Privacy Policy

Effective July 3, 2026

SimplifyPocket is built on a simple principle: your financial data is yours. We do not sell it, share it for advertising, or connect to your bank accounts. This policy explains what we collect, why we collect it, who processes it on our behalf, and how it is protected.

Data we collect

The table below summarizes every category of data we collect, what falls inside it, and why we need it. All of this data is linked to your account and is used solely to operate the service for you.

CategoryWhat we collectWhy we collect it
Contact InfoEmail address, first name, last name — which you enter directly, or that we receive from Apple or Google if you use their sign-inTo create your account, sign you in, and send transactional emails (verification, password reset, subscription confirmations, account deletion notices).
IdentifiersA user ID assigned by our authentication provider, and a push notification token if you opt in to notificationsTo recognize you across sessions and to deliver push notifications you have requested.
Financial InfoThe accounts, balances, transactions, categories, merchants, budgets, and recurring items you manually enterTo provide the core service — tracking and analyzing the financial data you choose to enter. We do not connect to banks or read your statements.
PurchasesSubscription status, plan, billing period, and an opaque customer identifier from Stripe or AppleTo grant access to paid features and process renewals. Card numbers are handled entirely by Stripe or Apple and are never sent to or stored by SimplifyPocket.
User ContentTransaction notes, custom category and merchant names, feedback you submit, and notification preference settingsTo store the labels and notes you create so the app behaves the way you set it up.
Voice TranscriptsThe text transcribed from your voice when you use the AI voice transaction feature. Audio is transcribed on your device and is never uploaded. Only the resulting text is sent to our servers.To run the AI parser that extracts transaction details (amount, date, merchant, category) from what you said. Transcripts are processed in real time and are not retained on our servers beyond the duration of the request.
DiagnosticsServer-side request logs (HTTP method, masked IP, response code, response time), plus crash reports and error diagnostics from the app (stack trace, app version, OS version, device model)To keep the service reliable and to diagnose problems. Sensitive fields and credentials are redacted before logging, and crash/error reports have PII scrubbing enabled so your personal and financial data are not sent with them. We do not record your screen.

We do not collect: your location, your contacts, photos or camera content, health data, browsing history outside SimplifyPocket, advertising identifiers, or any data from other apps.

How we use your information

We use the information we collect to:

· Create and maintain your account

· Provide the SimplifyPocket service — store and display the financial data you enter

· Process your subscription payment and grant access to paid features

· Send transactional emails (verification, password reset, subscription receipts, account deletion notices)

· Deliver push notifications you have opted into

· Respond to your support requests

· Diagnose errors and keep the service reliable

We do not use your financial data for advertising, analytics profiling, credit scoring, or any purpose other than running the service for you. We do not sell your personal information to any third party, ever.

Service providers

We work with a small number of trusted service providers to operate SimplifyPocket. These providers may process your data on our behalf only for the limited purposes described below.

ClerkAuthentication and identity

Email, name, password (handled directly by Clerk — we never see or store your password), session tokens.

StripeWeb subscription payments

Email, billing address, payment method (handled directly by Stripe). We receive only a customer ID and subscription status.

AppleSign in with Apple and iOS subscription payments (In-App Purchase)

If you use Sign in with Apple, we receive your name (first sign-in only) and email address — or a private relay address if you choose "Hide My Email." For subscriptions, your Apple ID and payment details are handled directly by Apple; we never see your Apple ID or card.

GoogleSign in with Google

If you use Sign in with Google, we receive your name, email address, and Google account identifier so we can create or match your account. Sign-in is handled by Google; we never see your Google password.

RevenueCatiOS subscription state sync

An opaque user identifier and your iOS subscription entitlement state, so the app knows what features to unlock.

ResendTransactional email delivery

Your email address and the contents of transactional messages we send (verification, password reset, subscription receipts, account deletion notices).

AnthropicAI parsing for voice transactions

The text transcript of a voice transaction (e.g. "twenty dollars at Whole Foods yesterday") plus a short context list of your existing categories and merchants so the model can match by name. No audio is sent. No persistent identifier is sent, so Anthropic does not know which SimplifyPocket user the request belongs to. Anthropic does not train on this data and retains it briefly for abuse monitoring per their API terms.

ExpoPush notification delivery

A device push token (if you opted in) and the title/body of notifications we send you.

SentryCrash and error diagnostics

Crash reports and error diagnostics (stack trace, app version, OS version, device model). PII scrubbing is enabled, so we do not intentionally send your personal or financial data, and we do not use session replay (no screen recording).

RailwayApplication hosting and database

All of the data described in the "Data we collect" table, stored at rest in an encrypted PostgreSQL database in the United States.

VercelHosting for our marketing site, plus anonymous traffic analytics on simplifypocket.com

Standard web request data (pages visited, referrer, browser, country) for the marketing site. The iOS app does not use Vercel Analytics.

We do not track you across other apps or websites

SimplifyPocket does not use advertising identifiers (such as Apple's IDFA), does not share your data with advertisers or data brokers, and does not track your activity across other companies' apps or websites. We do not display third-party advertising inside the app. As a result, the iOS app does not present an App Tracking Transparency prompt.

Push notifications

If you grant permission, we send push notifications for the categories you enable: budget alerts, large transactions, low account balances, recurring transaction reminders, and important service messages. You can change or disable these at any time inside the app under More → Notification preferences, or completely in your device's Settings app under SimplifyPocket → Notifications.

Voice transactions and AI

SimplifyPocket includes an optional voice feature that lets you add a transaction by speaking. You open it by tapping the plus button and choosing Voice. From there, you hold the microphone button and speak. Your iPhone transcribes your speech to text on the device using Apple's on‑device speech recognition. The audio itself never leaves your phone.

The resulting text is sent to our backend, which forwards it to Anthropic, the large language model provider we use. Along with the transcript we send a short list of your existing categories and merchants so the model can match the transaction to entities you already have. Anthropic returns a structured draft (amount, date, type, suggested category, suggested merchant) that we show you on the confirmation screen. Nothing is saved until you tap Save.

Anthropic does not train on the data we send through their API and retains it briefly for abuse monitoring under their commercial API terms. We do not send Anthropic any persistent identifier, so they cannot link a request to a specific SimplifyPocket user.

The voice feature is optional. You can use SimplifyPocket entirely without it. iOS will ask for microphone and speech recognition permission the first time you try the feature. You can revoke either permission at any time in Settings → SimplifyPocket.

Data retention and deletion

Your data is retained for as long as your account is active. You can delete your account at any time from within the app under More → Delete account. When you do, your account is scheduled for permanent deletion and we automatically remove your personal information and financial data within 30 days. This grace period protects you from accidental deletions — during that window you can sign back in and tap Cancel deletion to restore everything.

Payment records may be retained by Stripe or Apple as required by their own legal and financial obligations. Anonymized diagnostic logs may be retained for up to 90 days for service reliability purposes.

Security

All data is encrypted in transit using TLS. Your data is stored in a managed PostgreSQL database with encryption at rest and access strictly limited to authenticated services. Passwords are hashed by our authentication provider and are never accessible to SimplifyPocket.

SimplifyPocket never connects to your bank. No bank credentials, no OAuth tokens to financial institutions, no third-party data aggregators. Your financial data exists only because you typed it in.

Your rights

You have the right to access, correct, or delete the personal information we hold about you. You can manage most of this directly from within the app. To request a full data export or for any other privacy request, contact us at the address below.

California residents have additional rights under the California Consumer Privacy Act (CCPA), including the right to know what personal information is collected and the right to opt out of the sale of personal information. We do not sell personal information.

Children

SimplifyPocket is not directed to children under 13. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided us with personal information, please contact us at the address below and we will delete it promptly. Children old enough to use the app should do so with the involvement of a parent or guardian, particularly for any subscription purchase.

Changes to this policy

We may update this policy from time to time. If we make material changes, we will notify you by email or with a notice inside the app before the changes take effect. The effective date at the top of this page reflects the most recent version.

Contact

Questions about this policy or your data? Email us at [email protected].