Pocketly · Last updated: August 1, 2026
Pocketly ("we", "our", or "us") is a personal expense-tracking app. This Privacy Policy explains what information we collect, how we use it, and your rights regarding that information. By using Pocketly you agree to the practices described here.
This data is stored in a local SQLite database on your device and is never transmitted to us or any third party.
| Data | Purpose | Recipient |
|---|---|---|
| Anonymous device ID (UUID) | Enforce free scan quota (10/month); link subscription entitlement to device | Our Vercel backend; RevenueCat |
| Receipt images (when you use cloud OCR scan) | Extract merchant, amount, and date from a receipt photo using AI vision | Our Vercel backend → Anthropic Claude API |
| Purchase / subscription information | Validate and manage in-app subscriptions (weekly, monthly, yearly) | RevenueCat; Apple App Store / Google Play |
| Anonymous usage events (screens viewed, feature-usage flags — never amounts, merchants, notes, or any financial values) | Understand which features are used so we can improve the app; optional — switch off anytime in Settings → Data & Privacy | PostHog (hosted in the EU) |
| Push token + anonymous device ID (only after you allow notifications) | Deliver push notifications such as feature news and subscription notices | OneSignal |
| Encrypted backup file (optional cloud sync) | Back up your data to your own cloud account; encrypted on your device before upload — we never see its contents and it never touches our servers | Your iCloud / Google Drive |
When you tap "Scan Receipt" using the cloud OCR feature, the image is compressed and
sent over HTTPS to our backend proxy hosted on Vercel
(pocketly-proxy.vercel.app). The proxy forwards it to Anthropic's Claude API
for text extraction. Receipt images are processed in real-time and are not stored
on our servers or Anthropic's servers after processing. The extracted data
(merchant name, total amount, date) is returned to your device and saved locally.
The on-device OCR feature (available on supported devices) processes images entirely on your device and never sends any data off-device.
Pocketly generates a random UUID the first time the app is installed and stores it securely on your device using the OS secure keystore. This ID is anonymous — it is not linked to your name, email, or any other personally identifiable information. It is used solely to count scan usage per device and to associate your RevenueCat subscription entitlement with your device.
Pocketly collects anonymous usage statistics through PostHog (hosted in the European Union) to understand which features are used and to improve the app. Events carry a random analytics ID and simple flags such as "an expense was added" — they never include amounts, merchant names, notes, account or category names, or any other financial content. The analytics ID is random, is not linked to your name or email, and is not an advertising identifier: Pocketly does not access the advertising ID (IDFA/AAID) and does not track you across other apps or websites.
Your choice: analytics can be switched off at any time in Settings → Data & Privacy → "Share anonymous usage data". The opt-out takes effect immediately and persists across app restarts. RevenueCat also forwards anonymous subscription events (e.g. "trial started") to PostHog so we can understand subscriptions without collecting anything new. We process this anonymous, opt-out measurement on the basis of our legitimate interest in improving the app.
If you allow notifications, Pocketly registers your device with OneSignal, our push delivery provider. OneSignal receives a push token and the same anonymous device ID described above — nothing else. We use push for messages such as feature announcements and subscription-related notices (for example, a free trial ending). Most reminders in Pocketly (bills, budgets, income) are local notifications scheduled on your device and involve no server at all. You can stop push at any time by disabling notifications for Pocketly in your system settings, and you can ask us to delete the associated device record (see "Your Rights").
| Service | Purpose | Privacy Policy |
|---|---|---|
| RevenueCat | In-app subscription management | revenuecat.com/privacy |
| Anthropic (Claude API) | AI-powered receipt text extraction | anthropic.com/privacy |
| PostHog (EU Cloud) | Anonymous product analytics | posthog.com/privacy |
| OneSignal | Push notification delivery | onesignal.com/privacy_policy |
| Vercel | Hosting for our backend proxy | vercel.com/legal/privacy-policy |
| Apple App Store / Google Play | App distribution and payment processing | Apple & Google privacy policies |
| Permission | Why it's needed |
|---|---|
| Camera | Take photos of receipts for OCR scanning |
| Photo Library / Storage | Pick existing receipt images from your gallery |
| Biometrics / Fingerprint | Optional app lock using Face ID or fingerprint — processed entirely on-device |
| Notifications | Optional local reminders (bills, budgets, income) and, if enabled, remote push (feature news, subscription notices) |
| Internet | Cloud OCR, subscription validation, and restore purchases |
Pocketly is not directed to children under 13 (or the applicable age in your jurisdiction). We do not knowingly collect personal information from children.
Because most data is stored exclusively on your device, you can delete it at any time by clearing app data or uninstalling the app. You can switch off usage analytics in Settings → Data & Privacy whenever you like. To have server-side records deleted — the anonymous analytics profile (PostHog), the push device record (OneSignal), or the subscription record (RevenueCat) — email us and we will remove them; they are keyed only by the anonymous IDs described above. EU/UK users additionally have the rights of access, rectification, erasure, restriction, and objection under the GDPR. For any other requests or questions, contact us at the email below.
All data transmitted to our servers is encrypted in transit using TLS. Sensitive local data (such as your device ID) is stored in the OS secure keystore (iOS Keychain / Android Keystore). We do not store financial data on any server.
We may update this policy from time to time. The "Last updated" date at the top of this page will reflect any changes. Continued use of Pocketly after an update constitutes acceptance of the revised policy.
If you have questions or concerns about this privacy policy, please contact us at:
ahmedclubust@gmail.com