny receives from your bank, who can see it, and how to revoke access.
How Penny gets your data
Most banks connect through Plaid. You sign in with Plaid, not Penny, so Penny never receives your bank password. Apple Card, Cash, and Savings connect through Apple's FinanceKit, which reads Wallet on your iPhone with your permission.
Connections are read-only. Penny receives:
- Account names, types, and last four digits
- Current and available balances, and credit limits
- Transactions, including pending ones
- Merchant details, where the bank provides them
Penny never receives your bank login credentials, full account numbers, or statements, and can't move money.
Who can see it
- Everyone in your household sees every account and transaction in it. Keep private finances in a separate household.
- Authorized Penny staff, as needed to operate the service, provide support, investigate issues, or meet legal obligations.
- Service providers, as needed to deliver Penny's features. See the service provider list for what each provider handles.
Penny uses encrypted connections, hashed passwords, encrypted bank connection tokens, and household access controls. Penny doesn't sell your personal information. The privacy policy explains what we collect, including diagnostics, and why.
Receipt images and exports use temporary download links; anyone with a valid link can access the file until it expires. Profile, household, account, and merchant images use public URLs, so avoid using sensitive documents as display images.
Revoking access
Choose the action that matches what you want to stop or remove:
- Delete the account in Penny to stop syncing it.
- Remove Penny in your bank's third-party access settings to revoke the connection. For Apple accounts, turn Penny off under iOS Settings → Privacy & Security → Financial Data.
- Delete your Penny account to remove your login, profile, and households you still own. Shared data in households someone else owns stays with those households.
Reporting a security issue
Report vulnerabilities through Contact us.
Last updated on
