PocketCoder Privacy Policy

Effective date: August 30, 2026

Qtpi Bonding LLC (“PocketCoder,” “we,” “us,” or “our”) provides PocketCoder Pro, including its Aeroform/PN provisioning and operational features. This Privacy Policy explains what information the PocketCoder Pro app and PocketCoder-operated services process.

1. PocketCoder is primarily a client for your infrastructure

PocketCoder Pro helps you provision and operate infrastructure that you own or control. We do not host or administer your PocketBase instance, VPS, cloud provider account, application database, chats, prompts, code, or other data stored on your own infrastructure.

The privacy practices for data stored on your VPS are also governed by your own configuration, access controls, backups, and policies. If you use a third-party provider such as Linode/Akamai, that provider’s privacy policy and terms also apply.

2. Information stored on your own server

Depending on how you configure PocketCoder, your own PocketBase deployment may store information such as:

This information is sent to and stored on the PocketBase/VPS endpoint you configure. It is not automatically copied into a PocketCoder-hosted database by the PocketCoder Pro app.

3. Information processed by the app

The app may process the following on your device:

Sensitive local values are stored using platform secure-storage facilities where available. You are responsible for securing your device and removing local credentials when the device is transferred, lost, or no longer trusted.

4. Cloud-provider authorization and OAuth relay

When you authorize a cloud provider or another OAuth-connected service, PocketCoder may process authorization codes and tokens to complete the action you requested.

For the PocketCoder OAuth relay:

The relay is not intended to be a permanent credential store. Provider tokens may subsequently be stored by the PocketCoder deployment or app components needed to perform the authorized operation. You control whether to authorize a provider and may revoke that authorization through the provider.

The relay may produce limited operational error logs, such as provider name, HTTP status, and whether a token was present. It is designed not to log authorization codes, request bodies, client secrets, or token responses.

5. Push notifications

If you enable push notifications, PocketCoder processes a device push token, device name or model, push-service identifier, and the associated user/device relationship so notifications can be delivered.

PocketCoder uses Firebase Cloud Messaging for push delivery. The device registration is associated with your user record on your configured PocketBase server. You can disable notifications through your device or app settings.

6. Purchases and subscriptions

PocketCoder uses RevenueCat and the applicable Apple or Google billing systems to provide subscriptions, trials, purchase validation, and restoration. RevenueCat acts as a data processor on our behalf for this purpose.

These services may receive an app-specific or server-user identifier, device type and operating system, purchase and transaction activity, product and entitlement information, and other information needed to validate or restore a purchase. PocketCoder does not receive or store your full payment-card number through the app.

Apple, Google, and RevenueCat process information under their own policies and terms:

7. Local diagnostic reports

PocketCoder includes a local diagnostic inbox to help you understand application failures. Diagnostic records are stored only on your device and are not automatically transmitted to PocketCoder or a third party.

A diagnostic record may contain limited structured information such as an error type, mapped error code, developer-controlled source or operation label, stack trace, timestamp, and a user-facing error key. The diagnostic capture system is designed not to include passwords, authorization tokens, request bodies, or arbitrary user content.

You can view, delete, or copy diagnostic reports. If you copy a report and send it to support, you choose what to disclose and the report becomes part of that support conversation.

PocketCoder does not currently use Firebase Analytics, Firebase Crashlytics, Sentry, or a similar automatic crash-reporting service in the app build covered by this policy.

8. Information you send to support

If you contact us, we may receive your contact information, correspondence, attachments, diagnostic reports, and other information you choose to provide. We use it to respond, troubleshoot, provide support, and improve the Service.

Support contact: marketing@qtpi.app

9. How we use information

We use information processed by PocketCoder-operated services to:

We do not sell personal information. We do not use your chats, prompts, code, or server data for advertising.

10. Information sharing

We may share limited information with service providers that help operate the Service, including:

We may also disclose information when required by law, to protect rights and safety, or in connection with a corporate transaction. We do not provide third parties access to your PocketBase data merely because you use the PocketCoder Pro app.

11. Retention and deletion

PocketCoder retains information only for as long as reasonably necessary for the purposes described in this policy, unless a longer period is required by law or needed to resolve a dispute.

Short-lived OAuth exchange records are configured to expire after approximately 60 seconds and are deleted after claim attempts. Support correspondence and purchase records may be retained for the periods required for support, accounting, fraud prevention, and legal compliance.

For push delivery, the PocketCoder-operated Supabase database holds a hashed relay binding, your PocketCoder user identifier, and a daily quota record. The daily count is overwritten when a new day begins. These records are retained until you use “Delete PocketCoder Pro Data” in the app, at which point the app requests their deletion. PocketCoder does not use a separate support-ticket database; support correspondence is retained in our Proton Mail mailbox only as long as reasonably necessary to respond, troubleshoot, prevent abuse, or meet legal obligations.

Data stored on your own PocketBase/VPS is your responsibility to retain or delete. PocketCoder cannot delete or modify that data on your behalf unless you explicitly authorize an operation through the Service.

Local app data can be removed by logging out, removing saved server or credential data when the relevant app controls are available, clearing the app data, or uninstalling the app.

PocketCoder Pro subscribers can request deletion of PocketCoder-operated account data directly from the app by selecting “Delete PocketCoder Pro Data” in Settings. This sends an authenticated request through your own PocketBase server to PocketCoder’s push-relay service, which deletes your push-notification binding and quota records and removes your customer record from RevenueCat, our subscription-management provider. This is not a best-effort action: if any part of the deletion fails, the app reports an error rather than a false success. This feature does not delete data stored on your own PocketBase/VPS, which remains yours to manage as described above, and it cannot cancel an already-active Apple or Google subscription — you must cancel a subscription through the applicable app store, as described in Section 6.

Deleting PocketCoder Pro data does not itself delete records independently maintained by Apple, Google, Firebase Cloud Messaging, RevenueCat, your cloud provider, your AI provider, or another authorized integration. Apple and Google retain purchase, refund, and subscription records under their own policies. We request deletion of the PocketCoder-associated RevenueCat customer record as described above, but any provider’s retention of records is governed by that provider’s own policy and applicable law. To delete data held by your cloud, AI, or other third-party provider, use that provider’s deletion process.

To request deletion of information held by PocketCoder-operated services, contact marketing@qtpi.app. We may need to retain limited information when required by law or necessary to establish, exercise, or defend legal claims.

12. Security

We use reasonable technical and organizational measures appropriate to the information processed by the Service. No device, network, cloud provider, or software system is completely secure. You are responsible for securing your device, provider account, VPS, PocketBase instance, credentials, backups, and access permissions.

13. Children

PocketCoder is not directed to children and is not intended for use by anyone under 18 years old. We do not knowingly collect personal information from anyone under 18 through PocketCoder-operated services.

14. International processing

PocketCoder and its service providers may process information in countries other than the country where you live. Where required, we use appropriate mechanisms for international data transfers.

15. Changes to this policy

We may update this Privacy Policy when the Service or legal requirements change. We will post the updated policy and update the effective date. Where required, we will provide additional notice or request consent.

16. Contact

Qtpi Bonding LLC
Privacy contact: marketing@qtpi.app
Website: pocketcoder.org