Legal

Privacy Policy

Last updated

Pocketbell is built to know as little about you as it can while still delivering your notifications. This policy covers the Pocketbell apps for iPhone, iPad and Mac, the Pocketbell service at api.pocketbell.dev, and this website. Pocketbell is made by SR WORKS LLC (“we”).

The short version

  • You sign in with Apple, and we never ask for your name or email address.
  • We keep the notifications your Sources send so they can show in your inbox, for as long as your plan’s history lasts, then we delete them.
  • There is no advertising, no tracking, and no analytics in the apps.
  • You can delete your account from the app at any time, and everything goes with it.

What we collect

Your account

When you sign in with Apple, we receive Apple’s stable identifier for you, and nothing else: Pocketbell requests neither your name nor your email address. We keep a hash of each session token your devices use, never the token itself.

Your devices

For each device you sign in on, we keep its name, its platform (iPhone, iPad or Mac), the push token Apple issues for it, and your settings for it, such as its sounds, quiet hours and which Sources it receives. If you use Live Activities, we keep the tokens Apple issues for them.

Your notifications

We store what your Sources send: titles, messages, links and their titles, action buttons, tags, image addresses, and the delivery details, such as priority, sound and schedule. We also record each notification’s state on each device: when it was sent, when the device reported it delivered, when it was read, acknowledged or answered, and on which device, with the answer given. For a webhook Source, we keep the most recent event it received, so the app can show it while you set up the Source.

For a Claude Code Source, Claude Code sends us each permission prompt: the tool’s name, its input (such as the command, or the file and the edit), the project’s folder name, and Claude Code’s session identifier. A prompt answered at your computer before we notify you is discarded once it’s answered. One that reaches your devices is kept like any other notification. Commands can contain secrets, so don’t use a Claude Code Source where that matters to you.

Images are not stored by us. Your devices download an attached image directly from the address the sender gave.

Your Sources

We keep each Source’s name and settings. API keys are stored only as hashes, and webhook addresses carry long random secrets. A Source’s signing secret for callbacks is kept as is, because signing requires it.

Purchases

When you buy Pocketbell Pro, Apple handles the payment. We receive the signed transaction from the App Store, including the product, the dates, and whether it was renewed, refunded or canceled, so the server knows your plan. We never see your payment details.

Quiet hours

If you set quiet hours, we keep the hours and your time zone, so Normal notifications can arrive silently at the right time.

Technical logs

Our servers keep short-lived technical logs, which include IP addresses, to operate the service and protect it from abuse.

What we don’t collect

No name, no email address, no contacts, no location, no advertising identifier, and no analytics or tracking of any kind in the apps. We don’t sell data, and we don’t share it with anyone for advertising.

How long we keep it

  • Notifications are deleted once they are older than your plan’s history: 7 days on Free, or 90 days on Pro. A notification you delete has its text erased from our servers at once.
  • Devices are removed when you remove them in the app, and their push tokens are discarded when Apple reports them no longer valid.
  • Sessions end when you sign out, or after 90 days unused.
  • Your account and everything in it is deleted when you delete your account in the app (Settings, then Delete Account). At the same time we ask Apple to revoke Pocketbell’s access to your Sign in with Apple ID.

Backups of our database are kept for disaster recovery, and deleted data leaves them as they expire.

Who else is involved

  • Apple provides Sign in with Apple, delivers every notification through the Apple Push Notification service, and processes App Store purchases.
  • OVHcloud hosts our servers, in Canada and the United States.
  • Cloudflare serves this website and our DNS, and handles the email sent to [email protected]. It sees visitors’ IP addresses as part of doing so.

Nothing in Pocketbell’s delivery path uses Google or Firebase.

Security

Everything between the apps, the senders and our servers travels over HTTPS. API keys and session tokens are stored only as hashes. Every address our servers contact for you, such as a callback, is checked so it cannot be used to reach private networks.

This website

pocketbell.dev sets no cookies and runs no analytics. It uses your device’s own fonts and loads nothing from other websites.

Your rights

You can see your notifications, Sources and devices in the app, and delete any of them, or your whole account, there. If you’d like a copy of your data, or have a question about it, email [email protected]. Depending on where you live, including the EU, the UK and California, you may have further rights over your data, and you can use them the same way.

Children

Pocketbell is not directed at children under 13, and we do not knowingly collect data from them.

Changes

If this policy changes, we’ll update this page and the date at the top. For a significant change, we’ll tell you in the app as well.

Contact

SR WORKS LLC, [email protected]