Privacy Policy

Pocketly  ·  Last updated: August 1, 2026

Pocketly ("we", "our", or "us") is a personal expense-tracking app. This Privacy Policy explains what information we collect, how we use it, and your rights regarding that information. By using Pocketly you agree to the practices described here.

Short version: Your financial data never leaves your device. What does go off-device: an anonymous device ID (scan quotas, subscription validation), receipt images you choose to scan via cloud OCR, anonymous usage statistics (no amounts, no merchants — and you can switch them off in Settings), a push token if you allow notifications, and — if you enable cloud sync — an encrypted backup stored in your own iCloud or Google Drive.

1. Information We Collect

1a. Data stored only on your device

This data is stored in a local SQLite database on your device and is never transmitted to us or any third party.

1b. Data transmitted off-device

Data Purpose Recipient
Anonymous device ID (UUID) Enforce free scan quota (10/month); link subscription entitlement to device Our Vercel backend; RevenueCat
Receipt images (when you use cloud OCR scan) Extract merchant, amount, and date from a receipt photo using AI vision Our Vercel backend → Anthropic Claude API
Purchase / subscription information Validate and manage in-app subscriptions (weekly, monthly, yearly) RevenueCat; Apple App Store / Google Play
Anonymous usage events (screens viewed, feature-usage flags — never amounts, merchants, notes, or any financial values) Understand which features are used so we can improve the app; optional — switch off anytime in Settings → Data & Privacy PostHog (hosted in the EU)
Push token + anonymous device ID (only after you allow notifications) Deliver push notifications such as feature news and subscription notices OneSignal
Encrypted backup file (optional cloud sync) Back up your data to your own cloud account; encrypted on your device before upload — we never see its contents and it never touches our servers Your iCloud / Google Drive

2. How We Use Your Information

3. Receipt Images & OCR Processing

When you tap "Scan Receipt" using the cloud OCR feature, the image is compressed and sent over HTTPS to our backend proxy hosted on Vercel (pocketly-proxy.vercel.app). The proxy forwards it to Anthropic's Claude API for text extraction. Receipt images are processed in real-time and are not stored on our servers or Anthropic's servers after processing. The extracted data (merchant name, total amount, date) is returned to your device and saved locally.

The on-device OCR feature (available on supported devices) processes images entirely on your device and never sends any data off-device.

4. Device Identifier

Pocketly generates a random UUID the first time the app is installed and stores it securely on your device using the OS secure keystore. This ID is anonymous — it is not linked to your name, email, or any other personally identifiable information. It is used solely to count scan usage per device and to associate your RevenueCat subscription entitlement with your device.

5. Anonymous Usage Analytics

Pocketly collects anonymous usage statistics through PostHog (hosted in the European Union) to understand which features are used and to improve the app. Events carry a random analytics ID and simple flags such as "an expense was added" — they never include amounts, merchant names, notes, account or category names, or any other financial content. The analytics ID is random, is not linked to your name or email, and is not an advertising identifier: Pocketly does not access the advertising ID (IDFA/AAID) and does not track you across other apps or websites.

Your choice: analytics can be switched off at any time in Settings → Data & Privacy → "Share anonymous usage data". The opt-out takes effect immediately and persists across app restarts. RevenueCat also forwards anonymous subscription events (e.g. "trial started") to PostHog so we can understand subscriptions without collecting anything new. We process this anonymous, opt-out measurement on the basis of our legitimate interest in improving the app.

6. Push Notifications

If you allow notifications, Pocketly registers your device with OneSignal, our push delivery provider. OneSignal receives a push token and the same anonymous device ID described above — nothing else. We use push for messages such as feature announcements and subscription-related notices (for example, a free trial ending). Most reminders in Pocketly (bills, budgets, income) are local notifications scheduled on your device and involve no server at all. You can stop push at any time by disabling notifications for Pocketly in your system settings, and you can ask us to delete the associated device record (see "Your Rights").

7. Third-Party Services

Service Purpose Privacy Policy
RevenueCat In-app subscription management revenuecat.com/privacy
Anthropic (Claude API) AI-powered receipt text extraction anthropic.com/privacy
PostHog (EU Cloud) Anonymous product analytics posthog.com/privacy
OneSignal Push notification delivery onesignal.com/privacy_policy
Vercel Hosting for our backend proxy vercel.com/legal/privacy-policy
Apple App Store / Google Play App distribution and payment processing Apple & Google privacy policies

8. Permissions

Permission Why it's needed
Camera Take photos of receipts for OCR scanning
Photo Library / Storage Pick existing receipt images from your gallery
Biometrics / Fingerprint Optional app lock using Face ID or fingerprint — processed entirely on-device
Notifications Optional local reminders (bills, budgets, income) and, if enabled, remote push (feature news, subscription notices)
Internet Cloud OCR, subscription validation, and restore purchases

9. Data Retention

10. Children's Privacy

Pocketly is not directed to children under 13 (or the applicable age in your jurisdiction). We do not knowingly collect personal information from children.

11. Your Rights

Because most data is stored exclusively on your device, you can delete it at any time by clearing app data or uninstalling the app. You can switch off usage analytics in Settings → Data & Privacy whenever you like. To have server-side records deleted — the anonymous analytics profile (PostHog), the push device record (OneSignal), or the subscription record (RevenueCat) — email us and we will remove them; they are keyed only by the anonymous IDs described above. EU/UK users additionally have the rights of access, rectification, erasure, restriction, and objection under the GDPR. For any other requests or questions, contact us at the email below.

12. Security

All data transmitted to our servers is encrypted in transit using TLS. Sensitive local data (such as your device ID) is stored in the OS secure keystore (iOS Keychain / Android Keystore). We do not store financial data on any server.

13. Changes to This Policy

We may update this policy from time to time. The "Last updated" date at the top of this page will reflect any changes. Continued use of Pocketly after an update constitutes acceptance of the revised policy.

14. Contact Us

If you have questions or concerns about this privacy policy, please contact us at:
ahmedclubust@gmail.com