Privacy Policy
The short version
- We collect what we need to run the Service: your account info, the situations and documents you submit, and basic usage data.
- We do not sell your personal information.
- We do not use your content to train AI models. Our AI provider (Anthropic) is contractually prevented from training on it either.
- You can export or delete everything from inside the app at any time.
- We use industry-standard encryption in transit and at rest.
1. What we collect
Account information
When you sign up: your email address, the authentication provider you used (email + password, Sign in with Apple, or Google), and an optional display name.
Case content
The information you put into your cases: typed descriptions, voice transcripts (we transcribe on-device when possible), photographs of documents, PDF uploads, OCR text extracted from your documents, AI summaries and drafts, and any tags or notes you add.
Subscription information
Whether you have an active subscription, when it expires, and which plan you're on. We receive this from RevenueCat after the App Store or Google Play processes your purchase. We do not see or store your payment card details — those stay with Apple or Google.
Device and usage data
Device model, operating system version, app version, locale, language, time zone, crash reports, and basic interaction events (e.g. "user opened paywall," "user submitted case") so we can improve the Service. We do not use third-party advertising trackers.
2. How we use it
- To run the Service. We send your case content to AI providers to generate summaries and drafts, run OCR on your documents, store them in your private vault, and let you retrieve them.
- To improve the Service. We analyze aggregated, anonymized usage to find bugs, identify slow code paths, and prioritize features.
- To communicate. We email you transactional notices (account confirmations, subscription renewals, password resets, exported case packets you send to yourself).
- To enforce our Terms. We review reports of abuse and may inspect specific accounts when there is reason to suspect a Terms violation.
- To comply with law. We may disclose information when legally compelled (subpoena, court order, lawful request from a government agency).
We do not use your information for ad targeting, profile sales, or anything that benefits a third party at your expense.
3. Sub-processors we share with
We rely on a small number of vendors to run the Service. Each is contractually limited to processing your data only on our instructions:
| Vendor | What they do | Where they process |
|---|---|---|
| Anthropic, PBC | AI inference (Claude). Will not train on your content per their API terms. | United States |
| Google LLC (Firebase / Cloud Vision) | Authentication, database, file storage, server functions, document OCR. | United States |
| RevenueCat, Inc. | Subscription management. | United States |
| Resend, Inc. | Transactional email delivery. | United States |
| Apple Inc. / Google LLC (App Store / Play) | Payment processing, IAP receipts. | United States |
4. How long we keep it
- Active accounts: we retain your data for as long as your account is active.
- Deleted accounts: we delete your case data and account information within 30 days of your deletion request.
- Audit logs: security and access logs are retained for up to 12 months.
- Backups: we purge automated backups on a rolling 30-day cycle.
5. Security
We protect your information using:
- Encryption in transit (TLS 1.2+) for all network traffic;
- Encryption at rest at the platform level (Firebase / Google Cloud);
- Per-user database security rules — your data is readable only by your authenticated account;
- Server-side enforcement of all sensitive actions (subscription state, audit logs, AI key handling);
- Optional in-app PIN to gate access to your vault on device.
No system is perfectly secure. If we ever discover a security incident affecting your data, we will notify you and any required authorities within the timeframes set by applicable law.
6. Your rights
Regardless of where you live, you have the right to:
- Access a copy of the data we hold about you.
- Export your case content (in-app: Settings → Export my data).
- Correct inaccurate information in your account.
- Delete your account and content (in-app: Settings → Delete account).
- Withdraw consent at any time by deleting your account.
California residents (CCPA/CPRA)
You have additional rights under the California Consumer Privacy Act, including the right to know what categories of personal information we collect and the right to opt out of "sale" or "sharing." We do not sell or share your personal information for advertising purposes. To exercise your rights, email privacy@usepocketcounsel.com.
European users (GDPR)
If you reside in the European Economic Area, the United Kingdom, or Switzerland, you have rights under the General Data Protection Regulation including access, rectification, erasure, restriction, portability, and objection. Our legal basis for processing is performance of the contract you accept by signing up, plus our legitimate interest in operating and improving the Service. To exercise rights or contact our data protection point of contact, email privacy@usepocketcounsel.com.
7. Children
The Service is not intended for users under 18. We do not knowingly collect personal information from children. If we become aware that an account belongs to a person under 18 we will delete it.
8. International transfers
The Service is operated from the United States and our sub-processors are located in the United States. By using the Service from outside the United States, you consent to the transfer and processing of your information in the United States, which may have data protection laws different from those in your country.
9. Changes
We may update this Policy. If a change is material, we will notify you in-app or by email at least 30 days before it takes effect. We will keep prior versions on file and link to the most recent change log here when one exists.
10. Contact
Blixum, LLC
378 Sierra Drive
Traverse City, Michigan 49685
Privacy questions: privacy@usepocketcounsel.com
General support: support@usepocketcounsel.com