Privacy policy
Last updated 1 August 2026
This policy explains what PockitTrail collects, why it collects it, and what you can ask us to do with it.
Who we are
PockitTrail is operated by Xeontrix LLC. In this policy, "we" and "us" mean Xeontrix LLC, and "you" means the person using the service.
For any question about this policy, or to ask us to delete your data, write to privacy@xeontrix.com.
What we collect
Account details: your email address, your name if you give one, and an encrypted password. We never see your password in readable form.
What you enter: your workspaces, expenses, income, budgets, accounts, contacts, invoices, purchase plans, notes and any files or receipts you upload.
Technical records: basic server and error logs that record the time of a request, its result and the browser that made it. These help us keep the service working.
We do not buy data about you, and we do not run advertising or third-party tracking pixels.
How we use it
To run the service: to show you your figures, keep your workspace in sync between your devices, and let the people you invite see the workspace you shared with them.
To keep it secure: to detect abuse, investigate faults and recover from them.
To contact you about the service itself, such as a security notice or an important change. We do not send marketing email unless you ask for it.
Where it is stored
Your data is held in a Supabase project backed by PostgreSQL. Every table is protected by row-level security, so a query can only reach rows belonging to a workspace you are a member of.
Traffic between your device and the service is encrypted in transit. Backups are encrypted at rest.
AI features
Some features are optional and only run when you start them: reading a receipt, a shop card or a quotation from a photo, turning a typed or spoken sentence into an entry, and reading a research note for shop names and prices.
When you use one of those, the text or image you supplied is sent to Google's Gemini API to be read, and the result is returned to you for review before anything is saved. Nothing is sent to that API unless you trigger one of these features.
We do not send your stored figures, your account details or your workspace history to any AI provider for training.
Who else can see your data
People you invite to a workspace, at the role you gave them. An editor can change what is in that workspace; a viewer can only read it. You can remove a member at any time.
Our infrastructure providers, who process data on our instructions so the service can run: Supabase for the database, storage and authentication, our hosting provider, and Google for the AI features described above.
We do not sell your data, and we do not share it with anyone else except where the law requires it.
Cookies
We set the cookies needed to keep you signed in and to remember your theme choice. There are no advertising or analytics cookies. Clearing them signs you out.
Keeping and deleting your data
We keep your data for as long as your account exists. You can delete individual records at any time from inside the app.
Ask us to delete your account and we will remove your workspaces and their contents within 30 days, apart from anything we are required to keep by law. Encrypted backups age out on their own cycle.
Your rights
You can ask for a copy of the data we hold about you, ask us to correct it, or ask us to delete it. Write to privacy@xeontrix.com and we will answer within 30 days.
Children
PockitTrail is not intended for children under 13, and we do not knowingly collect their data.
Changes to this policy
If we change this policy we will update the date at the top of this page, and we will tell you in the app before any change that materially affects you takes effect.

