1. Who we are
This policy describes how Pocket Money Buddy (“we”, “us”, “the app”) handles personal information when you use our iOS or Android app, create an account, or contact support.
Pocket Money Buddy is a personal finance app. You can track wallets, transactions, budgets, goals, debts, recurring payments, and reports. The app UI is available in English, Hindi, Gujarati, and Marathi. Optional features include cloud backup, receipt scanning, an in-app coach, ads on the free plan, and Premium subscriptions.
Questions: support@pocketmoneybuddy.com.
2. Information we collect
Account
- Email address, display name, and (if you use Google or Apple sign-in) the name or photo those services share with us.
- A unique user ID created by Firebase Authentication.
- Password is handled by Firebase Auth. We do not store your password in our own database.
Financial data you enter
- Wallets and balances, transactions, categories, budgets, savings goals, debts, in-app contacts, recurring rules, and subscriptions.
- This data is stored on your device in an encrypted local database. If you are signed in, it can also sync to our cloud (Firebase Firestore) as ciphertext so you can restore it or use it on another device. See Encryption.
Receipts and media
- If you scan a receipt, we upload the photo to Firebase Storage so our servers can read amount, merchant, and date.
- Camera and photo-library access stay on the device until you choose an image. We do not browse your camera roll.
AI coach
- Messages you send to Pocket Money Buddy Coach, plus the money context needed to answer (for example recent transactions or budgets).
Device and app
- App version, platform (iOS or Android), language preference (English, Hindi, Gujarati, or Marathi), and a random analytics ID stored on the device.
- PIN lock is stored in the device’s secure storage and is never sent to our servers. Face ID / fingerprint stay on the device.
- Local reminders (bills, budgets, debts) are scheduled on your device.
Purchases and ads
- Subscription status is managed by Apple, Google, and RevenueCat (entitlement, product, renewal — not your full card number).
- On the free plan, Google AdMob may collect advertising identifiers if you allow tracking (iOS App Tracking Transparency).
Support
- Whatever you send us by email, including your address and the contents of the message.
3. How we use information
- Provide the app: sign-in, sync, backup, reports, and Premium features.
- Process receipts and coach chats when you use those features.
- Show ads on the free plan and measure whether they load.
- Understand product usage when you opt in to analytics, so we can fix bugs and improve the app.
- Send transactional email such as password-reset links (via Firebase Auth).
- Respond to support requests, including data-export and account-deletion requests.
- Enforce our Terms of service and comply with law.
We do not sell your personal information. We do not use your transaction list to sell you third-party financial products.
4. Who we share it with
We use service providers that process data on our behalf:
- Google Firebase — authentication, cloud database, file storage, Remote Config, Cloud Functions, and (if you opt in) Analytics.
- Google Sign-In and Sign in with Apple — only if you choose those buttons.
- Google AdMob — ads on the free plan.
- RevenueCat — subscription status with the App Store and Google Play.
- OpenAI and Google Gemini — receipt reading and coach replies, only when you use those features. Receipt images and prompts are sent to those providers to generate a result.
- Exchange-rate providers — currency conversion rates, not your personal ledger.
We may also disclose information if required by law, to protect users, or as part of a merger or sale of the service (you would still be covered by this policy or a successor policy).
5. Analytics, tracking, and ads
Analytics are off until you opt in (first-run screen or Settings → Privacy). If you opt in, Firebase Analytics may record screens, button taps, app version, platform, and a random install ID. You can turn this off later in Settings → Privacy.
On iPhone, Apple may also show an App Tracking Transparency prompt. Allowing tracking lets advertising and measurement partners use the Identifier for Advertisers (IDFA). Denying it does not block the rest of the app.
Free accounts may see banner and interstitial ads from AdMob. Premium removes ads.
6. AI features
Receipt scan and coach chat send the content you provide (and limited related money data for the coach) to our cloud functions and then to AI providers. Do not upload images or messages you do not want processed that way. AI output can be wrong; always check amounts and advice before you save or act on them.
7. Storage, retention, and security
- On device: your ledger lives in an encrypted local database. App-lock PIN (a salted hash) and encryption keys stay in the phone’s secure storage — iOS Keychain and Android Keystore — not in ordinary app preferences.
- In the cloud: signed-in money records, receipt files, and coach messages are encrypted on the device before upload. Firebase (project region includes Asia Southeast) stores ciphertext. Access is limited to your account.
- Export: Settings → Backup lets you export your data as JSON (that file is plaintext on the device you export to — keep it safe).
- Local reset: Settings → Backup can wipe local rows you own. That does not by itself delete your cloud account.
- Retention: we keep account and synced data while your account is active. After a deletion request we remove or anonymise personal data we control, except where we must keep a record (for example billing or legal claims).
No method of transmission or storage is 100% secure. Use a strong password, keep the app lock on, and treat this as a personal money tracker — not a bank.
8. Encryption
Pocket Money Buddy encrypts sensitive money data on your device before it is written to the local database or sent to the cloud. Encryption keys are not stored on this website, in Shared Preferences / UserDefaults, or in our public HTML pages.
- Local database: the on-device ledger file is encrypted at rest. The key that opens it is generated on the phone and kept in iOS Keychain or Android Keystore. That local key is never uploaded.
- Cloud sync: wallets, transactions, budgets, goals, debts, notes, receipt images, and coach chat are encrypted with AES-256-GCM using a per-user data key. The raw key stays on your devices’ Keychain/Keystore. The cloud holds a wrapped copy so you can restore on a new phone after you sign in — not so staff can browse amounts in the Firebase console.
- App lock: your PIN is stored as a salted hash in Keychain/Keystore. Face ID and fingerprint never leave the device. We cannot read or reset your PIN.
- When we decrypt: the running app decrypts data in memory so you can use it. If you use receipt scan or the coach, our servers decrypt only in memory for that request, then store or return encrypted data again. Analytics (if you opt in), ads, and account email are not the encrypted ledger.
Someone with an unlocked phone and the open app can see your ledger — that is expected. A copy of the cloud database or a stolen receipt file without your keys shows encrypted data, not rupees and names.
9. Your rights and choices
Depending on where you live (including India under the Digital Personal Data Protection Act, and regions with GDPR-style laws), you may have the right to access, correct, export, restrict, or delete personal data, and to withdraw consent.
- Edit your display name in Settings → Profile.
- Turn analytics on or off in Settings → Privacy.
- Export data from Settings → Backup.
- Sign out from Settings.
- Request account and cloud-data deletion on the delete account page, or by emailing support@pocketmoneybuddy.com from the address on the account. We aim to complete deletion within 30 days. Apple and Google manage App Store / Play purchases separately; cancel subscriptions in those stores if needed.
10. International transfers
Our providers may process data in India, Singapore, the United States, and other countries. By using the app you understand that your information may be stored outside the country where you live, with safeguards those providers offer.
11. Children
Pocket Money Buddy is not directed at children under 13 (or the minimum age in your country). We do not knowingly collect personal information from children. If you believe a child has created an account, contact us and we will delete it.
12. Changes
We may update this policy. The “Last updated” date at the top will change. Continued use of the app after an update means you accept the revised policy. Material changes may also be noted in the app or by email if we have it.
13. Contact
Privacy and data requests: support@pocketmoneybuddy.com
More ways to reach us: Contact support.
This page is written to match how the current app works. It is not legal advice.