Privacy Policy
The short version. Your transactions live on your phone. Pocksy does not upload them, cannot read them, and works completely without an account. If you sign in and press Back up, a copy goes to a database that only your account can open. Receipt photos you attach are stored the same way. Everything else on this page is detail.
Who is responsible
Pocksy is published by Himanshu Kumar Singh, operating as a sole trader in the United Kingdom. For the purposes of UK GDPR, Himanshu Kumar Singh is the data controller.
Questions, requests, or complaints: support@pocketfinance.uk.
Using Pocksy without an account
The app is fully usable as a guest. Transactions, categories, debts, reminders and reports are stored in a database on your device and are not uploaded. Deleting the app deletes them.
Guests are given an anonymous identifier so that receipt photos can be stored against something. It is not linked to your name, email, or any other account.
What we collect, and why
If you sign in
| Data | Why | Legal basis |
|---|---|---|
| Email address | To identify your account across devices. Apple's Hide My Email is supported and gives us a relay address instead. | Performance of a contract |
| Name | Shown on your profile screen. Optional — sign-in works without it. | Performance of a contract |
| Account identifier | An opaque ID that ties your subscription and your photos to you. | Performance of a contract |
If you attach a receipt or profile photo
The image is stored on Cloudflare R2 under an address only your account can write to. It can only be opened through a link that is cryptographically signed and expires within the hour. Nobody browsing the storage can reach it, and nothing analyses, scans or reads the image.
The connection between a photo and the transaction it belongs to exists only in the database on your phone. Someone with full access to our storage would find a pile of photographs and no ledger to read them against.
If you turn on cloud backup
Cloud backup is a Premium feature and a button you press. Nothing is uploaded until you press it. When you do, a copy of your transactions, categories, debts and reminders is written to a Google Firestore document keyed to your account, readable only by you. It exists so that your records survive changing phone or leaving Apple.
Legal basis: performance of a contract. You can delete it at any time by deleting your account in the app.
Always, unless you switch it off
| Data | Why | Legal basis |
|---|---|---|
| Crash reports | A crash nobody reports is a crash nobody fixes. Reports contain the technical state of the app at the moment it failed, plus your device model and iOS version. | Legitimate interests |
| Usage events | Which screens are used and which flows are abandoned. An event records that a transaction was added and its type — never the amount, the merchant, the note, or the photo. | Legitimate interests |
Both can be switched off in Profile → Privacy & Security. Off means collection stops at the source; it is not gathered and then withheld.
Advertising
The free version shows advertisements supplied by Google AdMob. AdMob receives standard device and advertising signals in order to select an advertisement. It is never given your transactions, balances, categories, reminders or photographs.
iOS will ask whether you allow tracking. If you say no, advertising is contextual rather than personalised and nothing else in the app changes. If you say yes, AdMob may use your device's advertising identifier across apps, which pays more and is what keeps the free version free.
Legal basis: consent, given through Apple's tracking prompt and withdrawable at any time in iOS Settings → Privacy & Security → Tracking.
Premium removes advertising entirely.
Purchases
Payment is handled by Apple. We never see your card details. RevenueCat records that a subscription exists so that it follows you between devices, and receives your account identifier and the receipt Apple issues — no financial data from the app.
What we never collect
- Bank credentials. Pocksy does not connect to any bank.
- Your transaction amounts, merchant names, notes or category names — unless you explicitly turn on cloud backup, and then only into your own document.
- Your location.
- Your contacts. Names on the lend-and-borrow screen are typed by you and never leave the device.
- The contents of your photographs.
Who processes data on our behalf
| Processor | Purpose | Where |
|---|---|---|
| Google (Firebase) | Sign-in, crash reports, usage analytics, cloud backup | EU / US |
| Google (AdMob) | Advertising in the free version | EU / US |
| Cloudflare | Receipt and profile photo storage | EU / global edge |
| RevenueCat | Subscription status | US |
| Apple | Payments, and iCloud sync if you enable it | Per Apple's terms |
Transfers outside the UK rely on the UK International Data Transfer Addendum or an adequacy decision, as applicable to each provider.
How long it is kept
- On your device: until you delete the data or the app.
- Photos and cloud backup: until you delete them, or until you delete your account, which removes both.
- Crash and usage data: retained by Google on our behalf for up to 14 months.
Your rights
Under UK GDPR you may request access to your data, correction of it, deletion of it, a portable copy, or restriction of how it is used. You may also object to processing carried out under legitimate interests.
Deleting your account is built into the app — Profile → Account → Delete account. It removes your sign-in, your cloud backup and your stored photos. Transactions saved on your device are deliberately left alone; deleting an account is not the same as asking to lose what you typed, and Settings → Reset app data does that separately and explicitly.
For anything else, email support@pocketfinance.uk. We aim to reply within 30 days.
If you are unhappy with our response you can complain to the Information Commissioner's Office at ico.org.uk.
Children
Pocksy is not intended for anyone under 18 and asks you to confirm your age on first launch. That confirmation records only whether you passed — your date of birth is never stored. We do not knowingly collect data from children. If you believe a child has provided us with data, email us and we will delete it.
Security
Data in transit is encrypted with TLS. Photos are stored in an access-controlled bucket and served only through short-lived signed links. Backup documents are protected by rules that permit access only to the account that owns them. No system is perfect, and we make no absolute guarantee.
Changes
If this policy changes materially we will update the date at the top and note the change in the app. Continuing to use Pocksy after a change means you accept the revised policy.