Privacy Policy
Last updated: 7 October 2026
1. Who is responsible for your data
The data controller for the personal data described here is:
- Business name: OLEKSII BOROVYK
- NIP: 6762677371
- Registered address: Chełmiec, ul. Magazynowa 49A/2, 33-395, Polska
- General contact: support@pickapocket.app
- Privacy contact: privacy@pickapocket.app
The GDPR applies to all of our processing, so the rights described below are the same for you wherever you live.
2. What we collect
What you give us: email address and first and last name, which are required to create an account; preferred language, which is optional; and your password. The password reaches our server over an encrypted connection only to be checked, and we store it only as a cryptographic hash.
What you create in the app: wallets and their descriptions, categories, budgets, savings goals, expenses, expense splits, payments between members of a shared wallet, recurring payment rules and templates. This is financial information about you, and we treat it accordingly. Other members of a wallet you share see your first and last name and what you add to it.
Wallets you create without an account, or keep only on your phone, never reach us: they are stored on that device. On an iPhone they are also included in the phone's backup to iCloud or to your computer, if you back the phone up. When you have an account, new wallets stay only on your phone until you turn on Global sync in your profile.
What is collected automatically: a device token and the app's language if you enable push notifications; audit records of changes to wallets, categories, expenses and payments between members, which show who made the change and when, the IP address and the device or browser used, and what changed, including names and amounts; technical crash and error reports, and performance measurements for a sample of requests to our server. Our server's logs record your account ID, the address requested and your app or browser details when a request is refused.
For signing in securely: for each device on which you confirmed a sign-in with a code from your email, we keep its identifier, stored only as a cryptographic hash, the device model and system version the app reports (for example “iPhone 15 Pro, iOS 27”), and when the device was added and last used. The one-time codes we email you are also stored only as cryptographic hashes. We also count failed sign-in attempts in a row.
When you change your email address: the new address, until you confirm it with a code we send there. We also tell your old address which new address was requested, and, if the new address already belongs to an account, we tell that address that someone tried to switch to it.
If you turn on the app lock: your PIN and, if you set one, your recovery phrase, stored only on your device and only as salted cryptographic hashes. We never receive them.
When a wallet's owner invites someone to it: the email address the owner typed, the wallet the invitation is for, who sent it, whether it allows editing and when access would end, and whether it was accepted, declined, withdrawn or left to expire. The invited person may not have an account yet. In that case this is all we hold about them, and it came from the owner who invited them, not from them.
When you write to us: your email address, your name if your email shows it, and whatever you put in the message.
On this website: nothing is stored on your device unless you choose a language or switch the theme. If you do, your browser saves that choice. It is not sent to us or to anyone else. You can delete it by clearing this site's data in your browser settings.
The site is hosted by Cloudflare. To deliver a page, Cloudflare receives what every browser sends with a request: your IP address, the address of the page and information about your browser. We have turned off request logging for the site, so we do not keep this data.
| Name | Set when | Purpose | Kept for | Consent required |
|---|---|---|---|---|
theme |
You press the theme switch | Remembers the theme you chose, light or dark | Until you clear this site's data in your browser | No |
language_selected |
You press EN, PL or UA | Remembers that you chose the language yourself, so the site no longer redirects you to the version in your browser's language | Until you clear this site's data in your browser | No |
There is no consent banner: the site uses no cookies, and these two entries are saved only at your request, which needs no consent (Article 399(3)(2) of the Polish Prawo komunikacji elektronicznej).
We do not collect: your bank credentials, card numbers, or access to your bank accounts. The app never connects to your account; from banks it only takes public exchange rates (see section 4).
3. Why we use it, and on what legal basis
- To provide the app: creating and running your account, storing your records, synchronising devices and shared wallets. Basis: performance of our contract with you (Art. 6(1)(b) GDPR).
- To keep the service secure: detecting and investigating unauthorised access and abuse, recognising the devices you sign in on, sending one-time codes by email, and diagnosing errors. Basis: our legitimate interest in a secure, working service (Art. 6(1)(f) GDPR).
- To deliver invitations to shared wallets: one email to the address the wallet's owner typed, and a push to that account's devices if the address belongs to an account. Both name the owner by first name and name the wallet. The email carries no link: the person decides in the app whether to join, and sees nothing else in the wallet until they accept. An owner can send at most 20 invitations a day. Basis: for the owner who invites, our contract with them (Art. 6(1)(b) GDPR); for the invited person, our legitimate interest in letting owners share a wallet with someone who then chooses whether to join (Art. 6(1)(f) GDPR).
- To answer your messages to support@pickapocket.app and privacy@pickapocket.app. Basis: our legitimate interest in answering the people who contact us (Art. 6(1)(f) GDPR). When you ask us to act on your rights under the GDPR, handling that request is our legal obligation (Art. 6(1)(c) GDPR).
- To show you this website. Basis: our legitimate interest in delivering the pages you open (Art. 6(1)(f) GDPR).
- Push notifications: basis: your consent (Art. 6(1)(a) GDPR), which you can withdraw at any time.
4. Who else processes your data
We use a small number of service providers who process data on our behalf and under contract. We do not sell your data, and we do not share it for advertising.
- Railway Corporation (USA): hosting of our server and database. The server and the database are in the EU (Amsterdam); Railway may process data in the USA.
- Mailjet (Sinch Email, part of Sinch AB (publ), Sweden; the contracting company is the one set by Mailjet's Terms of Service): transactional email: one-time codes (account activation, sign-in, password reset, email change, account deletion), security notices (a registration attempt with your address, a request to change your address, an attempt to switch another account to your address, codes slowed down after many requests), invitations to shared wallets and the welcome email. We have turned off open and click tracking. Emails are stored in the EU; Mailjet's support may access them from the USA.
- Google LLC (USA, Firebase Cloud Messaging): delivery of push notifications. On an iPhone, Google passes them to Apple Inc. (USA, Apple Push Notification service), which delivers them. Both may process data outside the EEA (section 5).
- Functional Software, Inc. (Sentry, USA): crash and error reports from the app and the server, and performance measurements for 10% of requests. Reports are stored in the EU (Frankfurt); Sentry keeps some related data, such as metadata, in the USA.
- Zoho Corporation B.V. (Utrecht, the Netherlands): the mailboxes support@pickapocket.app and privacy@pickapocket.app. Servers in the EU (Amsterdam and Dublin).
- Cloudflare, Inc. (San Francisco, USA): DNS for pickapocket.app and hosting of this website. Runs on a global network, so it may process data outside the EEA.
- Public exchange-rate services (Monobank, NBU): the app requests rates from your device, which makes your IP address visible to them, and our server requests them too. No account data is sent.
We may also disclose data where we are legally required to, for example in response to a lawful order from a competent authority.
5. Where your data is stored
Our server, our database, stored emails and crash reports are located in the European Union. Some providers may still process data outside the European Economic Area, mainly in the United States:
- Railway, which hosts the server and the database, may process any data the app sends to us in the USA.
- Sentry keeps some data about crash reports, such as metadata, in the USA.
- Mailjet's support may access emails from the USA.
- Google, and on an iPhone also Apple, may deliver push notifications through servers outside the EEA. Only the device token and the notification text are involved. The text names the wallet; a notification about an invitation or a new member also names the person who invited you or who joined your wallet. It never contains amounts or your financial records.
- Cloudflare may handle a request when you open this website anywhere on its global network. Only the request data described in section 2 is involved, and never anything from the app.
- Zoho, when you write to us. The mailboxes are stored in the EU, but Zoho's company in India works for Zoho Corporation B.V. as a sub-processor, so the messages may be accessed from there. This is covered by an agreement between Zoho companies based on the Standard Contractual Clauses.
Transfers to Railway are made on the basis of the standard contractual clauses adopted by the European Commission (Implementing Decision (EU) 2021/914), which form part of the data processing agreement with Railway. As at the date of this version, that agreement is being signed; until it is signed, these safeguards do not apply. Transfers to Sentry, Mailjet's support company Mailgun Technologies, Google and Cloudflare in the United States rely on their certification under the EU-U.S. Data Privacy Framework, and on the Standard Contractual Clauses if that certification lapses. Apple delivers notifications to iPhones under the terms Apple sets for app developers.
A copy of your data is also stored on your own device, in an encrypted local database, so that the app works offline.
6. How long we keep it
- Account and financial records: until you delete your account. One exception: when another member split an expense with you in their wallet, the amount of your share stays in that expense after you delete your account, without your name, email or account ID, so that the expense keeps its full amount. It no longer counts in anyone's balance. Payments between you and other members of a shared wallet stay in the same way, without anything that identifies you.
- Invitations to shared wallets: an invitation can be answered for 7 days, or until the access it offers would end if that is sooner. Once it is accepted, declined, withdrawn or has expired, it is deleted 30 days later. Deleting your account deletes the invitations you sent and those addressed to your email.
- Audit records (described in section 2): up to 12 months, then deleted, even for an expense, category or wallet you deleted sooner. We keep them after account deletion because they are what allows us to investigate unauthorised access and abuse. When you delete your account, we erase the names and amounts from the records of your own actions and of the wallets you own. Records of what other members did in their own wallets, such as a payment between you and them, keep your account ID and the amount until they expire.
- Our server's logs: kept by Railway for 7 days.
- Account deletion requests and their audit trail: a request holds the account's email address, the IP address and device it was made from, and the reason, if you gave one. A request whose code is never entered is cancelled after 24 hours; completed and cancelled requests are kept for 30 days, so that we can show what happened to them if needed, and then deleted. If a deletion fails partway, we keep the request until the account is fully deleted.
- Push tokens: until you sign out, remove the device from the device list, delete your account, or Google tells us the token no longer works.
- Your devices: until you remove the device from the device list in the app, reset your password (which removes all devices), or delete your account. Simply logging out does not remove a device.
- One-time codes: valid for 10 minutes. The stored hash stays until the next code of the same kind replaces it, you change your email address, or you delete your account.
- Accounts whose email address was never confirmed: deleted 24 hours after registration.
- Wallets only on your device: wallets you create without an account, or keep only on your phone, are stored on that device and, on an iPhone, in its backups. We never receive them. When you move a wallet from the cloud to your phone, we delete it from our servers.
- Your messages to us: 12 months after the last message in the conversation, then deleted.
- Visits to this website: we keep no request logs.
7. Your rights
You have the right to access, correct, delete, port and restrict your data, to object to processing based on our legitimate interest, and to withdraw consent at any time.
You can delete your account directly in the app, and you can export a wallet to a CSV or PDF file from your profile. For a complete copy of everything we hold, email privacy@pickapocket.app and we will provide it within one month.
Full details are on our GDPR Rights page, including how to lodge a complaint.
8. Children
Pick a pocket is not intended for children under 16, and we do not knowingly collect their data. If you believe a child has created an account, write to privacy@pickapocket.app and we will delete it.
9. How we protect your data
Traffic between the app and our servers is encrypted. Passwords are stored only as cryptographic hashes. The local database on your device is encrypted. Access to production data is limited to what is necessary to operate the service.
No system is perfectly secure. If a breach occurs that is likely to put your rights at risk, we will notify the supervisory authority and, where required, you.
10. Changes and contact
If we make material changes to this policy, we will email the address of your account and publish the new version on this page with a new date at the top. If you use the app without an account, this page is where you will find them. For any privacy question, write to privacy@pickapocket.app.