Privacy Policy
Last updated: September 11, 2026
1. The Truth Matrix
We believe a privacy policy should be an audit table, not a wall of prose. Below is the complete list of every surface where the app or this website touches your data, including sensitive surfaces that stay entirely on your device. If a surface isn't in this table, it doesn't exist. Every network row here can be confirmed by inspecting the app's own traffic; see our verification guide.
| Surface | What we collect | Where it goes | Retention |
|---|---|---|---|
| App: normal use | Nothing | Nowhere | N/A |
| App: purchase or restore | Purchase receipt and store account identifier required to complete or restore the purchase | Apple App Store or Google Play. PocketVault Finance validates entitlements locally and does not send financial data to the store. | Governed by the store account and receipt-retention rules |
| App: "Share diagnostic logs" (only if you tap Send) | PII-scrubbed app logs for the period you pick, gzipped and attached, plus your app version and platform name (e.g. "Android"). No device model, no OS version, no hardware details; the app doesn't collect them. | Cloudflare Worker → Resend → our support inbox | 90 days, then deleted |
| App: AI model download | Cloudflare handles the connection to the R2 fallback. PocketVault Finance converts the connection IP into a one-day rate-limit code; the raw IP is not stored in its KV data. | HuggingFace (primary) or our Cloudflare R2 mirror (fallback) | The pseudonymous rate-limit code is retained for no more than 25 hours. Cloudflare's own edge logging is governed by Cloudflare. |
| App: bank SMS read (Android, opt-in) | Sender and message text from the date range you choose. PocketVault Finance may inspect non-bank messages on-device to decide what to ignore. | Stays on your device. Never transmitted off-device. Enforced by the CI grep audit described in §11. | Raw sender and message text are deleted after a message is parsed or skipped. Retryable failures are retained in the encrypted queue for up to 7 days. A message that looks like a transaction but could not be read, and one from a sender you have not yet identified, keep their text for up to 60 days — both are waiting on you to act on them, and are erased at that point whether or not you did. |
| App: share-sheet text intake (per-share, user-initiated) | Text you explicitly share to PocketVault Finance from another app (e.g., a bank notification you select and share). Nothing is read without that deliberate share action. | Buffered on your device (App Group container on iOS), parsed into a reviewable transaction on next app open. Never transmitted off-device. | Buffer drained on next app open; transaction row retained per the standard import retention |
| App: iOS Shortcut SMS intake (opt-in, user-configured) | SMS body and sender forwarded by a Shortcuts automation you set up yourself. Apple does not give third-party apps direct SMS access; only the Shortcut you authorise can hand a message to PocketVault Finance. | Buffered in an App Group container on your device, drained into the encrypted local database. Never transmitted off-device. | Buffer drained on next app launch; transaction row retained per the standard import retention |
| App: iOS Shortcut buffer overflow counter | An integer count of how many SMS were dropped because the buffer filled before the app could drain it (no SMS content, just the count). | App Group UserDefaults on your device only. | Cleared when you dismiss the overflow notice in the app |
| App: receipt capture (opt-in, when available) | The receipt image or file you provide, the OCR text extracted from it, and the structured fields derived locally. | Stays on your device. Never transmitted off-device. | Until you delete the receipt or clear app data |
| App: on-device LLM inference | The prompts and outputs of the local language model: your chat queries, imported text being parsed, and the model's responses. The model file itself was downloaded once (see "AI model download" row above). | Stays on your device. Local model runtime only; no cloud AI services are contacted. | Per-session; prompts are not persisted beyond the current chat or import flow |
| Website: page views | Cloudflare Web Analytics: cookieless, aggregate page views and country, no cross-site tracking, no fingerprint | Cloudflare Analytics dashboard | 6 months, aggregate only |
| Website: /feedback form (only if you submit) | Only what you type. An optional reply-to email if you choose to provide one. | Cloudflare Worker → Resend → our support inbox | 90 days, then deleted |
| Website: /roadmap vote (only if you vote) | A keyed SHA-256 hash (HMAC) of your network address (your IPv4 address, or the /64 block of an IPv6 address), the feature and the day, plus the vote direction. The key changes every UTC day and the address itself is never written to our database. Cloudflare Turnstile checks the vote. | Cloudflare D1 (vote tally) | Until the tally is reset for that feature |
| Website: newsletter (only if you subscribe) | The email address you provide. No tracking pixels. No click tracking. Plaintext + HTML, both unwrapped. | Cloudflare D1 + Resend (sending) | Until you unsubscribe; the row is hard-deleted, not flagged. An address nobody confirms is deleted after 30 days. |
| Website: /survey answers (only if you answer) | Your answers and whether you picked India or the US. No email, IP address, user agent or other identifier is stored with them. | Cloudflare D1 (survey responses) | Kept as anonymous research data. Nothing in a response identifies you, so none can be traced back to you. |
| Website: /survey Premium discount email (only if you leave one) | The email address you type and the region you picked, in a separate list that has no link to your survey answers. | Cloudflare D1 + Resend (one email asking you to confirm, then one email when Premium opens) | Until you remove it with the link in our email; removal hard-deletes the row. An address nobody confirms is deleted after 30 days and is never emailed again. |
| Web demo (app.pocketvault.finance) | Nothing about you. The demo runs the real app on invented finances that ship inside the page; there is no sign-up, no account and nothing to connect. It writes the persona you picked and that persona's assumptions to your browser's local storage so the screens can read them, and makes no network request after the page has loaded — you can watch that in your browser's network panel. | Your browser. Cloudflare serves the page itself, so Cloudflare's own edge logging applies to fetching it, as it does for any page on this site. | Until you clear your browser storage. Nothing is written anywhere else, so there is nothing for us to retain or delete. |
The app's outbound surface, in one sentence: HuggingFace model downloads, our R2 fallback mirror, optionally-attached scrubbed logs, and user-submitted feedback. Nothing else, ever.
2. What We Never Collect, From Anyone, Anywhere
Across the app and this website, we do not collect, transmit, or have any access to:
- Your financial accounts, balances, or transaction history
- Bank credentials, passwords, or authentication tokens
- Budgets, spending categories, or financial goals
- AI chat conversations, prompts, or model responses
- Your name, profile photo, location, contacts, calendar, or device identifiers
- Behavioural telemetry: which buttons you tap, which screens you visit, how long you spend
- Crash reports or stack traces (you may opt to attach scrubbed logs to a feedback submission, but that's it)
There is no account required to use the app; you never create a username or profile with us. The app works fully offline.
3. On-Device AI Processing
PocketVault Finance's AI features (transaction categorisation, natural language queries, forecasting) run entirely on your device using local language models: Gemma, Qwen, or Apple Foundation Models on iOS 26+. Your prompts, financial context, and model responses are never sent to external servers; no cloud AI services (OpenAI, Google, Anthropic, etc.) are used.
Models themselves are downloaded once from HuggingFace (or our R2 mirror as fallback). After download they live on-device and the network is never touched for inference.
4. Data Stored on Your Device
All user data is stored locally in an AES-256 encrypted SQLCipher database on your device. The encryption key is stored in platform secure storage (Keychain on iOS/macOS, Keystore on Android, DPAPI on Windows) and is never transmitted. Because this data resides solely on your device, you maintain full control over it. Uninstalling the app or clearing its data permanently deletes all records.
5. P2P Sync
Local-network P2P sync is not available in this release. PocketVault Finance will not expose it until the transport provides authenticated encryption for every financial payload.
6. Diagnostic Logs (Opt-In, Per-Submission)
If you contact us through the app's "Share diagnostic logs" flow, you can optionally attach recent application logs to help us reproduce a bug. Before they leave your device, those logs are PII-scrubbed (emails, phone numbers, and file paths are stripped) and truncated to 50 KB. The app shows you exactly what will be sent, and you can decline the log attachment entirely while still sending the message. Attached logs are deleted from our inbox within 90 days.
7. Website Analytics
This website (pocketvault.finance) uses Cloudflare Web Analytics, a cookieless, server-side measurement system that counts aggregate page views without cookies, fingerprints, cross-site tracking, or any per-visitor identifiers. We see "this page got 412 views from Germany this week" and that's all. We do not add Google Analytics, Plausible, Mixpanel, or any other analytics tool.
The website also uses your browser's timezone setting (via the standard Intl API) to display pricing in your local currency. This detection happens entirely in your browser; no location data is sent to any server.
8. /feedback, /roadmap, /survey, and Newsletter (All Opt-In)
The website offers four optional ways to share input with us:
- /feedback: a public form. We see only what you type. An optional reply-to email is yours to provide or omit. Submissions are protected by Cloudflare Turnstile (a cookieless CAPTCHA) and rate-limited per IP, but the IP is not stored alongside your message.
- /roadmap: vote on candidate features. To prevent ballot-stuffing without tracking voters, each vote is protected by Cloudflare Turnstile and stored only as a keyed hash of your network address, the feature and the day. The address never touches our database, and because the key changes every UTC day, votes from different days cannot be linked to each other without our server secret. Vote tallies are public.
- /survey: a short pricing survey. Answers are stored anonymously. If you leave an email for the Premium discount, it goes to a separate list with no link to your answers, and we send one email asking you to confirm it. Only confirmed addresses are ever emailed again, and only when Premium opens; unconfirmed ones are deleted after 30 days.
- Newsletter: opt-in via double confirmation: the link in our email opens a page where you press Confirm. We send at most one email per month. There are no tracking pixels and no click tracking. Unsubscribing hard-deletes your row immediately, and an address nobody confirms is deleted after 30 days.
9. Children's Privacy
PocketVault Finance is not directed at children under the age of 13. Because we collect no personal information at all, this is inherently satisfied. If you believe a child has provided data through the app or website, please contact us and we will take appropriate steps.
10. Your Rights and Control
Because your data lives on your device, you have complete control at all times:
- Access: All your data is viewable within the app.
- Deletion: Clear all data from the app settings, or uninstall the app entirely.
- Portability: Export your financial data in standard formats from within the app.
- Newsletter: Click the unsubscribe link in any email and press Unsubscribe; your row is deleted, not flagged.
- Survey discount email: Use the remove link in our email, or email privacy@pocketvault.finance; the row is deleted, not flagged.
- Feedback / diagnostic logs: Email privacy@pocketvault.finance referencing the date of your submission and we will delete it ahead of the 90-day schedule.
11. How We Enforce This Policy in Code
To keep this policy from becoming an aspirational document, our release pipeline grep-scans
the built APK and IPA artifacts for forbidden SDK domains
(googleapis.com, firebase, crashlytics,
sentry.io, amplitude, mixpanel, posthog,
segment.com) and fails the build on any match. The "no telemetry" promise is
enforced by CI rather than by intention alone.
12. Changes to This Policy
If we ever change this policy, we'll update the "Last updated" date at the top of this page and announce the change in the next changelog entry and newsletter. Any change that adds a new row to the truth matrix above will be called out explicitly.
13. Contact
Questions about privacy? Email us at privacy@pocketvault.finance.