Privacy Policy — EveryPenny
Last updated: 8 September 2026 Data Controller: LLC "Natural Intelligence" (ТОВ «Природній інтелект»), a limited liability company incorporated in Ukraine, company registration number (ЄДРПОУ) 46203933. Registered address: 28e Mykhaila Maksymovycha Street, building 3, apt. 275, Kyiv 03195, Ukraine (вулиця Максимовича Михайла, буд. 28е, корпус 3, кв. 275, м. Київ 03195, Україна). Contact: [email protected]
EU Representative (Art. 27 GDPR) As the controller is established outside the EU/EEA, we have appointed an EU representative under Art. 27 GDPR for individuals in the EU/EEA. Our representative is the company Data Protection Representative Limited (trading as DataRep). You may contact DataRep, in addition to or instead of us, on any matter relating to the processing of your personal data and the exercise of your GDPR rights.
You can reach our representative:
- By email: [email protected] — please quote <EveryPenny> in the subject line.
- By webform: www.datarep.com/data-request
- By post: to DataRep, at the address below for your country. Please mark your correspondence to "DataRep" (not to EveryPenny) — otherwise it may not reach the representative.
| Country | Postal address (always address to "DataRep") |
|---|---|
| Austria | DataRep, City Tower, Brückenkopfgasse 1/6. Stock, Graz, 8020, Austria |
| Belgium | DataRep, Rue des Colonies 11, Brussels, 1000 |
| Bulgaria | DataRep, 132 Mimi Balkanska Str., Sofia, 1540, Bulgaria |
| Croatia | DataRep, Ground & 9th Floor, Hoto Tower, Savska cesta 32, Zagreb, 10000, Croatia |
| Cyprus | DataRep, Victory House, 205 Archbishop Makarios Avenue, Limassol, 3030, Cyprus |
| Czech Republic | DataRep, Platan Office, 28. Října 205/45, Floor 3&4, Ostrava, 70200, Czech Republic |
| Denmark | DataRep, Lautruphøj 1-3, Ballerup, 2750, Denmark |
| Estonia | DataRep, 2nd Floor, Tornimae 5, Tallinn, 10145, Estonia |
| Finland | DataRep, Luna House, 5.krs, Mannerheimintie 12 B, Helsinki, 00100, Finland |
| France | DataRep, 72 rue de Lessard, Rouen, 76100, France |
| Germany | DataRep, 3rd and 4th floor, Altmarkt 10 B/D, Dresden, 01067, Germany |
| Greece | DataRep, Ippodamias Sq. 8, 4th floor, Piraeus, Attica, Greece |
| Hungary | DataRep, President Centre, Kálmán Imre utca 1, Budapest, 1054, Hungary |
| Iceland | DataRep, Laugavegur 13, 101 Reykjavik, Iceland |
| Ireland | DataRep, The Cube, Monahan Road, Cork, T12 H1XY, Republic of Ireland |
| Italy | DataRep, Viale Giorgio Ribotta 11, Piano 1, Rome, Lazio, 00144, Italy |
| Latvia | DataRep, 4th & 5th floors, 14 Terbatas Street, Riga, LV-1011, Latvia |
| Liechtenstein | DataRep, City Tower, Brückenkopfgasse 1/6. Stock, Graz, 8020, Austria |
| Lithuania | DataRep, 44A Gedimino Avenue, 01110 Vilnius, Lithuania |
| Luxembourg | DataRep, BPM 335368, Banzelt 4 A, 6921, Roodt-sur-Syre, Luxembourg |
| Malta | DataRep, Tower Business Centre, 2nd floor, Tower Street, Swatar, BKR4013, Malta |
| Netherlands | DataRep, Cuserstraat 93, Floor 2 and 3, Amsterdam, 1081 CN, Netherlands |
| Norway | DataRep, C.J. Hambros Plass 2c, Oslo, 0164, Norway |
| Poland | DataRep, Budynek Fronton ul Kamienna 21, Krakow, 31-403, Poland |
| Portugal | DataRep, Torre de Monsanto, Rua Afonso Praça 30, 7th floor, Algès, Lisbon, 1495-061, Portugal |
| Romania | DataRep, 15 Piaţa Charles de Gaulle, nr. 1-T, Bucureşti, Sectorul 1, 011857, Romania |
| Slovakia | DataRep, Apollo Business Centre II, Block E / 9th floor, 4D Prievozska, Bratislava, 821 09, Slovakia |
| Slovenia | DataRep, Trg. Republike 3, Floor 3, Ljubljana, 1000, Slovenia |
| Spain | DataRep, Calle de Manzanares 4, Madrid, 28005, Spain |
| Sweden | DataRep, S:t Johannesgatan 2, 4th floor, Malmo, SE - 211 46, Sweden |
This representative is appointed for the EU/EEA only. DataRep is not appointed as our representative in the United Kingdom or in Switzerland. DataRep handles your data as set out in its own privacy notice at www.datarep.com/privacy-policy.
For general or product questions (anything that is not a data-protection request), please write to EveryPenny directly at [email protected] rather than to our representative.
Summary (the short version)
EveryPenny is a personal finance app. It stores as little about you as possible, and only what's needed to show you your own money. We never sell or share your data with advertisers.
Specifically, we hold:
- An identifier from the sign-in provider you chose (Apple, email, or Google) so we can recognise you across sign-ins. If you signed in with Apple's Hide My Email, all we ever see is a relay address — your real email never reaches us.
- Your email address if you signed in with Apple without Hide-My-Email, with our email magic-link, or with Google. We never see a password — Apple, our magic-link sender (Resend), and Google handle that respectively.
- The manual accounts, balances, and transactions you enter yourself.
- The bank accounts and transactions we sync on your behalf if you connect a bank (we only read; we never move money).
- The crypto exchange balances and card transactions we sync if you connect a crypto exchange (currently Bybit, including Bybit EU) — read-only, via an API key you create in your own exchange account. We refuse keys that would allow trading or withdrawals.
- Encrypted bank and exchange access credentials (bank tokens and exchange API keys) so we can re-sync your data later without asking you to re-log in. Each user's credentials are encrypted with a per-user subkey derived from a master key plus your account id, so they can't be cross-decrypted between users.
- Device tokens so we can send you push notifications (e.g. a reminder that a subscription charge is due tomorrow).
Everything is stored in the European Economic Area (Frankfurt, Germany). You can delete your entire account from inside the app at any time. You can also remove a single bank account or a single sub-account of a connected bank without deleting the rest of your data — see Your rights below.
1. What data we collect
1.1 Data you give us directly
| Category | Examples | Purpose |
|---|---|---|
| Account identity | Provider-issued user id (Apple opaque string, Google sub, or our internal id for email sign-in), email address (or Apple private relay), display name (first sign-in only) |
Recognise you at sign-in; send security notifications |
| Device identity | Identifier-for-vendor (hashed), APNs device token, device model name | Push notifications, session revocation |
| Manual-entry finance data | Account names, currencies, balances, transaction dates, amounts, merchants, categories | Core app feature |
1.2 Data we receive from third parties on your behalf
| Source | Data | Triggered by |
|---|---|---|
| Monobank | Account list, balances, statements, near-real-time transaction events | You choose Monobank in the Connect Bank flow. Where we have been granted Monobank Corporate API access, we receive transaction events from your bank as they happen via an authorised webhook (no polling). Otherwise we use the legacy public API where you paste a personal X-Token from api.monobank.ua. Either way, the access is read-only — we cannot initiate payments. |
| Enable Banking | Account list, balances, statements (read-only) | You connect an EEA bank under PSD2; data is fetched via the aggregator after your bank's Strong Customer Authentication |
| Bybit / Bybit EU | Wallet balances (Funding, Unified Trading, Earn savings), Bybit Card transaction history where the exchange's API provides it (amount, currency, date, merchant name, merchant category code) | You connect a crypto exchange by creating a read-only API key in your own Bybit account and pasting it into EveryPenny. We verify the key's permissions with Bybit and reject any key that allows trading or withdrawals. We also read Bybit's public market prices to value crypto holdings — that request contains no personal data. |
| Apple | Identity token verification via Apple's JWKS; server-to-server notifications about account deletion or Hide-My-Email toggles | Apple's internal lifecycle events |
Verified email + name from your Google account (returned in the OAuth id_token and verified against Google's JWKS) |
You choose "Continue with Google" at sign-in | |
| Resend | Delivery of our magic-link sign-in email to your inbox | You choose "Continue with email" at sign-in |
| fawazahmed0/exchange-api + Frankfurter | Foreign-exchange rate data (public, no personal data shared) | Automatic, every few hours |
1.3 Data we derive automatically
- Recurring pattern detection — we cluster your transactions to identify subscriptions and recurring bills. This happens on our servers and the output stays in your account.
- Hashed attribution — when you sign in, we store an HMAC-SHA256 hash of your IP address and User-Agent so we can recognise suspicious logins without storing the raw values.
- Privacy-preserving product analytics — to understand whether the app is useful (did people who signed up come back? did they create their first budget?), we record a small set of pseudonymous, predefined events: sign-up, sign-in, app-opened, and "key action" beats (a budget/goal created, a bank connected, a transaction added, a recurring subscription confirmed). These events carry only the event name and a coarse, hard-coded type — never amounts, merchant names, account names, categories, or any free text. The only identifier attached is your opaque account ID (the same UUID used internally), set only after you sign in and cleared when you sign out. Because that ID could in principle be linked back to you, we treat these events as pseudonymous (GDPR Recital 26), not anonymous; events fired before you sign in carry no identifier at all. See Appendix B for exactly what our analytics processor receives.
1.4 Data we do NOT collect
- Raw IP addresses or User-Agent strings (we keep only keyed hashes for fraud/abuse detection). This holds for the website too — its two analytics events carry no IP, User-Agent, browser, OS, or screen information (see Appendix B.1).
- Advertising identifiers.
- Location data. We never request GPS, Wi-Fi, or CoreLocation access. PostHog's server-side IP-to-location lookup is disabled at the project level, and the client IP address is discarded at ingestion, so no IP-derived country, city, postal code, or coordinates are derived or stored.
- Contacts, photos, microphone, or camera access.
- Biometric data. Face ID / Touch ID stay on your device — they never reach our servers.
- Your bank or exchange login credentials (passwords, 2FA). You generate a read-only token on Monobank's own site, or a read-only API key on Bybit's own site, and give it to us directly; we never see your Monobank or Bybit password. We store the credential you give us encrypted (see §6) and refuse any exchange key that would permit trading or withdrawals.
2. Legal basis (GDPR Art. 6)
- Contract (Art. 6(1)(b)) — everything we need to provide the product you signed up for. Account identity, manual entries, bank sync, push notifications.
- Legitimate interest (Art. 6(1)(f)) — hashed attribution for fraud/abuse detection; Sentry error reports; audit event log; privacy-preserving product analytics (pseudonymous, no directly-identifying PII, EU-hosted) to improve the app. The analytics signal is opt-out at any time from Settings → Privacy → Share Product Analytics; turning it off drops any in-flight events and stops further collection immediately.
- Consent (Art. 6(1)(a)) — connecting a bank or crypto exchange is explicit consent. You can withdraw consent at any time by disconnecting the bank or exchange inside EveryPenny (and, for Bybit, additionally by deleting the API key in your Bybit account).
3. Where the data lives
| Category | Processor | Region | Encryption at rest |
|---|---|---|---|
| Postgres (users, accounts, transactions, audit log) | Neon Inc. | eu-central-1 (Frankfurt) | AES-256 at the storage layer, with additional AES-256-GCM column-level encryption on bank tokens using a per-user HKDF-derived subkey (so a row pasted from one user's column to another's fails to decrypt) |
| Redis (sessions, idempotency, BullMQ jobs, magic-link rate-limit counters) | Upstash, Inc. | eu-central-1 (Frankfurt) | TLS in transit; encrypted at rest |
| Errors + traces | Sentry (Functional Software, Inc.) | EU region, Frankfurt (US company; EU-US Data Privacy Framework, with EU SCCs as a fallback) | Sentry-side encryption; we scrub PII server-side before anything leaves our process |
| Product analytics (pseudonymous events) | PostHog (PostHog, Inc.) | EU Cloud (Frankfurt) | PostHog-side encryption; we send only predefined event names + an opaque account ID, never PII or financial content. GeoIP location lookup is disabled at the project level and client IP addresses are discarded at ingestion, so neither your IP nor any IP-derived location is stored |
| Logs | Fly.io (Hashicorp region tag fra) |
Frankfurt | Fly's internal encryption |
| Push notifications | Apple Push Notification Service | global | Apple-managed |
| Transactional email | Resend Inc. | EU region (US company; EU-US Data Privacy Framework, with EU SCCs as a fallback) | Resend-managed; we send only the recipient address + a single Penny-voice sign-in link or bug-report payload |
| In-app purchases / entitlements | RevenueCat, Inc. | US (Standard Contractual Clauses) | App Store receipt + your opaque account id; no financial content |
| Website purchases (billing) | Paddle.com Market Ltd. (merchant of record) | EU/US (SCCs / Data Privacy Framework) | Your email + payment details, handled by Paddle as the seller |
All data stays in the European Economic Area except for these transfers, for which we rely on the safeguards in Chapter V of the GDPR: the Apple Push Notification service (Apple, global, under its own data-processing addendum); Sentry (US company — we use its EU region, under the EU-US Data Privacy Framework, with EU Standard Contractual Clauses as a fallback); Resend (US company — we use its EU region, under the EU-US Data Privacy Framework, with EU Standard Contractual Clauses as a fallback); RevenueCat (US, under Standard Contractual Clauses); and Paddle (our website payment merchant of record, under SCCs / the Data Privacy Framework).
One further flow exists only if you create it: if you connect a global Bybit account, our servers exchange data with Bybit's API, which Bybit operates outside the EEA. That communication happens at your explicit request, using the key you created, to sync your own exchange data — a transfer to an independent controller you have a direct contractual relationship with, occasional and necessary for the service you asked us to perform (Art. 49(1)(b)-(c) GDPR). Bybit EU connections are served by Bybit EU GmbH from within the EU.
4. How long we keep it
- Your live data — as long as your account is active.
- Deleted account — your
usersrow and every record tied to it (accounts, transactions, bank connections, device tokens, sessions) are removed from our production database immediately when you tap Delete Account (or when Apple tells us your Apple ID was permanently deleted). Cascade-deleted rows are gone from live Postgres within the request. Neon's point-in-time backup snapshots continue to hold the pre-delete state for up to the retention window of our Neon plan (currently 6 hours) after which they expire naturally. - Bank, exchange & transaction data — transactions, balances, and derived insights (categories, recurring charges) are kept on a 24-month rolling window from each transaction's date; older entries age out automatically. On account deletion everything is cascade-deleted immediately (see above).
- Audit / security events — kept for up to 24 months, then
deleted or irreversibly anonymised. On account deletion the
userIdis set toNULLimmediately, so any record still inside that window is no longer tied to you personally. - Product analytics (PostHog) — pseudonymous event data is retained for 12 months, then deleted. No financial content or PII is ever sent (see §7 and Appendix B).
- Error monitoring (Sentry) — PII-scrubbed error events are kept for 90 days, then deleted.
- Session rows — pruned 90 days after expiry (anonymous data only — no PII).
- Idempotency keys — pruned 30 days after creation (hashes of request bodies, no PII).
- Sync cache (Redis) — 24 hours; nothing permanent.
5. Your rights (GDPR Art. 15-22)
You have the right to:
- Access your data — email us and we'll send you a JSON export of everything we hold.
- Correct inaccurate data — edit in-app, or email [email protected].
- Delete your account — tap Delete Account in Settings. Your data is removed from our live production database the moment the request completes. Two narrow exceptions, detailed in §4: encrypted database backups hold the pre-deletion state for up to ~6 hours before expiring naturally, and security/audit-log entries are retained for the period stated in §4 with your identifier removed so they no longer identify you.
- Delete a single bank account or sub-account — long-press an account in EveryPenny and choose Disconnect bank (removes the entire connection and every transaction tied to it) or Remove this account (removes one bank-synced sub-account and its transactions while leaving the rest of the connection intact). Both are scoped to that account; nothing else is touched.
- Port your data — the export above is in portable JSON.
- Object to processing — disconnect banks; disable push notifications in iOS Settings.
- Withdraw consent — disconnecting a bank revokes EveryPenny's access immediately.
- Complain — to the data-protection authority of your EU country, or to Ukraine's Office of the Commissioner for the Protection of Personal Data.
We respond to any request within one month of receipt. For complex or numerous requests we may extend this by up to two further months, and will tell you within the first month if we do (GDPR Art. 12(3)).
6. Security
We follow industry best practices for a finance app:
- TLS 1.3 everywhere. HSTS with preload.
- All bank tokens and exchange API keys encrypted with per-user HKDF-derived AES-256-GCM subkeys, with the user's identifier bound into the auth tag so a row can't be cross-decrypted between users.
- Exchange API keys are accepted only if read-only: at connect time (and again on every sync) we check the key's permissions with Bybit and refuse keys that allow trading or withdrawals.
- Identity tokens from Apple and Google are verified against the respective provider's JWKS (JSON Web Key Set) on every sign-in — we never trust an unverified token.
- Email magic-link sign-in nonces are stored as SHA-256 hashes (never plaintext), expire 15 minutes after generation, are single-use, and are rate-limited per email and per IP to deter abuse.
- Refresh tokens stored as SHA-256 hashes, never plaintext; rotated on every use; device-bound.
- Session revocation on logout, on Apple account deletion, on request.
- Rate limiting at both the edge (Cloudflare) and the application tier.
- WAF + DDoS protection via Cloudflare.
- Append-only audit log on every money-touching action.
- Automated CVE scanning and dependency updates on every CI run.
No system is 100 % secure. If we discover a personal-data breach, we'll notify the relevant supervisory authority without undue delay and, where feasible, within 72 hours, and we'll tell affected users without undue delay where the breach is likely to put their rights at high risk — as GDPR requires.
7. Who else processes your data
These are the only companies that ever touch your data, in the specific roles below. GDPR distinguishes two kinds of recipient, so we list them separately: processors that act only on our instructions under a data-processing agreement (DPA), and independent controllers that decide their own purposes and have their own privacy notices.
7.1 Processors (act only on our instructions, under a DPA)
| Processor | Role | Region | DPA |
|---|---|---|---|
| Neon Inc. | Managed Postgres | EU (Frankfurt) | Neon DPA |
| Upstash, Inc. | Managed Redis | EU (Frankfurt) | Upstash DPA |
| Fly.io, Inc. | Application hosting + logs | EU (Frankfurt) | Fly DPA |
| Cloudflare, Inc. | DNS + WAF + DDoS | EU edge | Cloudflare DPA |
| Functional Software, Inc. (Sentry) | Crash + error reporting (PII scrubbed) | EU region (US company; EU-US Data Privacy Framework, with EU SCCs as a fallback) | Sentry DPA |
| PostHog, Inc. | Privacy-preserving product analytics | EU Cloud (Frankfurt) | PostHog DPA |
| Resend Inc. | Transactional email (sign-in links, bug reports) | EU region (US company; EU-US Data Privacy Framework, with EU SCCs as a fallback) | Resend DPA |
| RevenueCat, Inc. | In-app subscription management — Apple IAP entitlement tracking (app user ID, subscription status, purchase events; no payment card data — Apple handles payments) | US (Standard Contractual Clauses) | RevenueCat DPA |
7.2 Independent controllers (they set their own purposes; their own notices apply)
| Controller | Why your data reaches them |
|---|---|
| Apple Inc. | Sign in with Apple, push notifications, and App Store purchases — Apple is the seller (merchant of record) for in-app purchases |
| Google LLC | Identity, if you choose "Continue with Google" |
| Paddle.com Market Ltd. | Merchant of record for website purchases — Paddle is the seller you contract with, and handles billing, tax, and refunds (receives your email + payment details) |
| Enable Banking Oy | EEA bank-account aggregator and the licensed PSD2 account-information provider for the connections you authorise |
| Universal Bank (Monobank) | The Ukrainian bank you connect — a direct relationship between you and your bank |
| Bybit (Bybit Fintech Limited; for Bybit EU accounts, Bybit EU GmbH — a MiCA-regulated EU entity) | The crypto exchange you connect — a direct relationship between you and your exchange. You create a read-only API key in your own Bybit account; our servers then query Bybit's API with it on your behalf |
| Meta Platforms Ireland Ltd. | Website only, and only with your consent: if you accept the marketing-cookies banner on everypennyapp.com, the Meta Pixel measures whether our Facebook/Instagram ads lead to App Store visits (see Appendix B.2). Decline it and no data ever reaches Meta |
FX and crypto market rates come from public sources (Frankfurter, fawazahmed0/exchange-api via jsDelivr / Cloudflare, and Bybit's public market-price API); only currency codes are sent — no personal data, so no DPA is needed.
We'll update these lists whenever we add or swap a recipient. Material changes trigger an in-app notice.
8. Children
EveryPenny is not directed at anyone under 16. We do not knowingly collect data from minors. If you believe a minor has signed up, contact us and we'll delete the account.
9. Changes to this policy
Significant changes are announced in-app before they take effect, and you'll be asked to re-consent. The change history is available on request.
10. Contact
For any privacy-related question or request: [email protected]
Appendix A — What Sentry actually receives
Sentry is initialised with sendDefaultPii: false and a scrubber that removes every key whose name matches email, phone, password, token, secret, iban, pan, dateOfBirth, address, firstName, lastName, fullName, and many other finance-adjacent terms, recursively, before any event leaves the process.
What Sentry sees:
- Sanitised stack traces
- HTTP route names (e.g.
POST /auth/apple) — never path params with ids - Error class + message (with PII regex-scrubbed)
- Opaque userId (UUID) — never the Apple user id or email
What Sentry never sees:
- Any bank account number, balance, or transaction amount
- Any real or relay email address
- Any authentication token in any form
Appendix B — What PostHog actually receives
PostHog is configured for the EU Cloud (eu.i.posthog.com) with autocapture, session replay, screen-view capture, and application-lifecycle autocapture all disabled. PostHog's server-side GeoIP enrichment is disabled at the project level, and the client IP address is discarded at ingestion — so no country, city, latitude/longitude, or postal code is ever derived or stored from your IP. (As an additional safeguard, the SDK also registers $geoip_disable: true on every event.) Person profiles are created only for identified users (personProfiles = .identifiedOnly), so events fired before sign-in carry no identifier (anonymous); events after sign-in are pseudonymous — tied to the opaque account ID below, not to your name or email. Every event in the app is fired explicitly from code — there is no automatic data collection.
The complete set of events we ever send:
signup/signin— that an account was created or a returning user signed inapp_opened— the app came to the foreground (powers retention reporting)activated— the user completed their first meaningful action on this installkey_actionwith atypeof one of:bank_connected,transaction_added,budget_created,goal_created,recurring_confirmedbank_connect_started/bank_connect_completed/bank_connect_failed— the bank-connection funnel. Properties:provider(which integration),institution(the bank's display name from our own built-in list),reconnect(whether this was a re-connection),duration_s(how many seconds the bank's authentication took, on success), andreason(a coarse, server-generated failure category on failure — never anything you typed)first_total_seen— the dashboard rendered with a connected bank for the first time on this install. Properties:banksandaccounts— counts only, never balancesbank_requested— you tapped which bank you couldn't find in our list, chosen from a fixed set of bank names we ship with the app. Your typed search text is never sent — only the tapped entry's identifier.import_source_selected— which competitor app you tapped on the import picker, as an identifier from the fixed list of tiles the app ships. Your files and their contents never pass through analyticsdemo_entered/demo_exited— you turned the sample-data ("demo") mode on or off. No propertiespaywall_viewed,checkout_started,subscription_started,subscription_purchased,subscription_cancelled,subscription_refunded— the subscription funnel. Properties come from fixed vocabularies only:source(onboarding,settings,bank_connect_gate, orrecurring_promo),plan(monthly,yearly, orlifetime),rail(app_storeorpaddle), and onsubscription_purchasedasandboxflag that marks our own TestFlight/App-Review test purchases. Prices and amounts are never sentrecurring_candidates_shown/recurring_candidate_reviewed— whether you engage with the subscriptions the app detected;outcomeis one ofconfirmed,rejected,snoozedshare_generated/share_completed— you created or shared a share-card image;surfaceis one ofsubscription_scan,one_true_total, anddestinationmay beinstagram_stories. The image itself (and any amounts drawn in it) never passes through analytics
What PostHog sees:
- The event names above and their property values, all drawn from the fixed vocabularies listed with each event
- An opaque account ID (UUID), attached only after sign-in and cleared on sign-out
- Standard SDK metadata (app version, OS version, device model, coarse library context)
What PostHog never sees:
- Any amount, balance, merchant name, account name, or category name
- Any transaction content or free-form text you typed
- Your email address, display name, or any other PII
- Any advertising identifier (we collect none)
This feature is key-gated: with no PostHog project key configured, the SDK is never initialised and nothing is sent at all.
Appendix B.1 — The website (everypennyapp.com)
Separately from the app, the marketing website measures two things, so we can tell how many people who reach the site go on to the App Store. The website does not use the PostHog SDK: it sends a plain HTTPS request containing only the fields listed below, so this list is the payload rather than a summary of it.
The complete set of website events:
web_pageview— a page was opened. Properties: the path (/,/uk/,/pl/), the page language, the campaign token if you arrived from one of our ads, and the hostname only of the referring site (e.g.l.instagram.com) — never the full referring URL.web_appstore_click— an App Store button was tapped. Properties: which button on the page, the page language, and the campaign token if present.
The website stores nothing on your device for this: no cookies, no localStorage, no sessionStorage written by analytics. The identifier attached to these two events is a random value generated in memory when the page loads and discarded when you leave it; it cannot follow you between page loads or between sites. The cookie banner the site shows is not about this measurement — it exists solely for the optional Meta Pixel described in Appendix B.2, which never loads unless you accept.
What the website never sends: your IP address or User-Agent string, your browser or operating system, your screen size, the full URL or its query string, any form input, and any advertising identifier. As with the app, PostHog's GeoIP lookup is disabled at the project level and client IP addresses are discarded at ingestion.
If your browser sends a Do Not Track or Global Privacy Control signal, the website sends nothing at all.
Appendix B.2 — Meta Pixel (website, consent only)
To tell whether our Meta (Facebook/Instagram) ads actually lead people to the App Store, the website can load the Meta Pixel — but only after you tap "Accept" on the consent banner. Until then, nothing is downloaded from Meta and no request to Meta's servers is made; if you tap "Decline", the pixel never loads and your choice is remembered in your browser so we don't ask again. The only thing stored before you decide is nothing; the only thing stored after you decline is the word "denied".
With your consent, the pixel sends Meta exactly two kinds of events: a page view, and a "Lead" event when you tap an App Store button. The pixel is Meta's own code and may set Meta cookies in your browser; for this processing Meta Platforms Ireland Ltd. is an independent controller under its own Data Policy. Legal basis: your consent (GDPR Art. 6(1)(a)); you can withdraw it at any time by clearing this site's data in your browser, after which the banner will ask you fresh.
The iOS app itself contains no Meta SDK and no Meta code of any kind. Ad-to-install measurement on iOS uses Apple's SKAdNetwork, which is aggregated and crowd-anonymized by design: Apple sends Meta install counts, never your identity, and nothing about it involves data collected by the app.