WHAT WE KEEP
Privacy
Updated September 10, 2026
Penny Pincher watches prices for you, which means it has to hold on to a few things: who you are, what you are watching, and what those things have cost. That is the whole shape of it. Below is the specific version — every category we collect, everyone who touches it, and how to get it back or get rid of it. No boilerplate, no pages of definitions.
Penny Pincher is operated from the United States. In this policy, "we" and "us" mean Penny Pincher; "the app" means the iPhone app and its share extension; "this site" means app.pennypincher.com.
What we collect
- Your account. An email address and a password, or a Sign in with Apple or Sign in with Google identifier instead. Passwords are stored hashed with a modern password hash — we never store the password itself, and we can't read yours. No system is perfectly secure, so use a password you don't use anywhere else. If you sign in with Apple or Google, we get whatever name and email address those providers pass along.
- Your subscription, if you buy one. Apple takes the payment; what reaches us is the receipt. We store the Apple transaction records for Penny Pincher Pro — the product identifier, the timestamps for purchase, renewal and expiry, the transaction identifiers Apple issues, the amount and currency Apple charged, whether it is set to renew, what state Apple says it is in, the timestamp if Apple ever revokes it, whether the purchase came from the live store or a test environment, and a random identifier our app makes up so that receipt can be matched to your account — because that record is what switches Pro on. Your card details are not in it. They never come to us at all. "Subscriptions and billing" further down is the longer version.
- The products you share. The link, plus the title, image, price and variant (size, color) we read from that page, your target price and your notification preferences. This is your watch list — without it there is nothing to watch.
- Price observations. Every time our checkers look at one of these products we store the price and the time we saw it. Worth knowing: these are stored against the product, not against you. One product's history is shared by everyone watching it, and it can outlive any one account. Nothing in it points back to a person.
- Push tokens. If you allow notifications, Apple gives us a device token so an alert can reach your phone. It identifies a device, not a person, and it disappears when you turn notifications off.
- Where the install came from. If you installed the app after tapping an Apple Ads campaign, the app asks Apple which campaign brought it here. Only the question is local: iOS generates a token on the device, the app sends that token to Apple over HTTPS, and Apple's servers send back the answer. We store that answer with your account at the moment the account is created — never later, and never on an ordinary sign-in. What Apple hands back is campaign-level numbers: the identifiers it assigns to the campaign, the ad group, the keyword and the ad, the country or region the tap came from, the dates of the click and the impression, and a few bookkeeping fields — conversion type, claim type, placement. That is the whole record, and none of it describes a person: no identity, no advertising identifier, no device fingerprint. It sits outside App Tracking Transparency and raises no permission prompt because there is nothing personal in it to permit. If you found us any other way — a link, a search, a friend — there is nothing to ask Apple about and nothing gets recorded. Ads we run on Meta's platforms are measured a different way, by Meta's own software inside the app from version 1.0.2 onward; "Advertising measurement in the app" below is the whole of that.
- Diagnostics. Crash reports and server error logs, so that the thing that broke can be fixed. These can include a product URL, because that is usually what broke. From version 1.0.2 Meta's kit collects crash reports of its own, described under "Advertising measurement in the app" below.
- A beta request, if you sent one. Before Penny Pincher was on the App Store, this site carried a form for asking to join the TestFlight beta. That form is gone and we are not taking requests any more. The records it made — the name and email address you typed, an approximate location for the request, and any campaign tags the visit carried — still exist while we retire them, and you can have yours deleted today by asking. One scrambled copy of part of each request also went to Meta at the time, so we could tell which ads brought testers; that copy is on Meta's retention schedule, not ours, and we cannot recall it. Both are spelled out under "This website" below.
- What you email us. If you write in for support, we keep the message and our reply, for as long as it's useful to have the thread.
What we do with it
Run the service. That is the entire list. Your email signs you in and carries the occasional message about the service; your watch list tells our workers what to check; your push token is how a price drop reaches your lock screen; your subscription receipt is how the app knows you have Pro; your diagnostics tell us which store stopped parsing this week.
We look at aggregate numbers — how many products are being watched, which sites fail to parse, how long a check takes, which channels people arrive from — to keep Penny Pincher working and to know where it's worth telling people about it. That is counting, not profiling. We don't build advertising profiles about you, we don't score you, and no automated decision here has a legal effect on anyone. We do measure whether our own ads worked, and because that means an ad network is involved, it is written out in full in "Advertising measurement in the app" below rather than left to be inferred from a sentence like this one.
What we don't do
- We don't sell or rent your personal data. Not to retailers, not to brokers, not to anyone. Two things reach an ad network, and we would rather name them than bury them. The first is in the app, from version 1.0.2 onward: Meta's measurement software tells Meta that the app was installed, opened, bought from or crashed, so the ads we run for Penny Pincher can be judged on what they actually produced — "Advertising measurement in the app" below is the whole of it, down to the last field. The second is finished: while the beta form was up, sending it made our server report to Meta that a signup had happened, in the scrambled form spelled out under "This website" below, so the ads that paid for the beta could be judged on testers rather than on clicks. Both are measurement, not an audience list — nothing is uploaded to build an audience, and nobody buys a list of our users, because there isn't one. No advertising pixel or tag runs on this site, and with the beta form retired nothing you can do on these pages tells Meta anything whatsoever. If you sent that form and would rather it hadn't happened, say so and we'll take your beta request out of our records; "Your data, on request" further down is the route.
- We don't carry third-party analytics or trackers inside the app, and we don't track you across other apps or sites. From version 1.0.2 the app carries exactly one third-party SDK — Meta's, described below — and its only job is measuring our own advertising: it shows you nothing, asks Meta nothing about you, and never reads your device's advertising identifier, because we never ask for permission to. There are no ads in Penny Pincher. Beside it sits Apple's AdServices, which answers the campaign question described above — a system framework built into iOS rather than somebody's SDK, and it answers with campaign numbers, never with you.
- We don't ask for your contacts, your location, or your photo library, and we don't collect your browsing history. We see the products you explicitly share with us, and nothing else you do on your phone.
- We don't hand your watch list to the stores in it. When a price gets checked, the request comes from our servers, not from your phone — the shop sees us, not you.
- We don't send marketing email. What you will get: the alerts you chose (as push notifications on your phone), the account email that keeps the account working — sign-in, verification, password resets, security notices — the subscription mail that goes with paying us, which is a welcome when Pro starts and a reminder before a free trial turns into a charge, and a heads-up when these policies change materially.
Advertising measurement in the app
We buy ads for Penny Pincher on Meta's platforms — Facebook and Instagram — and from version 1.0.2 onward the app carries Meta's software development kit so those ads can be judged on what they actually produced: whether an install, or something you did afterwards, followed one of our ads. That is its whole job. It shows you nothing. There are no ads inside Penny Pincher, nothing here asks Meta what to put in front of you, and no part of your watch list is involved.
What it sends Meta on its own. That the app was installed, and that it was opened. Purchases made through the App Store — which product, and the price — never your payment details, which we don't see either. Crash reports the kit itself collects — the crashes its own code was involved in, not every crash the app has. And basic details about the device: model, iOS version, language, time zone, app version, and the carrier or network type. Meta's servers see the network address your phone's request came from, the way any server does when your phone talks to it; we don't add it and we don't store it. Everything hangs off a random identifier the kit makes up for that install — not a name, not an account, not a device id. We also tell Meta when an account gets created — but only for email-and-password sign-ups: one event that says "registered", carrying nothing about you but the fact that it happened. Creating an account with Apple or Google tells Meta nothing, because those doors can't tell a new account from a returning sign-in.
What it never sends. We don't ask for tracking permission, so the app never reads your device's advertising identifier — without permission iOS hands back nothing but zeros, and we have that collection switched off in the kit besides. Meta gets no name, no email address, and nothing you type into the app. On top of that we set Meta's Limited Data Use option, which restricts what Meta is allowed to do with what it receives under US state privacy laws.
Matching an install back to a specific ad is Apple's job, not the kit's. Apple's SKAdNetwork tells Meta, in aggregate, that an install followed one of our ads; it names no person and no device, and the kit's only part is to register the install with Apple on first launch. It is the same idea as the Apple Ads question described above — a count, not a file on you. For anything Meta works out on its own side from the events above, Meta's Privacy Policy, linked just below, is the governing document rather than this page.
What you can do about it. Deleting your account ends everything we hold about it, and Deleting your account below is the list of what goes. Meta's side is Meta's: what it may do with these events, and how long it keeps them, are governed by Meta's Privacy Policy rather than by this page, and the switches for it are in your own Meta Ad preferences.
How a price check actually works
Checks run from our servers on a schedule. For most sites the reading is plain mechanical work: fetch the page, pull out the number, store it with a timestamp.
The first time somebody shares a product from a site we don't know yet, we may send that page's content — its HTML and text — to an AI provider, Anthropic and/or OpenAI, to work out which part of the page is the title, the price and the variant. We send the page, not you: no name, no email, no account data, nothing about who shared it. Whatever method wins gets saved as a fixed rule for that site, so the AI is a first look, not part of the recurring check loop. Under both providers' API terms, data sent through their APIs is not used to train their models.
Amazon products work differently: their price data comes from Keepa, a third-party Amazon price service. We send Keepa product identifiers such as an ASIN, never anything about you.
Product images are copied to our own storage (Cloudflare R2) rather than hotlinked, so viewing your watch list doesn't quietly ping a retailer's servers from your phone.
Other stores, and affiliate links
The "at other stores" and "similar deals" features are powered by Sovrn, a comparison and affiliate network. We pass product information to find matching offers; we don't pass your identity.
Some outbound links to retailers — from those features, and possibly other store links in the app — may be affiliate links, which means we may earn a commission if you buy, at no extra cost to you. It never affects which prices we show you or when an alert fires. Once you tap through to a store, you are on their site under their privacy policy and their terms, not ours. The same disclosure lives on Terms.
Subscriptions and billing
Penny Pincher Pro is bought through Apple, which makes Apple the shop. We never see your payment details — no card number, no billing address, nothing of the sort. That part happens between you and your Apple Account, and we are not in the room for it. There is nothing here to leak because there is nothing here.
What does reach us is the receipt, and we keep all of it: the product identifier, the timestamps for purchase, renewal and expiry, the transaction identifiers Apple issues, the amount and currency Apple charged, whether the subscription is set to renew, what state Apple says it is in — trialling, running, in a grace period, expired — the timestamp if Apple ever revokes it, and which environment the purchase came from. One field in there is ours rather than Apple's: a random identifier our app makes up at the moment you buy, whose entire job is to let Apple's receipt be matched to your account. The amount is worth being plain about, since it is the one number here that sounds financial: it is Apple's record of what it billed, and knowing what a month of Pro cost tells us nothing whatsoever about the card it came off.
That record is the entire reason Pro works — it is what our servers read to decide your account gets hourly checks instead of daily ones. We use it for that, for answering "did my renewal go through?", for sending the two mails that go with it (a welcome, and a warning before a free trial becomes a charge), and for counting how many subscriptions there are. Nothing else. This stored record goes to no ad network, and none of it is part of the one hashed report described further down — the app's own purchase event, which carries only the product and the price and never these fields, is set out under "Advertising measurement in the app" above.
It lives as long as your account does and it goes when your account goes. One thing worth stating plainly, because it is what catches people out: deleting your Penny Pincher account does not cancel the subscription. That lives in your Apple Account — Settings → Apple Account → Subscriptions — and cancelling it there is yours to do. Terms has the rest of that deal, including refunds, which are Apple's.
Who else touches it
These are tools we use to run Penny Pincher, not audiences we sell to. Each one gets only the slice it needs to do its job.
- Apple. Distributes the app through the App Store — and through TestFlight if you are running a pre-release build — delivers push notifications through APNs, and provides Sign in with Apple. Apple is also the shop: it takes the payment for Penny Pincher Pro, holds the payment details we never see, emails the receipts, and hands us the transaction record described above. If an install came from an Apple Ads campaign, Apple is what answers the app's attribution question: the app sends Apple a token iOS generated on the device, and Apple's servers reply with campaign numbers. Nothing about you goes the other way. One thing did go the other way while the beta ran: if you asked for an invitation, the name and email you gave us were added to the TestFlight group, and Apple was what emailed you the invitation. That form is retired, so nothing here adds anyone to a TestFlight group any more.
- Google. Provides Sign in with Google — only if that's how you signed in.
- Cloudflare. Serves this marketing site and stores the mirrored product images. It also ran the site's one request handler, the one behind the beta form — that is how an IP address became the approximate location a beta request was recorded with, and the IP itself was never stored. That handler is still deployed, but no page on this site calls it any more, so all Cloudflare does here now is serve files and process the standard request logs described under "This website".
- Meta. Only ever to measure our own advertising, in two places. In the app, from version 1.0.2 onward, Meta's kit reports installs, opens, App Store purchases, crashes and the device basics, against a random per-install identifier — no name, no email, no advertising identifier, nothing from your watch list, and under Meta's Limited Data Use restriction. "Advertising measurement in the app" above is the full field list. On this site, only ever from the beta form: when someone sent it our server told Meta a signup had happened and handed it a one-way scrambled version of the email address and first name, the network address the request came from, the description the browser sends about itself, the path of the page the form was on, and a Facebook ad's click id if that was how they got here. Meta never received an address or a name in readable form, and no Meta code has ever run on this site. With the form retired, nothing on these pages sends Meta anything at all; what was already sent sits on Meta's retention schedule rather than ours.
- Anthropic and OpenAI. The first-look extraction described above. Page content only.
- Keepa. Amazon price data, from product identifiers only.
- Sovrn. Cross-retailer offers and affiliate links, from product information only.
- Our hosting and database provider. Runs the servers your account and watch list live on — and the download redirect, which is ours rather than a third party's.
- The retail sites themselves. They see our server's requests when we fetch a product page. They do not see you.
We may also disclose data if the law genuinely requires it, or to protect the service and its users from abuse or fraud. If Penny Pincher were ever sold or merged, accounts would move with it under this same policy. We'd say so on this page, and you can delete your account at any time.
This website
app.pennypincher.com is a set of static files. There is nothing to fill in on it any more — every page here is a file. The site sets no cookies, runs no third-party analytics, carries no ad pixels — nothing from Meta or anyone else runs inside these pages — and loads nothing from anyone else's server: the fonts, the images and the three small scripts are all ours. Cloudflare serves it and processes standard request logs — IP address, user agent, what was requested — to deliver the page and keep it standing up, and what we see of that is aggregate operational metrics, not visitors. One request handler is still deployed in front of these files, left over from the beta form described next; no page on this site calls it.
The beta form, which is retired. Until Penny Pincher reached the App Store, this site had one form on it — asking for a TestFlight invitation — and it was the one thing here that wrote anything down about you. It is gone: no page renders it, and we are not taking requests any more. The records it made still exist while we retire them, so here is the whole of one. We kept the name and the email address you typed. We kept an approximate location for the request — country, region, city, time zone, and the network operator your connection belonged to — which Cloudflare derived from your IP address and passed to us; the IP address itself was never part of that record and we did not store it. We kept your browser's user-agent string and the address of the page the form was on. And we kept whatever campaign tags the visit arrived with, described two paragraphs down. It was used for two things: sending you the invitation you asked for, and knowing which channels the beta's testers came from. Nothing else. The invitation email itself came from Apple, because TestFlight is Apple's, and your address went to Apple for that purpose when we added you to the beta group. A scrambled copy of part of that record also went to Meta, for the second of those two purposes, and the next paragraph is the whole of it.
The one thing that left for Meta. Some of the advertising for the beta ran on Facebook and Instagram, so when — and only when — you sent that form, our server told Meta that a signup had happened. That is how we could tell which ads actually brought testers rather than just clicks. What went with it, in full: a hashed version of your email address and a hashed version of your first name; the network address the request came from; the description your browser sends about itself; the address of the page you sent the form from — the path alone, with the query string and any campaign tags stripped off it; and, if you arrived by clicking a Facebook ad, that ad's click id. Hashed means scrambled one way, into a fixed string of letters and numbers that cannot be turned back — Meta can check it against a scramble of an address it already has, and that is all it can do with it. Your email address and your name never left here in readable form. Nor did anything else: not your location, not the pages you read before or after — only the one the form was on — and nothing from the app, which reports to Meta on its own account and is written out under "Advertising measurement in the app" above. And nothing at all was sent for a visit that didn't send the form. There has never been a Meta pixel in these pages, never any Meta code of any kind on this site, and nothing in your browser has ever talked to Meta. With the form gone, that report has nothing left to fire on: read the page, close the tab, and this site tells Meta nothing about you.
One thing here is still measured, so here is exactly how. If you arrive on a campaign link, the tags it carries — utm codes, a plain "ref" tag, an ad network's click id — are kept for the visit in your browser's own per-tab storage. That storage is first-party and short-lived: nothing reads it but this site, it sends itself nowhere, and the browser throws it away when you close the tab. It now leaves this site in exactly one place: those tags ride along when you tap a download button, because the button goes through our own redirect service rather than straight to the store. The redirect logs the campaign tags, your browser's user-agent string, the site that referred you and the time — and deliberately leaves out your IP address; it isn't in the record we keep. The purpose is counting which channels bring people to the app. That is the entire purpose: no profile behind it, no third party in it, and nothing about the tap sent to an ad network — tapping a download button reports to nobody outside our own servers. (While the beta form was up, the same tags were also part of the record it made, and a Facebook ad's click id among them was the one that carried on to Meta.)
Worth being exact about what is left, because it is the whole distinction this page rests on. A download click is counting: no name, no email, no IP address, nothing that points at a person, and nothing that goes anywhere but to us — and it happens only because you tapped something. A beta request was a record about you: the same campaign tags, but attached to the name and email you typed — and it was the single moment anything on this site reached an ad network, in the hashed form described above. That was the exception, it took filling a form in and sending it, and it cannot happen here any more. All of that is about this site; what the app sends Meta is a separate arrangement, and "Advertising measurement in the app" above is the whole of it.
How long we keep it
Your account and watch list stay while your account does, and so do the install campaign and the subscription records attached to it. Diagnostics and error logs are kept only as long as they're useful for fixing what broke. The download-click records contain nothing about a person; we keep them while the campaigns they count are still being evaluated, and clear them out once they aren't. The beta program has ended, so the requests it collected have no purpose left: we are retiring those records, and if you sent one you don't have to wait for us — ask and yours goes, which is what "Your data, on request" below is for. The two things we can't set a clock for are the ones already at Meta: the hashed signup reports sent while that form was up, and the app's advertising-measurement events. Once sent, both sit on Meta's own retention schedule under Meta's policy, not ours. Push tokens go when you turn notifications off. Support email lives in the inbox as long as the conversation is worth having.
Deleting your account
Delete your account in the app and what is attached to it goes with it: your watch list, your alerts, your push tokens, the campaign the install came from, the Apple transaction records behind a Pro subscription, the account itself. There is no shadow copy waiting in case you come back.
What deletion cannot reach is the subscription itself, because it isn't ours: cancel Pro in Settings → Apple Account → Subscriptions, and do that first if you are leaving — an account that no longer exists still can't stop Apple charging for one.
Two honest exceptions. A product's price history is stored against the product, not against you, so a chart of what a rice cooker cost last spring can outlive your account — nothing in it points back to a person. And the things above with their own clocks — diagnostics, error logs, support email — expire on those clocks rather than at the moment you delete; if you want a support thread gone too, say so and we'll delete it.
Your data, on request
Want a copy of what we hold, or a correction, or a deletion you can't do from the app? Email contact@pennypincher.com and we'll do it — no form to fill in, no verification theatre beyond proving you control the address on the account.
If you're in California, the EU, the UK or somewhere with similar rules, the law gives you rights over your data: access, correction, deletion, a copy in a portable format, the right to object to or restrict some processing, and the right not to have it sold or shared. We answer those requests the same way for everyone, wherever you live, and we won't treat you worse for asking. If you think we've got something wrong, you can complain to your local data-protection authority — though email us first; it's faster. We don't hold any privacy certification and don't claim one.
Children
Penny Pincher isn't built for children and isn't directed at anyone under 13. Don't create an account if you're under 13. If we find out we're holding an account for someone who is, we'll delete it.
Where your data lives
Our servers and database run with a hosting provider, and your data may be processed in the United States and/or Europe. The third parties above may process data in their own locations. Whichever side of the Atlantic it's sitting on, the rest of this page still applies to it.
This page will change
Penny Pincher is young software, now on the App Store, and this page moves as it grows. When it does, we'll change the date at the top, and for anything material we'll say so in the app or by email rather than quietly editing the fine print.
Ask us
Questions, deletions, or a bug that made us store something we shouldn't have: contact@pennypincher.com. More ways to reach a person are on Contact; the rules of the road are on Terms.