Privacy
Your books are not an advertising product.
SamePocket is built for private household and business bookkeeping. We do not sell personal information, run third-party advertising, or track you across other companies’ apps or websites.
Who is responsible
SamePocket (“SamePocket,” “we,” “us,” or “our”) operates the service and is responsible for the practices described here. SamePocket is a United States service for invited adult users. Questions or requests may be sent to [email protected].
Information we collect
- Account and identity information: name, email address, authentication identifiers, household membership, role, and invitation status.
- Business, household, and client information: business profile, addresses, client names and contacts, invoice details, recurring plans, notes, categories, splits, and review decisions.
- Financial information: financial institution and account names, account type, masked account numbers, balances, transactions, dates, amounts, merchant descriptions, Nickel invoice and bill records, connection status, and identifiers or tokens needed to maintain a connection. SamePocket does not receive the bank password you enter inside Plaid Link.
- Documents and communications: tax or bookkeeping documents you choose to upload, invoice PDFs, support messages, and attachments you deliberately send.
- Device, service, and security information: app and operating-system version, IP address, request time, authentication and audit events, error details, and similar information needed to operate, secure, and troubleshoot the service. We do not include third-party advertising or behavioral-analytics SDKs.
Where information comes from
We receive information from you; another person who invites you to a shared SamePocket household; the devices and browsers you use; Plaid and the financial institutions you authorize; Nickel when you authorize its read-only connection; and service providers that help us authenticate, host, protect, back up, or support SamePocket.
How we use information
- Provide account access and keep an invited household’s shared books synchronized.
- Import authorized account data, suggest matches or categories, preserve your decisions, and create summaries and exports.
- Create and review local invoice drafts, synchronize authorized Nickel invoice and bill records, and display read-only summaries. The current beta does not create, change, send, pay, or cancel anything in Nickel.
- Send account, security, service, beta, and support messages.
- Detect abuse, protect accounts, diagnose failures, maintain backups, and comply with law.
- Manage the early-access list and understand how a request reached our website.
SamePocket does not use financial or bookkeeping information to advertise to you, build advertising profiles, or make decisions about credit, employment, housing, insurance, or eligibility.
Shared households
People you invite can see shared information. Members of a SamePocket household may be able to view its connected accounts, transactions, classifications, invoices, clients, documents, and activity. Review the person and role before accepting or sending an invitation. Do not add someone who should not see the household’s business and personal finances.
When we disclose information
- To your household members, according to the membership and role you choose.
- To Plaid and connected financial institutions, when you choose to connect, refresh, or disconnect an account. Plaid describes its practices in its End User Privacy Policy.
- To Nickel, when you connect, synchronize, refresh, or disconnect the read-only integration. The current beta does not send invoice or client information from SamePocket to a recipient through Nickel. Nickel describes its practices in its Privacy Policy.
- To vendors working for SamePocket, for hosting, Cloudflare network protection and delivery, authentication, email, encrypted backups, and support. They may process only the information needed for the service they provide and are expected to protect it.
- For legal or safety reasons, when reasonably necessary to comply with law, protect rights and security, investigate abuse, or respond to lawful process.
- In a business transaction, such as a financing, merger, acquisition, or sale, subject to appropriate confidentiality and notice where required.
We do not sell or rent personal information. We do not share it for cross-context behavioral advertising or targeted advertising.
Bank connections and consent
Connecting a financial account is optional. Before Plaid Link opens, SamePocket explains the requested data and purpose. Plaid Link handles institution credentials and consent; SamePocket receives the authorized account and transaction information plus a server-side token used to keep that connection working. Disconnecting stops new account data from being retrieved and asks Plaid to remove SamePocket’s connection. Bookkeeping records already imported remain until you delete them or the applicable account or household is deleted.
Nickel connection and consent
Connecting Nickel is optional. Nickel handles sign-in and consent; SamePocket receives a server-side OAuth grant and uses a fixed allowlist limited to searching invoices and bills. The app receives summaries and a small set of items needing attention. It has no generic Nickel tool endpoint and the current beta cannot create customers, create or send payment links, upload invoice files, move money, pay bills, issue refunds, or change Nickel records.
SamePocket encrypts the OAuth credentials and stores synchronized invoice and bill snapshots inside the connected household’s protected server records. Disconnecting asks Nickel to revoke the grant, clears the credentials, and deletes the synchronized Nickel snapshot from SamePocket. It does not delete the separate Nickel account or records held by Nickel.
Website and waitlist
When you request early access, we collect the email address you submit and a limited source value from an utm_source or ref parameter or the referring page. Our host and Cloudflare also receive ordinary request and security information such as IP address, browser details, requested page, and time. We use this information only to manage early access, secure the site, and contact you about SamePocket.
The website loads fonts from Google. Your browser therefore makes a request to Google that can include technical information such as your IP address, browser, and referring page. Google’s handling is described in its Privacy Policy. SamePocket does not use advertising cookies or analytics pixels on this site.
Retention and deletion
- Account and bookkeeping data is kept while the account or shared household is active and as needed to provide the service. When an authorized deletion request is completed, active copies are deleted or de-identified unless retention is required for security, dispute resolution, legal compliance, or another purpose we explain.
- Encrypted backups are not used as live records and normally age out on a 30-day rotation. Data removed from the active service may remain inaccessible in those backups until that rotation completes.
- Waitlist information is kept until early access is offered, you ask us to remove it, or it is no longer useful for the beta. Support records are kept only as long as reasonably needed to answer the request, prevent repeated problems, and protect the service.
- Security and audit records are kept for the period reasonably needed to detect, investigate, and document misuse or incidents.
Third parties keep information under their own policies and legal duties. Removing a SamePocket connection does not automatically delete a separate Plaid or Nickel account you created directly with that provider.
Your choices and rights
You can correct profile and bookkeeping information, manage household access, disconnect a bank, change device permissions, export records, and initiate account deletion through SamePocket. You may also ask to access, correct, delete, or obtain a copy of personal information by emailing us from your account address. We may verify identity and authority before acting. We will respond as required by applicable law and will not discriminate against you for exercising a privacy right.
Read the step-by-step Privacy Choices page. If we cannot honor a request, we will explain why and how to appeal where applicable.
Security
SamePocket uses encrypted network connections, access controls, tenant separation, protected server-side connection tokens, encrypted backups, and limited administrative access designed to protect information. No system can guarantee absolute security. Protect your device and sign-in methods, and email [email protected] promptly if you believe an account or connection has been compromised.
Children and location
SamePocket is intended for adults in the United States and is not directed to anyone under 18. We do not knowingly collect personal information from children. The service is operated in the United States; providers may process information in other locations under their own policies.
Changes
We may update this policy as SamePocket changes. We will update the effective date and provide additional notice before a material change when appropriate. We will request new consent when required rather than applying a materially different use to existing information without notice.
Contact
Email privacy questions or requests to [email protected]. Please do not email bank passwords, full account numbers, tax documents, Plaid tokens, or other sensitive records.