Privacy policy
The short version
poqui has no accounts. What you log — amounts, shop names, items, notes — is written to a database inside the app on your iPhone and is not uploaded to us.
Three things do leave your phone, and only in these situations:
- Purchases. If you subscribe, Apple and RevenueCat handle the purchase and tell the app what you are entitled to.
- Voice entry. Apple transcribes what you say. This happens on your iPhone where your device supports it, and on Apple's servers where it does not.
- The optional AI features. When they are switched on, a small derived summary — never your list of entries — goes through our own server to a language-model provider, is used to produce one answer, and is not kept.
Everything below explains those three in detail. If you turn the AI features off and never use voice, poqui sends nothing at all except what Apple needs for a purchase.
1. Who is responsible
poqui is made by an individual developer established in Italy. That person is the data controller for the limited processing described here.
FILL IN: full legal name
FILL IN: street address
FILL IN: postcode, city, Italy
FILL IN: VAT number or codice fiscale, if applicable
Email: hello@poqui.app
This is the trader address that also appears on the App Store product page, as EU law requires. No data protection officer is appointed; the controller answers privacy questions directly at the address above.
2. What poqui stores on your iPhone
poqui keeps a SQLite database inside its own container on your device. We have no access to it, no copy of it, and no way to read it remotely. It contains:
- Entries: the amount and currency, the date and time, the shop name, the item, the category, any note, how the entry was made (pad, voice, Pause) and, where voice or text parsing was used, the raw line you typed or said.
- Shops: the names of places you have logged, how often, and the totals per shop — so the app can suggest them next time.
- Learned suggestions: small associations such as "this shop is usually groceries", built only from your own corrections.
- Pauses, parked items and the Saved ledger: what you considered buying, what you decided, and the amounts you did not spend.
- Settings: your currency, whether haptics are on, whether the AI features are on, and reminder timings.
- A counter of AI calls the app has made, so it can show you your remaining allowance without asking a server.
This database is protected by iOS's own file encryption. poqui does not add a second layer of encryption on top of it, so a device passcode is what actually protects it. Nothing in this section is transmitted to poqui.
3. Device backups
If you have iCloud Backup switched on, or you back your iPhone up to a computer, the backup includes poqui's database along with the rest of your apps. That copy sits in your own Apple account or on your own computer, under Apple's terms and your own control. poqui cannot read it and is not told it exists.
This is why we do not tell you your data "never leaves your device": in the ordinary iPhone configuration, a copy of it is in your backup. If you would rather it were not, turn poqui off in Settings › [your name] › iCloud › Manage account storage, or delete the backup.
4. The anonymous installation identifier
poqui has no accounts, so there is nothing that identifies you as a person. When the app first runs it generates a random identifier for that installation and stores it on the device. It is used for exactly two things: attaching your purchases so they can be restored, and counting your monthly AI allowance.
It is never joined to a name, an email address, a phone number or an advertising identifier, and it is never combined with data from other companies. In the app it is shown in Settings as your Support ID, so you can quote it to us when you write in. Treat it as private: give it to us, not to anyone else.
Deleting the app and reinstalling produces a new identifier, which is also why you use Restore purchases after a reinstall.
5. Purchases and subscriptions
Every payment is made to Apple, not to us. We never see your card, your billing address or your Apple Account email. Apple gives us anonymous sales and payout reports, and country-level totals.
To know what you have paid for, the app uses RevenueCat as a processor. RevenueCat receives the anonymous installation identifier, the App Store transaction and receipt information for your purchase, and basic technical attributes of the installation such as the app version, the device model, the operating system version, the country and the time zone. It returns which subscription you hold and until when.
RevenueCat never receives any amount, shop, entry, note or Pause. There is no money data in this path at all.
6. The optional AI features
poqui works completely offline. Four features can optionally call a language model, and each one is controlled by a switch in Settings › Privacy: Cloud parsing and Cloud assistance. Turn them off and no request is made, ever; Pause and the Weekly Letter fall back to templates computed on your phone.
What is sent, exactly
| Feature | What is sent |
|---|---|
| Reading an unclear entry | The single line you typed or dictated (up to 200 characters), what the on-device parser already worked out from it, your language and your currency. Only when the on-device parser could not read it and cloud parsing is on. |
| Pause | The purchase you are considering — its amount, currency, and the shop, item and category if you gave them — plus a handful of totals derived from your own entries, such as what you have already spent at that shop in the last thirty days. |
| Weekly Letter | Totals for the week and month, up to five category totals, up to three shop names with visit counts, how many Pauses you had and how they ended, your logging streak, and progress against a goal if you set one. |
| Ask | Your question (up to 500 characters), the same kind of totals as above, and up to the last six turns of that conversation so a follow-up makes sense. |
What is never sent:
- your list of entries, and no entry-by-entry amounts;
- your notes, and the dates of individual purchases;
- your location;
- your identifier — it is used by our own server to count your allowance and stops there; the request that reaches the model provider carries no identifier of any kind.
Where it goes
The request goes first to our own small proxy server, hosted in the European Union, which checks your allowance. The proxy then calls OpenRouter, which forwards it to the language-model provider we have selected for that job. We configure OpenRouter to route only to providers that do not retain prompts for training, and we do not send OpenRouter any identifier for you.
What is kept
Nothing you send and nothing the model answers is written to a database. Our proxy stores only counters — how many AI messages this installation has used this month, whether this week's Letter has been produced — keyed to the anonymous identifier, in a Redis store hosted in the EU (Upstash), each with an automatic expiry.
Our diagnostic log lines are restricted, in code, to a fixed list of technical fields: which job ran, which model, token counts, how long it took, the status, and an error code with a short error detail. They are not designed to carry your content. One honest exception: when a model's answer is rejected because it contains a figure we cannot trace back to your own data, the recorded error detail can include that rejected figure. Those log lines are held by our hosting provider for a short retention window measured in days.
The model never invents an amount. Every figure in an answer must already appear in the summary we sent, or the answer is thrown away and your allowance is given back. This is a product rule, and it is also why the app shows a question mark rather than a guess.
7. Voice entry and Apple speech recognition
Holding the talk button records audio only while you hold it, and hands it to Apple's speech recognition through iOS. poqui does not receive, store or upload the audio, and does not keep the recording after the sheet closes. Only the resulting text is written to the local database.
Recognition runs on your iPhone where your device and language support it. Where it does not, iOS sends the audio to Apple's speech service, which processes it under Apple's own privacy policy. The app asks iOS for on-device recognition, but iOS makes the final decision and does not always tell the app what it chose. We therefore cannot promise that a given dictation stayed on your phone.
To improve accuracy, the app also supplies a short list of shop names from your own history as recognition hints. When a dictation is handled on Apple's servers, those shop names go with the audio. If you would rather no shop names were involved, use the number pad instead of the talk button. Denying the microphone or speech permission is fully supported: the pad works exactly the same.
8. Notifications
The reminders poqui sends — about something you parked, or a nudge to log — are scheduled by iOS on your device. There is no push server and no push token, and they keep working in airplane mode. Nothing about them reaches us.
Should a future version add server-sent push notifications, they would be delivered through OneSignal as a processor, which would receive a push token and the anonymous installation identifier and no money data. That is not part of this version, and this policy will be updated before it is.
9. Location
This version of poqui does not request or use your location. If a later version offers to name the shop you are standing in, it will ask for when-in-use location at that moment, pass the coordinates to Apple Maps to find nearby places, store only the place name you accept, and never send coordinates to our servers. This policy will be updated before that ships.
10. Diagnostics and analytics
poqui contains no advertising SDK, no attribution SDK, no advertising identifier and no third-party analytics or session-recording tool. We do not track you across apps or websites, and we ask no permission to do so.
Apple gives every developer aggregate figures — downloads, crashes, a small set of usage statistics — for apps on the App Store. Whether your device contributes to them is your choice, in Settings › Privacy & Security › Analytics & Improvements on your iPhone. That data reaches us already aggregated and cannot be traced back to you.
11. This website
poqui.app is a set of static pages hosted on Cloudflare Pages. It sets no cookies, runs no analytics script and loads nothing from a third party — every file it uses is served from poqui.app itself. Cloudflare processes standard request data, including your IP address, to deliver the pages and protect them from abuse.
12. Processors and recipients
| Who | What they get | Why |
|---|---|---|
| Apple | Your purchase and billing relationship; dictation audio when recognition is not on-device; aggregated app analytics if you allow them | Selling the app, transcribing speech, distributing the app |
| RevenueCat, Inc. (USA) | Anonymous installation identifier, App Store receipt and transaction data, basic device and app attributes | Knowing and restoring what you have paid for |
| OpenRouter, Inc. (USA) | The AI request described in section 6, with no identifier attached | Routing the request to a language-model provider |
| Language-model providers | The same request, to produce one answer | Generating the Pause line, the Weekly Letter, an Ask answer or a parsed entry. Selected for not retaining prompts for training |
| Upstash (EU region) | Counters keyed to the anonymous identifier. No request content of any kind | Enforcing your monthly allowance |
| Cloudflare, Inc. | Website request data; hosting for this site | Serving poqui.app |
| FILL IN: proxy host | Runs the AI proxy described in section 6 and its short-lived technical logs | Hosting the proxy in the EU |
| OneSignal, Inc. (USA) | Push token and anonymous identifier — only if a future version enables server-sent notifications | Not in use in this version |
Each of these acts as our processor under a data processing agreement, except Apple, which is an independent controller for your purchase and for speech recognition.
13. Transfers outside the EEA
Our proxy and its counters run in the European Union. RevenueCat, OpenRouter, Cloudflare, OneSignal and some language-model providers are established in the United States, so the limited data described above may be processed there. Those transfers rely on the European Commission's Standard Contractual Clauses, or on the EU–US Data Privacy Framework where the recipient is certified under it. You can ask us which mechanism applies to a particular recipient.
14. Legal bases
- Providing the app you installed
- Performance of a contract with you, Article 6(1)(b) GDPR. This covers the purchase and subscription handling in section 5.
- The AI features
- Your consent, Article 6(1)(a) GDPR, given by leaving those switches on after the first-run explanation. Withdraw it at any time in Settings › Privacy, with no effect on the rest of the app and no effect on processing already carried out.
- Voice entry, microphone and speech recognition
- Your consent, given through the iOS permission prompt and revocable in iOS Settings at any time.
- Allowances, abuse prevention and keeping the proxy up
- Our legitimate interests, Article 6(1)(f) GDPR: preventing one person from exhausting a shared service, and protecting it from attack.
- Serving this website
- Our legitimate interests, Article 6(1)(f) GDPR: delivering the pages and keeping them secure.
The data you log is often financial detail about your own life. We treat it as sensitive in practice; it is not a "special category" under Article 9 GDPR unless you choose to type something that is, which is one more reason we keep it on your phone.
15. How long anything is kept
- On your phone: until you delete the entry, or until you delete the app. There is no automatic expiry, and free accounts see thirty days of history without anything older being erased.
- AI request and answer content: not retained. It exists for the seconds it takes to produce one answer.
- Allowance counters: monthly counters expire automatically a couple of days after the month they belong to; a marker that an installation has been seen expires after about ninety days; replay-protection markers after minutes.
- Technical logs: retained by our hosting provider for its standard window, a matter of days.
- Purchase records at RevenueCat and Apple: for as long as the purchase relationship needs them, and as long as Apple's own tax and accounting obligations require.
16. Your rights
Under the GDPR you have the right to ask for access to your personal data, to have it corrected or erased, to have processing restricted, to object to processing based on legitimate interests, to receive your data in a portable form, and to withdraw consent at any time.
Most of these you exercise directly, without us, because we hold no copy: the data is on your phone, where you can read, edit, correct and delete every entry, and export it. For the little we do hold — the purchase record and the counters — write to hello@poqui.app and quote your Support ID from Settings › About.
Because we deliberately do not know who you are, Article 11 GDPR applies: without that identifier we may be genuinely unable to find anything to act on, and we will say so rather than ask you for proof of identity we have no use for.
You may also complain to a supervisory authority. In Italy that is the Garante per la protezione dei dati personali; you can equally go to the authority where you live.
17. How to delete your data
- Delete individual entries in the app. Every entry in Today and in your history can be edited or deleted, and the deletion is immediate and permanent.
- Delete the app. Removing poqui from your iPhone destroys the database with it. There is no server-side copy to ask us about, because your entries were never sent to us.
- Remove the backup copy, if you want it gone. See section 3 — a device backup you made yourself may still contain the data. That copy is under your control, in your Apple account or on your computer.
- Ask us to delete what is server-side. Email hello@poqui.app with your Support ID and we will delete the allowance counters attached to it and ask RevenueCat to delete the purchase record for that identifier. Deleting the purchase record means the subscription can no longer be restored to that installation; we will say so before doing it.
Cancelling a subscription is a separate thing and is done through Apple — see the support page.
18. Children
poqui is a general-audience app rated 4+, and it is not directed at children. We do not knowingly process the personal data of a child under the age at which consent is valid in their country. If you believe a child has provided data to us, write to us and we will delete it.
19. Changes to this policy
If what the app does changes, this page changes first. The version and date at the top always say which text is in force. A material change — a new processor, a new category of data leaving the device — will be announced in the app before it takes effect, and where it relies on consent, it will ask you again.
20. Contact
hello@poqui.app. One person reads that inbox and answers it. Privacy questions are answered within thirty days, usually in a day or two.