Verify our privacy claims

Last updated: July 31, 2026

PocketVault's privacy claim is simple: your financial data stays on your device, and the app never phones home with analytics, telemetry, or ads. You shouldn't have to take our word for that. This page shows how to confirm it yourself, on the device you install it on — by watching what the app actually does, not by trusting a promise.

The reference for everything below is the truth matrix in our privacy policy — the complete list of every surface where data could leave your device. If the app contacts anything not in that table, that's a discrepancy we want to hear about: email us and we'll treat it as a critical issue.

Method 1 — Watch the network traffic

This is the strongest check: capture every connection the app makes and read the list of hosts. You need no special access to our systems and no trust in us — you're observing the app on your own device.

On Android

Install PCAPdroid from the Play Store or F-Droid. It captures traffic entirely on-device using Android's VPN API — no root, and nothing is sent to a third party. Start a capture, use PocketVault normally for a few minutes (add transactions, open the dashboard, run an AI query), then stop it and review the connections log.

On iOS

Turn on Settings → Privacy & Security → App Privacy Report. After you use the app, the report lists every domain each app has contacted. For a full request-level view, put the device behind a Mac running a proxy such as Proxyman or Charles.

What you should see

Only the endpoints listed in the truth matrix — the AI model file you chose to download, and any diagnostic logs you explicitly sent. Both are things you started: if you don't download a model and don't send diagnostic logs, a capture of an entire session should show no connections at all. You should never see an analytics, crash-reporting, ad, or account/login service, and your transactions and balances should never appear in any request body.

Method 2 — Pull the plug

Put the device in airplane mode and keep using PocketVault. Adding transactions, budgeting, viewing reports, backup and restore, and biometric unlock all keep working offline. That's the proof there is no cloud dependency for your data: it was never on a server to begin with. The only things that need a connection are the optional extras — the one-time AI model download and sending us diagnostic logs.

Method 3 — Read the store privacy label

On the app's store listing, the App Store App Privacy card and the Google Play Data safety section describe what the app collects and shares. These are declarations the store holds us to. Cross-check them against the truth matrix — they should agree.

What the app does contact, and why

Two things, and you start both of them yourself. Currency conversion is not one of them — exchange rates ship inside the app and are edited on your device, so switching currencies never touches the network.

  • AI model download — when you choose an on-device model, its files are downloaded once and then run entirely offline. No prompts or financial data are sent anywhere to use the AI.
  • Diagnostic logs you send — only if you open "Share diagnostic logs", review the report on screen and tap Send. It carries PII-scrubbed app logs plus your app version and platform name, and nothing else about your device. Nothing is sent in the background.

General feedback and feature requests aren't collected in the app at all — those links open this website in your browser, so the app itself never sends them.

Peer-to-peer sync isn't in this release; when it ships it stays on your local network and never touches our servers. Everything else — your accounts, transactions, budgets, goals, and the AI's answers — never leaves the device.

If something doesn't match

If you capture a connection that isn't accounted for above or in the truth matrix, please email us with what you saw. A privacy claim that can't survive inspection isn't worth much — so we'd rather you check than trust.