Skip to content
← Back to Pocketbird
Privacy

Your money stays yours.

Local-first, opt-in sync, on-device AI, no ads, no data selling — the full PDPA notice, in plain language.

Last updated · 5 August 2026 · v2.0
01

TL;DR

Pocketbird is a local-first personal finance app: your data lives primarily on your device and is uploaded only if you enable and consent to cloud sync. The AI features run on your iPhone or iPad. There are no ads, no trackers, and your data is never sold. The full notice below explains everything under Thailand's PDPA.

  • Your ledger lives on your device first; cloud sync is opt-in.
  • Bank SMS and slips are read by on-device AI — the messages are never uploaded.
  • Connecting an AI assistant (like Claude) is optional, off by default, and revocable.
  • Export or delete everything, any time, in the app (PDPA).
02

Data controller & contact

Pocketbird is operated by its developer, Nattapong Pallawal, as the data controller. No separate Data Protection Officer is appointed (the PDPA Section 41 mandatory-appointment criteria are not met); the developer handles data-subject requests directly. For privacy requests that can't be completed in the app, email [email protected].

03

Data we collect & where it lives

We collect only what the app needs to function. Everything below syncs to the cloud only while cloud sync is on; otherwise it stays on your device.

  • Account details — email; your password is stored hashed by the authentication system.
  • Financial records — amounts, types, categories, tags, notes, dates, payment sources, accounts and transfers, pockets, trips, and the people or shops you record transactions with.
  • Settings & goals — custom categories, savings pockets, budgets, recurring items, debts, credit-card limits and statement days.
  • Your financial profile (salary, payday, goal) syncs with your account so a new device can restore it. Device preferences (notification, reminder, app-lock settings) stay on your device only.
  • Slip/receipt photos and trip covers are stored, while sync is on, in a private storage area tied to your account (JPEG, size-capped) and are deleted with their records and your account.
  • Consent records — purpose, policy version, timestamp; an append-only log that syncs whenever you're signed in so withdrawals reach every device.
  • Group features (require an account + the cloud-sync consent) — group name, your per-group display name, shared bills and shares, and shared-pocket contributions are stored in the cloud and visible to that group's members. Payment receiving channels were removed on 29 July 2026: the app collects no PromptPay numbers, bank accounts, or national IDs, and no previously added channel remains in storage.
  • In-app feedback & feature votes (1.9) — if you send feedback, we store your message and topic with basic app context (app version, iOS version, device model, language), never your financial records; allowing a reply lets the developer answer once to your account email, which is not stored with the message. If you vote on candidate features, your vote is stored and others see only anonymous totals. Both are deleted with your account.
  • Push notifications — if you use group features with notifications on, this device's Apple push token is registered with your account; the notification content (member names, bill/pocket titles, amounts) is delivered through Apple's push service, which may process it outside Thailand. The token is removed on sign-out and deleted with your account.
  • Crash & hang diagnostics (2.0) — if the app crashes or freezes, a technical diagnostic report from Apple's MetricKit (app and iOS versions, device model, and the technical call stack) is uploaded when the app next opens so the problem can be found and fixed. These reports are deliberately not linked to your account: they carry no identifier and none of your financial data.
  • Coarse usage statistics (2.0, switchable off in Settings → Share usage statistics) — event name, time, and app version only (for example that a transaction was logged or a recurring item was created): never amounts, notes, names, or anything you typed. Tied to your account so returning-use statistics can be computed, and deleted with it. Processed, together with crash diagnostics, on the basis of legitimate interest (PDPA Section 24(5)).

We do NOT collect national-ID card images, location, biometric identifiers, or other sensitive data under PDPA Section 26. Bank SMS and slips are parsed by on-device AI and are never uploaded. There is no ad tracking and your data is never sold.

04

Purposes & consent

Processing is based on your consent (PDPA Section 19), asked per purpose before any financial data is stored:

  • Store and process financial data on this device — required; the app cannot work without it.
  • Sync data to the cloud — optional, off until you turn it on, revocable any time.
  • Let a connected AI assistant read your data — optional, off by default.
  • Let a connected AI assistant create and edit your data — optional, off by default, separate consent.

Every grant or withdrawal is recorded in an append-only log, so there is always an auditable history of what you consented to, which version, and when.

05

Cloud sync & cross-border transfer

If you enable cloud sync, your synced data is stored with our processor, Supabase Inc., whose database runs on AWS infrastructure in ap-southeast-2 (Sydney, Australia) — outside Thailand, under the Australian Privacy Act 1988.

Protections in place for this transfer: the destination is governed by the Australian Privacy Act 1988, every connection uses TLS with stored data encrypted at rest, and Row Level Security means your personal records are accessible only by your account (group records only by that group's members).

You control the transfer: withdraw sync consent any time and the app immediately stops sending and pulling financial data. Data synced before a withdrawal remains in the cloud until you delete those records or your account.

06

Connecting an AI assistant

If you connect your own AI assistant (for example Claude by Anthropic, in the United States), the records you ask it to read are sent — at your direction — to that provider, which may be outside Thailand and may not offer the same level of data protection as Thai law. This is optional, off by default, granted by a separate consent, and revocable any time by deleting the connection or its access token.

If you also grant the separate edit consent, you can ask the assistant to create or change your own records on your instruction. Because it must find the right record before changing it, granting write access also lets it read those records. It never acts on its own and never touches anyone else's data.

07

Retention & deletion

Your data is kept for as long as you use the app. Deleted records are first marked as deleted so the deletion reaches all your devices, then erased permanently and automatically — in the cloud after 90 days, and on the device 30 days after the deletion has synced.

When you delete your account, your personal data — in the cloud and on the device — is deleted immediately, including your photos in private storage. Records you shared with a group stay with that group so other members' records remain intact; the link to your account and your display name are removed.

08

Your rights (PDPA)

  • Withdraw consent — Settings → Privacy (PDPA).
  • Access & export — Settings → Export Data: a portable JSON bundle of your financial records (transactions, categories, tags, pockets, debts, trips, recurring items, accounts, people, budgets), CSV, and per-cycle CSV/PDF reports; group data has its own export.
  • Object / restrict — turn off cloud sync and use the app on-device only.
  • Erase — Settings → Delete Account & All Data.

You also have the right to lodge a complaint with Thailand's Personal Data Protection Committee (PDPC).

09

Processors

Supabase Inc. processes synced data (Postgres database, authentication, private media storage) under its standard service terms, with Amazon Web Services hosting the infrastructure. Apple processes Sign in with Apple and delivers push notifications; its on-device frameworks power Siri, widgets, and the AI features without sending your data to us. Aside from these, no third party receives your data except a service you choose to connect yourself — such as an AI assistant, which receives only the data you ask it to read.

The service providers Supabase itself uses (per the list Supabase publishes) that are relevant to hosting are Amazon Web Services (our region: Sydney), Cloudflare, Google, and Fly.io.

10

This website

  • Cookies: necessary cookies keep the site working and are always on. Preferences (theme/language), analytics, and marketing cookies run only after you allow them — today the site ships no third-party scripts at all, so nothing loads even if allowed.
  • Proof of consent: when you make a cookie choice, we record the choice, method, policy version, and a salted hash of your IP address as PDPA proof-of-consent — kept in server logs, not a database.
  • Web sign-in: signing in on this site (for example to approve an AI-assistant connection) uses the same Supabase account as the app; only the anonymous/publishable key is used on this host.
  • Hosting: the site is self-hosted by the developer and served through Cloudflare's network (transport only).
11

Changes to this notice

This is version 2.0 of the notice. If the wording or purposes change, the version number is bumped and the app shows the consent screen again before processing under the changed purposes. The version you consented to is always visible in Settings → Privacy (PDPA).

12

Contact

Questions? Email [email protected]. We reply within a day, by a real person.