Privacy Policy
We build software with a local-first philosophy and zero-knowledge privacy. Here is how your data is handled across our applications and services.
1. Core Philosophy: Local-First & Data Ownership
We believe your data belongs to you. Our software architecture is intentionally designed with a local-first, privacy-respecting foundation.
Desktop applications built by Penny Codes store primary operational databases directly on your device rather than on centralized multi-tenant servers. We do not sell, rent, monetize, or harvest personal information.
2. Church CMS & Winners CMS Desktop Applications
Local Database Storage
All congregation records, member profiles (names, phone numbers, emails, birthdays, addresses), groups, attendance, financial contributions, and notes are stored locally on your device in a dedicated SQLite database. Penny Codes does not have access to your local database files.
SMS Communications & Gateway Transmission
When an authorized staff member initiates an SMS broadcast or individual message, the recipient phone numbers and message content are transmitted securely over HTTPS directly to the configured SMS provider (Hubtel, Twilio, or Termii) to fulfill message delivery. Credentials (API keys, client secrets, and sender IDs) are managed locally on the user's computer.
Zero-Knowledge Encrypted Backups
When you create local or cloud backups, the database is encrypted on your machine using age passphrase encryption before being saved or uploaded. Cloud backups are stored in an encrypted state where only you hold the decryption passphrase. Penny Codes cannot decrypt, view, or recover your backup contents without your secret passphrase.
License Validation & Hardware Device Identifier
To enforce single-device license limits without collecting personal machine details, our software generates a one-way cryptographic SHA-256 hash of the machine identifier. This non-reversible token is transmitted solely to verify license seat activation.
Payment Processing
License and credit purchases are processed directly through authorized payment gateways (such as Hubtel Checkout). We do not collect, process, or store credit card numbers or mobile money PINs on our servers.
3. Third-Party Services & Integration
Our applications may integrate with third-party service providers solely to perform necessary technical functions:
• SMS Delivery: Hubtel (Ghana/International), Twilio (Global), Termii (Nigeria/Regional).
• Cloud Storage (Encrypted Backups): Cloudflare R2 object storage for licensed cloud backup archives.
• Payment Gateways: Hubtel Checkout for in-app license purchases.
Each third-party service processes data in accordance with their respective privacy policies and industry-standard security protocols.
4. Data Security
We implement robust technical and architectural safeguards to protect your information:
• Local password verification utilizes salted bcrypt hashing.
• All external API communications use TLS 1.3 / HTTPS encryption in transit.
• Cloud backup archives employ industry-standard zero-knowledge passphrase encryption.
5. Data Retention & Deletion
Because your operational data resides on your local device, you maintain complete control over data retention. You may edit, export, or permanently delete records and database files at any time by removing the application or clearing application data.
For cloud-synced encrypted backups, deleting your cloud backups permanently purges the encrypted archives from storage.
6. Children's Privacy
Our applications and websites are intended for use by organizations, businesses, and administrators. We do not knowingly collect personal information directly from children under the age of 13.
7. Contact & Inquiries
If you have any questions about this Privacy Policy or how your data is handled, please contact Penny Codes at business@pennycodes.dev or through our website at https://pennycodes.dev.
Looking for project details or architecture docs? Visit our work or contact us directly.