Legal

Privacy Policy

Pockets reads your bank notifications so you don’t have to type transactions in by hand. That only works if you trust it, so here is exactly what happens to your data — in plain language, with no gaps.

Last updated 27 July 2026

The short version

  • Bank SMS and notification text is parsed on your device. The raw text is never sent to our servers.
  • Only the structured result — amount, currency, merchant, date — is synced, and only after you turn syncing on.
  • We do not sell your data, share it with advertisers, or use it to build advertising profiles.
  • You can permanently delete your account and its data from inside the app at any time.

Who we are

Pockets is a personal and shared expense-tracking app operated from Uzbekistan at pockets.uz. For any privacy question, or to exercise any right described here, write to privacy@pockets.uz.

What we collect

Account information

Your email address, display name, default currency, and a cryptographic hash of your password (we never store the password itself). This is what identifies your account.

Financial data you create or capture

Transactions (amount, currency, merchant name, category, date, and any note you add), pockets and who belongs to them, budgets, savings goals, split shares and settlements, and any receipt images you choose to upload. This is the content of the app — it exists because you asked Pockets to track it.

Device information

Platform (Android, iOS, or web), an optional device name, and — only if you enable push notifications — a push token issued by Expo’s push service. We use these to deliver the nudges you opted into and to sync the right device.

Diagnostics

Crash and error reports through Sentry, which may include your user id, the screen you were on, and a stack trace. The web version of the app additionally uses LogRocket for session replay so we can reproduce interface bugs; it is not used in the Android or iOS apps.

Notification and SMS access (Android)

This is the part that deserves the most detail, because it is the most sensitive permission the app asks for.

  • Pockets can read incoming SMS messages (READ_SMS, RECEIVE_SMS) and posted notifications (through Android’s notification listener) in order to recognise bank payment alerts. Both are optional — the app works fully without them, you just type transactions in yourself.
  • Matching and parsing happen entirely on your device, using a rule set downloaded from our server. The message body never leaves your phone. We do not receive it, store it, or have any way to read it.
  • You choose which apps and senders Pockets is even allowed to look at. Anything outside that allowlist is dropped at the point of capture and is not processed at all.
  • What can be sent to our servers is the parsed result: a transaction amount, currency, merchant, timestamp, and a confidence score. Nothing else from the message travels with it.
  • A local capture log on your device records what was seen and what was done with it, so you can audit the feature yourself. That log is never synced.

Where your data is stored

Transactions and account data are stored in a PostgreSQL database on a server we operate in Europe. Encrypted database backups are kept in Backblaze B2 in Germany (eu-central-003). Receipt images, if you upload any, are stored in the same Backblaze bucket. All traffic between the app and our servers uses HTTPS.

Unsynced data — the capture log, your personal parsing rules, pending transactions waiting for connectivity, and your app-lock PIN — is stored only in the app’s local database on your device.

How long we keep it

Account and transaction data is kept for as long as your account exists. When you delete your account, it is removed immediately as described below. Encrypted backups made before the deletion roll off on their own retention schedule within 30 days. Sentry error reports are retained by Sentry for up to 90 days.

Deleting your account and your data

In the app, open Settings → Delete account, confirm with your password, and the deletion runs immediately. You can also request it by writing to privacy@pockets.uz from the email address on the account.

What gets deleted:

  • Your account, sign-in credentials, registered devices, and push tokens.
  • Every pocket you are the only member of, along with all its transactions, budgets, goals, categories, recurring series, and receipts.
  • Your pocket-routing rules and any parsing rules you submitted to us.
  • All locally cached data on the device you delete from.

What survives, and why: pockets you share with other people are not deleted, because they contain those people’s financial records too. You are removed from them, and if you owned one, ownership passes to another member. Your share of a shared expense stays in that pocket’s ledger so the other members’ balances remain correct.

Who else sees your data

We do not sell personal data and we do not share it for advertising. Data is processed on our behalf only by the infrastructure providers this app needs to function: Backblaze (backups and receipt storage), Sentry (error reporting), LogRocket (web session replay), and Expo (push notification delivery). Other members of a pocket you join can see the transactions in that pocket — that is the point of a shared pocket.

We will disclose data if we are legally required to. We have no interest in doing so otherwise.

Your rights

You can access your data (it is all visible in the app), correct it, export the transactions in a pocket, and delete your account outright. Write to privacy@pockets.uz if you would like any of this done for you rather than doing it yourself in the app.

Children

Pockets is not directed at children under 13, and we do not knowingly collect their data. If you believe a child has created an account, contact us and we will delete it.

Changes to this policy

If this policy changes in a way that affects what we collect or how we use it, we will update the date at the top and notify you in the app before the change takes effect.