Privacy Policy

Effective date: 19 July 2026 · Last updated: 5 August 2026

This is a first draft prepared for review by a qualified UK solicitor before production release. It only describes technology and safeguards that are actually implemented.

1. Who is the data controller

Okunola Digital Studio Limited is the data controller for personal data processed through WealthPocket.

2. Contact details

Privacy questions and rights requests: hello@wealthpocketapp.com.

3. Personal information collected

Your first name, email address (if you create an account), and the information described below.

4. Financial profile information

Your chosen income band and financial goals, used to tailor the 52-week path.

5. Net worth, asset and debt information

The account names, types, balances, and optional liability details (provider, interest rate, monthly payment, linked property, notes) you choose to enter, plus month-end snapshots of your totals and their composition.

6. Onboarding answers

Name, income band and goals selected during onboarding.

7. Goals and responsibilities

The goal categories you select (for example saving, investing, debt, family).

8. Coach conversations and prompts

Messages you send to Ada and a summary of your progress (never your raw account balances; net worth is rounded) are processed to generate replies and metered for fair use.

9. Device and diagnostic information

If you send feedback from inside the app, we receive your message along with the screen you sent it from, your app version and build number, your device model and your OS version, so we can reproduce the problem without asking you to describe your phone. If you email a bug report instead, the draft includes the same details and you can delete any line before sending. If the app crashes, a crash report is sent automatically (section 21a).

10. Usage and analytics information

We use a product analytics tool to understand whether the app works and where people get stuck. It receives a fixed list of product events — for example that the app was opened, that onboarding finished, that a week was completed, or that a paywall was opened — and never records your screen, your taps or the pages you view. Section 21a sets out exactly what is and is not sent, and how to ask for it to be erased. Server logs (for security and rate-limiting) include hashed IP addresses, never raw ones. We run no advertising SDKs and no ad networks.

11. Subscription and purchase-status information

Your subscription status (active plan, renewal events) is received from Apple via RevenueCat so the app can unlock what you paid for. We never see your card details.

12. Support emails and attachments

Emails you send to our support address, including anything you attach, are kept as long as needed to resolve your query.

13. Where the information comes from

Directly from you, from your device (diagnostics you choose to send), and from Apple/RevenueCat (purchase status).

14. Why each category is processed

To provide the service you asked for (tracking, curriculum, coach), to operate subscriptions, to keep the service secure and fairly used, and to answer your messages.

15. Lawful basis for each processing purpose

Performance of a contract (providing the app and subscriptions); legitimate interests (security, abuse prevention, service improvement); consent where required (for example notifications); legal obligation (tax and accounting records for purchases).

16. AI processing and AI service providers

Ada is powered by Google's Gemini API. Your questions and a rounded progress summary are sent to Google to generate answers. Conversations are not used by us to train models. Do not include information in coach messages that you do not want processed by an AI provider.

17. Analytics and crash reporting providers

Two, both hosted in the EU: PostHog (product analytics, EU Cloud) and Sentry (crash reporting, European region). Neither receives your balances, account names, net worth, goals or anything you type. Section 21a describes what each one gets.

18. Cloud hosting and database providers

Supabase hosts our database in London (UK/EU infrastructure). Row-level security ensures your records are only readable by your authenticated account.

19. Authentication providers

Supabase Auth manages accounts. Sessions are stored on your device in the iOS keychain.

20. Apple and Google sign-in

If you sign in with Apple or Google, we receive your verified email (or Apple's private relay address) and no password. We never see your Apple or Google credentials.

21. Who information is shared with

Only the processors needed to run the service: Supabase (hosting and authentication), Google (AI processing for Ada), Resend (sending account emails such as confirmation and password reset), Google Workspace (our support mailbox), Netlify (website hosting), RevenueCat (subscription management), Apple (billing), Sentry (crash reporting) and PostHog (product analytics). We do not sell personal data and we do not show ads. If you pair with an accountability partner, they see your first name and weekly progress only — never balances, accounts or ledger; this is enforced at the database level.

21a. Crash reporting and product analytics

We use two tools to understand whether the app works and where people get stuck. Both are configured deliberately narrowly, and both store their data in the EU.

Neither tool receives your balances, account names, net worth, goals, journal entries or anything you type. The only identifier attached to either is your account's internal ID — a random value that means nothing outside our own database — and it is cleared when you sign out. Deleting your account removes it from our records; ask us at the address above if you also want your Sentry and PostHog history erased.

22. International data transfers and safeguards

Our database is in London, our account emails are sent from within the EEA (Ireland), and our crash reporting and product analytics are hosted in the EU (Sentry on its European region, PostHog on EU Cloud). Some processors (Google, RevenueCat, Apple, Netlify) may process data outside the UK; where they do, transfers rely on UK-approved safeguards such as the UK Addendum to Standard Contractual Clauses or adequacy regulations.

23. Retention periods

Your data is kept while your account exists. Deleting your account permanently deletes your server-side records. Support emails are kept up to 24 months. Purchase records are kept as required by law.

24. Security measures

What is actually implemented: TLS in transit; the app's local financial data is encrypted at rest on your device with AES-256-GCM, with the key held in the iOS keychain; database row-level security; signed webhooks; server-side rate limiting; hashed IP addresses. We do not claim end-to-end encryption: our servers process your synced data to provide the service.

25. Account deletion

Profile > Delete account permanently deletes your account and all server-side data (accounts, history, progress, partner links, coach usage records). For security this requires a recent sign-in.

26. Your rights

You have rights of access, correction, deletion, restriction, portability and objection under UK GDPR. Email hello@wealthpocketapp.com and we will respond within one month.

27. Automated decision-making and profiling

We do not make legally significant automated decisions about you. The app tailors educational content to the income band and goals you choose; Ada generates educational responses. Neither produces legal or similarly significant effects.

28. Children's privacy

WealthPocket is not intended for under-18s and we do not knowingly collect children's data. If you believe a child has created an account, contact us and we will delete it.

29. Marketing choices

We do not send marketing emails unless you opt in (for example a waitlist). Every marketing email includes an unsubscribe link. In-app notifications are off by default and controlled in Profile.

30. Changes to the policy

Material changes will be notified in the app or by email, with the dates above updated.

31. How to complain to WealthPocket

Email hello@wealthpocketapp.com with "Privacy complaint" in the subject. A real person reads and answers every message.

32. Right to complain to the ICO

You can also complain to the UK Information Commissioner's Office at ico.org.uk/make-a-complaint or on 0303 123 1113.