Privacy Policy

1. Introduction

This Privacy Policy applies to the Pocket Pals app (the "Application") for iOS and Android devices that was created by Hello and Build (the "Service Provider") as a Freemium service with optional paid Pro tier features.

This policy describes how we collect, use, and protect your information when you download and use the Application.

2. Information Collection and Use

2.1 Information You Provide
The Application collects information that you voluntarily provide, including:

Account Information: Email address, name, password (for email/password authentication)

Profile Information: Avatar selection (emoji or photo), name display

Trip Data: Trip names, descriptions, currencies, budgets, participant information, and expense details you enter

Participant Information: Email addresses or phone numbers of participants you add to shared trips

Photos and Media: Images you upload for expense receipts, trip photos, or avatar photos (stored locally and on Supabase)

Payment Information: Processed through RevenueCat for in-app subscription purchases (not directly stored by the Service Provider)

2.2 Information Automatically Collected
The Application automatically collects:

Device Information: Device model, operating system version, app version, device identifier

Usage Analytics: Features used, screens visited, session duration, crash reports (via Firebase Crashlytics)

Authentication Data: Login timestamps, authentication method (Google, Apple, or email)

Camera & Photo Library Access: Only when you explicitly choose to upload a photo or take a receipt photo. The Application requests these permissions and only accesses what you select.

2.3 What We Do NOT Collect
The Application does NOT:

Collect precise geolocation or GPS data

Use Artificial Intelligence (AI) to process your personal data

Track your location history

Access your contacts without your explicit action

Share your data with third parties for marketing purposes

3. How We Use Your Information

The Service Provider uses the collected information for:

Core Functionality: Creating trips, managing expenses, splitting costs, and settling balances with participants

Authentication & Security: Verifying your identity, managing sessions, and preventing unauthorized access (using Supabase Row-Level Security)

Communication: Sending trip invitations, expense notifications, payment reminders, and account updates

Service Improvement: Analyzing crashes and errors to improve app stability and performance

Subscription Management: Processing subscription purchases via RevenueCat and managing your Pro tier access

Legal Compliance: Responding to legal requests and enforcing our terms

The Service Provider does not use marketing emails unless you explicitly opt in. Notification preferences can be managed in the app settings.

4. Data Storage, Synchronization, and Security

4.1 Hybrid Data Storage and Sync Architecture
The Application uses a hybrid sync model combining local and cloud storage for reliability and offline access:

Local Storage (On Your Device):

AsyncStorage: Trip names, expenses, and participant info cached locally for offline access

Offline Support: You can view and add expenses without internet connection

Automatic Sync: Changes sync to cloud when connection is restored

Cache Validity: Local data updated with server data on each sync using timestamp comparison

Cloud Storage (Supabase - PostgreSQL):

Primary Database: All trip, expense, and participant data stored on secure Supabase servers

Encryption: Database encryption at rest; HTTPS/TLS encryption in transit

Backup: Automated backups for disaster recovery and data protection

Global CDN: Supabase uses geographically distributed servers for reliability

Real-Time Synchronization:

Subscriptions: WebSocket connections sync changes in real-time when online

Conflict Resolution: Newer timestamps take precedence if data conflicts during offline-to-online sync

Push Notifications: Real-time notifications for new expenses, settlements, and trip updates

Sync Delays: Sync may be delayed by network conditions or Supabase availability

4.2 Row-Level Security (RLS) and Access Control
The Service Provider implements PostgreSQL Row-Level Security policies to protect your data:

RLS Policies Enforce:

You can only view and edit your own trips and expenses

Participants you invite can only view shared trip data

Free users cannot modify data on shared trips (read-only access)

Pro users can invite both Free and Pro users to shared trips

Deleted trips (soft-deleted with deleted_at timestamp) are excluded from participant access

RPC (Remote Procedure Calls) Validate:

Tier verification before accepting trip invitations (free users: unlimited shared trips allowed)

Expense rate limiting (free users: max 5 per owned trip)

Settlement calculations and payment status updates

Participant addition with email invitation verification

4.3 Payment Information and RevenueCat

No Direct Storage: The Service Provider DOES NOT store credit card information

Processed by RevenueCat: All in-app purchase and subscription payments processed through RevenueCat

PCI Compliance: RevenueCat handles PCI-DSS compliance for payment security

Subscription Status: Only subscription status (active/cancelled/expired) is stored locally; payment details never stored

4.4 Trip Data Ownership and Sharing

Your Ownership:

You own all data for trips you create (full control)

Trip data includes expense records, participant information, and settlement history

You can delete trips anytime (soft-delete after 30 days permanent removal)

Shared Trip Access:

Participants you invite can view ALL trip details, expenses, and settlement amounts

Free users invited to Pro trips have read-only access (cannot add expenses)

Pro users invited to shared trips have full read-write access (can add expenses, mark payments)

Participant data (names, emails) is shared with all other participants on that trip

4.5 Tier-Based Data Access

Free Tier Access:

Can create 1 owned trip with full control

Can view and manage own expenses on owned trips

Can view (read-only) unlimited shared trips owned by Pro users

Cannot add expenses to shared Pro trips

Cannot archive trips (Pro feature only)

Pro Tier Access:

Can create unlimited owned trips with full control

Can add unlimited expenses to own trips

Can add unlimited email-invited participants to own trips

Can add expenses to and manage shared Pro trips

Can mark settlements as "Paid" for all trip participants

Can archive trips (retain up to 10 for 1 year)

5. Third-Party Services

The Application uses the following third-party services:

5.1 Backend & Authentication

Supabase (supabase.com): Database, real-time sync, and authentication

Supabase Privacy Policy: <https://supabase.com/privacy>

Data stored in their secure PostgreSQL servers

5.2 Authentication Providers

Google Sign-In (Google Inc.): OAuth authentication

Google Privacy Policy: <https://www.google.com/policies/privacy/>

Apple Sign-In (Apple Inc.): OAuth authentication

Apple Privacy Policy: <https://www.apple.com/privacy/>

5.3 In-App Purchases & Subscriptions

RevenueCat (revenuecat.com): Manages Pro tier subscriptions and in-app purchases

RevenueCat Privacy Policy: <https://www.revenuecat.com/privacy>

Handles payment processing; you never provide credit card info directly to the Service Provider

5.4 Crash Reporting

Firebase Crashlytics (Google Inc.): Collects anonymized crash reports to improve app stability

Firebase Privacy Policy: <https://firebase.google.com/support/privacy>

Crash reports do not contain personal data or trip information

5.5 App Distribution

Google Play Store (Google Inc.) or Apple App Store (Apple Inc.): Distribution and download management

Google Play Privacy Policy: <https://www.google.com/policies/privacy/>

Apple App Store Privacy Policy: <https://www.apple.com/privacy/>

6. User Permissions

The Application requests the following device permissions, which you can grant or deny:

Camera: Capture receipt photos or trip images (Only when you choose to take a photo)

Photo Library: Select photos from your device gallery (Only when you choose to upload a photo)

Microphone: Record video for trip documentation (Only when you choose to record video)

Notifications: Send trip invites, expense alerts, and reminders (Based on your notification preferences)

Important: You can modify these permissions in your device settings. The Application will not function properly if you deny access to Camera and Photo Library if you want to add photos to expenses.

7. Data Retention and Deletion

7.1 How Long We Keep Your Data

Active Account: Data is retained as long as your account is active and you use the app

Inactive Account: Data is retained for 12 months after your last login before being considered for deletion

After Account Deletion: All personal data, trips, and expenses are permanently deleted from the Service Provider's servers within 30 days of your request

7.2 How to Delete Your Account
To delete your account and all associated data:

Go to Profile -> Account Settings

Tap "Delete Account" at the bottom

Confirm the deletion

Alternatively, contact the Service Provider at [email protected] with "Delete My Account" in the subject line

Your trip data will be permanently removed from the Service Provider's servers, although participants may have downloaded copies of shared trip information.

8. Children's Privacy

The Application is not intended for users under 13 years of age. The Service Provider:

Does not knowingly collect personal information from children under 13

Will immediately delete any data discovered to be from a child under 13

Will not market or solicit to users under 13

If you are a parent or guardian and believe your child has provided personal information, please contact the Service Provider immediately at [email protected].

9. Your Privacy Rights

Depending on your location, you may have the right to:

Access: Request a copy of the personal data the Service Provider holds about you

Correction: Request corrections to inaccurate information

Deletion: Request deletion of your personal data (right to be forgotten)

Portability: Receive your data in a portable format

Opt-Out: Disable notifications and marketing communications

To exercise these rights, contact [email protected] with your request. The Service Provider will respond within 30 days.

10. Third-Party Sharing

The Service Provider does not sell, rent, or share your personal data with third parties for marketing purposes.

The Service Provider may share your information only in these circumstances:

With Trip Participants: Your name, avatar, and participation status in shared trips

Legal Requirement: When required by law, court order, or government request

Service Providers: With trusted partners (Supabase, RevenueCat, Firebase) who handle data on our behalf

Business Transfer: In the event of merger, acquisition, or sale of assets (with notice)

11. Your Consent

By downloading, installing, or using the Application, you are consenting to the collection and use of your information as described in this Privacy Policy.

12. Changes to This Privacy Policy

The Service Provider may update this Privacy Policy at any time. Changes will be effective immediately upon posting the updated policy in the Application or on our website.

You are advised to review this Privacy Policy regularly for any changes.

Continued use of the Application after any changes constitutes your acceptance of the new Privacy Policy.

13. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our privacy practices:

Email: [email protected]
Subject Line: Privacy Policy Inquiry
Response Time: Within 30 days

Compliance

This Privacy Policy complies with:

Apple App Store privacy requirements

Google Play Store privacy requirements

GDPR (General Data Protection Regulation) for EU residents

CCPA (California Consumer Privacy Act) for California residents

Last Updated: June 25, 2026