Who is responsible
Pocket Pivot is currently operated by Alberto Becerra as an independent developer. Alberto is responsible for Pocket Pivot’s handling of the personal data described here. Contact alberto@pocketpivot.app for privacy questions or requests.
What Pocket Pivot does
Pocket Pivot turns read-only spending history into calendar heatmaps, factual local views, and widgets. Sample data is synthetic and does not require a Pocket Pivot account or bank connection.
Direct bunq bank data
The first release supports a direct connection for bunq Pro and Elite customers who choose to create a personal API key in the bunq app. Pocket Pivot uses that key from the iPhone to request the accounts, balances, and transaction history needed for its views. The connection is read-only in Pocket Pivot: the app cannot create payments or move money. No Pocket Pivot server receives the personal API key or performs background bank synchronization. Other banks are not available in this release.
On-device storage
Imported transaction history is stored locally in app-managed files protected by iOS and excluded from backups. The personal bunq API key is stored separately in iOS Keychain. Widgets receive aggregate daily totals, not transaction descriptions, counterparties, or bank credentials.
Notifications and background refresh
Notifications and background refresh are separate, optional controls. Daily Brief and Weekly Insights are prepared and scheduled on your iPhone. Exact totals are off by default and, if you separately enable them, are rendered on the device rather than sent to a notification service. Server Connection Alerts are not available in build 17: new selection, enrollment, and delivery fail closed. Authenticated deletion and scheduled cleanup may still remove notification-enrollment or delivery records retained from an earlier build.
When you enable background refresh, iOS may occasionally let Pocket Pivot request updated bunq data directly from your iPhone and stage it for the next foreground merge. This work is best effort: iOS may defer or skip it, and a scheduled task does not guarantee current transactions. Manual refresh remains the reliable recovery path.
Legacy provider data
Enable Banking and Plaid are not active connection options in Pocket Pivot 1.0. An existing installation may retain local credentials or tokens, connection and account identifiers, account details, historical transactions, counterparty details, and corresponding encrypted server records from an earlier version so that data is not silently destroyed during upgrade. The 1.0 release controls block active legacy-provider connection, discovery, callback, transaction, synchronization, and notification-enrollment routes in beta and production, and skip active scheduled refresh. Plaid webhook deliveries may be acknowledged without reading or storing their body so the provider does not retry them. Scheduled legacy-provider work is limited to deletion and revocation retries, tombstone enforcement, and bounded retention cleanup.
Provider authorization may remain until it expires or is revoked. Base connection and pending-revocation records remain until successful disconnect or deletion. Retained transaction snapshots and most Enable Banking connection records expire no later than 90 days after their last write; Plaid webhook receipts expire after 30 days, and successful-deletion tombstones are retained for up to 90 days. You can use the app’s deletion control to request revocation and removal sooner. Release source and configuration are audited separately from the versions running on hosted services.
Analytics
Pocket Pivot does not track you across other companies’ apps or websites. Website analytics are disabled for 1.0. In the iPhone app, product analytics are off until you choose to enable them. When enabled, a persistent random installation identifier and minimized events may describe onboarding, paywall, trial or purchase state, connection success, retention, refresh outcomes, technical error categories, network type, and a banded refresh duration through PostHog’s EU service. They exclude transaction content, balances, merchants, financial categories, account names, IBANs, bank credentials, free text, and bank-level behavioural profiles. Turning analytics off prevents future capture immediately and starts verified deletion of the local analytics identifier. If iOS Keychain is temporarily unavailable, analytics remains off and Settings shows deletion as pending until a retry succeeds. Opt-out does not automatically erase events already held by the analytics service. Hosted retention, deletion, and IP-capture settings require separate operational verification. Pocket Pivot does not sell personal information or bank data.
Pocket Pivot Plus subscriptions
Pocket Pivot Plus is an auto-renewable subscription purchased through Apple. Apple processes payment details and determines localized price and introductory-offer eligibility. Pocket Pivot receives StoreKit product, entitlement, transaction-state, and eligibility information to unlock features, restore purchases, and handle offline access, grace period, billing retry, expiration, refund, or revocation. Family Sharing is off for version 1.0. Purchase-history analytics is sent only if you separately opt into product analytics.
Without Plus, you can use synthetic sample data and view personal data already cached on your device. Plus unlocks live bunq connection and network refresh, best-effort background refresh, the widget, and local Daily Brief and Weekly Insights. Server Connection Alerts are not available in build 17. Ending Plus does not delete cached financial data.
Interest forms
The unsupported-bank form collects your email address, bank, and country so we can measure demand and send relevant availability updates. The separate partner form collects your name, email address, organisation, and an optional note so Alberto can respond about partnership or backing interest. Submitting either form is your affirmative request for that specific follow-up; you may withdraw it at any time. When a form submission is accepted, its record is stored with Cloudflare and expires automatically 12 months after the latest submission unless you ask us to delete it sooner. A generic notification may be sent through Cloudflare Email Service to Pocket Pivot’s Outlook inbox, but it excludes the submitted fields and email address. The two intents remain separately labelled and are not sold or added to unrelated marketing lists. This policy does not by itself prove that the corresponding website route has been deployed.
Why data is used
Bank data is processed to provide the direct connection and spending views you request, or to contain, delete, and complete the bounded cleanup of retained legacy-provider records. Local notification categories and background refresh are processed only after you enable each separate control. Historical server-notification records are processed only for authenticated deletion and bounded cleanup. Optional analytics is processed only after your consent, which you can withdraw in Settings. Interest-form details and in-app bug reports are processed because you explicitly request the stated follow-up or support. Minimal security logs may be processed where needed to protect and operate the service.
Processing locations
On-device bank data stays on your iPhone except for direct requests your iPhone makes to bunq. Retained legacy-provider records, residual server-notification records awaiting deletion or bounded cleanup, and accepted interest records use Cloudflare infrastructure. Opted-in analytics uses Cloudflare and PostHog’s EU service. Interest notifications, in-app bug reports, and direct support messages pass through Cloudflare Email Service or the relevant inbound email provider and are delivered to an Outlook mailbox. These providers may process data outside the European Economic Area, so Pocket Pivot does not promise EU-only processing except where a service is expressly identified as EU-hosted. Contact us if you need more information about relevant providers and transfer safeguards.
Support and bug reports
If you email support, the message and address are handled through the email providers. The in-app bug-report sender is a TestFlight-only collection surface: Debug builds display it for testing but cannot send, and the App Store release hides it. In TestFlight, pressing Send submits your description plus the app version, build number, release channel, device model, and iOS version through Cloudflare Email Service to Pocket Pivot’s Outlook inbox. The bounded report does not send screenshots, attachments, recent app logs, a persistent installation identifier, raw app errors, connection counts, or transaction counts. Do not include bank passwords, API keys, account details, IBANs, or transaction details in free text.
Repository source does not automatically expire support or bug-report email copies, and the current mailbox retention setting has not yet been verified. This is an operational launch gate. You may request earlier deletion, subject to identity verification and any applicable legal obligation.
Deletion and disconnect
Settings can delete local transaction history, filters, analytics identity, notification schedules and enrollment, widget data, and locally stored connection material from the device. Deleting the personal API key in the bunq app separately revokes it at bunq. Deleting dormant-provider data attempts remote revocation and server deletion before local credentials are removed; if a remote step fails, the app keeps a visible pending state so you can retry. For interest-form, support-message, bug-report, historical analytics, or residual notification-record deletion, email us with enough information to locate the record. We may need to verify your request.
Your privacy choices
Depending on the law that applies to you, you may ask to access, correct, delete, restrict, or receive a copy of your personal data, object to certain processing, or withdraw consent without affecting earlier lawful use. You may also complain to your local data-protection authority. We may need to verify that a request comes from the person whose data it concerns.
Independent product
Pocket Pivot is independent and is not affiliated with, endorsed by, or sponsored by bunq. “bunq” is used only to identify the compatible banking service.
Financial advice
Pocket Pivot is a spending-awareness tool. Pattern insights and examples are not financial, investment, tax, or legal advice.
Contact
For privacy, deletion, or support questions, email alberto@pocketpivot.app.