Privacy Policy
Pocketfold is an offline-first travel planner for iOS and Android. This policy describes what data the app handles, what stays on your device, and the three situations in which data leaves it.
1. The short version
- Everything you enter — trips, flights, hotels, activities, visa notes, checklists, expenses, attachments, reminders — is stored only on your device. There is no account and no cloud copy. We cannot see it.
- Data leaves your device in exactly three cases: (a) you choose to scan a document, (b) the app refreshes currency exchange rates, (c) you buy or restore a subscription through Google Play or the App Store.
- We do not show ads, do not use advertising identifiers, and do not collect analytics or crash reports.
2. Data stored on your device
All trip content lives in a local database inside the app’s private storage. Attachments (tickets, bookings, photos) are copied into the app’s private folder. Reminders are local notifications scheduled on the device.
On Android the app opts out of Google’s automatic cloud backup, so this database is not uploaded to your Google account. On iOS the app’s data is included in device backups you configure yourself (iCloud or computer backups); those are governed by Apple’s terms.
You can export all of it as a single backup file (Settings → Export) and import it on another device. You can delete all of it at any time (Settings → Delete all data). Uninstalling the app deletes it too.
3. Document scanning (optional, Pocketfold PRO feature)
When you tap “Scan” and pick or photograph a ticket, boarding pass, booking confirmation, passport or similar document, the app sends that image or PDF to our recognition server so the fields can be filled in for you. Nothing is sent unless you choose to scan; the app asks for your consent before the first scan.
What happens on our side:
- The file is received by a server we operate on Google Cloud Run in the
europe-west1(Belgium) region. It is held in memory only for the duration of the request; we do not write it to disk or to any database. - The file is forwarded to the Google Gemini API (Google LLC / Google Ireland Ltd) for text recognition. Google acts as our processor. Under the Gemini API terms for paid services, Google does not use this content to train its models, but may retain prompts for a limited period for abuse detection. See Google’s Gemini API terms.
- The recognised fields are returned to your device and stored there, like anything else you type. We do not keep the file or the recognised text. Always check recognised data against the original document.
- Together with the file, the request carries an anonymous app identifier (see section 5) and an app token that identifies the Pocketfold app, not you.
What we retain about the request:
- Standard server logs (Google Cloud Logging): your IP address, request time, response code, request size and duration. No file contents, no recognised text. Retained for 30 days, then deleted automatically.
- Usage counters needed to enforce scan limits: a daily count of scans per IP address (to cap free usage and protect the service from abuse) and a per-period count of scans per anonymous app identifier or, for subscribers, per store purchase reference. Counters contain numbers and dates only — never document content.
Documents you scan may contain sensitive personal data (name, passport number, date of birth, nationality). We process them solely to fill in the form on your device and for no other purpose.
4. Currency exchange rates
When you open an expense screen the app may request the day’s exchange rates from a rate server we operate. The request contains no user data — it asks for the current rate table and nothing else. As with any web request, that server sees your IP address in its standard logs.
5. Subscriptions and purchases (RevenueCat)
Pocketfold PRO is sold through Google Play and the App Store. Payment is handled entirely by Google or Apple; we never see your card or bank details.
To know whether your subscription is active, the app uses RevenueCat (RevenueCat, Inc.), a subscription-management service. RevenueCat generates a random, anonymous app identifier on your device (it is not tied to your name, email or Google/Apple account) and receives from the store the purchase receipt: product bought, purchase and expiry dates, transaction identifiers. RevenueCat’s own policy: revenuecat.com/privacy.
The same anonymous identifier is sent with each scan request (section 3) so our server can look up your plan and count your scans. Our server queries RevenueCat with that identifier; the answer is cached for one minute.
6. Notifications
Reminders are scheduled locally on the device with the operating system’s notification service. No notification data leaves the device and we run no push server.
7. Permissions the app asks for
| Permission | Why |
|---|---|
| Notifications | Reminders for check-in, departure, visa deadlines and checklist items |
| Run after reboot (Android) | Re-arm scheduled reminders after the device restarts |
| Internet | Scanning, exchange rates, purchases — nothing else |
| Photos / files (via the system picker) | Attach a ticket or photo, or pick a document to scan. The app uses the system photo and file pickers and receives only the items you select; it has no access to your library |
| Camera (via the system camera) | Photograph a document to scan or attach. The app receives only the photo you take |
8. Third parties
| Party | What they receive | Role |
|---|---|---|
| Google Cloud (Cloud Run, Cloud Logging, Firestore) | Scanned files in transit, request logs, usage counters | Hosting provider / processor |
| Google Gemini API | Scanned files | Text-recognition processor |
| RevenueCat, Inc. | Anonymous app identifier, store receipts | Subscription-management processor |
| Google Play / Apple App Store | Your purchase | Merchant of record |
We do not sell personal data and do not share it with anyone for advertising or marketing.
9. Security
All network connections use TLS. Server-side counters and logs are stored in Google Cloud under access controls limited to the developer. The database on your device is protected by your device’s own security (passcode, encryption) — we recommend keeping it enabled, since the app can hold copies of travel documents.
10. Data retention summary
| Data | Where | How long |
|---|---|---|
| Trip content, attachments | Your device only | Until you delete it or uninstall |
| Scanned file | Our server memory; Google Gemini | Seconds (request duration); Google — per its abuse-monitoring retention |
| Server request logs | Google Cloud Logging | 30 days |
| Free-tier daily counters (per IP) | Firestore | Current day; older documents are purged |
| Scan counters (per anonymous id / purchase reference) | Firestore | Current billing period, plus purchase references needed to prevent double-crediting |
| Purchase records | RevenueCat, Google/Apple | Per their policies |
11. Your rights
You can view, export and delete all on-device data yourself from the app. To ask us to delete the server-side counters associated with your anonymous identifier, or for any other request about your data, email stan.kozlovskii@gmail.com and include the anonymous identifier shown in Settings → About.
12. Children
Pocketfold is not directed at children under 16 and we do not knowingly collect data from them.
13. Changes
We will post any changes on this page and update the effective date. Material changes to what leaves your device will also be announced in the app.
14. Contact
Stanislav Kozlovskii
stan.kozlovskii@gmail.com