Back

Privacy

Last updated 3 August 2026

What smilepenny stores, why it is allowed to, who else sees it, and how to get rid of it. Written against what the app actually does rather than what a template says.

The short version

smilepenny holds your email address, whatever name and birthday you choose to give, the budget you set, and the transactions you enter or connect. It uses them to show you your own money and to send you a small number of emails. It does not sell anything to anybody, and it does not use your bank data for advertising or profiling.

What is stored

Your email address, which is how you sign in. Your name and date of birth, both optional - the birthday is used only to send you a note on the day and a reminder a month before, and deleting the date stops both.

Your budget: your income, your split, and every planned expense, including previous versions so that looking back at an earlier month shows what you were planning at the time.

Your transactions: what was spent, when, where, and which type of expense it is. If you connect a bank, this includes the accounts and cards you shared and their transactions - from the start of the month you joined onwards, and no earlier. We do not import your history from before smilepenny existed for you.

The access tokens for your bank connection. These are held so that syncing works and are never readable from your browser - the database refuses every request for them except from the server itself.

A record of which emails have been sent to you, so the same one is never sent twice.

Why we are allowed to hold it

Most of it because you asked for the service and it cannot work otherwise - that is performance of a contract under UK GDPR.

Your bank data because you gave explicit consent at your bank, and you can withdraw it there or here at any time.

Your date of birth because you chose to give it. It is optional, and removing it in Settings deletes it.

Who else sees it

Supabase stores the database and handles sign-in. Vercel runs the app. Plaid provides the open banking connection. Resend sends the emails. Sentry receives error reports, which may include the description of a transaction if the failure involved one.

That is the entire list. Nobody else receives your data, and none of these are permitted to use it for their own purposes.

How long it is kept

For as long as you have an account. Deleting it removes everything in the same moment - every table listed above references your account and goes with it, including the record of emails sent. Nothing is kept back.

Disconnecting a bank ends the access immediately and deletes the stored tokens. You choose at that point whether to keep the transactions already imported or remove them.

Your rights

You can download a copy of everything we hold, and delete your account outright, both from Settings - neither needs our involvement. Anything you want corrected, tell us and we will.

If you think we have handled your data badly, tell us first - but you can complain to the Information Commissioner's Office at ico.org.uk regardless.

Getting in touch

Email hello@smilepenny.com for anything on this page. Deleting your account and downloading your data are both in Settings and do not need us.

smilepenny is not yet operating with real bank connections. This page describes the product honestly and is not legal advice; it is being reviewed before anybody's real bank data is handled.