Legal

Privacy policy

Last updated 9 October 2026

Your statement stays in your browser.

In short

  • Files are read in your browser. We never see them.
  • History stays on your device, unless you choose to keep a copy in your own Google Drive. We never see that copy.
  • An account keeps a few facts. No statement content.
  • No ads. No tracking.
  • Delete your account on the Account page.

1. Who is responsible for your data

Evrim Mete Öztürk, an individual sole trader based in Türkiye, trading as Pennyproof, is the controller of the personal data described here. Address: Bilkent University, Dormitory 76, Bilkent, 06800 Çankaya, Ankara, Türkiye. Email: support@evrimmete.com.

2. The free route: nothing is sent to us

When you use Pennyproof without an account, your PDF, CSV or Excel file is opened and read inside your browser, on your device. The contents of the file, the amounts in it and the file name are never sent to our servers. We cannot see them, so we cannot lose them, sell them or hand them over.

The page itself loads from our host. Like any website, the host sees that your browser asked for the page, which includes your IP address and browser type, for security and to keep the site running.

3. What stays on your device

Your conversion history and your dashboard are stored only on your device, in your browser's storage (IndexedDB and localStorage). We do not receive a copy. You can delete it from the Settings menu on the dashboard ("Delete all data"), or by clearing the site data in your browser. If you clear your browser data or switch device, it is gone, unless you keep a copy in your Google Drive or in a backup file (both below). We cannot restore it.

Keeping your data in your Google account (Plus, optional)

Off until you turn it on. It comes with Plus and the plans above it, and with a trial.

What is kept. Your saved statements (every row and figure as converted), your edits, categories and category rules, account names, and your dashboard layout and other dashboard choices. A Google Sheet called "Pennyproof transactions" lists every transaction. It is a copy: changes made in the sheet are not read back. Exchange rates, the Smart categories consent and the tab you were on stay on each device.

Where. In a folder called Pennyproof in your own Google Drive, under your Google account. Your browser sends it straight to Google (googleapis.com). Our servers never receive this data or your Google access token. The token is kept only in the page's memory, is never stored, and is gone when you close the page.

What Pennyproof may open. Only the files Pennyproof itself made in your Google Drive. Google calls this permission "drive.file". Pennyproof cannot see or change any other file in your Drive. The page loads Google's sign-in script only when you open the Google Drive card, reach for Connect, or have syncing on.

Stopping and deleting. "Stop syncing" stops it on that device and leaves the files in your Drive. "Delete my Pennyproof files from Google Drive" asks twice, then moves the Pennyproof folder to your Google Drive bin, where Google deletes it for good after 30 days (you can empty the bin sooner). "Take back access to Google Drive" removes Pennyproof's permission at Google. You can also remove it in your Google Account under Third-party connections. Deleting your Pennyproof account does not touch your Google Drive, because we have no access to it.

Pennyproof's use of information received from Google APIs will adhere to Google API Services User Data Policy, including the Limited Use requirements. In plain words: the data is used only to keep your copy and show it back to you in Pennyproof. It is not used for ads, not sold, not used to train any model, and nobody at Pennyproof can read it, because it never reaches us.

Backup files (optional)

"Back up to a file" on the dashboard saves one file on your device with your statements and changes. Nothing is sent anywhere. The file has no password, so anyone who has it can read your statements. Keep it somewhere safe. "Restore from a file" adds what is in the file to this device, including statements you deleted after making the backup, and removes nothing.

Converting currencies (optional)

To convert currencies we fetch public ECB rates by date; your amounts stay on your device.

This only happens if you choose Show everything in on the dashboard, with or without an account. The request holds a start date and an end date, nothing else: no amounts, no currencies, no descriptions and no cookies. Our server gets the euro reference rates from the European Central Bank's public files and keeps them for 12 hours. Our code does not store or log the dates you ask for. The rates are saved on your device, so the dashboard can convert offline after the first time.

4. If you make an account

An account is optional. If you make one, we store:

WhatWhy
Your email addressTo identify your account and send you sign-in emails.
How you sign in (magic link or Google). With Google: your Google account id and the email address Google confirms (we ask Google for your email and basic profile only)To let you sign in, and to keep one account for one email address.
Your plan, credit balance and a ledger of credit changesTo give you what you paid for and keep a record.
Per-job counts of pages and files (no content)To take the right credits and apply fair use limits.
A hashed version of your IP addressTo apply daily limits for people without accounts and to prevent abuse.
Paddle customer and subscription idsTo link your account to your purchases.

We do not store your statements, the amounts in them, account numbers or file names.

If we later add a feature that needs a file to be sent to a third party, it will be opt-in. We will explain what is sent, and to whom, before you use it.

Smart categories (paid, optional)

Smart categories is off until you turn it on. It comes with paid plans.

Our rules on your device sort your rows first. Only the merchants they are not sure about are sent, and for each one only: the cleaned merchant text (numbers, emails, handles and card or account numbers taken out), whether it is money in or out, a rough size of the amount, such as "10 to 100", and up to two short facts from a fixed list, such as "recurring monthly" or "paid by direct debit". The exact amount never leaves your device. Our server cleans the text again, cuts it to 80 characters and sends these to TypeSafe, which acts as our processor, to suggest a category. Nothing else is sent: no file, no file name, no dates, no balances, no account numbers and no name or email of yours. We do not store or log the text.

A merchant text can still hold a name, such as the person you paid. You can turn smart categories off at any time.

5. Why we use your data

  • To provide the service you asked for (account, sign-in, credits, plans). This is needed to perform our contract with you.
  • To keep the service safe and fair (bot protection, daily limits, abuse prevention). This is our legitimate interest in running a secure service.
  • To keep billing and tax records as the law requires.

We do not use your data for advertising or profiling, and we do not sell it.

6. Who else handles data

WhoRoleWhat they do
CloudflareProcessor (acts for us)Hosts the service and stores account data.
ResendProcessorSends sign-in emails.
Cloudflare TurnstileProcessorBot protection on the sign-in form.
TypeSafeProcessorOnly if you turn on Smart categories on a paid plan: suggests categories from cleaned merchant text, money in or out, a size band and up to two fixed short facts. See the Smart categories section.
GoogleIndependent, if you choose Google sign-in or Keep my data in my Google accountConfirms who you are. If you turn on Keep my data in my Google account, stores those files in your own Google Drive, under your agreement with Google. We never receive them. See Google's privacy policy.
PaddleIndependent controller, as Merchant of RecordTakes payment, handles tax, invoices, refunds and chargebacks. See Paddle's privacy policy.

Payment details go to Paddle, not to us. We never see your full card number.

7. Cookies and tracking

We use no analytics, no advertising and no tracking cookies. We use only strictly necessary cookies: one that keeps you signed in (your session), one that ties a sign-in link to the browser that asked for it, and one that ties a Google sign-in to the browser that started it (it holds a random value for 15 minutes). Because they are strictly necessary, we do not show a cookie banner for them. Paddle may set its own cookies on its checkout. That is covered by Paddle's policies.

8. How long we keep data

  • Account data is kept until you delete your account.
  • Ledger and billing records are kept for as long as the law requires, even after you delete your account.
  • Device data (history, dashboard) is kept only on your device, until you delete it.
  • Your Google Drive copy is kept in your Google Drive until you delete it there or from the Google Drive card. Stopping syncing or ending your plan does not delete it.
  • Error logs on our server hold short codes such as "payment check failed", never statement data, file names or email addresses, and are deleted after at most 7 days.

9. Deleting your data

You can delete your account from the Account page. That removes your account data, apart from the billing records we must keep. For data on your device, use "Delete all data" on the dashboard. For your copy in Google Drive, use "Delete my Pennyproof files from Google Drive" in the dashboard's Settings, or delete the Pennyproof folder in Google Drive yourself.

10. Your rights

Depending on where you live, you may have the right to see the data we hold about you, correct it, delete it, restrict or object to how we use it, move it to another service, and complain to your data protection authority. In the UK, that is the Information Commissioner's Office. If you live in California or another US state with a privacy law, you have similar rights, and we do not sell or share personal data for advertising. To use any of these rights, write to support@evrimmete.com. We aim to answer within one month.

11. Moving data between countries

We are based in Türkiye, and our providers may handle data in other countries, including the United States and the EU or UK. Where the law requires, we rely on safeguards such as standard contractual clauses or the providers' own data transfer frameworks.

12. Children

Pennyproof is not meant for anyone under 18, and we do not knowingly collect data from children.

13. Changes

If we change this policy in a way that matters, we will update the date at the top and tell account holders by email.

14. Contact

Evrim Mete Öztürk, Bilkent University, Dormitory 76, Bilkent, 06800 Çankaya, Ankara, Türkiye
Email: support@evrimmete.com