Privacy Policy — EveryPenny

Last updated: 21 June 2026 Data Controller: LLC "Natural Intelligence" (ТОВ «Природній інтелект»), a limited liability company incorporated in Ukraine, company registration number (ЄДРПОУ) 46203933. Registered address: 28e Mykhaila Maksymovycha Street, building 3, apt. 275, Kyiv 03195, Ukraine (вулиця Максимовича Михайла, буд. 28е, корпус 3, кв. 275, м. Київ 03195, Україна). Contact: [email protected]

EU Representative (Art. 27 GDPR) As the controller is established outside the EU/EEA, we have appointed an EU representative under Art. 27 GDPR for individuals in the EU/EEA. Our representative is the company Data Protection Representative Limited (trading as DataRep). You may contact DataRep, in addition to or instead of us, on any matter relating to the processing of your personal data and the exercise of your GDPR rights.

You can reach our representative:

Country Postal address (always address to "DataRep")
Austria DataRep, City Tower, Brückenkopfgasse 1/6. Stock, Graz, 8020, Austria
Belgium DataRep, Rue des Colonies 11, Brussels, 1000
Bulgaria DataRep, 132 Mimi Balkanska Str., Sofia, 1540, Bulgaria
Croatia DataRep, Ground & 9th Floor, Hoto Tower, Savska cesta 32, Zagreb, 10000, Croatia
Cyprus DataRep, Victory House, 205 Archbishop Makarios Avenue, Limassol, 3030, Cyprus
Czech Republic DataRep, Platan Office, 28. Října 205/45, Floor 3&4, Ostrava, 70200, Czech Republic
Denmark DataRep, Lautruphøj 1-3, Ballerup, 2750, Denmark
Estonia DataRep, 2nd Floor, Tornimae 5, Tallinn, 10145, Estonia
Finland DataRep, Luna House, 5.krs, Mannerheimintie 12 B, Helsinki, 00100, Finland
France DataRep, 72 rue de Lessard, Rouen, 76100, France
Germany DataRep, 3rd and 4th floor, Altmarkt 10 B/D, Dresden, 01067, Germany
Greece DataRep, Ippodamias Sq. 8, 4th floor, Piraeus, Attica, Greece
Hungary DataRep, President Centre, Kálmán Imre utca 1, Budapest, 1054, Hungary
Iceland DataRep, Laugavegur 13, 101 Reykjavik, Iceland
Ireland DataRep, The Cube, Monahan Road, Cork, T12 H1XY, Republic of Ireland
Italy DataRep, Viale Giorgio Ribotta 11, Piano 1, Rome, Lazio, 00144, Italy
Latvia DataRep, 4th & 5th floors, 14 Terbatas Street, Riga, LV-1011, Latvia
Liechtenstein DataRep, City Tower, Brückenkopfgasse 1/6. Stock, Graz, 8020, Austria
Lithuania DataRep, 44A Gedimino Avenue, 01110 Vilnius, Lithuania
Luxembourg DataRep, BPM 335368, Banzelt 4 A, 6921, Roodt-sur-Syre, Luxembourg
Malta DataRep, Tower Business Centre, 2nd floor, Tower Street, Swatar, BKR4013, Malta
Netherlands DataRep, Cuserstraat 93, Floor 2 and 3, Amsterdam, 1081 CN, Netherlands
Norway DataRep, C.J. Hambros Plass 2c, Oslo, 0164, Norway
Poland DataRep, Budynek Fronton ul Kamienna 21, Krakow, 31-403, Poland
Portugal DataRep, Torre de Monsanto, Rua Afonso Praça 30, 7th floor, Algès, Lisbon, 1495-061, Portugal
Romania DataRep, 15 Piaţa Charles de Gaulle, nr. 1-T, Bucureşti, Sectorul 1, 011857, Romania
Slovakia DataRep, Apollo Business Centre II, Block E / 9th floor, 4D Prievozska, Bratislava, 821 09, Slovakia
Slovenia DataRep, Trg. Republike 3, Floor 3, Ljubljana, 1000, Slovenia
Spain DataRep, Calle de Manzanares 4, Madrid, 28005, Spain
Sweden DataRep, S:t Johannesgatan 2, 4th floor, Malmo, SE - 211 46, Sweden

This representative is appointed for the EU/EEA only. DataRep is not appointed as our representative in the United Kingdom or in Switzerland. DataRep handles your data as set out in its own privacy notice at www.datarep.com/privacy-policy.

For general or product questions (anything that is not a data-protection request), please write to EveryPenny directly at [email protected] rather than to our representative.

Summary (the short version)

EveryPenny is a personal finance app. It stores as little about you as possible, and only what's needed to show you your own money. We never sell or share your data with advertisers.

Specifically, we hold:

Everything is stored in the European Economic Area (Frankfurt, Germany). You can delete your entire account from inside the app at any time. You can also remove a single bank account or a single sub-account of a connected bank without deleting the rest of your data — see Your rights below.

1. What data we collect

1.1 Data you give us directly

Category Examples Purpose
Account identity Provider-issued user id (Apple opaque string, Google sub, or our internal id for email sign-in), email address (or Apple private relay), display name (first sign-in only) Recognise you at sign-in; send security notifications
Device identity Identifier-for-vendor (hashed), APNs device token, device model name Push notifications, session revocation
Manual-entry finance data Account names, currencies, balances, transaction dates, amounts, merchants, categories Core app feature

1.2 Data we receive from third parties on your behalf

Source Data Triggered by
Monobank Account list, balances, statements, near-real-time transaction events You choose Monobank in the Connect Bank flow. Where we have been granted Monobank Corporate API access, we receive transaction events from your bank as they happen via an authorised webhook (no polling). Otherwise we use the legacy public API where you paste a personal X-Token from api.monobank.ua. Either way, the access is read-only — we cannot initiate payments.
Enable Banking Account list, balances, statements (read-only) You connect an EEA bank under PSD2; data is fetched via the aggregator after your bank's Strong Customer Authentication
Apple Identity token verification via Apple's JWKS; server-to-server notifications about account deletion or Hide-My-Email toggles Apple's internal lifecycle events
Google Verified email + name from your Google account (returned in the OAuth id_token and verified against Google's JWKS) You choose "Continue with Google" at sign-in
Resend Delivery of our magic-link sign-in email to your inbox You choose "Continue with email" at sign-in
fawazahmed0/exchange-api + Frankfurter Foreign-exchange rate data (public, no personal data shared) Automatic, every few hours

1.3 Data we derive automatically

1.4 Data we do NOT collect

2. Legal basis (GDPR Art. 6)

3. Where the data lives

Category Processor Region Encryption at rest
Postgres (users, accounts, transactions, audit log) Neon Inc. eu-central-1 (Frankfurt) AES-256 at the storage layer, with additional AES-256-GCM column-level encryption on bank tokens using a per-user HKDF-derived subkey (so a row pasted from one user's column to another's fails to decrypt)
Redis (sessions, idempotency, BullMQ jobs, magic-link rate-limit counters) Upstash, Inc. eu-central-1 (Frankfurt) TLS in transit; encrypted at rest
Errors + traces Sentry (Functional Software, Inc.) EU region, Frankfurt (US company; EU-US Data Privacy Framework, with EU SCCs as a fallback) Sentry-side encryption; we scrub PII server-side before anything leaves our process
Product analytics (pseudonymous events) PostHog (PostHog, Inc.) EU Cloud (Frankfurt) PostHog-side encryption; we send only predefined event names + an opaque account ID, never PII or financial content. GeoIP location lookup is disabled at the project level and client IP addresses are discarded at ingestion, so neither your IP nor any IP-derived location is stored
Logs Fly.io (Hashicorp region tag fra) Frankfurt Fly's internal encryption
Push notifications Apple Push Notification Service global Apple-managed
Transactional email Resend Inc. EU region (US company; EU-US Data Privacy Framework, with EU SCCs as a fallback) Resend-managed; we send only the recipient address + a single Penny-voice sign-in link or bug-report payload
In-app purchases / entitlements RevenueCat, Inc. US (Standard Contractual Clauses) App Store receipt + your opaque account id; no financial content
Website purchases (billing) Paddle.com Market Ltd. (merchant of record) EU/US (SCCs / Data Privacy Framework) Your email + payment details, handled by Paddle as the seller

All data stays in the European Economic Area except for these transfers, for which we rely on the safeguards in Chapter V of the GDPR: the Apple Push Notification service (Apple, global, under its own data-processing addendum); Sentry (US company — we use its EU region, under the EU-US Data Privacy Framework, with EU Standard Contractual Clauses as a fallback); Resend (US company — we use its EU region, under the EU-US Data Privacy Framework, with EU Standard Contractual Clauses as a fallback); RevenueCat (US, under Standard Contractual Clauses); and Paddle (our website payment merchant of record, under SCCs / the Data Privacy Framework).

4. How long we keep it

5. Your rights (GDPR Art. 15-22)

You have the right to:

We respond to any request within one month of receipt. For complex or numerous requests we may extend this by up to two further months, and will tell you within the first month if we do (GDPR Art. 12(3)).

6. Security

We follow industry best practices for a finance app:

No system is 100 % secure. If we discover a personal-data breach, we'll notify the relevant supervisory authority without undue delay and, where feasible, within 72 hours, and we'll tell affected users without undue delay where the breach is likely to put their rights at high risk — as GDPR requires.

7. Who else processes your data

These are the only companies that ever touch your data, in the specific roles below. GDPR distinguishes two kinds of recipient, so we list them separately: processors that act only on our instructions under a data-processing agreement (DPA), and independent controllers that decide their own purposes and have their own privacy notices.

7.1 Processors (act only on our instructions, under a DPA)

Processor Role Region DPA
Neon Inc. Managed Postgres EU (Frankfurt) Neon DPA
Upstash, Inc. Managed Redis EU (Frankfurt) Upstash DPA
Fly.io, Inc. Application hosting + logs EU (Frankfurt) Fly DPA
Cloudflare, Inc. DNS + WAF + DDoS EU edge Cloudflare DPA
Functional Software, Inc. (Sentry) Crash + error reporting (PII scrubbed) EU region (US company; EU-US Data Privacy Framework, with EU SCCs as a fallback) Sentry DPA
PostHog, Inc. Privacy-preserving product analytics EU Cloud (Frankfurt) PostHog DPA
Resend Inc. Transactional email (sign-in links, bug reports) EU region (US company; EU-US Data Privacy Framework, with EU SCCs as a fallback) Resend DPA
RevenueCat, Inc. In-app subscription management — Apple IAP entitlement tracking (app user ID, subscription status, purchase events; no payment card data — Apple handles payments) US (Standard Contractual Clauses) RevenueCat DPA

7.2 Independent controllers (they set their own purposes; their own notices apply)

Controller Why your data reaches them
Apple Inc. Sign in with Apple, push notifications, and App Store purchases — Apple is the seller (merchant of record) for in-app purchases
Google LLC Identity, if you choose "Continue with Google"
Paddle.com Market Ltd. Merchant of record for website purchases — Paddle is the seller you contract with, and handles billing, tax, and refunds (receives your email + payment details)
Enable Banking Oy EEA bank-account aggregator and the licensed PSD2 account-information provider for the connections you authorise
Universal Bank (Monobank) The Ukrainian bank you connect — a direct relationship between you and your bank

FX rates come from public sources (Frankfurter and fawazahmed0/exchange-api, via jsDelivr / Cloudflare); only currency codes are sent — no personal data, so no DPA is needed.

We'll update these lists whenever we add or swap a recipient. Material changes trigger an in-app notice.

8. Children

EveryPenny is not directed at anyone under 16. We do not knowingly collect data from minors. If you believe a minor has signed up, contact us and we'll delete the account.

9. Changes to this policy

Significant changes are announced in-app before they take effect, and you'll be asked to re-consent. The change history is available on request.

10. Contact

For any privacy-related question or request: [email protected]


Appendix A — What Sentry actually receives

Sentry is initialised with sendDefaultPii: false and a scrubber that removes every key whose name matches email, phone, password, token, secret, iban, pan, dateOfBirth, address, firstName, lastName, fullName, and many other finance-adjacent terms, recursively, before any event leaves the process.

What Sentry sees:

What Sentry never sees:

Appendix B — What PostHog actually receives

PostHog is configured for the EU Cloud (eu.i.posthog.com) with autocapture, session replay, screen-view capture, and application-lifecycle autocapture all disabled. PostHog's server-side GeoIP enrichment is disabled at the project level, and the client IP address is discarded at ingestion — so no country, city, latitude/longitude, or postal code is ever derived or stored from your IP. (As an additional safeguard, the SDK also registers $geoip_disable: true on every event.) Person profiles are created only for identified users (personProfiles = .identifiedOnly), so events fired before sign-in carry no identifier (anonymous); events after sign-in are pseudonymous — tied to the opaque account ID below, not to your name or email. Every event in the app is fired explicitly from code — there is no automatic data collection.

The complete set of events we ever send:

What PostHog sees:

What PostHog never sees:

This feature is key-gated: with no PostHog project key configured, the SDK is never initialised and nothing is sent at all.