Privacy
The short version. We do not hold your money and we do not want your child’s personal information. A child using Pennies Up never gives us an email address, a phone number or a photograph. We ask you for their date of birth, and nothing about them is ever collected from them.
We do not sell personal information, and we do not share it for advertising.
Who we are
Pennies Up is operated by PenSnap Software, LLC. You can reach us about anything on this page at [email protected].
What we collect from parents
- Your email address, used to sign you in and to contact you about your household. Sign-in is a six-digit code sent to that address; we do not require a password.
- Your household’s name and timezone. The timezone is captured from your browser when you set up, and it is what makes allowance land on the right day for you.
- What you enter about your children — a display name, a date of birth, and the money settings you choose.
- Security and audit records — sign-in attempts, session activity, and changes to settings, so that account access can be investigated if something looks wrong.
Children’s privacy
This section is the notice required by the Children’s Online Privacy Protection Act for children under 13.
We collect information about a child, from you
The information in Pennies Up about a child is entered by a parent, not collected from the child. That distinction is built into the system rather than promised: a child who has no login exists in our database only as a record you created, with no credentials attached to it.
What a child with a login gives us
A child never provides an email address or a phone number. Signing in is a household code plus choosing their name plus a PIN that you set. Internally their record carries a placeholder address ending in @penniesup.invalid — a reserved, undeliverable domain. It is an identifier, not a way to contact anyone, and nothing is ever sent to it.
We ask a parent for a date of birth
We store your child’s date of birth. It is used for two things and nothing else: to decide which version of the interface they see, and to decide the day their own sign-in becomes available.
This changed, and we would rather say so than not. We previously stored a birth year alone, on the reasoning that an age band was all any of these decisions needed. It was not quite true. A child’s own sign-in is not available before they are six, and with a year alone that fell on the 1st of January in the year they turned six — up to eleven months early. An age limit you cross early is not an age limit, so we ask for the day.
A date of birth is more identifying than a year, which is why it is used for nothing else, is never shown to anyone outside your household, is not sent to any third party, and is deleted with the rest of your household’s data when you delete your account. Children added before this change still have only a year on file, and we have not invented a date for them.
What we do not do
- We do not show advertising to children. Ever.
- We do not disclose a child’s information to third parties for their own purposes, and we do not sell it.
- We do not require a child to disclose more than is reasonably necessary to use the app, as a condition of using it.
Your rights as a parent
You may review the information we hold about your child, delete it, and refuse to permit any further collection or use of it — without that decision costing you access to the rest of your household. Email [email protected] and we will act on it.
How long we keep it
We keep a child’s information only for as long as is reasonably necessary to provide the feature it was collected for, and we do not keep it indefinitely.
- While your household is active — a child’s record and their money history are kept, because the history is the product. A balance is the sum of its entries; deleting the entries deletes the balance.
- When you delete a child — their personal details are deleted within 30 days.
- When you close your household — everything belonging to it is deleted within 30 days.
- Sign-in codes expire after five minutes, and expired records are purged automatically after a day.
- We delete rather than archive. Where a record must persist for security or legal reasons, it is reduced to the minimum needed for that purpose.
Third parties, and the coach
We use a small number of service providers to run the product — hosting, our database, and email delivery for sign-in codes. They act on our instructions and may not use your information for their own purposes.
The AI money coach described on our home page is not built yet. When it is, sending a child’s words to a model provider is a disclosure to a third party, and it will require your separate, explicit consent — agreeing to give your child a login is not agreeing to that. Until you give it, the coach stays switched off.
Security
Passwords and PINs are hashed with argon2id and are not recoverable by us. Sessions use rotating tokens that are invalidated if one is ever replayed. Sign-in attempts are rate-limited and lock out after repeated failures. Money records cannot be edited or deleted, by us or by anyone — the database refuses; a correction is a new entry.
We do not claim “bank-level” or “military-grade” security, because those phrases do not mean anything.
Changes
If we change how we handle children’s information in a way that matters, we will tell you and, where the law requires it, ask for your consent again rather than assuming it.
This notice describes our actual practices and is published in good faith. It has not yet been reviewed by counsel, and will be before we begin charging for Pennies Up.