Privacy Policy

Last updated: 1 October 2026

ProducePocket is a tool for buying produce: you build a purchase folder, show product barcodes at the register, record what you paid, and keep receipts. This policy explains exactly what the app stores, what leaves your phone, and what does not.

ProducePocket does not sell your data, does not share it for advertising, and does not use it for advertising or profiling. There is no advertising identifier, no ad network, no analytics or tracking SDK, and no device fingerprinting in the app.

ProducePocket does rely on a small number of outside companies to make the app work — for sign-in, syncing, receipt storage, and handling subscriptions. These are service providers: they process data only to deliver the part of the service they are responsible for, on ProducePocket's instructions, and are not permitted to use it for their own marketing. That is a different thing from selling data or sharing it with advertisers, neither of which happens. Each one is named below, with what it actually receives.

Who processes your data, and what they get

Your account

A signed-in account is required to use ProducePocket — you cannot create a folder, build a catalog, or check out without one. Sign-in is provided by Clerk, an authentication service. Your email address, password, verification requests, and session information are handled by Clerk. If you choose to sign in with Google or Apple instead, that provider also processes your sign-in. Session credentials are stored in your device's secure storage (the iOS Keychain).

Your purchase records and receipts are never sent to Clerk. Your account identifier is also used as your subscription identifier with RevenueCat, so a subscription you buy stays attached to the right account across your devices.

What syncs between your devices

Once you are signed in, the following sync automatically through ProducePocket's own server whenever you have an internet connection, so they are available on any device where you sign in with the same account:

This does not require a subscription. Records are kept strictly separated by account: signing in on a new device pulls down only what belongs to that account. The server stores this data on Cloudflare's infrastructure.

Receipt photos

A receipt photo you take is always saved on your own device first. The actual image file is only ever uploaded to the cloud if you have an active Premium subscription. In that case it is stored as a private file on ImageKit, a third-party image hosting service, by way of ProducePocket's own server — the upload never goes directly from your phone to ImageKit, and viewing a backed-up receipt requires a short-lived link issued only after the server confirms the receipt belongs to your account.

Without an active subscription, a receipt photo stays only on the device that took it, even though the receipt's other details still sync as described above.

Barcode images

An original barcode image — whether imported from your workbook or photographed by you — is never uploaded anywhere, with or without a subscription. It stays on your device. Only the barcode number itself is used and synced.

Camera and photo access

ProducePocket asks for camera and photo library access so you can scan or photograph a barcode, or attach a receipt photo to a folder. A barcode photo is only ever processed on the device and is never uploaded. A receipt photo is handled as described above. The app does not record audio and does not request microphone access.

Exports

When you use an export feature in Settings, the file is created on your device and handed to iOS's own share sheet. You choose where it goes — Files, AirDrop, Mail, or anywhere else. ProducePocket does not send it anywhere and does not keep a copy.

Deleting your account

You can delete your account from within the app, in Settings. Deletion is immediate and permanent: your sign-in, your synced catalog, folders, checkout records, and receipt records, and any receipt photos backed up to the cloud are all erased. This cannot be undone, and there is no recovery window — export anything you want to keep before you delete.

Signing out, by contrast, preserves everything. Signing back in on this device or another brings your synced records back. Removing the app removes its data on that device only; if you were signed in, your synced records are still recoverable by signing in again elsewhere.

Children

ProducePocket is a business tool for produce buyers and is not directed at children. It does not knowingly collect information from anyone under 13.

Changes to this policy

This page describes the app's current account, sync, and storage behavior. If data handling changes, this page will be updated before that change ships.

Contact

Questions about privacy, or a request about your data, go to producepocketsupport@gmail.com.