← Pocketmate
Privacy Policy

Real privacy,
not promises.

Last updated · September 2026

Introduction

Pocketmate (“we”, “us”, “our”) operates the Pocketmate mobile application. Pocketmate is a home-screen widget for two people, and it also contains a personal digestive-health diary. This Privacy Policy explains what data we collect, how we use it, what a person you connect with can see, and how we protect it. Parts of this data are sensitive health data and we treat them accordingly.

One principle runs through everything below: nothing is shared until you switch it on. Every widget surface is released individually, and none of them start released.

What we collect

  • Account data: email address and authentication credentials. If you sign in with Apple or Google instead, the identifier and email address that provider hands us. Nothing else comes across from either account.
  • Profile data: nickname, chosen avatar, and a short friend code that others use to connect with you.
  • Widget data: the value behind each widget surface you use, such as your current status text, a countdown date, or a running bet. Stored so both phones can show the same thing.
  • Coarse location (only with the Distance widget, only if you enable it): latitude and longitude rounded to two decimal places before they leave your device. See below.
  • Sleep state (only with the Sleep widget, only if you enable it): whether you are currently asleep, since when, and how many hours you slept. Derived from Apple Health. See below.
  • Contact checksums (only if you enable contact discovery): SHA-256 hashes of your own phone numbers and email addresses. Never your address book. See below.
  • Connections: who you are connected with, and pending requests.
  • Entry data: Bristol type, color, symptoms, optional notes, timestamp.
  • AI vision fields (only when you take a photo): volume, texture, moisture, color uniformity, undigested particles. These are derived from the photo, not the photo itself.
  • Onboarding selections: tracking reasons (Curious / Medical mode) for personalisation.
  • Device data: push notification token (only if you enable reminders).
  • Subscription state: entitlement (free / premium), managed via RevenueCat.

What the other person can see

Sharing is per surface and off by default. When you release a surface, the person you are connected with sees that one value on their home screen, and nothing else comes with it. You can switch any surface back off at any time, which stops the sharing immediately.

Friends always see only these: nickname, avatar, and how many entries you logged this week.

  • Streak and calendar week are shared only if you turn them on. Both default to off.
  • Status, sleep, distance, countdown and bet are shared only for the surfaces you release.
  • Bristol types, symptoms, notes and photos are never shared with anyone. There is no setting that turns this on. They are not part of any response another user can request.

Contacts: checksums, never your address book

Contact discovery is optional and off by default. It answers one question, which of the people you already know are on Pocketmate, without either side uploading an address book.

If you enable it, Pocketmate takes your own phone numbers and email addresses, normalises them, and publishes a SHA-256 hash of each. To find matches, your device hashes the identifiers in your address book locally and sends only those hashes for comparison. The comparison happens against published hashes; the numbers themselves never leave your phone, and we never learn who is in your contacts.

Turning contact discovery off deletes your published hashes rather than hiding them. Nobody can find you that way afterwards.

Location: rounded before it leaves the device

The Distance widget is optional and off by default, and it needs a separate consent step before anything is read.

Pocketmate reads your position only while the app is open. There is no background location tracking. Before the coordinates leave your device they are rounded to two decimal places, which is roughly one kilometre of precision, and only those rounded values are stored. The distance between you and your person is calculated from two such rounded positions. Your exact position never leaves your phone, and we cannot reconstruct it.

Apple Health: sleep, read only

The Sleep widget is optional and off by default, and it needs a separate consent step before anything is read.

If you enable it, Pocketmate reads sleep analysis and nothing else from Apple Health. It never writes anything back to Health. What is stored and shown is the derived state, whether you are asleep, since when, and how many hours, not the raw samples.

Sleep is health data. If you release the Sleep surface, the person you are connected with sees it on their home screen. That is the entire point of the feature, and it is why it is off until you switch it on, and why switching it off stops it at once.

Photos: device only

Photos are stored exclusively in the app sandbox at App/Documents/photos/ on your own device and are never uploaded to our servers. iOS and Android encrypt the app sandbox automatically with your device passcode. You can delete all photos at any time in Settings.

AI classification: pass-through, not stored

When you classify a photo, it is sent once to Anthropic (Claude AI Vision, US servers)for analysis. The AI extracts the Bristol type, color, and the five vision fields listed above. According to Anthropic's published policy, the photo is not retained and not used for AI training. We do not store the photo server-side either, only the extracted fields land in your account.

Account data in the EU

All entry data is encrypted on Supabase servers in the European Union (eu-central-1, Frankfurt). Row-Level-Security ensures only your account can access your entries. We use TLS/SSL in transit and AES-256 at rest.

Health data (GDPR Art. 9)

Two kinds of data in Pocketmate are special-category personal data (“data concerning health”) under GDPR Art. 9: your stool tracking entries and your sleep data from Apple Health. We process both on the legal basis of your explicit consent.

The consents are separate and granted at different moments. Tracking consent is given during onboarding. Sleep consent is given on its own screen, the first time you enable the Sleep widget, and it covers both reading the data and, if you release that surface, showing it to the person you are connected with.

You can withdraw either one independently, by switching the Sleep surface off, by disconnecting from a person, or by deleting your account in Settings. Withdrawal takes effect immediately and does not affect processing that already happened.

Third parties

  • Supabase, database, authentication, storage (EU/Frankfurt).
  • Anthropic (Claude AI), one-time image analysis. No storage, no AI training.
  • RevenueCat, subscription state for App-Store-mediated purchases.
  • Apple Push Notification Service / Firebase Cloud Messaging, push notifications (token-based, no content).
  • Apple (Sign in with Apple), authentication only, when you choose this method.
  • Google (Sign in with Google), authentication only, when you choose this method. We receive your email address and name; no other Google data is requested, and nothing is written back to your Google account.
  • Vercel, hosts myloo.org including the influencer click logger (7-day-TTL hashed IP, no raw IP stored).

We do not sell, rent, or share your personal data with advertisers, data brokers, or any third party not listed above.

Your rights (GDPR)

  • Access your personal data
  • Correct inaccurate data
  • Delete your account and all data (in-app: Settings → Account → Delete account)
  • Export your data
  • Withdraw consent any time

Contact: feedback+pocketmate@reply.getklar.org

Data retention

Data is kept while your account is active. On account deletion, all personal data is irreversibly removed within 30 days, account, entries, photo path references, push tokens, widget values, coarse location, connections, and any published contact checksums.

Two things are shorter-lived by design. The shared Moments timeline keeps only the last six months. Contact checksums are deleted as soon as you switch contact discovery off, without waiting for account deletion.

Children's privacy

Pocketmate is not intended for children under 16. We do not knowingly collect data from children under 16.

Not a medical device

Pocketmate is a tracking and educational tool, not a medical device. Tips, scores, and AI classifications are general gut-health guidance, not individual medical advice or diagnosis. For persistent symptoms or uncertainty, please consult a healthcare professional.

Changes

We may update this Privacy Policy. Significant changes will be communicated via in-app notification or email. The “Last updated” date above reflects the current version.

Contact

Questions about this Privacy Policy: feedback+pocketmate@reply.getklar.org