Penni Technologies, Inc. ("Penni", "we", "us", or "our") operates penni.so and the Penni AI bookkeeping service. This policy explains what data we collect, how we use it, and your rights.
What We Collect
When you connect Penni to your accounts, we access and process:
- Gmail email content, we read emails to identify financial transactions (receipts, invoices, subscription charges). We do not store email content permanently; we extract transaction data and discard the raw email.
- Accounting platform data, we read your chart of accounts, vendors, invoices, bills, and bank balances to power bookkeeping, cash flow forecasting, and invoice tracking. Today we connect to QuickBooks Online; additional platforms are in development.
- Bank and card account data (when you connect an account through our data partners Quiltt and MX), we receive transactions and balances on a read-only basis to reconcile your books. Your banking credentials go to our data partners, never to Penni, and we cannot move money, initiate payments, or change anything in your account.
- Account identifiers, your email address, phone number, business name, and accounting platform company ID to associate your data and deliver your service.
- Usage data, basic logs of interactions with Penni for debugging and service improvement.
How We Use Your Data
Your data is used exclusively to provide the Penni service:
- Automated bookkeeping, categorizing and posting expenses to your accounting platform
- Invoice tracking and AR aging alerts
- Cash flow forecasting
- Tax deadline reminders
- Delivering summaries and alerts by text message (SMS) and email
We do not use your financial data to train AI models, sell to third parties, or for any purpose beyond operating your account.
Google User Data and Limited Use
Penni's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Penni requests a single Gmail scope, gmail.readonly, and uses it only to identify receipts, bills, invoices, and payment confirmations in your inbox and propose bookkeeping entries you approve or decline. Penni never sends, modifies, or deletes your mail. Google user data is never used for advertising, never sold or transferred for others' commercial purposes, and never used to train AI models. Humans do not read your email except where you explicitly ask us to, where required for security or to comply with law, or on data that has been aggregated and de-identified. You can revoke Penni's access at any time at myaccount.google.com/permissions.
We Do Not Sell Your Data
We never sell, rent, or share your personal or financial information with third parties for their own commercial purposes. Period.
Data Storage & Security
- Email content is processed in memory and not stored permanently. Only extracted transaction fields (vendor, amount, date, category) are retained.
- Accounting platform and Gmail OAuth tokens are stored securely and used only to access your accounts on your behalf.
- All data is encrypted in transit (TLS) and at rest.
- We use Supabase for data storage with row-level security.
Third-Party Services
Penni integrates with the following services to operate:
- Intuit QuickBooks Online API, to read and write your accounting data. Governed by Intuit's Privacy Statement.
- Quiltt and MX, our bank data partners, to connect your bank and card accounts on a read-only basis for reconciliation. Governed by Quiltt's and MX's privacy policies.
- Google Gmail API (via Nylas), to read your email for transaction detection. Governed by Google's and Nylas's privacy policies.
- Anthropic, to process data with AI for categorization and document reading. Your financial data is not used to train AI models.
- Twilio, to send and receive text messages (SMS). Governed by Twilio's Privacy Policy.
- Resend, to deliver report and service emails. Governed by Resend's Privacy Policy.
- Stripe, to process payments and subscriptions. Governed by Stripe's Privacy Policy.
- Supabase, for encrypted database storage; Vercel and Netlify, for application and website hosting.
Disconnecting Your Accounts
You can revoke Penni's access at any time:
- QuickBooks Online: Settings → Apps → disconnect Penni.
- Bank connections (Quiltt/MX): disconnect any linked bank from your Penni settings, which immediately stops further access.
- Gmail: https://myaccount.google.com/permissions → find Penni → Remove.
- SMS: reply STOP to unsubscribe at any time.
- Cancel subscription: manage from your billing portal or email connor@penni.so.
Once disconnected, Penni can no longer access or process your data.
Data Deletion
You can request full deletion of your data at any time. Email connor@penni.so with the subject "Delete my data" from the email associated with your account.
- Account data, OAuth tokens, vendor mappings, and customer memory deleted within 30 days.
- Some operational logs (billing, security audits) retained as required by law for up to 7 years.
- Once deleted, your data cannot be recovered.
Your accounting data remains in your accounting platform regardless, your books are always yours.
Children's Privacy
Penni is a business financial service and is not directed to individuals under 18. We do not knowingly collect data from minors.
Changes to This Policy
We may update this policy as the service evolves. We'll notify active users of material changes via SMS or email. The "last updated" date at the top reflects the most recent revision.
Contact
Questions about this policy or how we handle your data? Email connor@penni.so directly. Connor reads every privacy email personally.