Privacy Policy
Last updated: 5 September 2026 · Applies to the Canny Penny iPhone app and cannypenny.com
Canny Penny ("we", "us") helps you track grocery spending by reading your supermarket receipts. This policy explains what personal data we process, why, and your rights. We built Canny Penny to keep the amount of personal data we hold to a minimum.
1. Who we are (data controller)
The data controller is Mikhail Mendel, operating Canny Penny (United Kingdom). Canny Penny is currently in limited testing; we will register with the UK Information Commissioner's Office (ICO) before general release, and our registration number will appear here once issued. For any privacy question or to exercise your rights, contact us at [email protected].
2. What we collect and why
Account & sign-in
You sign in with Sign in with Apple. We ask Apple only for your first name — we do not request or receive your email address. Your first name is kept on your device to personalise the app (for example, so Penny can address you by name); we do not store it on our servers. We identify your account only by a pseudonymous Apple identifier and a private, random @cannypenny.com forwarding address. If you ask Penny to email you setup instructions for automatic forwarding, you give us the address at that moment; we use it once to send the guide, then discard it — it is never stored in our database. Legal basis: performance of our contract with you (providing the app).
Receipts you send us
When you forward a receipt email to your Canny Penny address, or photograph a receipt in the app, we process its contents to extract items, prices, promotions, store and date. We use the AI providers listed in section 6 to read receipts; they act under a data processing agreement and do not use your data to train their models.
For emailed receipts, we automatically remove the personal details we can detect from the receipt text — postcodes, phone numbers, email addresses, card numbers, address lines, and names where we can identify them — before the text is sent to our AI providers.
When you photograph a receipt, the photo is sent to our AI provider to be read — we cannot remove personal details from an image beforehand, so information visible on the receipt may be included. We do not keep the photo after processing; what we store is the extracted items and prices, with personal details removed from any stored receipt text.
Legal basis: performance of our contract with you.
Spending data
The extracted items, prices and categories are stored in your account so the app can show your spending, price trends and savings suggestions. Legal basis: performance of our contract.
Support correspondence
If you contact support, we process the content of your messages (and any screenshots you attach) to help you, and we may reply to you by email. We delete them from our support mailbox when the ticket is closed; our email provider then purges them from its systems, including backups, within about three months. Legal basis: our legitimate interest in providing support.
Technical & diagnostic data
To run and secure the service, our infrastructure providers automatically process basic technical data such as your IP address and device or app identifiers, and we keep minimal operational logs (e.g. processing status, error codes, timestamps). Our logs are designed to contain no receipt content and no personal contact details. Legal basis: our legitimate interest in running and securing the service.
3. AI features
Canny Penny uses artificial intelligence. Penny, our in-app assistant, is an AI — not a human. AI is also used to read your receipts and to generate spending and savings suggestions. Your receipts and messages are processed by our AI providers (listed in section 6), which do not use your data to train AI models. We remove personal details from emailed receipt text before it is sent for reading; receipt photos and chat messages are sent as they are — an image cannot be filtered in advance, and a message is read as you typed it — and we remove personal details from what we then store (see section 2). Because AI works automatically, its output can occasionally be wrong or incomplete (see our Terms). We do not use AI to make decisions that have legal or similarly significant effects on you.
4. What we do NOT do
- We do not sell your personal data or use it for advertising.
- Our AI providers do not use your data to train their models.
- We do not store your email address or name on our servers.
- We do not retain raw receipt text after it has been processed.
5. Aggregated, anonymised insights
We may create and share aggregated, anonymised insights — such as market-level grocery price trends (for example, the average price of a product across supermarkets over time). These are produced by combining data from multiple users, and a figure is only shown when enough people have bought the same product that it cannot be traced back to you or reveal any individual purchase. Once anonymised in this way, the information is no longer personal data. In future we may also use aggregated, anonymised price data from across our users to power price comparisons in the app — for example, typical prices for a product at different shops; if we do, these would be based on combined data and would never reveal any individual user's purchases. We never sell or share data that identifies you or your individual purchases.
6. Service providers (processors)
We use a small number of trusted providers to run Canny Penny. Your account and spending data are stored in the United Kingdom (London). Each provider processes data on our behalf under a Data Processing Agreement. Where a provider processes data outside the UK/EU (our AI providers), that transfer is covered by Standard Contractual Clauses, and those providers do not use your data to train their models.
| Provider | Purpose | Region |
|---|---|---|
| Supabase | Database, authentication, app backend | UK (London, eu-west-2) |
| Amazon Web Services (SES, Lambda, S3) | Receiving & sending email; processing | UK (London, eu-west-2) |
| Anthropic (Claude) | AI reading of receipts & in-app assistant | Under DPA; no training on your data |
| Google (Gemini API) | Enriching product details via web search — e.g. pack size, ingredients, nutrition | Under DPA; no training on your data |
| Zoho Mail | Support mailbox | EU |
| Cloudflare | DNS / domain routing | Global (DNS only) |
Apple provides Sign in with Apple under Apple's own terms and privacy policy.
7. Cookies and tracking
This website uses no cookies, analytics, or third-party trackers, and its fonts are served from our own servers rather than a third party. The app stores only what is needed to keep you signed in and to run its features on your device.
8. How we keep your data secure
We take the security of your data seriously. Data is encrypted in transit, your account and spending data are stored in the United Kingdom, and we minimise the personal data we hold — removing personal details from receipts and not keeping the originals. Our service providers are bound by data processing agreements and maintain their own security measures. No online service can be guaranteed completely secure, but we work to protect your information.
9. How long we keep data
Your account data and spending history are kept while your account is active. Raw receipt text is not retained after processing. Support messages are deleted from our mailbox when the ticket is closed, and purged from our provider's backups within about three months. If you delete your account, your personal data is deleted from our systems.
10. Communications
We send you the service messages needed to run the app — for example, the one-time setup instructions for forwarding receipts, and replies when you contact support. We do not send marketing emails. If we ever introduce optional updates or offers, we will only send them with your consent, and you can opt out at any time.
11. Your rights
Under UK GDPR you have the right to access, correct, delete, restrict, or object to processing of your personal data, and to data portability. Because we hold as little about you as possible — we identify your account only by a pseudonymous Apple identifier and your private @cannypenny.com address, and never your name or personal email — the reliable way to exercise these rights is from within the app, where you are signed in: use Delete account and Download my data in Settings. You can also email [email protected], but we may ask you for information that lets us locate your account (such as your Canny Penny forwarding address); where we cannot identify you from a request, UK GDPR (Article 11) does not require us to act on it until you provide such information.
You also have the right to complain to the UK Information Commissioner's Office (ICO) at ico.org.uk.
12. Children
Canny Penny is not directed at children under 16 and we do not knowingly collect their data.
13. Changes
We may update this policy; the "last updated" date shows the current version. Material changes will be notified in the app.
14. Contact
Questions or requests: [email protected].