At Pocket Log, we believe your personal financial transactions, balances, and debt histories are private.
Pocket Log is designed under a Local-First architecture. All transactions, budget computations, debt profiles, and settings are stored and executed on your local Android device inside an encrypted SQLite/Room database.
Day-to-day money logging, analytics, and PDF statement generation do not require an active internet connection. You own your data entirely.
Key Principle: We do not operate proprietary user accounts, marketing servers, or centralized user databases. The developer has zero ability to view, monitor, monetize, or sell your financial records.
To protect against data loss when changing or losing devices, Pocket Log offers an optional Cloud Backup feature powered by Google Drive.
If you choose to enable Google Drive Cloud Backup, please review how your data is handled:
-
Restricted Scope (
drive.appdata): The application requests access strictly to the Google Drive Application Data folder (https://www.googleapis.com/auth/drive.appdata).
-
Zero Access to Personal Files: Under the
drive.appdata scope, Pocket Log can only access files that it creates itself within its own hidden folder. Pocket Log CANNOT view, read, modify, or delete your personal documents, photos, spreadsheets, or any other files stored in your Google Drive.
-
Direct Communication: Communication occurs directly between your Android device and Google's official Drive REST API over encrypted HTTPS/TLS. There are no intermediary developer servers, proxies, or relays.
-
Encrypted Archive: Backup snapshots are packaged into compressed, encrypted JSON archives containing your local database records before being uploaded to your Google Drive.
-
Google API Services User Data Policy: Pocket Log's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Opt-In Only: Cloud backup is completely optional. If you do not sign in with Google Drive, the app remains 100% on-device with zero network transmissions.
To eliminate ambiguity, Pocket Log does NOT collect, share, or monetize any of the following:
- Bank Credentials: We never integrate banking aggregators (e.g. Plaid, Yodlee) or request online banking passwords, account numbers, PINs, or credit card details.
- Personal Identification: We do not collect your legal name, physical address, national ID, or phone number.
- Advertising & Telemetry IDs: We do not collect the Google Advertising ID (GAID), Android ID, IMEI, or hardware serial numbers.
- Behavioral Tracking: We do not record or analyze your in-app actions, button clicks, screen visits, or financial habits.
- Precise Location Data: We do not request or track GPS, cellular, or Wi-Fi location coordinates.
When you use Pocket Log, data is saved locally inside the protected Android application sandbox (/data/data/com.jihan.pocketlog/):
- Income & Expenses: Amounts, categories, dates, transaction notes, and user-assigned tags.
- Debt & Loan Ledger: Profiles you create (e.g., personβs name), transaction types (lent or borrowed), total amount, settled repayments, and balance remaining.
- Balance Sources: Custom wallet names you specify (e.g., "Cash", "Primary Bank", "bKash") and balances.
- Budgets: Monthly overall and category-specific spending caps and warning percentages.
- User Preferences: Dark/light theme, currency symbol, Bengali/English language preference, and PIN hash.
Pocket Log requests only the minimum permissions strictly required for its features:
| Permission |
Type |
Purpose |
INTERNET & ACCESS_NETWORK_STATE |
Normal |
Used strictly when you initiate or schedule Google Drive Cloud Backups. Never used for advertisements or tracking. |
POST_NOTIFICATIONS |
Optional (Android 13+) |
Displays local daily reminders and budget alerts configured by you. Never used for marketing or background promotional push alerts. |
USE_BIOMETRIC / USE_FINGERPRINT |
Optional |
Enables App Lock using Android's native Keyguard. Verification occurs in your hardware's Secure Enclave/TEE. The app never receives raw biometric data. |
| Storage Access Framework (SAF) |
User-Prompted |
Used when you explicitly choose to export or import files (PDF statements, CSV spreadsheets, JSON backups) to your selected storage location. |
We enforce defense-in-depth measures to protect your financial records:
- Encrypted Preferences: Sensitive configuration values, such as your hashed App Lock PIN, are encrypted using AES (Advanced Encryption Standard) via DataStore.
- Android Sandbox Isolation: Android sandboxes application data. Other applications installed on your phone cannot access Pocket Log's internal SQLite database.
- Biometric Security: Biometric authentication is handled by Android's BiometricPrompt framework; no biometric data ever leaves your device's hardware chip.
- 30-Day Trash Quarantine: Deleted transactions are held in a local Trash bin for 30 days before permanent deletion, preventing accidental record loss.
You maintain complete ownership of your records with seamless export options:
- On-Device PDF Rendering: Statements are rendered locally using Android's native
PdfDocument API. No third-party conversion servers are involved.
- CSV Spreadsheets: Export your full transaction ledger to CSV format for analysis in Microsoft Excel, Google Sheets, or LibreOffice.
- JSON Backups: Export or import complete database archives for cross-device migration.
You have absolute control over your data retention and can delete any or all records at any time:
- Granular Deletion: Delete individual transactions, categories, balance sources, or debt profiles directly in the app.
- Empty Trash: Permanently purge deleted items anytime.
- Clear All App Data: Reset the application via Settings > Data Management > Clear All Data or Android System Settings > Storage > Clear Data.
- Google Drive Backup Deletion: Delete your cloud backup archive directly from the app or from your Google Account third-party apps settings.
For complete instructions on deleting data from both your device and Google Drive, please refer to our Account & Data Deletion Page.
Pocket Log does not integrate any third-party advertising or commercial analytics services:
- No Ad Networks: No AdMob, Unity Ads, AppLovin, or Meta Audience Network SDKs.
- No Analytics SDKs: No Google Firebase Analytics, Mixpanel, Segment, or Amplitude telemetry.
- Google Play Services: Used strictly for optional Google Drive OAuth authorization and cloud backup sync when chosen by the user.
Pocket Log is safe for users of all ages. We do not knowingly collect, solicit, or maintain personal information from children under the age of 13 (or 16 in the European Union). The app does not collect personal identity information and complies with COPPA and international privacy standards.
Pocket Log complies with the Google Play Developer Program Policies, including the User Data Policy, Financial Services Policy, and Data Safety Declaration requirements:
- Data Collected & Transmitted: Only user-initiated backup archives are uploaded to the userβs personal Google Drive account. No data is collected by the developer.
- Data Shared: Pocket Log does not share, broker, or sell user data to any third party.
- Security Practices: Data in transit is protected using modern HTTPS/TLS encryption. Data at rest is sandboxed in the private operating system partition.
If you have questions, feedback, or concerns regarding this Privacy Policy or your data protection rights, please contact:
This policy may be updated periodically to reflect new features. Changes will be posted to this page with an updated revision date.