Privacy Policy
Last Updated: August 26, 2026 | Version 1.16
The Short Version
- We never sell your data.
- We never connect to your bank.
- You can delete everything yourself, anytime.
- US only for now.
Introduction
PiggySize ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our service.
Information We Collect
We collect information that you provide directly to us, including:
- Account Information: Name, email address, and authentication credentials
- Financial Data: Income, expenses, bills, assets, and retirement planning information you choose to track
- Quiz Responses: If you complete our plan recommendation quiz, we record your answers so we can improve our recommendations and understand which features matter most. This happens when you finish the quiz, whether or not you create an account. The quiz is multiple choice: we store only the answers you picked, the plan we recommended and which version of the quiz you took. It contains no financial information and no free text. If you do not have an account, we store nothing alongside your answers that identifies you: no name, no email address, no IP address and no tracking identifier. If you go on to create an account in the same browsing session, we attach those existing answers to your account rather than storing a second copy, and they are deleted along with everything else when you delete your account.
- Usage Data: Information about how you interact with our service, including pages visited and features used
- Device Information: IP address, browser type, and device identifiers. When you create your account, we also record the IP address you signed up from and an approximate location derived from it by our hosting provider, and your device's timezone (e.g. Eastern, Central, Mountain, Pacific), used to show dates, times, and reminders correctly for your location.
- Cookies and Tracking: We use cookies and similar technologies (like local storage) to maintain your session and remember your preferences.
- Family Account Data: Information related to family accounts and shared access permissions, including the family member details (such as names and birthdays) that the account owner enters
- Paystub Images: If you use the paystub scanner, the image you upload is processed in memory to read the numbers and is never stored on our servers (see the AI Assistant section below)
- Support & Contact Data: If you contact us through our contact form (or ask our AI assistant to file a support ticket for you), we store your name, email address, and message so we can respond. See Data Retention below for how long we keep these and what we remove afterwards
- Partner Program Data: If you join our partner program, we store your referral code, referral activity, and commission records
- AI Assistant Data: Conversations with our Piggy AI assistant, including your questions, AI responses, and related usage metrics (see AI Assistant section below)
- Login & Security Information: Sign-in history (date and time, IP address, approximate location, device/browser, and sign-in method) and, if you enable two-factor authentication, your authenticator (TOTP) enrollment and one-way-hashed backup codes (see Login & Security Information section below)
- Browser Extension Data: If you install our optional browser extension and connect it to your account, we store a record of that connection — a device label you choose (for example, "Chrome on my laptop"), the dates it was created and last used, and a one-way cryptographic hash of its access token. The token itself is shown to you once and cannot be recovered by us. We do not receive the websites you visit or the products you view (see the Browser Extension section below).
How We Use Your Information
We use the information we collect to:
- Provide, maintain, and improve our financial tracking and retirement planning services
- Process your financial data and generate insights and calculations
- Enable family account features and manage shared access permissions
- Send you technical notices, updates, and support messages
- Send you security alerts when something important changes on your account (for example, a sign-in from a new device or location, a password change, or a change to your two-factor authentication settings)
- Send optional reminders that you choose to turn on, such as bill due dates, a monthly check-in, or an annual plan checkup — these are off unless you enable them, and every reminder email includes an unsubscribe link
- Send automated notifications regarding free trial status and expiration
- Respond to your comments, questions, and requests
- Monitor and analyze usage patterns to improve our service
- Detect, prevent, and address technical issues and security threats
AI Assistant (Piggy)
Our AI assistant feature ("Piggy") uses artificial intelligence to help you understand your finances. When you use Piggy:
- What We Collect: We store your conversation messages (your questions and the AI's responses), the page you were on when chatting, tool interactions (such as calculations performed), and usage metrics (message counts, response times, token usage).
- How It Works: Your messages, along with the relevant financial figures needed to answer them, are sent to Anthropic's Claude AI model for processing. Anthropic processes this data according to their own privacy policy. We recommend reviewing Anthropic's Privacy Policy for details on how they handle data.
- Paystub Scanner: If you scan a paystub, the image you upload is sent to Anthropic's Claude to read the numbers, processed in memory, and never stored on our servers — we keep only the figures you choose to save. The scanner is available on every plan; Free accounts include a limited number of scans.
- Quality and Safety: Our team may review AI chat conversations for quality assurance, safety monitoring, abuse prevention, and to refine how the assistant responds. Your conversations are never used to train the underlying AI model.
- Data Retention: Chat history is retained for the life of your account and is permanently deleted when you delete your account.
- Local Storage: Chat history is also cached in your browser's local storage for your convenience. You can clear this at any time through your browser settings or within the chat interface.
- Rate Limits: We track daily message counts per user to enforce usage limits.
Login & Security Information
To help you monitor access to your account and to protect it from unauthorized use, we collect information related to sign-ins and, if you choose to enable them, two-factor authentication features.
- Sign-In History: Each time you sign in, we record the date and time, the IP address the sign-in came from, an approximate location (city, region, and country) derived from that IP address, a summary of your device and browser, and the method used to sign in (for example, password, a connected account like Google or Apple, passkey, or two-factor authentication).
- Retention: We retain a rolling history of your most recent 50 sign-ins so you can review recent account activity. As new sign-ins are recorded, the oldest entries beyond the most recent 50 are automatically removed.
- Two-Factor Authentication (2FA): If you enable two-factor authentication, we store the information needed to verify future sign-ins, such as your authenticator app (TOTP). If you generate backup codes, we store them only as one-way cryptographic hashes; the codes themselves are shown to you once and cannot be recovered by us.
- Passkeys: If you set up a passkey to sign in, we store the passkey's public credential and related metadata — a device label (for example, "MacBook" or "YubiKey") and the dates it was created and last used — so you can sign in without entering a password. The passkey's private key stays on your device: it is never sent to us and we never store it.
- Why We Collect This: We use this information to secure your account, let you review your own sign-in activity, and detect and prevent unauthorized access. It is handled under the same data sharing and security practices described elsewhere in this policy.
Browser Extension
We offer an optional browser extension that shows what a price costs in hours of your work while you shop. It is not required to use PiggySize, it does nothing until you install it yourself, and it communicates only with PiggySize — it does not send your information to any third party.
- Where it runs: Only on online shopping sites we have built support for — major retailers such as Amazon, eBay, Best Buy, Walmart, and Target. It never runs on any other website. We expect to add retailers over time, so rather than freeze a list here: the sites the extension can read are always the ones listed in your browser's own permissions for it, and your browser asks you to approve any site we add before the extension can read it there. On a supported page it looks only for the product's price and a place to show its badge.
- What stays on your device: The price it reads, and the page you are on, never leave your browser. We do not receive the sites you visit, the pages you view, the products you look at, or the prices it reads. The calculation happens entirely on your own device.
- What we send to it: If you connect the extension to your account, we send only the figures the calculation needs: your after-tax and gross hourly pay, your daily take-home, and your retirement assumptions — the growth rate you use, your target retirement age, and how many years you have until it. We do not send account balances, bills, debts, goals, family information, or your name or email. Child accounts receive only the hourly figures, never the household's retirement assumptions.
- What is stored on your device: Those figures are cached in the browser's extension storage on your own device — never synced to your browser account — for up to 24 hours, alongside the extension's access token, the list of supported shopping sites it downloads (described below), and any sites you have switched the badge off for. Disconnecting or uninstalling the extension clears them.
- What we can see: When the cached figures are more than a day old, the extension asks our server for fresh ones. That request carries only its access token — no site, page, or price — and creates the same kind of record as any other visit (IP address and time), plus the "last used" date on the connection. Because that refresh happens only while you are on one of the supported shopping sites, it can tell us you used the extension that day, but not where.
- Checking which stores it supports: Separately from the refresh above, the extension periodically downloads the current list of shopping sites it supports and where to find the price on each one, so that a site we have fixed or newly added starts working without you having to reinstall anything. That request is anonymous: it carries no access token and nothing that identifies you or your account, it is not tied to your connection, and every copy of the extension receives the same file. It tells us nothing about where you shop — we cannot tell from it which sites you visit, or whether you visited a shopping site at all. As with any request to a website, our server records the IP address it came from and the time.
- Turning it off: You can disconnect the extension at any time from Settings, which permanently revokes its access token, and you can remove the extension from your browser like any other. You can also switch the badge off for individual sites from within the extension itself.
Analytics
We use Google Analytics to understand how visitors engage with our site. This helps us improve our service. Google Analytics uses cookies to track your interactions. The information collected is used to generate reports about website usage. You can decline analytics cookies at any time using the Decline button in our cookie banner, which turns analytics collection off on that device. You can also opt out by installing the Google Analytics Opt-out Browser Add-on. Ad-personalization signals in Google Analytics are disabled.
Advertising Measurement
We advertise PiggySize on third-party platforms, including ChatGPT (operated by OpenAI). To know whether those ads actually work, we use OpenAI's measurement pixel and conversion reporting:
- Ad-click identifier: If you arrive at our site after clicking one of our ads, the pixel stores a privacy-preserving click identifier in a first-party cookie on your browser.
- Conversion reports: When you create an account, we report a "registration completed" event to OpenAI. That report may include the click identifier, a one-way (SHA-256) hash of your email address, a one-way hash of your account identifier, your IP address, and your browser's user-agent string.
- What it never includes: your name or email address in readable form, your password, or any of your financial data.
- What it is for: measuring that an ad led to a signup so we can pay for ads based on results. We do not use it to build advertising profiles of you, and we do not show you targeted ads.
- Your choice: pressing Decline in our cookie banner turns ad measurement off on that device, including the conversion report.
- OpenAI processes this data under its own policies; see OpenAI's Privacy Policy.
Data Storage and Security
We implement appropriate technical and organizational measures to protect your personal information, including encryption of data in transit (TLS/HTTPS) and at rest, database row-level security that isolates each family's records, and secure authentication options including two-factor authentication. However, no method of transmission is 100% secure.
Data Sharing and Disclosure
We do not sell your personal information, and we do not share your financial information with advertisers or data brokers. We share information only in these limited ways: with your consent; to provide the family-account features you use; when required by law; and with the trusted service providers ("subprocessors") that operate PiggySize on our behalf. Each subprocessor receives only the information it needs for its role:
- Supabase — database hosting and account authentication.
- Vercel — application hosting, automated bot/abuse protection, and the IP-based approximate location used for sign-in history.
- Stripe — subscription billing and payment processing.
- Anthropic — powers the Piggy AI assistant and the paystub scanner; receives the financial figures or paystub image needed to generate a response, and only when you use those features. Anthropic's commercial API terms prohibit using this data to train its models.
- OpenAI — ad-conversion measurement for the ads we run on ChatGPT; receives only the signup conversion report described in the Advertising Measurement section above, and never your name in readable form or any of your financial data.
- Mailgun — sends our transactional email (verification, receipts, security alerts, reminders, invitations, and support messages).
- Google Analytics — aggregate website-usage analytics.
- Axiom — server logging and monitoring.
- Google reCAPTCHA — spam and bot protection on our public contact form.
Nobody else receives your data.
Your Rights and Choices
You have the right to access, correct, delete, and export your personal information. You can download a complete copy of your data at any time from Settings → Your Data, and the account owner can permanently delete the account and all of its data from Settings — deletion is permanent and cannot be undone. If you are unable to use these self-serve tools, or you need help exercising any of these rights, contact us and we will assist you. You can also opt out of non-essential communications at any time.
Data Retention
We retain your personal information for as long as necessary to provide our services. Upon account deletion, we delete or anonymize your information, with a few limited exceptions:
- Billing records: Invoice history may be retained for up to 7 years for tax compliance, with personal identifiers snapshotted.
- Operational and security logs: Retained in de-identified form (they are disconnected from your identity when your account is deleted).
- Partner commission records: If you signed up through a partner's referral link, the email address on that referral record is retained to preserve the accuracy of commission records.
- Email log: We keep a log of the transactional emails we send (including their content) for support and delivery troubleshooting.
- Browser extension connections: When you disconnect an extension we keep its record, marked as revoked, so you can still see that it existed and when its access ended. It is deleted when you delete your account.
- Support and contact messages: Messages you send us through the contact form, or that our AI assistant files on your behalf, are kept for 24 months so we can handle the request, follow up on it, and resolve any dispute about it. Anyone can use the contact form, including people who do not have an account, so these messages are kept separately from your account data and deleting your account does not remove them. After 24 months we automatically strip out the personal details: your name and email address are removed, the message is unlinked from your account, and any email addresses, phone numbers and links inside the message text are replaced. What remains is the category and the wording of the problem, which we use to spot recurring issues and improve our help pages. Because a message is written in your own words it may still describe you, so we continue to handle what remains carefully rather than treating it as fully anonymous.
- Why you left: After you delete your account we ask why, and we keep your answer so we can understand what to improve. What happens to the email address you give with it depends on the choice you make at the time. If you tick the box saying we may email you about your feedback, we keep the address for up to 24 months so we can actually follow up, and we use it for nothing else. If you do not tick it, we remove the address within 30 days. In both cases the reason and any comment you wrote are kept, with email addresses, phone numbers and links stripped out of the comment text, so we can see patterns in why people leave without holding on to who said what.
Children's Privacy
PiggySize is a family product, and we handle children's information carefully:
- No logins under 13: Children under 13 may not create or hold a PiggySize login. Family invitations require a birthday, and invitations for members under 13 are blocked.
- Teen (13–17) logins: A parent or guardian may invite a family member aged 13 or older to a limited "child" login. Child logins see only their own financial information — not the rest of the household's — their access is controlled by the account owner's permission settings, and they cannot use the AI assistant or run the family data export.
- Information about younger children: A parent or guardian may add children of any age as family members and record information about them (such as a name, a birthday, and savings set aside for them). This information is entered and controlled entirely by the parent or guardian — we do not collect it from the child — and the account owner can edit or delete it at any time.
- If you believe a child under 13 has created a login, please contact us and we will promptly delete it.
State-Specific Privacy Rights
Depending on your location (e.g., California, Virginia, Colorado), you may have additional rights under state law, including the Right to Know, Right to Opt-Out, and Right to Non-Discrimination.
Cookies and Similar Technologies
We use essential, functional, analytics, and ad-measurement cookies to keep you signed in, remember your preferences, understand how visitors use PiggySize, and measure whether our ads led you here. We also use your browser's local storage and temporary caching in a few specific ways:
- Ad-click measurement: If you arrive at PiggySize from an ad we run on ChatGPT, a first-party cookie stores a privacy-preserving click identifier so we can tell the ad worked (see the Advertising Measurement section above). Pressing Decline in our cookie banner turns this off.
- Free calculators: If you use our free public calculators, the numbers you enter are saved only in your browser's local storage on your own device, so they are still there when you return. This information is never transmitted to our servers.
- AI assistant: Your Piggy chat history is cached in your browser's local storage for your convenience. You can clear it at any time from your browser settings or from within the chat interface.
- Offline caching: As a Progressive Web App, PiggySize temporarily caches pages and responses in your browser (via a service worker) so it loads quickly and tolerates a spotty connection. This cache clears like any other browser cache.
- Browser extension: If you install our browser extension, the wage figures it needs are stored on your device in the browser's extension storage for up to 24 hours. The list of shopping sites it supports is stored there too, and is replaced as we update it. This is separate from the storage above and is removed when you uninstall the extension. See the Browser Extension section for what it does and does not send us.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last updated" date.
Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at:
Please reach out via our Contact Form for any privacy-related requests.
Questions about this privacy policy? Contact us
