Legal

Privacy Policy

Effective: May 20, 2026legal@pennylens.comprivacy@pennylens.com

We collect the data we need to make PennyLens work and as little else as we can get away with. This Policy explains exactly what that means — what we hold, why, where it lives, who can touch it, and how to get it back or have it deleted.

It is written to be readable first, with the formal requirements of GDPR, UK GDPR, CCPA/CPRA, and the Swiss FADP folded in. If anything below is unclear, email privacy@pennylens.com and we’ll answer in plain English.

For the documents this Policy points to — the DPA, the Subprocessor list, the international transfer instruments — see the linked references in each section.

01

Scope and roles

02

Key terms

03

Data we collect

04

Purposes and legal basis

05

Cookies, local storage, and SDK identifiers

06

Storage, retention, and deletion

07

Subprocessors and onward sharing

08

International data transfers

09

Security

10

Your rights — universal

11

California residents (CCPA / CPRA)

12

EEA, UK, and Swiss residents

13

Automated decision-making and profiling

14

Children

15

Data Processing Agreement

16

Data Protection Impact Assessment

17

Changes to this policy

18

Contact

Questions about this document? legal@pennylens.com. For privacy or data requests, see the privacy policy.