Pensum

Privacy policy

Last updated: [DATE]. Operator: [YOUR NAME OR ENTITY], [CONTACT EMAIL].

What we collect

When you sign in with Google we receive your Google account ID, email address, and name. We also record when you joined, the days you used Pensum (one entry per day, not what you did), which version of the Terms you accepted and when, and an approximate country based on your internet connection (from our network provider, Cloudflare) when you sign up and sign in. We store the budgets you create or join: accounts, categories, transactions, assignments, and who has access. We don’t ask for bank logins, and bank files you import are read in your browser; only the transactions you choose to import are sent to us.

How we use it

Only to run Pensum for you and the people you share budgets with. We don’t sell your data, show ads, or share it with anyone except the infrastructure providers that host the service (Oracle Cloud for servers and storage, Cloudflare for network delivery, Google for sign-in). Server logs record which pages were requested and when, never amounts, payees, or search terms.

Bank sync (optional)

If you connect a bank through SimpleFIN, Pensum stores one access key that lets it read your transactions and balances from SimpleFIN. It is encrypted with a key kept separately from the database and its backups, is never shown to anyone (including the operator), and is deleted the moment you disconnect. Pensum never receives your bank username or password. Transactions it fetches are stored like ones you import. You can also turn off Pensum’s access from your SimpleFIN account at any time.

What the operator can see

To run the service, the operator can see account information (email, name, sign-up date, last activity, country, terms acceptance), the names of budgets and who has access, and counts such as how many transactions a budget has. The operator’s tools do not show what’s inside your budgets: no amounts, payees, categories, or account balances. Administrative actions, such as suspending an account, are recorded in an audit log.

The public pages (the home page, the demo, and these policies) count visits anonymously, with no cookies: only daily totals of which page was viewed, the site that linked to it, any campaign tag in the link, approximate country, and phone or desktop. No IP address or identifier is stored. If you sign up, your account records where you first came from (for example, the site that linked to Pensum). The demo also counts, anonymously, when it is opened, whether something was tried, and clicks on “Create your account”; it never sends what you entered. Browsers set to Global Privacy Control or Do Not Track send none of this.

When Pensum shows you an announcement, it records that you saw it and whether you dismissed or acknowledged it, so you aren’t shown it again and so the operator can tell, for example, that people were notified of a pricing change.

Cookies

Pensum uses a single cookie to keep you signed in. It isn’t used for tracking or advertising.

Security

Traffic is encrypted, each budget is isolated at the database level, the database disk is encrypted, and backups are encrypted before they leave the server.

Your choices

You can download a copy of any budget from Settings. Deleting your account removes it, every budget you’re the only owner of, and your access to shared budgets, right away. Deleted data is purged from backups within 30 days.

Contact

Questions or requests: [CONTACT EMAIL]. Pensum is operated from Utah, United States.