Privacy Policy
Effective July 3, 2026
SimplifyPocket is built on a simple principle: your financial data is yours. We do not sell it, share it for advertising, or connect to your bank accounts. This policy explains what we collect, why we collect it, who processes it on our behalf, and how it is protected.
Data we collect
The table below summarizes every category of data we collect, what falls inside it, and why we need it. All of this data is linked to your account and is used solely to operate the service for you.
| Category | What we collect | Why we collect it |
|---|---|---|
| Contact Info | Email address, first name, last name — which you enter directly, or that we receive from Apple or Google if you use their sign-in | To create your account, sign you in with an emailed code, and send transactional emails (sign-in codes, subscription confirmations, account deletion notices). |
| Identifiers | A user ID assigned by our authentication provider, and a push notification token if you opt in to notifications | To recognize you across sessions and to deliver push notifications you have requested. |
| Financial Info | The accounts, balances, transactions, categories, merchants, budgets, and recurring items you manually enter | To provide the core service — tracking and analyzing the financial data you choose to enter. We do not connect to banks or read your statements. |
| Purchases | Subscription status, plan, billing period, and an opaque customer identifier from RevenueCat and the app store you purchased through (Apple or Google Play) | To grant access to paid features and process renewals. Payment details are handled entirely by Apple (on iPhone) or Google Play (on Android) and are never sent to or stored by SimplifyPocket. |
| User Content | Transaction notes, custom category and merchant names, feedback you submit, and notification preference settings | To store the labels and notes you create so the app behaves the way you set it up. |
| Voice Transcripts | The text transcribed from your voice when you use the AI voice transaction feature. On iPhone the audio is transcribed on-device and never leaves your phone. On Android, transcription uses the phone built-in speech recognizer, which sends the audio to the device speech service (for example Google) to produce the text. In every case SimplifyPocket itself never receives or stores the audio; only the resulting text is sent to our servers. | To run the AI parser that extracts transaction details (amount, date, merchant, category) from what you said. Transcripts are processed in real time and are not retained on our servers beyond the duration of the request. |
| Receipt Images | When you use the optional receipt-scanning feature, the single photo of a receipt you capture with the camera or choose from your library. The image is sent to our AI provider (Anthropic) to read the merchant, total, and date. | To turn a receipt into a transaction draft you review before saving. The image is processed in real time to produce that draft and is not stored on our servers afterward — only the transaction you confirm and save is kept. |
| Usage Data | Anonymized product-analytics events describing how you use the app — screens you view and in-app features you use — tied to your user ID. No financial amounts, transaction contents, names, or email addresses are included in these events. | To understand which features are used so we can improve the app. This data is never used for advertising and is never sold. It is processed by PostHog (see the service providers section). |
| Diagnostics | Server-side request logs (HTTP method, masked IP, response code, response time), plus crash reports and error diagnostics from the app (stack trace, app version, OS version, device model) | To keep the service reliable and to diagnose problems. Sensitive fields and credentials are redacted before logging, and crash/error reports have PII scrubbing enabled so your personal and financial data are not sent with them. We do not record your screen. |
We do not collect: your location, your contacts, your photo library or camera roll (the only image we ever receive is a single receipt you explicitly capture or choose to scan — see below), health data, browsing history outside SimplifyPocket, advertising identifiers, or any data from other apps.
How we use your information
We use the information we collect to:
· Create and maintain your account
· Provide the SimplifyPocket service — store and display the financial data you enter
· Process your subscription payment and grant access to paid features
· Send transactional emails (sign-in codes, subscription receipts, account deletion notices)
· Deliver push notifications you have opted into
· Respond to your support requests
· Diagnose errors and keep the service reliable
We do not use your financial data for advertising, analytics profiling, credit scoring, or any purpose other than running the service for you. We do not sell your personal information to any third party, ever.
Service providers
We work with a small number of trusted service providers to operate SimplifyPocket. These providers may process your data on our behalf only for the limited purposes described below.
Clerk — Authentication and identity
Email, name, and session tokens. Sign-in is passwordless — a 6-digit code emailed to you, or one-tap Apple or Google sign-in — so there is no password to see or store.
Apple — Sign in with Apple and iPhone subscription payments (In-App Purchase)
If you use Sign in with Apple, we receive your name (first sign-in only) and email address — or a private relay address if you choose "Hide My Email." For subscriptions on iPhone, your Apple ID and payment details are handled directly by Apple; we never see your Apple ID or card.
Google — Sign in with Google
If you use Sign in with Google, we receive your name, email address, and Google account identifier so we can create or match your account. Sign-in is handled by Google; we never see your Google password.
Google Play — Android subscription payments (Google Play Billing)
For subscriptions on Android, your Google account and payment details are handled directly by Google through Google Play Billing; we never see your Google payment method or card.
RevenueCat — iOS and Android subscription state sync
An opaque user identifier and your subscription entitlement state, so the app knows what features to unlock.
Resend — Transactional email delivery
Your email address and the contents of transactional messages we send (sign-in codes, subscription receipts, account deletion notices).
Anthropic — AI parsing for voice transactions, receipt scanning, and the Pocket chat assistant
For voice, the text transcript of what you said (e.g. "twenty dollars at Whole Foods yesterday"); for receipt scanning, the photo of the receipt you capture so the model can read the merchant, total, and date; for Pocket chat, your questions and the budget context you are asking about. In each case we also send a short context list of your existing categories and merchants so the model can match by name. No audio is ever sent, and receipt images are processed in real time and not stored by us afterward. No persistent identifier is sent, so Anthropic does not know which SimplifyPocket user the request belongs to. Anthropic does not train on this data and retains it briefly for abuse monitoring per their API terms.
Expo — Push notification delivery
A device push token (if you opted in) and the title/body of notifications we send you.
Sentry — Crash and error diagnostics
Crash reports and error diagnostics (stack trace, app version, OS version, device model). PII scrubbing is enabled, so we do not intentionally send your personal or financial data, and we do not use session replay (no screen recording).
Railway — Application hosting and database
All of the data described in the "Data we collect" table, stored at rest in an encrypted PostgreSQL database in the United States.
PostHog — Product and usage analytics inside the mobile app
Anonymized product-usage events — which screens you open and which in-app features you use — keyed to your SimplifyPocket user ID so we can understand how the app is used and improve it. We do not send your financial data, transaction contents, names, or email address as event properties, and we do not use it for advertising. Event data is processed in PostHog's United States region.
Vercel — Hosting for our marketing site, plus anonymous traffic analytics on simplifypocket.com
Standard web request data (pages visited, referrer, browser, country) for the marketing website only. In-app product analytics is handled by PostHog (described above), not Vercel.
We do not track you across other apps or websites
SimplifyPocket does not use advertising identifiers (such as Apple's IDFA or the Android Advertising ID), does not share your data with advertisers or data brokers, and does not track your activity across other companies' apps or websites. The product analytics described above (PostHog) measures only how you use SimplifyPocket itself — it is first-party and is never used to follow you across other apps or sites. We do not display third-party advertising inside the app. As a result, the iPhone app does not present an App Tracking Transparency prompt, and none is required. Android does not have an App Tracking Transparency mechanism; on Android we make the equivalent disclosures in the Google Play Data safety section, which reflect the same practices described in this policy.
Push notifications
If you grant permission, we send push notifications for the categories you enable: budget alerts, large transactions, low account balances, recurring transaction reminders, and important service messages. You can change or disable these at any time inside the app under More → Notification preferences, or completely in your device's Settings app under SimplifyPocket → Notifications.
Voice, receipt scanning, and AI
SimplifyPocket includes an optional voice feature that lets you add a transaction by speaking. You open it by tapping the plus button and choosing Voice. From there, you tap the microphone and speak. Your phone transcribes your speech to text using its built‑in speech recognition. On iPhone this happens entirely on‑device — the audio never leaves your phone. On Android, the app uses the Android system speech recognizer, which sends the audio to your device's speech service (such as Google) to transcribe it. Either way, SimplifyPocket itself never receives or stores your audio — only the resulting text is sent onward to be parsed.
The resulting text is sent to our backend, which forwards it to Anthropic, the large language model provider we use. Along with the transcript we send a short list of your existing categories and merchants so the model can match the transaction to entities you already have. Anthropic returns a structured draft (amount, date, type, suggested category, suggested merchant) that we show you on the confirmation screen. Nothing is saved until you tap Save.
SimplifyPocket also includes an optional receipt-scanning feature. When you choose Scan, you capture a receipt with your camera or pick one from your library, and that single image is sent to Anthropic's vision model to read the merchant, total, and date. As with voice, we also send a short list of your existing categories and merchants for matching, Anthropic returns a draft you review, and nothing is saved until you tap Save. The receipt image is used only to produce that draft — it is processed in real time and is not stored on our servers afterward. We never scan or read your photo library; only the one receipt you choose is ever sent.
Anthropic does not train on the data we send through their API and retains it briefly for abuse monitoring under their commercial API terms. We do not send Anthropic any persistent identifier, so they cannot link a request to a specific SimplifyPocket user.
Both features are optional. You can use SimplifyPocket entirely without them. Your phone will ask for microphone and speech‑recognition permission the first time you use voice, and for camera (or photo) permission the first time you scan a receipt. You can revoke any of these permissions at any time in your device's system settings — Settings → SimplifyPocket on iPhone, or Settings → Apps → SimplifyPocket on Android.
Data retention and deletion
Your data is retained for as long as your account is active. You can delete your account at any time from within the app under More → Delete account (on both iPhone and Android), or request deletion online from our Delete account page. When you do, your account is scheduled for permanent deletion and we automatically remove your personal information and financial data within 30 days. This grace period protects you from accidental deletions — during that window you can sign back in and tap Cancel deletion to restore everything.
Payment records may be retained by Apple or Google as required by their own legal and financial obligations. Anonymized diagnostic logs may be retained for up to 90 days for service reliability purposes.
Security
All data is encrypted in transit using TLS. Your data is stored in a managed PostgreSQL database with encryption at rest and access strictly limited to authenticated services. Sign-in is passwordless — handled by our authentication provider with emailed codes or one-tap Apple and Google sign-in — so there is no password for SimplifyPocket to store or expose.
SimplifyPocket never connects to your bank. No bank credentials, no OAuth tokens to financial institutions, no third-party data aggregators. Your financial data exists only because you typed it in.
Your rights
You have the right to access, correct, or delete the personal information we hold about you. You can manage most of this directly from within the app. To request a full data export or for any other privacy request, contact us at the address below.
California residents have additional rights under the California Consumer Privacy Act (CCPA), including the right to know what personal information is collected and the right to opt out of the sale of personal information. We do not sell personal information.
Children
SimplifyPocket is not directed to children under 13. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided us with personal information, please contact us at the address below and we will delete it promptly. Children old enough to use the app should do so with the involvement of a parent or guardian, particularly for any subscription purchase.
Changes to this policy
We may update this policy from time to time. If we make material changes, we will notify you by email or with a notice inside the app before the changes take effect. The effective date at the top of this page reflects the most recent version.
Contact
Questions about this policy or your data? Email us at [email protected].