Privacy Policy
Last updated: August 2026
This Privacy Policy explains how Pocket Locker ("the app", "we", "us") handles your information. We've written it to describe exactly what the app does — no more, no less.
The short version
Pocket Locker is built to work entirely on your device. By default, nothing you store in the app — documents, photos, passwords, notes — is ever sent to us or to any third party. We do not operate any servers that receive your data, and we cannot see, access, or recover it.
What's stored, and where
Everything you add to Pocket Locker — titles, notes, reference numbers, passwords, and any photos or PDFs you attach — is stored in a local database on your device only.
- Sensitive text fields (titles, notes, account/reference numbers, item names, passwords) are individually encrypted using AES-256 before they're written to the local database.
- The encryption key is generated on your device and stored in your phone's hardware-backed secure storage (the iOS Keychain or Android Keystore) — the same secure storage used for saved passwords system-wide. This key never leaves your device and is never transmitted anywhere, including to us.
- Passwords you save inside the app are stored using this same hardware-backed secure storage rather than the general database, for an extra layer of protection.
Optional Google Drive backup
Pocket Locker includes an optional backup feature that is off by default. If you choose to turn it on:
- You'll sign in with your own Google account through Google's standard sign-in process. We do not see or store your Google password.
- Your encrypted local database is uploaded to a special hidden folder in your Google Drive called the "application data folder." This folder is only accessible to Pocket Locker — it does not appear in your regular Google Drive, and no other app or person (including us) can see or access it.
- We request only the drive.appdata permission from Google — the most restrictive Drive permission available, which cannot read, modify, or see any of your other Drive files.
- You can disconnect this at any time from within the app, or by revoking Pocket Locker's access directly from your Google Account's permissions page.
Device permissions we ask for, and why
- Camera — to let you scan and photograph documents directly into the app.
- Photos — to let you attach existing photos from your device as documents.
- Biometrics (Face ID / Fingerprint) — to lock the app; handled entirely by your device's operating system, not by us.
- Notifications — to show you reminders for expiring documents that you've chosen to set.
None of these permissions are used to collect or transmit data to us. They exist solely so the app can function as described.
What we don't do
- We do not run analytics or tracking of any kind inside the app.
- We do not show ads, and we do not share, sell, or rent any information to advertisers or data brokers.
- We do not have user accounts, so there is no central record of who uses the app or what they've stored.
Deleting your data
Deleting a document moves it to the in-app Trash, where it's automatically and permanently removed after 30 days (or sooner, if you empty it manually). Uninstalling the app removes all local data from your device. If you've enabled Google Drive backup, that backup remains in your Drive until you delete it yourself, either from within the app or from your Google Account.
Children's privacy
Pocket Locker is not directed at children, and we do not knowingly collect information from children, consistent with the fact that we do not collect information from anyone.
Changes to this policy
If this policy changes — for example, if we introduce a new feature that affects how data is handled — we'll update this page and change the "Last updated" date above.
Contact us
Questions about this policy or how Pocket Locker works can be sent to support@pocketlocker.app.
Pocket Locker