Pensio Privacy Policy

Version 1.3.0 — Effective Date: May 31, 2026


1. Our Privacy Commitment

Pensio was built with a single privacy principle: the link between you and your spending data is the secret, not the spending data itself.

A receipt showing “Milk $5.50 at Countdown” is not private. Knowing that you bought milk at Countdown is private. Pensio encrypts this association — the link between your identity and your invoices — and gives you control over who can decrypt it, including whether we can.

We recommend you read Section 2 carefully. It describes the two protection modes available to you, and we recommend you choose Recovery Key mode for the strongest privacy guarantee we can offer.


2. Your Data Protection Options

You choose how your data is protected. Pensio offers two modes, selectable at any time in Settings > Security & Data.

Recovery Key Mode (Recommended)

Your encrypted data is protected by a Recovery Key that only you possess. Pensio cannot decrypt your data under any circumstances.

How it works: Your data is encrypted with a key (DEK) unique to your account. That key is wrapped using a key derived from your password, and separately wrapped using a key derived from your Recovery Key. We store a verification hash of the Recovery Key, never the key itself.

What this means:

We show your Recovery Key exactly once when you enable this mode. Treat it like a master password. Store it in a password manager or write it down and keep it safe.

Cloud Recovery Mode (Default)

New accounts default to Cloud Recovery for convenience. Your data is encrypted the same way, but the key is additionally wrapped with a server-side system key, allowing us to recover your data during email-based password resets.

What this means:

Comparison

ScenarioCloud RecoveryRecovery Key
Database stolenSafeSafe
DB + server configCould decryptSafe
Operator accessCould decryptCannot
Forgot passwordEmail resetNeeds key
Lost password + keyN/ALost

You can switch between modes at any time. Switching is instant and does not require re-encrypting your data.


3. Data We Collect

Account data: Email address, display name, and (for social login) OAuth provider ID. We do not collect phone numbers, physical addresses, or other personal details.

Invoice and receipt data: When you upload a document, our AI extracts structured information: vendor name, line items, amounts, and spending categories. We store this extracted data, not the original image or text (see Section 4).

Usage metadata: We log request counts, AI model used, and response latency per parse request. This is used for billing and quality monitoring. We do not log invoice content in these records.

Email inbox data (optional): When you connect your email account (Gmail, Outlook, or other providers), Pensio scans your inbox for invoice-related emails only. We collect:

What we do not do with your email:

You can disconnect your email account at any time in Settings > Connect Email, which immediately revokes Pensio’s access and deletes all stored tokens from your device.

What we do not collect: Location data, device identifiers beyond what is needed for session management, contacts, browsing history, or any data beyond what is in the documents you upload or the invoices detected in your connected email.


4. How We Process Invoice Data

When you upload an invoice or receipt, our AI pipeline extracts structured data, which is then split into two categories:

Commercial data (vendor names, product names, prices, categories) is stored in plaintext with no link to your identity. This is equivalent to publicly observable market information and feeds our aggregate market insights (see Section 6).

Personal association data (the link between you and your invoices, plus any buyer-identifying information) is encrypted with AES-256-GCM using your account-specific key and stored separately. Without the decryption key, this data is meaningless.

The original uploaded image or text is discarded after processing. We do not retain source documents.


5. Encryption Architecture

This section describes the technical mechanisms behind Section 2.

Key hierarchy:

Storage: We store only wrapped (encrypted) copies of your DEK, never the plaintext DEK. Your password and Recovery Key are never stored in any form that could be used to derive encryption keys.

Password changes: When you change your password (providing your old password), your DEK is unwrapped with the old password-derived key and re-wrapped with the new one. No recovery key or system key is involved. Your encrypted data is unaffected.

Password resets: Depending on your chosen mode, your DEK is recovered via the system key (Cloud Recovery) or your Recovery Key (Recovery Key mode), then re-wrapped with your new password.


6. Share Anonymous Data (Opt-in)

During onboarding we ask whether you want to share anonymous data to help us improve receipt recognition. This choice is off by default: nothing is shared until you opt in, and you can change your mind at any time in Settings > Privacy & Data > Share Anonymous Data.

What is shared when you opt in

How anonymity is enforced

Every upload arrives at our servers without a usable user-link. The user→invoice mapping is encrypted on-device with a key only you possess; our servers have no way to recover it on their own. From the server’s point of view your contributions are anonymous from the moment of upload.

7 days after upload, an anonymous copy of each contributed sample is emitted into the irreversible anonymous pool. The copy carries the commercial content only (image, OCR text, structured fields, your corrections) and contains no mapping back to your account or device. Your original receipt — and its encrypted user-mapping — stays in your account, unchanged; you continue to own and control it as you would any other receipt. But once a copy lands in the pool, neither you nor we can locate or recall it.

What we use anonymous data for

We use anonymous data only for the following purposes:

  1. Service quality improvements. Improving recognition accuracy, category inference, and OCR robustness for everyone.
  2. Aggregate economic analysis. Public-interest indicators such as inflation/CPI trends, regional price baselines, sector comparisons. Results may be published or shared in aggregate form.
  3. Aggregate insights and consulting services. We may sell anonymous aggregate insights derived from the data pool to third parties (e.g., retailers, researchers). Because the pool contains no user identifiers, such reports cannot be reverse-engineered back to any individual.

What we will not do with anonymous data

You can withdraw consent at any time. Withdrawal is forward-only — see §10.


7. Data Retention

Account data: Retained while your account is active. Deleted within 30 days of account deletion.

Personal invoice associations (encrypted): Deleted when you delete your account. Deletion is permanent.

Anonymous data pool (opt-in only): Each contributed sample is stored with an encrypted user-mapping that only your own key can unwrap — we do not retain any plaintext linkage at any point. 7 days after upload, an anonymous copy of the sample is emitted into the irreversible anonymous pool. The copy carries the commercial content (image, OCR text, structured fields, your edits) and no mapping at all; once in the pool it is retained indefinitely for the purposes listed in §6. Your original receipt and its encrypted mapping remain in your account, separate from the pool, and follow the personal-invoice retention rules above. While the 7-day window is still open the app can use your on-device key to cancel a pending contribution from Settings > Privacy & Data; after the window closes the anonymous copy is in the pool and neither you nor we can find it.

Parse event logs: Retained for 90 days, then permanently deleted.


8. Authentication and Key Data

Passwords: Hashed with Argon2id before storage. We never store plaintext passwords.

API keys: Encrypted with your account-specific DEK before storage. Shown to you once at registration. We cannot retrieve them after that.

Recovery Keys: If you enable Recovery Key mode, your Recovery Key is hashed with Argon2id for verification and used to derive a key-wrapping key. The plaintext Recovery Key is shown exactly once. We cannot retrieve or reset it.

Sessions: JWT tokens expire after 7 days.


9. Service Integrations

OAuth providers (Google, Apple): For account sign-in, we receive only provider ID and email for account identification. We do not access social profiles, contacts, or other data.

Email inbox integration (Gmail, Outlook): When you opt in to connect your email, Pensio requests the minimum read-only permission from each provider:

All email API calls are made directly from your device to the provider (Google or Microsoft). The Pensio backend is not involved in email access and never sees your email tokens or email content. Attachments are downloaded to temporary device storage, processed for invoice extraction, and immediately deleted.

AI-powered data extraction: Pensio uses AI models to extract structured data from your invoices and receipts. Only the commercial content of your document is processed by these models (vendor names, product descriptions, prices, dates). Your identity, account information, and any buyer-identifying details are never sent to any AI model.

No analytics SDKs. No ad trackers. We do not embed third-party analytics or advertising code in the app.


10. Your Rights

Access: View all your invoice data in the app at any time.

Portability: Export your data in JSON format from account settings.

Deletion (your account): Delete your account and all associated personal data at any time. Deletion is permanent and irreversible.

Withdraw anonymous-data consent (forward-only): Toggle off Settings > Privacy & Data > Share Anonymous Data at any time. From that moment on no further samples are uploaded from your device. Prior contributions that are still inside their 7-day window proceed to the anonymous pool on schedule unless you also cancel them individually below.

Cancel a pending contribution (within 7 days): Settings > Privacy & Data > Recent Contributions lists samples still inside the 7-day window. The app uses your on-device key to identify them and lets you cancel one before the anonymous copy is emitted. After the window closes the copy is in the pool and cannot be located or recalled by anyone. Your original receipt is separate — you can still delete it from your account at any time, but doing so after the window closes does not affect the pool copy.

Anonymous insights derived from the pool: Aggregate statistics, reports, and insights produced from anonymous data (see §6 purposes) cannot be unwound even if you withdraw consent or delete individual samples — they contain no personal information about you and are not personal data.

Contact: [email protected]


11. Children

Pensio is not intended for users under 16. We do not knowingly collect data from children.


12. International Data

Our servers are in New Zealand. Your account data and encrypted invoice associations are processed and stored there.


13. Changes

Material changes: 30 days notice via email and in-app notification. Non-material changes (typos, clarifications): updated without advance notice.


14. Contact

[email protected]