Skip to privacy notice
Pigget
Features Learn Banks HU Join the beta
Features Learn Banks Magyar Join the beta

PRIVACY NOTICE

Your budget is personal.
We treat it that way.

This notice explains, without euphemisms, what Pigget processes, why, where it goes, and what choices you have.

Effective 20 August 2026

THE SHORT VERSION

  • We do not sell personal data, show behavioural ads, or track you across other companies’ apps and websites.
  • Your budget is stored on your device and, when iCloud is available, in your private iCloud database.
  • Bank connection is optional. Pigget receives only the accounts you authorize through Synci.
  • Only if you opt in, we use PostHog’s EU service for pseudonymous app diagnostics or basic website measurement. Each has a separate choice.
  • You can export your budget and delete budgets inside the app.

1. Who is responsible

The controller for Pigget is Szőke Péter László e.v., a sole proprietor registered in Hungary (“Pigget”, “we”, “us”).

Privacy questions and requests: [email protected].

For bank-sync help, email Pigget bank-sync support with your bank name, country, and a description of what happened. Never send bank credentials, passwords, or authorization codes.

This notice covers the Pigget iPhone and iPad app, pigget.app, and the bank-connection gateway at api.pigget.app. Services you choose to connect, such as Apple, Synci, and GoCardless, also process data under their own privacy notices.

2. Data we process

Budget and financial data

This includes the budgets, account names and types, balances, transactions, payees, memos, categories, targets, expected income, currencies, exchange rates, and other planning information you enter, import, or ask Pigget to calculate. It also includes internal record identifiers needed to sync and edit that data.

Pigget stores this data locally and mirrors it through Apple CloudKit when iCloud is available. We do not operate a separate Pigget account database containing your ledger.

Optional bank connection data

If you connect a bank, Pigget receives information for only the financial accounts made available by that bank connection: account display information and type, currency, balance, synchronization time, and transaction details such as amount, currency, date, description, counterparty name, remittance text, and transaction identifiers. Pigget does not receive your bank password.

Our Cloudflare-hosted gateway uses a one-time CloudKit authentication token to verify that you can access the selected iCloud budget, derives an opaque household reference from CloudKit’s verified budget record, and relays bank information to the app without deliberately retaining account or transaction responses. Synci partner credentials and short-lived access tokens remain on the gateway. The one-time CloudKit token is not stored; the app stores only a signed, budget-scoped Pigget gateway session in the iOS Keychain.

Usage and diagnostic data

Analytics is off until you choose “Share Analytics.” If you opt in, PostHog receives a random installation identifier, a pseudonymous household identifier derived from the budget UUID, app and device information, operating-system information, IP-derived connection metadata, product-interaction events, and crash or error diagnostics. The household identifier lets us count a shared household once across its devices; it is not your name, email address, Apple identifier, or bank identifier. Feature events may include coarse properties such as a currency code, account or category type, import/export type, whether an optional field was used, and counts of selected accounts.

We do not identify you to PostHog by name or email, and we do not deliberately include transaction amounts, balances, payee names, memos, account names, category names, bank credentials, or exported files in analytics events. Diagnostic reports can contain technical stack information needed to understand a failure.

Subscription data

If you subscribe through the App Store, Apple handles your payment details. Pigget may receive an Apple-generated transaction or subscriber identifier, the product purchased, subscription status, renewal and expiry information, and refund or revocation status. We do not receive your full card or bank details.

Support and website data

If you contact us, we process your email address, message, attachments, and our correspondence. When you use the website or gateway, hosting and network providers may process ordinary request data such as IP address, time, requested URL, browser or device information, and security signals. Pigget’s website does not set advertising cookies or track you across other websites.

Website analytics is off until you choose “Allow analytics” in the website prompt. If you consent, PostHog’s EU service receives a pseudonymous browser identifier, page URL and title, referring page, campaign parameters, browser and device information, IP-derived connection metadata, and explicit TestFlight-link clicks. We disable session recording, heatmaps, surveys, automatic element capture, error capture, performance capture, and feature flags on the website. We do not send financial data, form contents, names, or email addresses in website events. Your consent choice is stored in your browser’s local storage.

Bank logos on the bank finder may be loaded from the relevant provider’s image host. That host receives ordinary connection data, including your IP address and browser headers. The bank finder itself searches a downloaded catalogue in your browser and does not send your searches to us.

3. Why we process data

PurposeDataLegal basis
Provide budgeting, sync, sharing, import, export, widgets, search, and supportBudget data, iCloud identifiers, support messagesPerformance of our contract with you (GDPR Art. 6(1)(b))
Provide the optional bank connection you requestSelected account and transaction data; iCloud authentication and budget-record identifiers; opaque household referencePerformance of our contract and steps taken at your request (Art. 6(1)(b))
Manage subscriptions and entitlementsPurchase and subscription statusPerformance of our contract (Art. 6(1)(b)); compliance with tax and accounting duties where applicable (Art. 6(1)(c))
Keep Pigget reliable and understand which app features or website pages workPseudonymous app usage and diagnostics; consented website page views and TestFlight clicksYour consent (Art. 6(1)(a)); you may withdraw app consent in Settings or change the website choice below
Protect the service and establish or defend legal claimsRelevant request, security, transaction, and correspondence recordsOur legitimate interests in protecting users and our business (Art. 6(1)(f)); legal obligations where applicable (Art. 6(1)(c))

Providing core budget data is necessary for Pigget to perform the features you ask for. Bank connection, iCloud sharing, notifications, and imports are optional. You may object to processing based on legitimate interests by contacting us; we will assess your request as required by law.

4. Where data goes

  • Apple: CloudKit/iCloud sync and sharing, device services, push delivery, and App Store subscriptions. Your iCloud account and Apple’s systems control iCloud access. See Apple’s Privacy Policy.
  • People you invite: if you share a budget through iCloud, invited participants can see and, according to the permission you choose, edit the shared budget.
  • Synci and GoCardless: Synci retrieves account data through licensed open-banking providers, currently GoCardless SAS, a French-supervised payment institution, with your consent. Synci and GoCardless process this data under Synci’s Privacy Policy, GoCardless’s Privacy Policy, and the GoCardless Bank Account Data End User Terms. You can object to their processing by contacting them.
  • Cloudflare: network security and the api.pigget.app Worker that verifies Pigget sessions and relays bank-connection requests.
  • PostHog: pseudonymous product analytics and error diagnostics, using PostHog’s EU ingestion and hosting service.
  • European Central Bank: Pigget downloads public reference exchange rates; the ECB receives ordinary network request data, not your budget.
  • Authorities or advisers: only where reasonably necessary to comply with law, protect rights, or handle a legal claim.

Where a provider processes personal data on our behalf, we require it by contract to use the data only for the agreed services, protect it to a standard equivalent to this notice and applicable law, assist with data-subject requests, and delete or return it when the service ends. Apple, Synci, and GoCardless may also act as independent controllers for processing they determine under their own terms and regulatory obligations.

We do not sell or rent personal data. We do not share it for cross-context behavioural advertising.

5. International transfers

We choose European hosting where it is available: Synci is established in Norway, GoCardless SAS in France, and PostHog data is sent to its EU service. Apple and Cloudflare are global providers and may process some data outside the EEA. Cloudflare relies on its EU–US Data Privacy Framework certification and, if that cannot apply, the European Commission’s Standard Contractual Clauses with supplementary measures. PostHog’s data-processing terms apply Standard Contractual Clauses where an EU-hosted service or its subprocessors require a restricted transfer. Apple applies the transfer safeguards described in its applicable service terms and privacy materials. You may email us for a copy of, or information about, the safeguard relevant to your data.

6. How long we keep data

  • Budgets: on your device and in iCloud until you delete them. A budget shared with another person is also available to that participant while the share remains active. Copies that you or another participant export are controlled by whoever holds the copy.
  • Pigget gateway session: the signed session is stored in the iOS Keychain for up to 180 days. The gateway verifies it without storing a server-side session record.
  • Bank connections at Synci: connections and accounts remain until you disconnect the bank in Pigget, delete the associated Pigget budget, or the bank or provider expires or revokes the connection. Synci retains fetched transactions, balances, and related bank logs for the configured retention window—at least 7 days and no longer than the maximum available to Pigget’s plan—then permanently deletes them, subject to records it must retain by law.
  • Usage and diagnostics: PostHog app events, crash diagnostics, and consented website events are retained for no more than 12 months, then deleted or irreversibly aggregated.
  • Website and gateway logs: Cloudflare request and security logs available to Pigget are retained for no more than 30 days, unless a specific security incident or legal claim requires the relevant record to be isolated for longer.
  • Support: correspondence is deleted within 24 months after the request is closed, unless it remains necessary for an active dispute or legal obligation.
  • Payment and legal records: for the period required by applicable tax, accounting, consumer-protection, and limitation laws.

Removing the app does not itself delete data already stored in iCloud or cancel an App Store subscription. Deleting a budget in Pigget removes that budget from Pigget’s local and synced store and requests deletion of its associated Synci bank connections. Disconnecting a bank in Pigget also requests deletion of the corresponding Synci connection and its provider-held data.

7. Your choices and rights

Depending on the circumstances, GDPR gives you rights to access, correct, erase, restrict, and receive a portable copy of personal data, and to object to processing based on legitimate interests. Where processing relies on consent, you may withdraw it without affecting earlier lawful processing. You also have the right not to be subject to a decision based solely on automated processing that has legal or similarly significant effects.

Pigget provides JSON and CSV exports in the app. You can delete individual budgets, stop sharing a budget, disconnect a bank in Pigget, manage iCloud through Apple, and manage or cancel a subscription in your Apple Account. You can opt in to or withdraw from app analytics under Settings → Privacy and Analytics. Turning analytics off stops future collection. The same screen shows the pseudonymous analytics identifier and prepares an email you can use to request deletion of previously collected analytics data. Website analytics has its own choice, which you can change below. Pigget’s local suggestions and forecasts do not make legal or similarly significant decisions about you.

To exercise a right concerning data we control, email [email protected]. We may need enough information to verify the request without collecting unnecessary identity documents. We normally respond within one month.

8. Complaints

Please contact us first if you can; we would like the opportunity to put things right. You may also complain to the supervisory authority where you live or work, or where the alleged infringement occurred.

Our lead authority is the Hungarian National Authority for Data Protection and Freedom of Information (NAIH), 1055 Budapest, Falk Miksa utca 9–11; postal address: 1363 Budapest, Pf. 9; email: [email protected]; website: naih.hu.

9. Security and children

We use platform security controls including the iOS Keychain, encrypted network connections, signed short-lived gateway tokens, access-scoped OAuth, and Apple’s private/shared CloudKit databases. No system is perfectly secure, so we minimize the data our own infrastructure stores.

Pigget is not directed to children under 16. Bank connection is available only to people aged 18 or older because it is provided under Synci’s and GoCardless’s end-user terms. If you believe a child has provided personal data to us improperly, contact us so we can investigate and delete it where appropriate.

10. Changes

We may update this notice when Pigget’s features, providers, or legal obligations change. We will post the revised notice here, change the effective date, and provide additional notice in the app when a change materially affects how we use personal data.

Pigget

Learn · Privacy · Contact

© 2026 Pigget