Privacy Policy
Last updated: April 13, 2026
Important: This is a template for a software product. It is not legal advice. Have a qualified attorney review and adapt it for your jurisdiction and business before you rely on it.
Who we are
PocketFlow (“we,” “us”) provides personal finance tools that may connect to your financial institutions through third parties such as Plaid Inc. Contact: use the support channel published on our website or product.
Information we collect
- Account data: email address, display name, authentication secrets (passwords are hashed; we do not store plaintext passwords), and security settings such as MFA enrollment.
- Financial data: when you link a bank, we may receive account metadata, balances, and transactions as made available by Plaid and your institution. Access tokens are encrypted at rest.
- Technical data: IP address, device/browser type, and timestamps in server logs for security and reliability.
How we use information
We use data to provide and improve the service, authenticate you, prevent fraud and abuse, and comply with law.
AI feature processing (if enabled)
If AI features are enabled, we may send your prompt text and selected budgeting context (for example totals and recurring-spend patterns) to our AI model provider to generate responses. Do not submit sensitive information that is unnecessary for budgeting assistance. AI outputs may be inaccurate and should be verified.
Sharing
We share data with service providers who help us run the product (e.g., hosting, database, Plaid for bank linking) under contracts that limit their use. We may disclose information if required by law or to protect rights and safety.
Retention
We retain information as long as your account is active and as needed for legal, tax, or security purposes. You may request deletion of your account subject to applicable exceptions.
Your rights
Depending on where you live, you may have rights to access, correct, delete, or export personal data, or to object to certain processing. Where the product provides them, you can download a data export or request account deletion from in-app settings. You may also contact us to exercise these rights or lodge a complaint with a data protection authority where applicable.
Children
PocketFlow is not directed to children under 13 (or the minimum age in your region), and we do not knowingly collect their data.
International transfers
If you access the service from outside the country where servers are located, your data may be transferred and processed across borders with appropriate safeguards where required.
Changes
We may update this policy and will post the revised version with a new “Last updated” date.