Skip to privacy notice
Pigget
Features Banks Contact

PRIVACY NOTICE

Your budget is personal.
We treat it that way.

This notice explains, without euphemisms, what Pigget processes, why, where it goes, and what choices you have.

Effective 12 August 2026

THE SHORT VERSION

  • We do not sell personal data, show behavioural ads, or track you across other companies’ apps and websites.
  • Your budget is stored on your device and, when iCloud is available, in your private iCloud database.
  • Bank connection is optional. Pigget receives only the accounts you authorize through Synci.
  • We collect pseudonymous feature-use and error diagnostics through PostHog’s EU service. We deliberately exclude transaction amounts, payees, memos, account names, and category names from analytics events.
  • You can export your budget and delete budgets inside the app.

1. Who is responsible

The controller for Pigget is Szoke Peter Laszlo e.v., a sole proprietor registered in Hungary (“Pigget”, “we”, “us”).

Privacy questions and requests: privacy@pigget.app.

This notice covers the Pigget iPhone and iPad app, pigget.app, and the bank-connection gateway at api.pigget.app. Services you choose to connect, such as Apple and Synci, also process data under their own privacy notices.

2. Data we process

Budget and financial data

This includes the budgets, account names and types, balances, transactions, payees, memos, categories, targets, expected income, currencies, exchange rates, and other planning information you enter, import, or ask Pigget to calculate. It also includes internal record identifiers needed to sync and edit that data.

Pigget stores this data locally and mirrors it through Apple CloudKit when iCloud is available. We do not operate a separate Pigget account database containing your ledger.

Optional bank connection data

If you connect Synci, Pigget receives information for only the financial accounts you select: account display information and type, currency, balance, synchronization time, and transaction details such as amount, currency, date, description, counterparty name, remittance text, and transaction identifiers. Pigget does not receive your bank password, Synci password, or unselected accounts.

Our Cloudflare-hosted gateway relays this information to the app but does not deliberately retain account or transaction responses. It stores randomly generated session state plus Synci access and refresh tokens so the connection can work. The app stores only an opaque gateway token in the iOS Keychain.

Usage and diagnostic data

When analytics is configured in a release of Pigget, PostHog receives a random installation identifier, app and device information, operating-system information, IP-derived connection metadata, product-interaction events, and crash or error diagnostics. Feature events may include coarse properties such as a currency code, account or category type, import/export type, whether an optional field was used, and counts of selected accounts.

We do not identify you to PostHog by name or email, and we do not deliberately include transaction amounts, balances, payee names, memos, account names, category names, bank credentials, or exported files in analytics events. Diagnostic reports can contain technical stack information needed to understand a failure.

Subscription data

If you subscribe through the App Store, Apple handles your payment details. Pigget may receive an Apple-generated transaction or subscriber identifier, the product purchased, subscription status, renewal and expiry information, and refund or revocation status. We do not receive your full card or bank details.

Support and website data

If you contact us, we process your email address, message, attachments, and our correspondence. When you use the website or gateway, hosting and network providers may process ordinary request data such as IP address, time, requested URL, browser or device information, and security signals. Pigget’s website does not set advertising cookies or run website analytics.

Bank logos on the bank finder may be loaded from the relevant provider’s image host. That host receives ordinary connection data, including your IP address and browser headers. The bank finder itself searches a downloaded catalogue in your browser and does not send your searches to us.

3. Why we process data

PurposeDataLegal basis
Provide budgeting, sync, sharing, import, export, widgets, search, and supportBudget data, iCloud identifiers, support messagesPerformance of our contract with you (GDPR Art. 6(1)(b))
Provide the optional Synci bank connection you requestSelected account and transaction data; OAuth tokensPerformance of our contract and steps taken at your request (Art. 6(1)(b))
Manage subscriptions and entitlementsPurchase and subscription statusPerformance of our contract (Art. 6(1)(b)); compliance with tax and accounting duties where applicable (Art. 6(1)(c))
Keep Pigget reliable and understand which features workPseudonymous usage and diagnostic dataOur legitimate interests in security, fault diagnosis, and improving Pigget (Art. 6(1)(f))
Protect the service and establish or defend legal claimsRelevant request, security, transaction, and correspondence recordsOur legitimate interests in protecting users and our business (Art. 6(1)(f)); legal obligations where applicable (Art. 6(1)(c))

Providing core budget data is necessary for Pigget to perform the features you ask for. Bank connection, iCloud sharing, notifications, and imports are optional. You may object to processing based on legitimate interests by contacting us; we will assess your request as required by law.

4. Where data goes

  • Apple: CloudKit/iCloud sync and sharing, device services, push delivery, and App Store subscriptions. Your iCloud account and Apple’s systems control iCloud access. See Apple’s Privacy Policy.
  • People you invite: if you share a budget through iCloud, invited participants can see and, according to the permission you choose, edit the shared budget.
  • Synci (Tonning, Norway): optional connection to accounts you already connected to Synci. Synci and its financial-data providers process that data under Synci’s Privacy Policy and its end-user terms.
  • Cloudflare: network security, the api.pigget.app Worker, and short-lived OAuth/session storage.
  • PostHog: pseudonymous product analytics and error diagnostics, using PostHog’s EU ingestion and hosting service.
  • European Central Bank: Pigget downloads public reference exchange rates; the ECB receives ordinary network request data, not your budget.
  • Authorities or advisers: only where reasonably necessary to comply with law, protect rights, or handle a legal claim.

We do not sell or rent personal data. We do not share it for cross-context behavioural advertising.

5. International transfers

We choose European hosting where it is available: Synci is established in Norway and PostHog data is sent to its EU service. Apple and Cloudflare are global providers and may process some data outside the EEA. Where GDPR requires a transfer mechanism, we rely on an adequacy decision, the EU–US Data Privacy Framework where applicable, or European Commission Standard Contractual Clauses together with appropriate supplementary measures. You may request information about the safeguard relevant to your data.

6. How long we keep data

  • Budgets: on your device and in iCloud until you delete them. A budget shared with another person is also available to that participant while the share remains active. Copies that you or another participant export are controlled by whoever holds the copy.
  • Synci gateway credentials: for up to 30 days after the session is last stored, or until you disconnect Synci. One-time OAuth state is kept for 10 minutes and completion codes for 5 minutes.
  • Usage and diagnostics: only for as long as reasonably needed to analyze product use, diagnose faults, and maintain security, after which they are deleted or aggregated.
  • Support: for as long as needed to resolve the request and maintain a reasonable record of the resolution.
  • Payment and legal records: for the period required by applicable tax, accounting, consumer-protection, and limitation laws.

Removing the app does not itself delete data already stored in iCloud or cancel an App Store subscription. Deleting a budget in Pigget removes that budget from Pigget’s local and synced store. Disconnecting Synci deletes Pigget’s gateway session but does not delete your Synci account or its bank connections.

7. Your choices and rights

Depending on the circumstances, GDPR gives you rights to access, correct, erase, restrict, and receive a portable copy of personal data, and to object to processing based on legitimate interests. Where processing relies on consent, you may withdraw it without affecting earlier lawful processing. You also have the right not to be subject to a decision based solely on automated processing that has legal or similarly significant effects.

Pigget provides JSON and CSV exports in the app. You can delete individual budgets, stop sharing a budget, disconnect Synci, revoke Pigget in Synci, manage iCloud through Apple, and manage or cancel a subscription in your Apple Account. Pigget’s local suggestions and forecasts do not make legal or similarly significant decisions about you.

To exercise a right concerning data we control, email privacy@pigget.app. We may need enough information to verify the request without collecting unnecessary identity documents. We normally respond within one month.

8. Complaints

Please contact us first if you can; we would like the opportunity to put things right. You may also complain to the supervisory authority where you live or work, or where the alleged infringement occurred.

Our lead authority is the Hungarian National Authority for Data Protection and Freedom of Information (NAIH), 1055 Budapest, Falk Miksa utca 9–11; postal address: 1363 Budapest, Pf. 9; email: ugyfelszolgalat@naih.hu; website: naih.hu.

9. Security and children

We use platform security controls including the iOS Keychain, encrypted network connections, signed short-lived gateway tokens, access-scoped OAuth, and Apple’s private/shared CloudKit databases. No system is perfectly secure, so we minimize the data our own infrastructure stores.

Pigget is not directed to children under 16. If you believe a child has provided personal data to us improperly, contact us so we can investigate and delete it where appropriate.

10. Changes

We may update this notice when Pigget’s features, providers, or legal obligations change. We will post the revised notice here, change the effective date, and provide additional notice in the app when a change materially affects how we use personal data.

Pigget

Privacy · Contact

© 2026 Pigget