What the first launch actually asks of you
First run exists to get two things settled before you record a single baht: an account to record it against, and your permission for Pocketbird to hold financial data at all. That is the whole of it — two screens. Everything after them is optional, and the app is already working while you do it.
Every cold launch opens with the coin mark for 1.7 seconds, then a 0.35-second fade into whatever comes next. It is decoration only — restoring your saved session, the first sync and the App Lock check all run underneath it. With Reduce Motion on the coin does not spin; it fades in and nothing else.
A brand-new account is not an empty app. Before you have tapped anything, Pocketbird has already seeded enough for the screens to make sense.
- 11 top-level categories and a set of subcategories are inserted on the very first launch, before you even sign in — food, transport, money sent home, student loan, e-wallet top-up, shopping, entertainment, bills and utilities, salary, side income and debt payment.
- A default profile is created for you: payday on day 1, no salary, no goal. All three are yours to change later.
- Thai public holidays are seeded once you are signed in — they are what the weekend/holiday payday shift reads from.
- Three reminders start on: the Daily Logging Reminder at 20:00, Budget Alerts, and Group Activity. Everything else — payday, bill-due, over-pace, weekly recap, end-of-day cash check, App Lock — starts off.
- The "what's new" sheet is marked as seen on a fresh install — someone who has met the whole app this minute does not need a list of what changed. It appears only after a version change.
Creating an account
The sign-in screen is the outermost gate. Nothing inside the app works before it — not the widget, not the share sheet. There are two ways in: Sign in with Apple at the top, and an email and password hidden behind one link.
- Tap "Use email instead" / "ใช้อีเมลแทน". The credential card opens and the keyboard lands in the email field.
- Check the pill above the card. On the first screen it starts on "Sign Up" / "สมัครสมาชิก", because anyone with a saved session never gets this far.
- Type your email, then a password of at least 6 characters.
- Tap the blue pill — "Sign Up" / "สมัครสมาชิก" or "Sign In" / "เข้าสู่ระบบ".
- The screen has no Close button, because there is nothing behind it.
- When sign-up needs email confirmation, the account exists but there is no session yet: "Signed up — check your email and tap the confirmation link to finish." / "สมัครสำเร็จ — เปิดอีเมลแล้วแตะลิงก์ยืนยันเพื่อเสร็จสิ้นการสมัคร".
- Signing up again with an address that already has an account does not error and does not send an email — you get "This email may already have an account — try signing in, or use a different email." / "อีเมลนี้อาจมีบัญชีอยู่แล้ว — ลองเข้าสู่ระบบ หรือใช้อีเมลอื่น".
- The return key walks the form: next moves from email to password, go submits.
Confirmation links, forgotten and changed passwords
Both emails Pocketbird can send you — the sign-up confirmation and the password reset — contain a link that opens the app directly. They use two different addresses internally, so a reset link can never be mistaken for a confirmation.
- Tapping the confirmation link on the same device signs you in without retyping anything: "Email confirmed — you're signed in." / "ยืนยันอีเมลเรียบร้อยแล้ว — เข้าสู่ระบบสำเร็จ".
- Opened on a different phone or after a reinstall, the email is still confirmed but the app cannot finish the handshake: "Email confirmed — sign in with your password." / "ยืนยันอีเมลเรียบร้อยแล้ว — เข้าสู่ระบบด้วยรหัสผ่านของคุณได้เลย".
- Confirmation links expire after 1 hour, and a mail scanner can consume one before you tap it. Either way you get "This confirmation link is invalid or has expired — sign up again to receive a new link." / "ลิงก์ยืนยันใช้ไม่ได้หรือหมดอายุแล้ว — สมัครใหม่อีกครั้งเพื่อรับลิงก์ใหม่".
- Forgot your password: switch the pill to "Sign In" / "เข้าสู่ระบบ", then tap "Forgot password?" / "ลืมรหัสผ่าน?".
- The "Forgot Password" / "ลืมรหัสผ่าน" sheet opens with whatever email you already typed pre-filled. Tap "Send Reset Link" / "ส่งลิงก์รีเซ็ต".
- Open the email on the same device and tap the link.
- Pocketbird opens "Set New Password" / "ตั้งรหัสผ่านใหม่" full screen. Type the new password twice and tap "Update Password" / "อัปเดตรหัสผ่าน", then "Done" / "เสร็จ".
- The reset confirmation never reveals whether that address has an account: "If that email has an account, we've sent a link to reset your password. Open it on this device to set a new one."
- A reset link opened on another device is refused on purpose: "Open the password reset link on the device where you requested it, or request a new one." / "เปิดลิงก์รีเซ็ตรหัสผ่านบนอุปกรณ์ที่คุณขอไว้ หรือขอลิงก์ใหม่อีกครั้ง".
- Tapping a reset link signs you in — a recovery session is a real session. Backing out of the Set New Password screen leaves you signed in with the old password still working.
- The Set New Password screen cannot be swiped away, and it waits about 600 ms after the link lands so any open sign-in sheet finishes closing first.
- Both alerts and the reset screen are held back until the splash has gone and, if App Lock is on, until you have unlocked. A link in an email cannot walk past Face ID.
The privacy consent screen
Right after sign-in comes the one hard gate: "Consent (PDPA)" / "ความยินยอม (PDPA)". Nothing is recorded until you accept it. It lists each purpose your data can be processed for, with a plain-language explanation under each, and the version of the policy you are agreeing to.
- Nothing is pre-ticked. "Accept & Continue" / "ยอมรับและดำเนินการต่อ" stays disabled while the required purpose is off, with a line under it explaining why: "This consent is required to use the app — the entire app is recording and calculating your financial data."
- Leaving Cloud Sync off raises a calm note above the button, not a red error: "Your data stays only on this iPhone. Without Cloud Sync it can't be restored if you switch or lose your phone. You can turn it on later in Settings."
- An optional purpose you leave off is stored as not-yet-consented, never as explicitly refused. Tapping through this screen on a second phone can never switch cloud sync off for your whole account.
- The consent log is append-only: every grant and every withdrawal inserts a new dated record, and nothing is ever edited or deleted.
- The current policy version is 2.0. When it is bumped this screen comes back — a consent recorded against an older version does not count.
- Only these two purposes appear here. The two AI-assistant permissions are deliberately kept out of first run — they live in More → Settings → Privacy & Security → Privacy (PDPA) and in the Connected Apps flow.
The four-step setup guide
After consent, a short welcome flow appears once: payday, first account, how much you have right now, first expense. It is a cover sitting on top of an app that already works — never a gate. Skip is in the top-left corner of every step, including the last one.
- "When do you get paid?" / "คุณได้รับเงินเดือนวันไหน?" — spin the wheel to your payday, "Day 1" to "Day 31" / "วันที่ 1" ถึง "วันที่ 31", then tap "Continue" / "ถัดไป".
- "Add your first account" / "เพิ่มบัญชีแรกของคุณ" — tap "Add Account" / "เพิ่มบัญชี". What you add appears in the list at once and the button becomes "Add Another Account" / "เพิ่มบัญชีอีก".
- "How much do you have right now?" / "ตอนนี้คุณมีเงินอยู่เท่าไหร่?" — type your balance into "Current Balance (THB)" / "ยอดเงินปัจจุบัน (บาท)", or leave it blank and set it later.
- "Log your first expense" / "จดรายจ่ายรายการแรก" — type an amount into "Amount (THB)" / "จำนวนเงิน (บาท)", optionally tap a category tile, then tap "Log It" / "จดเลย".
- Continue is blocked on two steps, and says why: step 1 until you have actually touched the wheel — "Set the day you're paid to continue, or skip for now." / "เลือกวันที่คุณได้รับเงินเพื่อไปต่อ หรือข้ามไปก่อนก็ได้" — and step 2 until one account exists. Skip bypasses both.
- Payday is saved the moment you leave step 1, not at the end of the flow — so skipping the rest still keeps the day you picked.
- The first expense goes through exactly the same save path as normal Quick Add, so it inherits tag automation, learned categories and your default payment source.
- When the cover closes, the ledger underneath shows "Logged %@" / "บันทึก %@ แล้ว" with an "Undo" / "เลิกทำ" button for 4 seconds.
- The flow only appears on a genuinely blank install. If the app already holds any live account or transaction, it is marked done silently and never shows — that is the case for anyone upgrading in place.
- It also holds off while a cloud restore might still be landing, so a returning user is never asked to set up an app that is about to fill itself in.
Your opening balance
Step 3 asks how much money you have right now for one reason: safe-to-spend is computed from a real balance, so on day one it has to start from your actual money rather than from zero. The figure is not a setting — Pocketbird turns it into one ordinary income adjustment in your ledger, which is why it can be checked, edited and undone like anything else.
- The adjustment is dated 1 second before your current cycle starts. It reads as money carried in, and it is not counted as this cycle's income — so your income figure for the month stays honest.
- It lands in the earliest-created account you have that is still live, not archived, and not a credit card.
- If the only account you added is a credit card, this step does nothing at all — a card's balance is money you owe, not money you have.
- If you also typed an opening balance inside the Add-Account form, that field is zeroed and folded into this one adjustment, so the same money is never counted twice.
- Leaving the field blank is fine. You can set the balance later by running the setup guide again, or let it build itself as you log income.
Payday, salary and the reminders
Everything the setup guide could have asked for lives on one screen afterwards, together with every reminder toggle: More → Settings → Profile & Setup → "Profile & Budget Cycle" / "โปรไฟล์ & รอบงบ". Budget cycles start on payday, and in a month too short for the day you picked, the cycle starts on the last day of that month instead.
The reminder toggles on the same screen all start off except three, and each one names its own schedule underneath it.
- "Daily Logging Reminder" / "แจ้งเตือนบันทึกรายวัน" — on by default, 20:00.
- "Budget Alerts" / "การเตือนงบประมาณ" — on by default; warns you as a category nears its budget and again if it goes over, for categories that have one.
- "Group Activity" / "กิจกรรมในกลุ่ม" — on by default, but it needs a signed-in account and cloud-sync consent to deliver anything.
- "Payday Reminder" / "แจ้งเตือนวันเงินเดือนออก" — off; fires at 09:00 on the day a cycle starts.
- "Weekly Recap" / "สรุปรายสัปดาห์" — off; defaults to Sunday at 18:00, with "Recap Day" / "วันสรุป" and "Recap Time" / "เวลาสรุป" beside it.
- "Bill-Due Reminder" / "เตือนบิลครบกำหนด", "Over-Pace Alert" / "เตือนใช้จ่ายเร็วเกินไป" and "End-of-Day Cash Check" / "เช็คเงินสดสิ้นวัน" (21:00) all start off.
Locking the app with Face ID
Your phone's own passcode protects the phone; App Lock protects this app in particular, for the moment you hand your unlocked phone to someone. It is off until you turn it on, and it is per-device — switching it on here does not lock Pocketbird on your other phone.
- Go to More → Settings → Privacy & Security → "App Lock" / "ล็อกแอป".
- Turn on "Lock App with Face ID" / "ล็อกแอปด้วย Face ID". It applies immediately — there is no Save.
- Next launch, or the next time you come back from the background, "Pocketbird Is Locked" / "Pocketbird ถูกล็อกอยู่" appears and the biometric prompt fires by itself.
- If you dismissed the prompt, tap "Unlock" / "ปลดล็อก" to bring it back.
- The footer states the deal plainly: "Requires authentication every time you open or return to the app." / "ต้องยืนยันตัวตนทุกครั้งที่เปิดหรือกลับเข้าแอป"
- If Face ID is unavailable or keeps failing, your device passcode is accepted instead — you cannot be locked out of your own records by a bad camera angle.
- Re-locking only happens after a real trip to the background. Control Centre, the biometric sheet itself and a quick peek at the app switcher do not re-prompt.
- The lock screen is fully opaque, so the app-switcher snapshot shows the lock, not your balances.
- At launch the lock engages before the saved session is restored, so the lock screen can appear while the app does not yet know whether you are signed in.
- Turning it off takes effect on the very next launch or foreground — no restart, no sign-out.
A new phone, and getting out again
First run is also what happens the second time — on a new phone, after a reinstall, or when someone else signs in on your device. Which of those you get depends entirely on whether you granted Cloud Sync.
- With Cloud Sync on, signing in on a new phone shows "Restoring your data" / "กำลังกู้คืนข้อมูลของคุณ" over skeleton rows while the first sync runs — never a false "you have nothing" empty state.
- Your consent log comes down with everything else, so the consent screen usually does not appear again, and the welcome flow is marked done silently once your data lands.
- If that first sync fails — the network dropped right after you signed in — the app does not hang waiting. It falls through and offers the welcome flow for what looks like a blank slate.
- Signing in with a different account on the same phone wipes the local store first, then restores the new account — consent and profile included. The new person gets the consent screen, fresh seeded categories and the welcome flow.
- Before you are signed in and consented, the Share Extension refuses politely — "Sign In Required" / "ต้องเข้าสู่ระบบก่อน" or "Consent Required" / "ต้องยินยอมก่อน" — and a Quick-Add widget tap is queued rather than lost.
Signing out is not a light action here. More → Settings → Account → "Sign Out" / "ออกจากระบบ" erases everything on this phone and returns it to a fresh-install state: "Signing out erases everything on this device. Synced data comes back when you sign in again." / "การออกจากระบบจะลบทุกอย่างในเครื่องนี้ ข้อมูลที่ซิงก์แล้วจะกลับมาเมื่อคุณเข้าสู่ระบบอีกครั้ง"
- Pending edits are pushed to the cloud first and the app waits for that sync to finish, so an online user does not lose anything unsynced.
- This device's push token is dropped server-side while the session is still valid, so the phone stops receiving that account's group notifications.
- If sign-out itself fails, the erase does not run at all — you stay signed in with your data intact.
- A full-screen "Signing out…" / "กำลังออกจากระบบ…" holds the app until the wipe is finished, so the sign-in screen never flashes over a half-erased store.
- The erase also clears the device-local onboarding latch, so the next account signed in on this phone is offered the welcome flow again.