Legal

Privacy Policy

What we collect

Your email (for email-code sign-in), or the identifier Apple or Google shares when you continue with those buttons. Older versions of the app also offered a guest mode, which stored a throwaway account; those accounts are deleted automatically when unused. Your study activity (answers, review schedule, streaks), your chosen exam sitting, and purchase records. We store your device's local timezone with each event so daily/weekly boundaries are correct for you. Apple may give us a Hide My Email address instead of your personal inbox.

Study reminders (optional). If you turn on the daily reminder, we also store a push notification token for your device (issued by Apple or Google through Expo's push service), whether the device is iOS or Android, and the hour you chose. If you never turn reminders on, no push token is collected.

Crash reports. If the app crashes, a report is sent to our error-monitoring provider (Sentry, a US-based provider). It contains technical details about the crash and your account identifier. It does not include your email, sign-in tokens, answers or notes. The app also sends an anonymous session signal so we can tell how many installs crash.

App usage signals. Newer versions of the app may record when you open the app and how far you get through setup, together with the app version and whether the device is iOS or Android. They never include question text, your answers, your notes or anything you type. We keep them for up to 180 days.

Sign-in records. The one-time sign-in code we email you and the record of the request are kept for 24 hours and then deleted. We also limit how many codes can be requested for an email address or from one network, to protect accounts, and keep a short-lived technical record of those requests (hashed, not your address) for up to two hours.

How we use it

To run the app: schedule your reviews (FSRS), show your stats, apply your plan, and process referrals and payments. We also look at study activity in aggregate and per account (for example how many people study each day, where new users stop, who stopped studying) to fix problems and improve the app. We don't sell your data, and there are no ads. The push token is used only to send the study reminders you turned on (for example, a nudge if you haven't studied today, your streak, or your exam countdown), never for marketing.

Who at PocketPass can see your data

A small number of PocketPass staff use an internal admin tool. It shows each account's email address, sign-up date, study activity (questions answered, accuracy, last active, streak, exam sitting), plan status and any questions the account reported. Staff can export a list of accounts with these fields as a spreadsheet, and can write private notes about an account (for example that we emailed you for support). Every time staff open an account or export a list, the admin tool records who did it and when. Staff use this to give support, keep the service running and understand how the app is used. It is not shared outside PocketPass except with the providers listed here.

Where it's stored

Data is stored with our infrastructure provider (Supabase, hosted in Canada in the ca-central-1 region). Email delivery uses a third-party provider. Our hosting provider also keeps ordinary technical logs of requests (such as IP address and time) for a short period. Sign in with Apple or Google is verified with those companies. If any processing occurs outside Canada, we'll disclose it here (PIPEDA cross-border notice).

Cross-border notice for reminders: reminders are delivered through the Expo push notification service (operated by Expo, a US-based provider), which passes them to Apple's or Google's notification service. These providers receive your push token and the text of the reminder, and process it outside Canada.

Other cross-border processing: crash reports go to Sentry (United States). Our application servers are hosted on Vercel, so requests may be handled in the United States before the data reaches the database in Canada.

Your rights (PIPEDA)

You can download your data anytime from Settings → Your data → Download my data (it includes your account, answers, review schedule, mock exams, saved questions, notes, reminders, sign-in methods, reports you sent, app usage signals and any staff notes about your account), and delete your account from Settings → Your data → Delete account (permanent deletion after a 30-day grace period). You can also ask us to correct your information or withdraw consent by writing to privacy@pocketpass.ca. If you are not satisfied with how we handle your information you can complain to the Office of the Privacy Commissioner of Canada (priv.gc.ca).

How to request account and data deletion

In the app, open Settings → Your data → Delete account (the Settings tab is called Me in older versions of the app). Deletion is permanent after a 30-day grace period. If you cannot open the app, email hello@pocketpass.ca from the address on the account and ask us to delete it. We will confirm and start the same 30-day deletion. You can also email privacy@pocketpass.ca.

Retention

We keep your data while your account is active. Guest accounts that have not been used for 30 days are deleted automatically. On deletion, data is purged after the 30-day grace window, except records we must retain for legal/accounting reasons. If you turn study reminders off, we stop sending them and delete your push tokens (this happens on our server, so it applies to every version of the app). A push token is also deleted when your account is purged, or if the push service reports that it is no longer valid.

Last updated: 7 October 2026. Privacy officer and contact: privacy@pocketpass.ca