Legal
Privacy Policy
What we collect
Your email (for email-code sign-in), or the identifier Apple or Google shares when you continue with those buttons. Guest mode stores a throwaway account so we can cap you at 5 questions a day; it is not a saved study plan. Your study activity (answers, review schedule, streaks), your chosen exam sitting, and purchase records. We store your device's local timezone with each event so daily/weekly boundaries are correct for you. Apple may give us a Hide My Email address instead of your personal inbox.
Study reminders (optional). If you turn on the daily reminder, we also store a push notification token for your device (issued by Apple or Google through Expo's push service), whether the device is iOS or Android, and the hour you chose. If you never turn reminders on, no push token is collected.
Crash reports. If the app crashes, a report is sent to our error-monitoring provider (Sentry, a US-based provider). It contains technical details about the crash and your account identifier. It does not include your email, sign-in tokens, answers or notes. The app also sends an anonymous session signal so we can tell how many installs crash.
How we use it
To run the app: schedule your reviews (FSRS), show your stats, apply your plan, and process referrals and payments. We don't sell your data, and there are no ads. The push token is used only to send the study reminders you turned on (for example, a nudge if you haven't studied today, your streak, or your exam countdown), never for marketing.
Where it's stored
Data is stored with our infrastructure provider (Supabase, hosted in Canada in the ca-central-1 region). Email delivery uses a third-party provider. Sign in with Apple or Google is verified with those companies. If any processing occurs outside Canada, we'll disclose it here (PIPEDA cross-border notice).
Cross-border notice for reminders: reminders are delivered through the Expo push notification service (operated by Expo, a US-based provider), which passes them to Apple's or Google's notification service. These providers receive your push token and the text of the reminder, and process it outside Canada.
Other cross-border processing: crash reports go to Sentry (United States). Our application servers are hosted on Vercel, so requests may be handled in the United States before the data reaches the database in Canada.
Your rights (PIPEDA)
You can download all your data anytime from Settings → Your data → Download my data, and delete your account from Settings → Your data → Delete account (permanent deletion after a 30-day grace period).
How to request account and data deletion
In the app, open Settings → Your data → Delete account (the Settings tab is called Me in older versions of the app). Deletion is permanent after a 30-day grace period. If you cannot open the app, email hello@pocketpass.ca from the address on the account and ask us to delete it. We will confirm and start the same 30-day deletion. You can also email privacy@pocketpass.ca.
Retention
We keep your data while your account is active. On deletion, data is purged after the 30-day grace window, except records we must retain for legal/accounting reasons. If you turn study reminders off, we stop sending them and delete your push tokens (this happens on our server, so it applies to every version of the app). A push token is also deleted when your account is purged, or if the push service reports that it is no longer valid.
Last updated: 30 September 2026. Privacy contact: privacy@pocketpass.ca