What Penny does with your data
Penny is a family operating system. To be useful, Penny has to hold genuinely personal data: school emails, flight confirmations, addresses, passwords, locations, photos of documents. This page is the plain-English version of how that works. The longer engineering version lives in our public security architecture page.
Effective: June 11, 2026. Last updated: June 11, 2026.
Who Penny is
Penny is operated by Sugar Inc., a Delaware corporation. Penny is in private beta with one family today (the Sugar family). Each family runs in its own isolated workspace at <family>.penny.is. One family’s data is never accessible to another.
What data Penny collects
Account and family roster
When an owner creates a family workspace, Penny records the owner’s name, email, and mobile phone number, and the same for any family member the owner adds. Family members can update their own record at any time.
Conversations with Penny
Every text message exchanged with Penny over iMessage, every chat turn on penny.is, and every email forwarded or auto-synced into Penny is stored. Bodies and attachments are kept so Penny can answer questions about them later.
Connected integrations
When an owner connects a Google account (Calendar + Gmail) or any other supported provider, Penny receives the data the user explicitly authorized through that provider’s consent flow. For Google specifically:
- Calendar: Penny reads events to display them in the family calendar and propose new ones. Penny does not modify or delete existing Google Calendar events in v0.1.
- Gmail (gmail.modify scope):Penny reads inbound mail to classify it (flight confirmation, receipt, school update, newsletter, work email). Penny may label messages as filed and, in future versions, send drafts on the user’s behalf. Penny does not permanently delete mail.
Owners can disconnect any integration at any time from /admin/integrations. On disconnect, Penny revokes the OAuth refresh token at the provider before deleting it locally.
Uploaded documents and photos
Files dropped into the chat or uploaded through the Files page are stored in a private Supabase Storage bucket. Penny runs them through a vision model to classify and extract structured data (e.g., flight number, expiry date).
Location data (optional)
When a member installs the Penny mobile app and opts in to location sharing, Penny records each family member’s location pings. Location data is visible to the member it describes and to family owners; it is not visible to other family members by default.
Automatic technical data
Standard server logs (IP address, user agent, page path) captured by Vercel during a request. Used for debugging and abuse detection only.
What Penny does NOT collect
- We do not run any third-party analytics, ad pixels, or tracking SDKs. There is no Google Analytics on penny.is.
- We do not store payment card numbers. Billing is handled by a PCI-compliant processor; we see the last four digits and the expiry date only.
- We do not collect biometric data (face, fingerprint, voice prints).
How Penny uses your data
- Deliver the product.Penny answers questions about your family’s schedule, files, contacts, and history.
- Classification. Inbound email and uploaded documents are classified so the right ones land on the calendar, in the vault, or on the Home feed.
- Replies on iMessage and web chat.Penny composes replies in the family thread using a large language model with the family’s data as context.
- Safety routing.If a family member messages Penny something that flags Penny’s safety detector (self-harm, abuse, immediate danger), Penny forwards an alert to family owners and tells the speaker it is doing so.
- Operations. Aggregated usage metrics for debugging, performance tuning, and incident response.
Penny does not use your data to train any machine learning model. Penny does not sell your data. Penny does not share your data with advertisers.
Sub-processors
Penny relies on the following companies to run the service. Each receives the minimum data necessary for its purpose.
- Anthropic, PBC (Claude API): receives text from email bodies, document OCR text, and chat turns for classification and reply generation. Zero Data Retention configuration enabled (no prompt or response retention at Anthropic beyond what is required to deliver the response).
- Supabase, Inc.: database and file storage. All persistent data lives here. SOC 2 Type II.
- Vercel, Inc.: web hosting + serverless functions + cron triggers. SOC 2 Type II.
- Google LLC: per-user OAuth provider for Calendar and Gmail. Penny reads from Google; Google does not receive your other data.
- SendBlue, Inc.: iMessage gateway for inbound and outbound messages.
- Resend, Inc.: transactional email delivery (welcome messages, owner alerts).
Where data lives
All persistent data lives in a single Supabase project hosted in us-west-1 (Oregon, United States). Backups and read replicas, where they exist, are in the same region. Penny does not move data outside the United States.
How long Penny keeps data
Specifics live in our public retention schedule. Summary:
- Structured brain extractions (calendar events, contacts, filed documents): kept indefinitely, since they are the product. Any family member can “forget” an entry within 60 seconds; owners can forget anything at any time.
- Raw inbound email bodies: 90 days, after which the body is redacted (sender + subject + extraction remain).
- Live location pings: 90 days at fine granularity.
- Audit log: 2 years.
- Integration credentials: kept while the integration is connected. Deleted (and revoked at the provider) on owner-initiated disconnect.
Your rights
Owners can exercise the following at any time:
- See your data. Every page in Penny is a view onto your data. Request a full export by emailing hello@penny.is; we deliver within 30 days.
- Correct your data. Most fields are editable in product. For anything else, email us.
- Delete your data. Request full deletion via the danger-zone page in admin or by email. All data is removed within 30 days, except audit log entries which persist (anonymized) for the audit-log retention window.
- Revoke integration access. Disconnect any integration at any time from
/admin/integrations. Penny revokes the OAuth refresh token at the provider immediately.
Children
Penny is a family OS, so it sees information about children: school emails, after-school schedules, photos of permission slips. By creating a family workspace, the owner consents to Penny processing this information about their children on the family’s behalf, in the family’s sole interest. Penny does not market to children, does not create accounts for children independent of their parent, and does not share children’s data with third parties beyond the sub-processors listed above.
If a child uses Penny directly (e.g., texts the family number from their own phone), their messages are stored under the family workspace owned by their parent. The parent can review, edit, or delete this data at any time.
Security
Credentials are encrypted at rest with a key that lives outside the database. Decryption is owner-gated and audit-logged. Service role access is scoped to ingest workers and cannot decrypt user secrets without a real owner session. Full architecture and the candid list of known gaps live at penny.is/security.
Cookies
Penny sets two cookies: a Supabase Auth session cookie (HttpOnly, Secure, SameSite=Lax) so you stay signed in, and a short-lived OAuth state cookie during Google connect. No tracking cookies, no advertising cookies, no analytics cookies. We do not use a cookie banner because we do not need consent for the cookies we set.
Changes to this policy
We will update this page when material changes happen. The “Last updated” date at the top of the page reflects the most recent revision. We will email every owner before a change that affects how we use existing data takes effect.
Contact
Email hello@penny.is for any privacy question. We respond within 5 business days, typically within 24 hours.
Penny is operated by Sugar Inc., Delaware. Postal address available on request.