PocketSense Privacy Policy
Last updated: 14 September 2026
PocketSense ("the app") is a personal-finance budgeting app for Android. It is published and operated by Cloudastra Technologies, Noida, India, who are responsible for the data described in this policy.
This policy explains exactly what the app collects, why, and what we do not do.
The short version
You do not need an account to use PocketSense. Without one, your financial data never leaves your device.
Every transaction, category, budget, and wallet balance is stored in a private database on your phone. If you never sign in, the only information that ever leaves your device is a crash report when something goes wrong — which carries no name, email, or financial data, but is not strictly anonymous, because it includes a random installation identifier.
If you do sign in, your financial data is backed up to your account so that reinstalling the app or moving to a new phone does not lose it. That backup is on by default and can be turned off at any time in Settings, in which case nothing about your money leaves the device.
Your backup is never sold, shared with anyone, or used for advertising or profiling. We access it only where strictly necessary to operate or repair the service, or where the law requires it.
What we collect
1. Nothing, if you don't sign in
PocketSense works fully without an account. In that mode we collect no personal information at all — no email, no name, no identifier you provided. Only the crash diagnostics in section 3 apply.
2. Account information — only if you choose to sign in
Signing in is optional. It identifies your account so your data can be restored when you reinstall the app or move to a new phone. It is handled by Google Firebase Authentication.
| Data | Why | Retention |
|---|---|---|
| Email address | To create and sign in to your account | Until you delete your account |
| Display name | To greet you in the app | Until you delete your account |
| Password | Stored only as a salted hash by Firebase; we never see it | Until you delete your account |
| Google account ID (if you use Google Sign-In) | To identify your account | Until you delete your account |
We do not sell, rent, or share this with anyone. It is not used for advertising or marketing, and we send no marketing email.
Signing in also enables backup of your financial data. See section 5.
3. Crash diagnostics — always, with or without an account
Handled by Firebase Crashlytics, and used solely to find and fix faults. This is the one thing that leaves your device even if you never sign in. Collected only when the app crashes or hits a serious error:
- The error and stack trace
- Device model, operating system version, and app version
- A random installation identifier
Crash reports contain no transaction data, amounts, categories, or notes, and carry no name or email. One report includes the file name of a database that could not be read — the name only, never its contents.
They are not linked to your account: we do not attach your user ID to them, so a crash report cannot be traced back to you. The random installation identifier means they are pseudonymous rather than truly anonymous.
Retention: up to 90 days.
4. App-usage detection — stays on your device
If you turn on the auto-prompt watcher and grant usage access, the app observes when you open only the payments apps you have chosen to watch (for example Google Pay, PhonePe, Paytm, BHIM). It prompts a few seconds after one is opened, while you are likely still paying.
- What is read: the package name of a watched app, and the times you opened and left it.
- What it is used for: one purpose only — showing you a notification asking whether you want to record an expense.
- Where it goes: nowhere. It is processed on your device, held only in your device's local storage, and is never transmitted, shared, or used for advertising or profiling.
- Control: turn the watcher off at any time in the app, choose which apps it watches in Settings, or revoke usage access in Android settings.
5. Your financial data — on your device, and backed up if you sign in
Transactions, amounts, categories, budgets, notes, and your wallet balance are always stored in a private database on your phone, which is what the app reads.
If you are signed in and backup is on, a copy is also stored in your private area of Google Cloud Firestore, so that reinstalling or changing phone restores your data instead of losing it.
| Where your money data lives | |
|---|---|
| No account | On your device only |
| Signed in, backup on (the default) | On your device, and in your account |
| Signed in, backup off | On your device only |
- What is backed up: transactions and their amounts, dates, notes and categories; your budgets; your wallet balance and monthly income.
- Where it is stored: Google Cloud Firestore, in the
asia-south2(Delhi, India) region. - Who can read it: you, through your signed-in account. Security rules deny every other account access to it. As the operator of the service we retain technical access, which we use only to keep the service working or when compelled by law — never for advertising, analytics or profiling, and we never sell or share it.
- Retention: until you delete it, or delete your account.
- Control: Settings → Back up to my account. Turning it off stops any further upload.
If you are not signed in, uninstalling the app permanently erases this data, because there is no copy anywhere else. Use Settings → Export to CSV to keep your own copy either way.
What we do not do
- We do not collect product analytics or track your behaviour in the app. The crash diagnostics in section 3 are the only exception, and exist solely to fix faults — Play's Data safety form classifies them under "Analytics", which is why they appear there.
- We do not use advertising, ad identifiers, or ad networks.
- We do not sell or share personal information with third parties.
- We do not collect your location, contacts, photos, files, SMS, or call logs.
- We do not read the contents of any other app, or any payment details.
- We do not require an account to use the app.
Permissions
| Permission | Why it is needed |
|---|---|
PACKAGE_USAGE_STATS |
Detect when you open a watched payments app, to prompt you. Optional — the app works without it. |
POST_NOTIFICATIONS |
Show expense prompts and budget alerts |
FOREGROUND_SERVICE (special use) |
Keep the watcher running reliably |
INTERNET |
Sign-in, backing up your data to your account, and crash reporting |
Your rights and choices
Use the app without giving us anything. Skip sign-in entirely; everything works.
Delete your account and all data. In the app: Settings → Account → Delete account. This erases your backed-up data from our cloud storage, removes your Firebase account, and deletes the local database and preferences on the device. It cannot be undone — export to CSV first if you want a copy.
You can also request deletion without installing the app. See Delete your account or email contact@cloudastra.in.
Export your data. Settings → Export to CSV produces a file containing every transaction, which you can save or share anywhere.
Withdraw consent. Turn off the watcher in the app, or revoke usage access in Android Settings, at any time.
Depending on where you live you may have additional rights (access, correction, portability, erasure). Contact us and we will respond within 7 days.
Children
PocketSense is intended for adults and is listed on Google Play for an audience of 18 and over. It is not directed at children, and we do not knowingly collect personal information from anyone under 18. If you believe a child has provided us with personal information, write to us and we will delete it.
How your data is protected
- Everything sent between the app and Google's services travels over TLS.
- Your backup is held in your own area of the database, and security rules deny every other account access to it.
- Your password is never stored by us in any form. Firebase holds only a salted hash of it.
- No account is required at all, so the safest option — giving us nothing — is always available to you.
No system is perfectly secure, and we do not claim otherwise.
Third-party services
- Google Firebase Authentication — privacy information (only if you sign in)
- Google Cloud Firestore — privacy information (only if you sign in and backup is on; stores your data in India)
- Google Firebase Crashlytics — privacy information
Your backup is stored in India (asia-south2, Delhi). Sign-in and crash
diagnostics are handled by Google's global infrastructure, so that data may be
processed on servers outside India, including in the United States, under
Google's own safeguards for international transfers.
Changes
If this policy changes materially we will update the date above and note the change in the app's release notes.
Contact
PocketSense is published and operated by:
Cloudastra Technologies Noida, Uttar Pradesh, India contact@cloudastra.in
Write to that address for any question about this policy, to exercise the rights above, or to raise a privacy concern. We respond within 7 days.