Privacy Policy
Effective August 24, 2026
Pengo is built so that we know as little about you as possible. This page describes absolutely everything that gets processed, and where.
The app (app.pengo.money)
- All financial data (transactions, accounts, budgets…) is stored exclusively on your device, encrypted with a password that only you know. No server of ours exists. We have no way to see your data.
- The app contains no analytics, telemetry, or tracking. You don't create an account with us.
- The app's only network connection: fetching exchange rates from the public api.frankfurter.dev API (only a currency pair and a date are sent, never amounts or anything personal; the API operator can technically see your IP address, as with any website) and downloading the app itself from our hosting (Cloudflare Pages).
- The Plus license key is verified exclusively on your device.
- The app remembers your settings (theme, language, home currency, and similar) on your device, in your browser's storage: it stays with you and is never sent anywhere.
The website (pengo.money)
- The website has no analytics of its own and uses no cookies or other tracking.
- Both the website and the app are hosted by Cloudflare Pages (Cloudflare, Inc.), which acts as our processor. Like any hosting provider, it technically processes access logs including your IP address, it needs them to operate and to protect against attacks; the legal basis is our legitimate interest in secure operation (GDPR Art. 6 (1)(f)). We have no access to these logs ourselves; Cloudflare retains them for a limited time under its own policies. Cloudflare is based in the US; the transfer is covered by its certification under the EU-US Data Privacy Framework and the European Commission's standard contractual clauses.
Purchasing Plus
- The purchase is processed by Paddle.com Market Ltd as the official reseller (Merchant of Record) (or the local Paddle entity for your country: Paddle.com Inc. in the US, Paddle.com (Canada) Ltd. in Canada). During payment, Paddle processes your email, country, and the payment or billing details you enter, under its own privacy policy; Paddle is an independent data controller for this data. Paddle.com Market Ltd is based in the United Kingdom, for which the European Commission has issued an adequacy decision. So the transfer requires no further safeguards.
- We receive transaction data from Paddle (email and transaction ID). We use it for two things: issuing and, if needed, reissuing the license key; the name embedded in the key is one you choose yourself when you collect the key (it can be a nickname); the legal basis is performance of the contract and our legitimate interest in after-sales support (GDPR Art. 6 (1)(b) and (f)); and bookkeeping, where the legal basis is compliance with our legal obligation (GDPR Art. 6 (1)(c) in conjunction with Czech Act No. 563/1991 Coll., on Accounting). We do not keep copies of issued keys; if you lose yours, we verify the transaction and issue you a new one.
- Email is required for the purchase: without it Paddle cannot issue you a receipt and we cannot deliver the license key. You choose the name on the license yourself when you collect the key; it's used only for display in the app.
- We retain accounting records of the transaction for 5 years from the end of the accounting period to which they relate (the Accounting Act); tax documents longer, if required by law. Alongside that, for the lifetime of the license we keep a minimal record of its issuance (transaction ID, date, and edition, without your name), so we can reissue the key even after the accounting records have been destroyed. We do not use them for anything other than the license and bookkeeping. Besides us, only processors we cannot operate without can access it (our email and hosting provider and our accountant/tax advisor), as well as public authorities to the extent required by law (typically the tax administration). We never sell it or pass it on for marketing.
- When you write to us at [email protected], we process your email address and the content of your message for the duration of handling it and for at most 3 years from when we close your request, for follow-up communication.
- The payment window is operated by Paddle. It only opens once you click the purchase button: only at that point does the payment script load from Paddle's servers, and Paddle stores technically necessary cookies for processing the payment and preventing fraud; without them the purchase couldn't be completed. Before the payment window opens, nothing is loaded from Paddle.
Your rights
The data controller for personal data from purchases is InSapientia, s.r.o. (contact details in the footer). You have the right to access your data, correct it, erase it (within the limits of statutory retention obligations), restrict its processing, port it, and object to processing based on our legitimate interest. You can exercise these rights at [email protected]. You also have the right to file a complaint with the Office for Personal Data Protection (uoou.gov.cz). GDPR rights simply don't apply against us for data in the app, because we don't have it: it exists only on your device.
Changes to this policy
We may update this policy. We'll publish the new version on this page with an effective date, and announce material changes on the website.