Skip to content

Security overview

Where your data lives, what our servers hold, the protections we actually use and how to report a vulnerability.

Your plan stays in your browser

Your balance, paychecks, bills, debts, payoff plan, check-ins and imported transactions are stored only in your browser's IndexedDB storage. They are kept separately for each account that signs in on that browser. No request to our servers carries them in readable form, so a breach of our servers can't expose them. If you turn on encrypted sync, your browser encrypts the plan (AES-256-GCM) before uploading it, with a key that reaches us only encrypted under your passphrase or recovery key, which we never receive.

Statement files (CSV or PDF) are read inside the browser tab. They are never uploaded.

What our servers hold

  • Your account: name, email address and sign-in methods (password hash, passkeys, two-factor settings) and your sessions.
  • Your subscription and billing state. Card details are handled by our payment provider, Creem, and never reach us.
  • The weekly check-in email schedule: on or off, weekday, hour, time zone and the last week an email was sent.
  • Anonymous daily counts from the free calculators, with no identifier attached.

The server never holds an amount from your plan. See the privacy policy for the full list and retention periods.

Protections in place

  • Email verification before sign-in. Sessions use HttpOnly, SameSite cookies.
  • Passwords are stored as hashes. Recovery links expire and are replaced by newer ones.
  • Optional passkeys and two-factor authentication with an authenticator app, set up from your account's security settings.
  • A strict content security policy with a per-request nonce. Pages load no third-party scripts, and the browser may only connect back to our own site.
  • Pages can't be embedded in frames on other sites.
  • Every account operation is checked on the server. Hiding a button in the browser is never the protection.

What we don't claim

No third-party audit or compliance certification has been done. Because your plan lives in your browser, anyone who can use your unlocked device and browser profile can see it. Lock your device, and don't use the planner on a shared computer profile.

Reporting a vulnerability

Please report security issues privately using the channel below. Don't open public issues for them. Tell us what you found and how to reproduce it.

Report a vulnerability

Report privately via support@pennykite.com. Please do not open public issues for security reports.