Privacy & Trust

How Pennifly handles your data and your money

This page is maintained by Pennifly Finance AB to answer common security, privacy, and money-handling questions about Pennifly. It describes current, app-visible practices — not an independent audit or certification.

What Pennifly does with money

Pennifly is a savings coach. We do not hold, custody, or move customer funds on our own books. The public app shows simulated balances so you can see how the habit works before any bank integration is in place.

A separate, invite-only test module ("Pennifly Transfer") lets a small number of authorised testers link their own bank accounts and move a chosen percentage of a skipped purchase between accounts they already own. Pennifly never touches the money — the bank does. Access requires a private code and a server-side feature flag; without both, the module is disabled.

Data we collect

  • Account details you enter: email, display name, language.
  • App activity you generate: skipped purchases, savings goals, garden progress, forum posts, feedback you choose to send.
  • Anonymous session identifiers used to keep the demo working when you are not signed in.
  • Basic technical logs (timestamps, error traces) needed to keep the service reliable.

We do not sell personal data and we do not run third-party ad tracking.

Where data is stored

Application data is stored in our managed backend inside the EU. Access is protected by row-level security policies so signed-in users only see their own records, and privileged operations run server-side.

Subprocessors

  • Managed backend and authentication provider (EU region).
  • Hosting and edge delivery for the web app.
  • Optional price-comparison lookups when you ask Pennifly to find a cheaper alternative.

We add new subprocessors only when needed to run the service and keep this list current.

Your rights

You can request a copy of your data, correct it, or ask us to delete your account at any time by contacting privacy@heypenny.cc. We respond within a reasonable time frame in line with applicable data-protection law (including the GDPR where it applies).

Security contact

Found a vulnerability? Please email security@heypenny.cc. Do not test against other users' accounts.

What this page is not

Pennifly is not a bank and does not provide investment advice. Names like "Pennifly fund" describe a savings destination inside your own bank — not a fund operated by Pennifly. We do not claim SOC 2, ISO, or PSD2 licensing. Any future licensed activity will be delivered via a regulated partner and disclosed here first.

← Back to home