Last updated: June 2026
This is a courtesy translation. In case of any discrepancy, the Dutch version prevails.
GDPR / AVG compliant
Peppies complies with European privacy law (GDPR, known in the Netherlands as the AVG). Your financial data, calendar and family information are never sold, rented or shared with advertisers, data brokers or other third parties. Only you (and the people you invite) have access to your data.
Peppies is an app that lets a family manage their calendar, groceries, budget, documents and more together. We handle your data with care and process no more than necessary. This policy explains which personal data we process, why, who we share it with and what rights you have.
Who is responsible?
Peppies is the data controller. Questions or a request about your data? Email privacy@peppies.app.
Financial data — our promise
Peppies is not a bank and has no access to your bank account. The budget data, transactions, savings goals and fixed costs you enter live only in your own environment.
- We do not see your financial data and do not use it.
- We never sell or rent it to third parties, advertisers or data brokers.
- It is not used for profiling, credit scoring or marketing.
- For subscription management, Mollie processes the payment only — they receive no budget data from the app.
- You can export or completely delete all your financial data at any time (see “Your rights”).
Which data do we process?
- Account details: name, email address and an encrypted (hashed) password.
- Family members: name, role, date of birth and whether someone is a child.
- Optional medical details per family member (blood type, allergies, medication) — see below.
- Calendar events (including those synced from Google/Outlook/Apple/Parro) and groceries.
- Budget, transactions, savings goals and fixed costs.
- Documents/warranty receipts and official documents.
- Loyalty cards (card number/barcode and photo).
- Family mail: forwarded emails, their content and attachments, and the summary of them.
- Usage data needed to make the app work (e.g. notifications, push subscription).
For what purpose and on which legal basis?
- Performance of the contract — to provide your account and the core features (calendar, groceries, budget, documents).
- Consent — for Pep and family mail. You can switch these on or off in Settings.
- Legal obligation — payment and administrative records for a subscription.
- Legitimate interest — partner offers in the app; you can opt out of these.
Smart features (Pep)
When you use Pep or family mail, we send the content needed for it (such as your question, a photo or the forwarded email) to our processor Anthropic (Claude, the technology behind Pep) to generate an answer or automatic filing. In Settings you decide whether Pep is on and which data it may use. For child accounts you can switch Pep off completely.
Financial budget data and transactions are not sent to Pep automatically, unless you explicitly ask about them in the chat.
If you email a bank statement to your family mail address, that file is read on our own servers and placed directly into your budget. The contents of a statement therefore do not go to Anthropic.
Children
A parent or guardian enters the details of family members and is responsible for them; children do not give consent independently. Child accounts have no access to Pep, modules or administration. Do not enter more data about children than necessary.
Special (sensitive) data
Medical details (blood type, allergies, medication) and official documents (such as a passport or driving licence) are special/sensitive data. They are optional, you enter them yourself, they are only visible within your own family and are not used for any other purpose. Forwarded family mail may unintentionally contain sensitive data — only forward what you really want to keep.
Who do we share data with (sub-processors)?
We share data exclusively with parties that help us deliver the service, and only the data that is strictly necessary for that:
- Neon / PostgreSQL — database storage (EU region).
- Vercel — hosting of the app.
- Anthropic (Claude) — the technology behind Pep, only when you activate it.
- Resend — outgoing email and incoming family mail.
- Mollie — payments and subscriptions (receives no budget data).
- Open-Meteo — weather forecast (location only, no personal data).
Data processing agreements are in place with all of these parties. We never sell your data and use no third-party tracking or advertising cookies. There are no other parties with access to your data.
Cookies
Peppies uses only a single functional cookie to keep you logged in. There are no analytics, tracking or marketing cookies. That is why no cookie banner is needed either.
How long do we keep data?
We keep your data for as long as you have an account. If you delete your account, we irreversibly erase all family data. Login and recovery links expire automatically (within 15 minutes to 1 hour).
Your rights (GDPR)
You have the following rights under the GDPR:
- Access & portability: download all your data via Settings → Account → Download my data.
- Erasure (right to be forgotten): delete your account and all family data via Settings → Account → Delete account.
- Rectification: change your data directly in the app.
- Objection: email privacy@peppies.app.
You can also lodge a complaint with the Dutch Data Protection Authority, the Autoriteit Persoonsgegevens.
Changes
We may update this policy. We will let you know in the app about important changes. The current version is always available on this page. Also see the terms of use.