Verify our privacy claims

Last updated: July 31, 2026

PocketVault Finance's privacy claim is simple: your financial data stays on your device, and the app never phones home with analytics, telemetry, or ads. You shouldn't have to take our word for that. This page shows four ways to confirm it yourself: three you run on the device you install it on, and one you read.

The reference for everything below is the truth matrix in our privacy policy, the complete list of every surface where data could leave your device. If the app contacts anything not in that table, that's a discrepancy we want to hear about: email us and we'll treat it as a critical issue.

Method 1: Watch the network traffic

This is the strongest check: capture every connection the app makes and read the list of hosts. You need no special access to our systems and no trust in us, because you're observing the app on your own device.

On Android

Install PCAPdroid from the Play Store or F-Droid. It captures traffic entirely on-device using Android's VPN API, with no root and nothing sent to a third party. Start a capture, use PocketVault Finance normally for a few minutes (add transactions, open the dashboard, run an AI query), then stop it and review the connections log.

On iOS

Turn on Settings → Privacy & Security → App Privacy Report. After you use the app, the report lists every domain each app has contacted. For a full request-level view, put the device behind a Mac running a proxy such as Proxyman or Charles.

What you should see

Only the endpoints listed in the truth matrix: the AI model file you chose to download, and any diagnostic logs you explicitly sent. Both are things you started: if you don't download a model and don't send diagnostic logs, a capture of an entire session should show no connections at all. You should never see an analytics, crash-reporting, ad, or account/login service, and your transactions and balances should never appear in any request body.

Method 2: Pull the plug

Put the device in airplane mode and keep using PocketVault Finance. Adding transactions, budgeting, viewing reports, backup and restore, and biometric unlock all keep working offline. That's the proof there is no cloud dependency for your data: it was never on a server to begin with. The only things that need a connection are the optional extras: the one-time AI model download and sending us diagnostic logs.

Method 3: Read the store privacy label

On the app's store listing, the App Store App Privacy card and the Google Play Data safety section describe what the app collects and shares. These are declarations the store holds us to. Cross-check them against the truth matrix; they should agree.

Method 4: Read the check that gates every release

The three methods above ask you to inspect a build after the fact. This one is the rule that decides whether a build is allowed to exist. Before any release artifact is uploaded, our pipeline unpacks it (an AAB, an APK and an IPA are all zip-of-zips, so it recurses into the nested archives too) and greps every unpacked file for the network endpoints belonging to the common analytics and crash-reporting SDKs. One match and the job exits non-zero, so the release stops there. A privacy promise that depends on a developer remembering it is fragile; a privacy promise the build refuses to violate is a property of the software itself.

The list it matches is deliberately made of reachable network endpoints, not brand names. A dependency that happens to ship a class called FirebaseFoo does not trip it; one that compiles in a real URL does. Here is the list in full, exactly as the pipeline holds it:

  • firebaseio.com
  • firebase-installations.googleapis.com
  • firebaseremoteconfig.googleapis.com
  • firebaseinappmessaging.googleapis.com
  • firebaseanalytics.googleapis.com
  • app-measurement.com
  • crashlytics.com
  • crashlyticsreports-pa.googleapis.com
  • sentry.io
  • ingest.sentry.io
  • amplitude.com
  • api.amplitude.com
  • mixpanel.com
  • api.mixpanel.com
  • posthog.com
  • app.posthog.com
  • segment.io
  • cdn.segment.com
  • fullstory.com
  • hotjar.com
  • datadoghq.com
  • bugsnag.com
  • instabug.com
  • launchdarkly.com
  • statsig.com
  • rollbar.com
  • logrocket.com

A second, earlier gate runs on every pull request and matches the same families against pubspec.lock by package name, so a dependency that would introduce one is caught at review time rather than at release time.

You do not have to take the description on trust either. Both gates are visible in the artifact you install: run Method 1 against a release build and the endpoints above should be absent from the connection log, because they are absent from the binary.

There is one thing this check cannot do, and it is worth stating plainly: it proves an artifact contains no known telemetry endpoint. It cannot prove the absence of a novel one nobody has thought to add to the list yet. That is why Method 1 exists, and why the list is written to be read and argued with rather than trusted.

What the app does contact, and why

Two things, and you start both of them yourself. Currency conversion is not one of them, because exchange rates ship inside the app and are edited on your device, so switching currencies never touches the network.

  • AI model download: when you choose an on-device model, its files are downloaded once and then run entirely offline. No prompts or financial data are sent anywhere to use the AI.
  • Diagnostic logs you send: only if you open "Share diagnostic logs", review the report on screen and tap Send. It carries PII-scrubbed app logs plus your app version and platform name, and nothing else about your device. Nothing is sent in the background.

General feedback and feature requests aren't collected in the app at all; those links open this website in your browser, so the app itself never sends them.

Peer-to-peer sync isn't in this release; when it ships it stays on your local network and never touches our servers. Everything else (your accounts, transactions, budgets, goals, and the AI's answers) never leaves the device.

If something doesn't match

If you capture a connection that isn't accounted for above or in the truth matrix, please email us with what you saw. A privacy claim that can't survive inspection isn't worth much, so we'd rather you check than trust.