Privacy Policy
Effective 23 September 2026. Last updated 23 September 2026.
Pocket Protect is a product of WeaveHub Technologies LLC, 418 Broadway, Suite N, Albany, New York 12207, United States ("WeaveHub," "we," "us," "our"). This policy explains what we collect, why, how long we keep it, who else sees it, and what you can require us to do. It applies to the Pocket Protect mobile apps, the web portal at app.pocketprotect.ai, and this website.
The short version
We do not sell your personal information, and we never have. We do not use what you submit to train anyone's AI models. Pocket Protect is built so that the content you submit for review lives in storage dedicated to your own Protection Circle, not in a shared pool. Most of what you send us is deleted automatically within 24 hours.
1. Information we collect
- Account information. Your identity as established through Sign in with Apple, Google, Facebook, a passkey, or an email address and password you set with us. Where a provider offers private relay addressing, we accept it; we do not require your real email address.
- Protection Circle data. Membership, roles, display names, invitations, and the order in which trusted people should be contacted.
- Submitted content. The messages, links, screenshots, phone numbers, voicemail, email content, and call material you or someone in your Circle submits for review. This is stored in a database and file storage bucket dedicated to your Circle alone.
- Assessment results. The outcome of a review, the reasons given, and any incident record created from it.
- Billing and entitlement state. Subscription and trial status received from Apple or our web payment processor. We do not receive or store your full card number.
- Technical and security logs. Request identifiers, timestamps, route names, coarse error information, and abuse signals. We deliberately do not log message bodies, transcripts, evidence, credentials, or full URLs.
2. Sensitive information
Content you submit for review may contain sensitive information, because scam messages often do: account numbers, financial details, health references, government identifiers, or one-time codes. We treat all submitted content as sensitive by default. We do not use it to infer characteristics about you, we do not use it for advertising, and we do not sell or share it. Where our systems detect a credential or a one-time code inside submitted content, we replace it with a typed placeholder before any further processing.
3. How we use information
- To assess whether something you submitted shows signs of a scam, and to explain why.
- To notify the trusted people you chose, under the rules you set. Only a High Risk result is shared automatically. Everything else stays private to you unless you ask for help.
- To operate accounts, Protection Circles, invitations, and subscriptions.
- To keep the service secure, detect abuse, and enforce rate limits.
- To meet legal obligations.
We do not use your content for advertising, profiling unrelated to scam assessment, or automated decisions that produce legal or similarly significant effects about you.
4. Artificial intelligence
To assess submitted content we send it to a third-party AI provider, currently OpenAI, through a gateway configured with payload logging and response caching disabled, so the content is not retained by the provider or by the gateway for training or any other purpose. The AI produces findings only. A separate, fixed set of rules decides the result you see, and the AI cannot override it. The AI cannot cause a result to be downgraded to a less cautious level.
5. How we share information
We do not sell personal information, and we do not share it for cross-context behavioural advertising. We disclose information only as follows:
- The people in your Protection Circle, according to the rules described above and the roles you assign.
- Service providers who process data on our instructions and are contractually barred from using it for their own purposes: Cloudflare (hosting, storage, and network security) and OpenAI (assessment, under the conditions in section 4).
- Payment providers, being Apple for in-app purchases and our web payment processor, which handle their own payment data under their own policies.
- Recipients you choose, when you create an evidence export or a secure share link. Those links expire and can be revoked by you.
- Legal and safety disclosures, where we are required by law, or where we believe in good faith that disclosure is necessary to prevent imminent physical harm or serious financial harm.
- Business transfers, if we are involved in a merger, acquisition, or sale of assets. We will give notice before your information becomes subject to a different privacy policy.
6. How long we keep things
- An ordinary submission or monitored call: the raw content is deleted within 24 hours.
- An incomplete upload: deleted after 30 minutes.
- An unconfirmed incident under review: kept while it is open, to a maximum of 90 days.
- A confirmed scam: kept until the protected person approves its deletion, because it is often the evidence a family needs for their bank, the police, or IC3.
- An export or secure share link: expires after a short configured period and can be revoked at any time.
- Account and Circle records: kept while the account exists, then deleted as described in section 8.
- Security logs: retained for a limited period for abuse prevention.
Closing an incident starts a seven-day recovery window before deletion runs, so an accidental closure can be undone. Your subscription status never shortens or lengthens any of these periods. A lapsed or cancelled subscription does not cause your evidence to be deleted sooner.
7. Security
Each Protection Circle is isolated at the infrastructure level, with its own database and its own private file storage. Our shared account system does not hold message bodies, transcripts, attachments, evidence, or mailbox credentials. Credentials and tokens are stored using platform secure storage, never in plain application storage. Access to a resource is derived from verified identity, tenant, role, and operation on every request. Security control failures deny rather than allow.
No system is perfectly secure. If a breach affects your personal information we will notify you and any regulator as required by applicable law.
8. Your rights and choices
Wherever you live, you may ask us to:
- Know what personal information we hold about you and how it is used.
- Access a copy of it in a portable format.
- Correct information that is inaccurate.
- Delete your information, subject to the exceptions in section 9.
- Withdraw consent or close your account at any time.
- Be free from discrimination for exercising any of these rights. We do not offer financial incentives in exchange for personal information.
To exercise any right, see Request Data Deletion, which covers access and correction requests as well. We verify that a request genuinely comes from the account holder before acting on it, because acting on an unverified deletion request would itself be a security failure. We respond within 45 days and may extend once by a further 45 days where permitted, telling you if we do.
You may use an authorised agent where your state allows it. We will ask the agent for proof of authorisation and may still verify your identity directly.
9. State privacy rights (United States)
Residents of California, Colorado, Connecticut, Virginia, and other states with comprehensive privacy laws have the rights listed in section 8, and additionally the right to opt out of the sale or sharing of personal information, of targeted advertising, and of profiling with legal or similarly significant effects.
We do none of those things. We do not sell personal information, we do not share it for cross-context behavioural advertising, we do not serve targeted advertising, and we do not profile you for anything other than assessing the content you ask us to assess. There is therefore nothing to opt out of, and we honour opt-out preference signals such as Global Privacy Control by default because our default is already the maximum opt-out.
California residents may also request the categories of personal information collected, the categories of sources, the business purpose, and the categories of third parties to whom it was disclosed. Those are set out in sections 1, 3, and 5 above. If we decline a request you may appeal by replying to our response; where your state provides one, you may also complain to your state Attorney General.
10. Outside the United States
We operate from the United States and our infrastructure providers process data in the United States and, for network delivery, in the region nearest to you. If you use Pocket Protect from outside the United States, you understand that your information will be transferred to and processed in the United States. Where the UK GDPR or EU GDPR applies to you, our lawful bases are performance of our contract with you for operating the service, your consent for submitting content for assessment, and our legitimate interests in securing the service and preventing abuse. You may object to processing based on legitimate interests, and you may complain to your supervisory authority.
11. Children
Pocket Protect is not directed at children and you must be at least 18 years old to create an account or to be added to a Protection Circle. We do not knowingly collect personal information from anyone under 18. If we learn that we have, we delete it. If you believe a child has given us information, contact us at the address below.
12. Changes to this policy
If we make a material change we will update the date at the top, and we will give notice in the app or by email before the change takes effect. Continuing to use Pocket Protect after a change takes effect means you accept the updated policy.
13. Contact
WeaveHub Technologies LLC, 418 Broadway, Suite N, Albany, New York 12207, United States
Privacy questions: support@pocketprotect.ai
Account and deletion requests: accounts@pocketprotect.ai