Privacy
Your books are not an advertising product.
SamePocket is built for private household and business bookkeeping. We do not sell personal information, run third-party advertising, or track you across other companies’ apps or websites.
Who is responsible
SamePocket (“SamePocket,” “we,” “us,” or “our”) operates the service and is responsible for the practices described here. SamePocket is a United States service for invited adult users. Questions or requests may be sent to [email protected].
Information we collect
- Account and identity information: name, email address, authentication identifiers, household membership, role, and invitation status.
- Business, household, and client information: business profile, addresses, client names and contacts, invoice details, recurring plans, notes, categories, splits, and review decisions.
- Financial information: financial institution and account names, account type, masked account numbers, transactions, dates, amounts, and merchant descriptions. SamePocket does not receive the bank password you enter inside Plaid Link. If you connect Nickel, SamePocket stores a limited read-only snapshot of invoice and bill status, due date, and outstanding amount; provider record identifiers are hashed.
- Documents and communications: tax or bookkeeping documents you choose to upload, invoice PDFs, support messages, and attachments you deliberately send.
- Device, service, and security information: app and operating-system version, IP address, request time, authentication and audit events, error details, and similar information needed to operate, secure, and troubleshoot the service. We do not include third-party advertising or behavioral-analytics SDKs.
- Luna requests and decisions: questions you deliberately send, the selected skill, limited client names and internal IDs, recent cash and invoice summaries, the response, confidence, member attribution, and review decisions. SamePocket does not retrieve bank credentials, provider tokens, account numbers or client contact details for Luna context. If you confirm Read receipt, the first supported original attachment is sent to OpenAI and may contain private information printed on that document. Do not include secrets in questions or attachments.
- AI app connections through MCP: the app name, selected Pocket, authorizing member, access scope, connection and expiry times, minimal tool-access events, and proposed changes with review details and decisions. Access events record the tool and attribution, not its arguments, returned financial content or credentials.
Where information comes from
We receive information from you; another person who invites you to a shared SamePocket household; the devices and browsers you use; Plaid and the financial institutions you authorize; and service providers that help us authenticate, host, protect, back up, or support SamePocket.
How we use information
- Provide account access and keep an invited household’s shared books synchronized.
- Import authorized account data, suggest matches or categories, preserve your decisions, and create summaries and exports.
- Create and review invoice drafts and, when you connect Nickel, read limited invoice and bill status. SamePocket cannot create, change, send, pay, refund, or delete anything through Nickel.
- Send account, security, service, beta, and support messages.
- Detect abuse, protect accounts, diagnose failures, maintain backups, and comply with law.
- Manage the early-access list and understand how a request reached our website.
SamePocket does not use financial or bookkeeping information to advertise to you, build advertising profiles, or make decisions about credit, employment, housing, insurance, or eligibility.
Shared households
People you invite can see shared information. Members of a SamePocket household may be able to view its connected accounts, transactions, classifications, invoices, clients, documents, and activity. Review the person and role before accepting or sending an invitation. Do not add someone who should not see the household’s business and personal finances.
When we disclose information
- To your household members, according to the membership and role you choose.
- To Plaid and connected financial institutions, when you choose to connect, refresh, or disconnect an account. Plaid describes its practices in its End User Privacy Policy.
- To Nickel, only when a household owner or admin chooses Connect, Sync, or Disconnect. SamePocket uses Nickel’s OAuth and MCP services for the requested read-only status sync and token revocation. Nickel describes its practices in its Privacy Policy.
- To OpenAI for Luna, only when a household member deliberately invokes a Luna action. The app explains which limited records accompany the question and asks separately before sending a receipt original. Responses are drafts or suggestions; creating shared client or invoice drafts requires owner/admin review. OpenAI describes its API data practices in its Enterprise Privacy information.
- To AI apps you authorize through MCP, when they request permitted shared records from the selected Pocket. These apps may include ChatGPT, Claude, Codex or another compatible client. Their providers' own privacy, retention and account settings govern information they receive; the Luna-specific API settings below do not apply to these separate connections.
- To vendors working for SamePocket, for hosting, Cloudflare network protection and delivery, authentication, email, encrypted backups, and support. They may process only the information needed for the service they provide and are expected to protect it.
- For legal or safety reasons, when reasonably necessary to comply with law, protect rights and security, investigate abuse, or respond to lawful process.
- In a business transaction, such as a financing, merger, acquisition, or sale, subject to appropriate confidentiality and notice where required.
We do not sell or rent personal information. We do not share it for cross-context behavioral advertising or targeted advertising.
Bank connections and consent
Connecting a financial account is optional. Plaid Link handles institution credentials and consent; SamePocket receives the authorized account and transaction information plus an encrypted server-side token used to keep that connection working. Disconnecting stops new retrieval and asks Plaid to remove SamePocket’s connection. Imported bookkeeping records remain in the shared pocket. You can archive a transaction to hide it from daily queues and later restore it; archiving is not deletion and does not rewrite accounting history.
Nickel
A household owner or admin may optionally connect Nickel Plus in Settings. OAuth access and refresh tokens are encrypted on the SamePocket server and never stored in the app. SamePocket permits only the read-only invoice and bill search tools, stores a limited normalized snapshot, and blocks every Nickel tool that could create, change, send, pay, refund, or delete. Disconnect asks Nickel to revoke the grant and removes the cached snapshot.
SamePocket AI
Luna memory: explicitly saved preferences stay separate for each Pocket and sync through Apple's iCloud key-value storage. Without iCloud they remain local and are not automatically copied into a newly signed-in iCloud account. Luna requests send saved rules as preferences, not permission to change records. Full rule lists are not stored in AI history, but author-private responses may reference them; approved changes can enter shared records. Forgetting a rule affects future requests after sync, not previous responses or exports. Markdown exports contain rule text, including any private details you typed. Review before sharing; the file grants no Pocket access. Imports are reviewed independent copies; later edits do not automatically cross family members' Apple accounts. MCP does not receive this private device memory.
An owner or admin can enter an OpenAI API key in Luna setup. SamePocket encrypts it on the server for that Pocket and never returns it to clients or includes it in prompts. Other owners/admins may replace or remove it; members' AI requests use the configured key and its API budget. The connection test sends the key only to OpenAI to check model access, with no accounting records. Removing a Pocket key does not revoke it at OpenAI, stop an already-running request, or remove an independently configured server fallback key. Encrypted copies may remain in backups under the retention policy below.
Luna can query all saved transaction history in the active Pocket's shared accounts and the requesting member's private accounts, including inactive accounts; archived entries and demo accounts are excluded. Relevant records, client/cash/invoice summaries, the current message, limited recent conversation, saved memory and optional finance profile are sent to OpenAI. Saved AI history is restricted to its author; approved client/invoice drafts and shared-account classifications become shared bookkeeping records. Closing chat clears the on-screen conversation, not saved work. Casual responses expire after 30 days. Structured suggestions and review decisions remain under the retention rules below. Original receipt files remain in the receipt inbox; full prompts and private memory documents are not stored in AI history. Requests use OpenAI's store=false setting, not a guarantee of zero provider retention.
Optional retailer lookup sends only a cleaned merchant label from an authorized saved transaction to a separate OpenAI web-search request, without conversation, amounts or account IDs. Cited summaries are cached per member/Pocket for seven days and saved in AI history. Optional after-sync review runs while the app syncs. Simple saved merchant rules are evaluated without paid AI; unclear new expenses may receive one paid proactive review per member/Pocket per rolling 24 hours. Only a hash of supplied rules is stored for cross-device deduplication. Finance profiles and review preferences sync through SamePocket's server. Category proposals require explicit in-app approval and are checked against the transaction's current version. Duplicate, unusual-amount and nearby-receipt hints do not delete or link records. Bill and budget worksheets do not post ledger entries or prove payment. Luna cannot send invoices, move money, confirm payment, disconnect banks or delete records.
Chat, retailer lookup and proactive review share a maximum $5 monthly allowance per Pocket across devices, using conservative reservations and cost estimates. Interrupted requests may retain a reservation or conservative charge. This allowance does not limit external use of the same API key, taxes, or other provider charges; use a dedicated OpenAI project with its own provider spending controls.
Connect your AI through MCP
An owner or admin can authorize an AI app for one selected Pocket in Settings → Connect your AI. The pairing review shows the requesting app and return address. Read access shares permitted account and transaction details, client names and email addresses, invoices and line items, receipt metadata, shared family-plan records and cash summaries. Member-owned private bank accounts and their transactions, private family plans, demo records, bank credentials, provider tokens, account identifiers, payment URLs, raw receipt email and original attachment files are excluded. Internal SamePocket record IDs may be included to identify records. The connection reads saved information; it does not refresh banks or Nickel.
Allowing proposals lets the app submit client, invoice-draft, shared-budget, category, receipt-match, and shared-account tag/default-use changes for review. By default, an owner or admin approves the exact change inside SamePocket. The connection creator may separately enable chat editing for that connection in SamePocket; when enabled, the originating AI client can apply only the exact saved proposal through its write tool. ChatGPT or Claude controls whether it displays a confirmation prompt, and SamePocket cannot force that prompt if you configure the client to allow the tool automatically. Keep the apply_proposal tool set to Ask and do not remember or always allow its approval. Proposals expire after seven days, and conflicting changes require a new proposal. MCP cannot send invoices, pay bills, move money, disconnect banks, delete financial records, or edit member-owned private accounts. This connection does not require or use your separately configured Luna OpenAI API key.
You can revoke access under Connected AI apps in SamePocket. Connections expire after 30 days and are checked against the authorizing member's current membership and role. Revocation stops subsequent requests using that connection; it does not delete information already received by the AI provider, undo approved changes or erase review history. Consult that provider's controls and privacy policy for information already shared. Connection metadata, minimal access events, proposals and decisions remain subject to this policy's bookkeeping, security, backup and deletion provisions; proposal expiry is not deletion of its audit record.
Website and waitlist
When you request early access, we collect the email address you submit and a limited source value from an utm_source or ref parameter or the referring page. Our host and Cloudflare also receive ordinary request and security information such as IP address, browser details, requested page, and time. We use this information only to manage early access, secure the site, and contact you about SamePocket.
The website loads fonts from Google. Your browser therefore makes a request to Google that can include technical information such as your IP address, browser, and referring page. Google’s handling is described in its Privacy Policy. SamePocket does not use advertising cookies or analytics pixels on this site.
Retention and deletion
- Account and bookkeeping data is kept while the account or shared household is active and as needed to provide the service. When an authorized deletion request is completed, active copies are deleted or de-identified unless retention is required for security, dispute resolution, legal compliance, or another purpose we explain.
- Encrypted backups are not used as live records and normally age out on a 30-day rotation. Data removed from the active service may remain inaccessible in those backups until that rotation completes.
- Waitlist information is kept until early access is offered, you ask us to remove it, or it is no longer useful for the beta. Support records are kept only as long as reasonably needed to answer the request, prevent repeated problems, and protect the service.
- Security and audit records are kept for the period reasonably needed to detect, investigate, and document misuse or incidents.
- AI records: casual Ask SamePocket questions and answers expire after 30 days. Structured suggestion, approval, rejection, model, cost, and member-attribution records remain with the household’s bookkeeping audit history.
Third parties keep information under their own policies and legal duties. Removing a SamePocket connection does not automatically delete a separate Plaid account or any separate account you created directly with another provider.
Your choices and rights
You can correct profile and bookkeeping information, manage household access, disconnect a bank, change device permissions, export records, and initiate account deletion through SamePocket. You may also ask to access, correct, delete, or obtain a copy of personal information by emailing us from your account address. We may verify identity and authority before acting. We will respond as required by applicable law and will not discriminate against you for exercising a privacy right.
Read the step-by-step Privacy Choices page. If we cannot honor a request, we will explain why and how to appeal where applicable.
Security
SamePocket uses encrypted network connections, access controls, tenant separation, protected server-side connection tokens, encrypted backups, and limited administrative access designed to protect information. No system can guarantee absolute security. Protect your device and sign-in methods, and email [email protected] promptly if you believe an account or connection has been compromised.
Children and location
SamePocket is intended for adults in the United States and is not directed to anyone under 18. We do not knowingly collect personal information from children. The service is operated in the United States; providers may process information in other locations under their own policies.
Changes
We may update this policy as SamePocket changes. We will update the effective date and provide additional notice before a material change when appropriate. We will request new consent when required rather than applying a materially different use to existing information without notice.
Contact
Email privacy questions or requests to [email protected]. Please do not email bank passwords, full account numbers, tax documents, Plaid tokens, or other sensitive records.