Pockets by Hoopy
Privacy Policy
Last updated: July 8, 2026
Pockets by Hoopy is a personal-finance app that helps you budget with
virtual "pockets" and a single Good to Go (safe to spend) number. This policy explains,
in plain language, exactly what data we collect, why, who we share it with,
and the choices you have. We built this app to help people — not to profit
from their data. We do not, and will not, sell your personal
information or use it for advertising — not now, and not if we grow.
1. Who we are
"Pockets by Hoopy" ("we," "us," "the app") is operated by the developer of
Pockets by Hoopy. For any privacy question or request, contact us at
support@byhoopy.com.
2. Information we collect
Account information
- When you sign up with email: your name, email address,
and a password (stored only as a secure hash by our authentication
provider — we never see or store your plaintext password).
- When you sign in with Google: your name, email address,
and profile picture, as provided by Google. We use this only to create or
access your account. We request no other Google data and access nothing
in your Google account beyond basic sign-in profile information.
Financial information (once you connect a bank)
Pockets is built around your bank data — connecting an account is how the
app works, and most of its features depend on it. We only receive the data
below once you connect a bank; if you never connect one, we never receive
it. When you do, our bank-data providers (Teller and Plaid — see below)
share with us:
- Account details: account name, type, masked account number, and balances.
- Transaction data: amounts, dates, merchant/description text, pending or
posted status, and category information supplied by the provider.
We do not receive or store your online-banking username or
password. Bank connections are handled by the provider; we store only an
encrypted access token that lets us fetch the data above.
Information you enter yourself
- Pockets, budgets, funding schedules, categories, goals, and any manual
transactions or notes you add.
- App preferences (sort order, theme, notification settings).
Technical information
- If you enable notifications, a push-notification token for your device.
- Basic operational logs (timestamps, error diagnostics) needed to run and
secure the service. We do not use third-party advertising or cross-site
tracking cookies.
3. How we use your information
- To provide the core service: calculating your Good to Go number,
forecasting, and budgeting across your pockets.
- To categorize and clean up your transactions (see the next section on
automated processing).
- To sync your accounts and, where you ask, refresh balances.
- To send you account and service emails, and any notifications you enable.
- To keep the service secure, debug problems, and prevent abuse.
4. Automated transaction categorization (AI processing)
To turn raw, messy bank descriptions (for example,
SQ *AL'S FRENCH FRYS 0421) into a clean merchant name and
category, we send transaction description text and amounts to a
third-party AI language-model provider that performs this parsing on our
behalf. This helps your transactions show up with readable names and
sensible categories.
- We send only what's needed to identify the merchant — the transaction's
description text and amount. We do not send your name,
email, account numbers, or balances.
- We use the results to build a shared library of merchant-name rules, so
common merchants are recognized in the future without sending anything to
the AI provider again.
- This parsing is performed by our AI provider, Anthropic, under their
commercial API terms. We don't control Anthropic's internal data
practices, so rather than make promises on their behalf we point you to
their own
Privacy Policy.
On our side: we send only the minimum described above, we never tie it to
advertising, and we never sell it.
5. Who we share data with
We share data only with the service providers ("subprocessors") that make
the app work. Each receives only what it needs to perform its function.
| Provider | Purpose | Data involved |
| Supabase | Database, authentication, and file storage | Your account, budgeting, and transaction data |
| Teller | Bank account connections | Bank account & transaction data (if you connect a bank) |
| Plaid | Bank account connections | Bank account & transaction data (if you connect a bank) |
| Google | "Sign in with Google" authentication | Your name, email, profile picture (only if you use it) |
| Anthropic (AI provider) | Merchant-name & category parsing | Transaction description text and amounts |
| Resend | Sending account & service emails | Your email address |
| Railway & Vercel | Application hosting | Data in transit while the app runs |
We do not sell your personal information, and we do not share it with data
brokers or advertisers. We may disclose information if required by law, or
to protect the rights, safety, and security of our users and the service.
6. Google user data
Our use of information received from Google APIs adheres to the
Google API Services User Data Policy,
including its Limited Use requirements. We use Google sign-in data only to
authenticate you and provide the app's features to you directly — we do not
transfer or use it for advertising, and humans do not read it except as
needed for security or to comply with the law.
7. Data retention and deletion
- We keep your data for as long as your account is active.
- You can disconnect a bank at any time from within the app; doing so
revokes our access token with the provider and removes the associated
local account data.
- You can delete your entire account from within the app. This revokes all
bank-provider tokens and deletes your personal data from our systems.
Some records may persist briefly in backups or logs before being
overwritten in the ordinary course.
- To request deletion by email, contact
support@byhoopy.com.
8. How we protect your data
- Data is transmitted over encrypted connections (HTTPS/TLS).
- Bank access tokens are encrypted at rest.
- We never receive your full card or bank-account numbers — they arrive
already masked, so we only ever see the last few digits.
- Every user's data is isolated by row-level security so one account
cannot read another's data.
- Only the minimum server code paths hold elevated database privileges,
and we access your data only to operate, support, and debug the
service — never to browse it out of curiosity.
No system is perfectly secure, but we take reasonable, industry-standard
measures to protect your information.
9. Your rights and choices
- Access & correction: most of your data is visible and
editable directly in the app.
- Deletion: delete your account in-app or by email.
- Bank connections: you choose which banks to connect,
and you can disconnect any of them at any time.
- Notifications: opt in or out in the app or your device
settings.
- Depending on where you live (for example, the EEA, UK, or California),
you may have additional rights to access, port, or restrict processing of
your data. Contact us to exercise them.
10. Children and family use
Pockets by Hoopy is not directed to children under 13 (or the minimum age
required in your country), and we do not knowingly collect their personal
information without verifiable parental consent.
We recognize that budgeting is a valuable skill to learn early. A parent or
legal guardian may create and supervise an account on behalf of a minor in
their household. By doing so, the parent or guardian consents to our
collection and use of that account's information as described in this policy
and takes responsibility for the minor's use of the app. If you believe a
child has provided us information without this parental involvement, contact
us at support@byhoopy.com and we
will delete it.
11. Changes to this policy
We may update this policy as the app evolves. When we make material changes,
we will update the "Last updated" date above and, where appropriate, notify
you in the app. Your continued use after an update means you accept the
revised policy.
12. Contact us
Questions, requests, or concerns? Email
support@byhoopy.com and we'll get
back to you.