Legal

Privacy Policy

Last updated: September 23, 2026

1. Introduction

This Privacy Policy describes how PennyHub and starkovs.dev ("the App", "we", "us") collect, use, and protect your information. The App is developed and operated by Mikhail Starkov, an independent developer based in Calgary, Alberta, Canada.

By using the App, you agree to the practices described in this policy. If you have questions, see the Contact section below.

2. Information We Collect

To provide the App's budgeting features, we collect and store:

  • Account information — your name and email address, used to create and secure your account.
  • Financial data you enter — transactions, categories, budgets, savings goals, and wallet balances that you manually add to the App.
  • Receipt photos — temporarily, for AI analysis only. Receipt images are not stored.
  • Authentication tokens — from Google Sign In or Apple Sign In, used to verify your identity when you log in.
We do not connect to your bank, request your banking credentials, or access any bank accounts. All financial data is entered manually by you.

3. How We Use Your Information

We use the information you provide solely to operate and improve the App — for example, syncing your data across devices, enabling family sharing, and providing customer support.

We do not sell, rent, or trade your personal or financial information to third parties for marketing or any other purpose.

4. Encryption & Security

Data is encrypted with TLS while in transit between your device and our servers. Your financial data is additionally protected with AES-256 encryption applied on your device before it ever leaves it, meaning it is stored in encrypted form and cannot be read by us.

5. Family Sharing

Family sharing is invite-only. As the account owner, you control who can join your household budget and what they can see or edit. Members you haven't approved cannot access your data, and you can revoke access at any time.

6. Third-Party Services

The App relies on a small number of trusted infrastructure providers to operate:

  • Firebase / Google Cloud — used for secure data storage, hosting, and app infrastructure.
  • Google Sign In (Google LLC) — optional authentication method. Data shared: your name and email address. Privacy Policy.
  • Apple Sign In (Apple Inc.) — optional authentication method. Data shared: your name and email (only on first sign in; may use a private relay email). Privacy Policy.
  • Google Gemini AI (Google LLC) — used for receipt scanning and text recognition. Receipt photos are sent to the Gemini API for analysis and immediately discarded; we do not store receipt images. Privacy Policy.

These providers do not have access to your financial data in readable form.

7. Device Security (PIN & Face ID)

PennyHub offers an optional app lock feature using a PIN code and/or Face ID / Touch ID.

  • PIN is stored locally on your device using the iOS Secure Enclave.
  • PIN is never transmitted to our servers.
  • Face ID / Touch ID data never leaves your device — it is managed entirely by iOS.
  • This feature is entirely optional and can be disabled in Settings.

8. Data Retention & Deletion

You can delete your account and all associated data at any time from Settings → Delete Account within the App. Deletion requests are processed, and your data permanently removed, within 30 days.

9. Children's Privacy

The App is not directed to, and is not intended for use by, children under the age of 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal information, please contact us and we will delete it.

10. Your Rights

You have the right to access, correct, or delete the personal information we hold about you at any time through the App's Settings, or by contacting us directly.

If you are located in Canada, you have additional rights under the Personal Information Protection and Electronic Documents Act (PIPEDA), including the right to know how your information is being used and to request access to or correction of your data.

11. Contact

Questions, requests, or concerns about this Privacy Policy or your data? Reach out anytime:

support@starkovs.dev