Privacy Policy
Version 1.2 · Last updated: September 19, 2026Official document
This Privacy Policy explains how Penny Pilot ("Penny Pilot", "the App", "we", "us") collects, uses, stores, and protects information when you use the Penny Pilot personal finance web application. It is written to accurately reflect how the application is actually built and operated today.
By creating an account and using Penny Pilot, you agree to the collection and use of information as described in this policy.
1. Information We Collect
1.1 Account & Authentication Information
When you register for Penny Pilot, we collect and store your name, email address, and optionally a phone number, together with a securely hashed password (Penny Pilot never stores your password in plain text). If you enable two-factor authentication or a passkey, we store the associated security metadata (e.g. a TOTP secret, hashed backup codes, or passkey credential data) needed to verify future sign-ins. Your account is active as soon as you complete signup; there is no admin-approval step that delays account activation.
1.2 Financial Data
Penny Pilot lets you record and manage income, expenses, transactions, budgets, savings, investments, bills/EMIs, and financial goals. This financial data is not stored in Penny Pilot's own central database. You choose where it is stored instead:
- Google Drive mode (recommended): stored as structured data files inside a "Penny Pilot" folder created in your own Google Drive, under your own Google account — see Section 2 below for details.
- This Device Only mode: stored only in this browser/device's local storage (IndexedDB). This data is never transmitted to, or held by, Penny Pilot's servers, database, or any Google account.
1.3 Activity & Security Logs
We keep a limited activity log tied to your account (e.g. login events, password/2FA changes, Google Drive connect/disconnect events) so that you and, where applicable, an administrator can review recent account activity for security purposes.
2. Google OAuth & Google Drive Access
This section applies only if you choose Google Drive mode. If you choose This Device Only mode instead, Penny Pilot does not request Google OAuth access or use Google Drive at all for your financial data.
In Google Drive mode, after you register (or later switch modes) you connect a Google account so the App can create and manage your financial workspace. Connecting uses Google's standard OAuth 2.0 sign-in flow, which asks you to explicitly grant Penny Pilot permission before any access is given.
The Google OAuth permissions ("scopes") Penny Pilot requests are:
- drive.file — a restricted Google Drive scope that only allows Penny Pilot to see, create, and modify files and folders that Penny Pilot itself creates in your Drive. Penny Pilot cannot browse, read, or modify any other file already in your Google Drive.
- userinfo.email — lets Penny Pilot read the email address of the connected Google account, so it can show you which account is connected and detect if you later connect a different one.
Using these permissions, Penny Pilot creates a root folder (named "Penny Pilot", or a similarly named folder if you choose to start a fresh workspace) in your Drive and writes your financial data into structured JSON files inside it. If you connect a Google account that already has an existing Penny Pilot workspace from a prior connection, you are explicitly asked whether to reuse that data or start a new, empty workspace — Penny Pilot never silently merges data between Google accounts.
3. How Your Financial Data Is Stored
Your financial records (transactions, budgets, investments, bills, goals, accounts, and categories) are written to versioned JSON data files inside your own Google Drive folder, which acts as the source of truth for that data. When a data file is updated, Google Drive automatically retains prior revisions of that file, which powers Penny Pilot's built-in "restore a previous version" feature — no separate backup copy of your financial data is kept by Penny Pilot outside of your own Drive.
Because this data lives in your Google Drive, it is subject to your own Google account's storage quota, access controls, and Google's own data-handling practices for files stored in Drive, in addition to this Privacy Policy.
In This Device Only mode, your financial records are instead written directly to this browser's local IndexedDB storage, with no equivalent Drive-style automatic version history — you are responsible for exporting your own backups using the App's export feature.
4. Token & Security Handling
When you connect Google Drive, Penny Pilot receives an OAuth access token and, where granted, a refresh token from Google. These tokens:
- Are encrypted at rest (AES-256-GCM) in Penny Pilot's database before being stored — they are never stored in plain text.
- Are used exclusively on the server to make authenticated Google Drive API calls on your behalf, to read and write your own Penny Pilot data files.
- Are never shared with, or made accessible to, other users of the application.
- Are automatically refreshed by Penny Pilot when they expire, using the stored refresh token, without requiring you to sign in to Google again.
Your Penny Pilot account session itself is maintained using signed, HTTP-only authentication cookies. Passwords are hashed before storage and are never stored or logged in plain text. If you enable two-factor authentication, sensitive account actions (such as disconnecting Google Drive or restoring an earlier data revision) may require you to re-verify your identity.
5. Data Retention & Deletion
- Financial data in Google Drive remains in your own Google Drive for as long as you keep it there. You can delete individual files, the entire "Penny Pilot" folder, or revoke Penny Pilot's access at any time directly from Google Drive or your Google Account permissions page — Penny Pilot does not control or retain a separate copy of that data.
- Financial data in This Device Only mode remains only in this browser's local storage for as long as you keep it there. Clearing this browser's site data, uninstalling the browser, or resetting the device deletes it permanently — Penny Pilot holds no copy anywhere else.
- Account data in Penny Pilot's database (your name, email, password hash, security settings, and activity log) is retained for as long as your account remains active.
- Account deletion: see the dedicated Account Deletion section (Section 6) below for how to request deletion of your account.
6. Account Deletion
You can currently request deletion of your Penny Pilot account and its associated account data (name, email, password hash, security settings, and activity log) by contacting Penny Pilot support at the email address listed in Section 11 (Contact). Self-service account deletion is not yet available within the App itself and is planned for a future update.
When we receive a deletion request, we will verify the request and process the deletion in accordance with applicable data-retention requirements and the data-retention practices described in Section 5 above. We do not commit to a fixed deletion timeline.
Account deletion removes your Penny Pilot account and account data from our database. It does not delete financial data already stored in your own Google Drive, or data kept in This Device Only mode on your browser/device — you control that data separately, as described in Sections 3 and 5.
7. Disconnecting Google Drive
You can disconnect Google Drive from Penny Pilot at any time from within the App's Settings. Disconnecting:
- Immediately deletes the stored OAuth tokens for that connection from Penny Pilot's database.
- Does not delete, modify, or move any files already saved in your Google Drive — your financial data remains exactly as it was, under your control.
- Means the App can no longer read or write your financial data until you reconnect, since Google Drive is required for that functionality.
You can also revoke Penny Pilot's access entirely from your Google Account's third-party app permissions page, which has the same effect from Google's side. If you are in This Device Only mode, none of this section applies — there is no Google Drive connection to disconnect.
8. Third-Party Services
Penny Pilot relies on the following third-party services to operate:
- Google (OAuth & Google Drive) — used to authenticate your Drive connection and to store your financial data, as described above. See Google's own Privacy Policy for how Google handles data within your Google account.
- Resend — an email-delivery provider used to send account-related transactional emails (e.g. security notifications), where email sending is configured.
- Hosting providers — the Penny Pilot backend and frontend are hosted on third-party cloud infrastructure providers, who process data only as needed to run the application (e.g. serving requests, storing the account database).
Penny Pilot does not sell your personal or financial data, and does not use third-party advertising or analytics trackers.
9. Cookies
Penny Pilot uses strictly necessary, first-party cookies to keep you signed in (signed, HTTP-only session cookies) and to remember basic preferences such as your light/dark theme. These cookies are not used for advertising or cross-site tracking. See the Cookie Notice for a full list of what's stored and why, and use the Cookie Preferences link in the footer at any time to change your choice for optional (non-essential) storage.
10. Your Rights
- Access & export: you can view your financial data at any time within the App, and export it using the App's built-in reporting/export features. Your primary financial data also remains directly accessible to you in your own Google Drive.
- Correction: you can edit or delete individual financial records directly within the App.
- Disconnection: you can disconnect Google Drive at any time, as described in Section 7.
- Account data requests: to request access to, correction of, or deletion of the account data Penny Pilot stores about you, contact us using the details in Section 11.
11. Contact
If you have questions about this Privacy Policy or how your data is handled, please contact:
- Email: superadminpennypilot@gmail.com
- Entity: Pranav Sai Kuna. No physical mailing address provided.
12. Changes to This Policy
We may update this Privacy Policy from time to time as the App evolves. Material changes will be reflected by updating the "Last updated" date at the top of this page.
Acceptance & Electronic Authorization
Acceptance of this document is recorded during account creation, through the required Terms of Service and Privacy Policy consent checkboxes and a typed electronic signature/authorization on the signup page — not by viewing this page on its own. If you have not yet created an account, you can return to signup to review and accept.
Questions about this Privacy Policy? See our Privacy Policy or the contact details below.