Pocket Friends
HomePrivacyTerms

Privacy Policy

Effective: August 19, 2026  ·  Last updated: August 19, 2026

Pocket Friends helps people spend time with friends in the real world. This Privacy Policy explains how Unfold Studio LLC, doing business as Pocket Friends (“Pocket Friends,” “we,” “us” or “our”), collects, uses, discloses, retains and protects personal information when you use our mobile app, website and related services (the “Service”).

Pocket Friends does not sell personal information, show third-party advertising, or use personal information for cross-app tracking or targeted advertising.

1. Scope

This Policy applies to the Service in the United States. A third-party service may process information under its own privacy policy when you use that service through Pocket Friends.

By using the Service, you acknowledge the practices described here. Where consent is required, we ask for it separately.

2. Location Privacy

Location access is optional and requires the operating-system permission. Pocket Friends requests location only while you are using the app; it does not collect location in the background or while the app is closed.

A foreground location fix may be used for the friend radar, nearby-place and neighborhood searches, venue selection, check-ins and location-sharing actions you choose. If precise sharing is off, the coordinate stored for sharing is rounded to approximately 110 meters.

Your stored current location is not public. It may be shown only to eligible accepted friends when both people have an active availability window and the applicable audience, block and Ghost-mode controls allow it. A point older than 15 minutes is not disclosed.

Pocket Friends physically clears stored current coordinates after the same 15-minute limit. A database job runs each minute to erase stale coordinates and coordinates whose age cannot be established.

We send a location fix or search text to Google Places or Geocoding when a nearby-place, venue or neighborhood request needs it. A chosen venue or meetup check-in may remain in the related plan or shared history as described in Section 7.

Location can be delayed or inaccurate. Pocket Friends is not an emergency-response, personal-security or family-monitoring service. Share only with people you trust.

3. Information We Collect

A. Account and Profile

  • A display name you choose and an internal profile identifier;
  • A telephone number if you upgrade an anonymous account using SMS verification;
  • A 13-or-older self-attestation during account creation; and
  • An optional avatar photo and profile or privacy settings.

This release has no account-email field, account password, date-of-birth or age-range field. Support email you voluntarily send is a support communication, not an account identifier.

B. Friends, Plans and User Content

  • Friend connections, requests, invitations, groups, close-friend choices, blocks and mutes;
  • Availability, mood, activities, public-place selections, plans, RSVPs, check-ins and attendance history;
  • Hang or event titles and descriptions, constrained friend or group pings and messages, and report notes; and
  • For web RSVP features, guest names, response status, plus-one names, optional decline notes, and wall posts or reactions when the host enables them.

Pocket Friends does not offer a general public feed or unrestricted direct-message inbox in this release. It does not accept video uploads.

C. Contacts

If you grant Contacts permission, the app reads contact names and phone numbers locally to help find people you know. Contact names, raw phone numbers and contact email fields are not uploaded. The app sends deterministic, salted phone-derived hashes for matching. We do not invite contacts without your direction.

D. Avatar Processing

If you choose an avatar, the app re-encodes the selected image to remove embedded metadata. Google Cloud Vision receives the re-encoded candidate image for SafeSearch classification before an approved avatar is stored by Supabase. No facial-recognition or biometric template is created.

E. Device and Operational Data

  • An Expo or Apple push token, notification preferences and delivery status;
  • App version, device and operating-system context needed to operate the Service; and
  • IP address, request timestamps and security logs ordinarily processed by our hosting and delivery providers.

This release has no payment SDK, advertising SDK or dedicated crash-reporting SDK.

F. Optional Product Analytics

Product analytics is off unless you explicitly turn it on. When enabled, PostHog may receive your internal profile identifier, event names or statuses, app/device context, and limited behavioral properties such as a public Google place identifier, bucketed check-in distance or feature state.

We do not intentionally send contact values, user-authored text, notification copy or coordinates to PostHog. Client and server analytics use the current account-level consent record. Turning analytics off stops new analytics forwarding and clears queued client analytics.

4. How We Use Information

  • Create, authenticate and maintain accounts;
  • Connect accepted friends and operate availability, radar, poke, planning, RSVP, group, check-in and messaging features;
  • Deliver push notifications and SMS verification;
  • Return nearby places, venues and map context;
  • Apply audience, Ghost, block, mute, content-safety and abuse-prevention controls;
  • Respond to reports, support requests and legal obligations;
  • Secure, debug and maintain the Service; and
  • Analyze and improve the product only when optional Product analytics is enabled.

We do not use precise location to infer sensitive characteristics or to target advertising.

5. How We Disclose Information

A. People You Choose

Accepted friends or plan participants see information according to the feature, audience and safety controls you use. For example, an eligible friend may see your current location, a plan participant may see your RSVP or message, and a host may see guest and moderation details needed to operate an event.

B. Processors

ProcessorInformationPurpose
SupabaseAccount identifier, phone-auth records, profile/social content, settings, location, contact-derived hashes, push tokensAuthentication, database, storage, realtime and server functions
Twilio through Supabase AuthPhone number and SMS delivery metadataSend and verify phone one-time codes; send event SMS only when that feature is enabled
Expo and Apple Push Notification servicePush token, notification payload and delivery metadataDeliver and diagnose notifications
Google Places / GeocodingSearch text and coordinates used for a nearby-place, venue or neighborhood requestReturn public place and map context
Google Cloud VisionRe-encoded candidate avatar imagePre-publication SafeSearch classification
PostHogInternal profile identifier and limited product-interaction data, only after opt-inOptional product analytics; never advertising or cross-app tracking

C. Legal, Safety and Business Disclosures

We may preserve or disclose information when reasonably necessary to comply with valid legal process, respond to an emergency involving serious harm, investigate fraud or abuse, enforce our agreements, protect users or defend legal claims.

Information may also be transferred in a merger, financing, acquisition, reorganization, bankruptcy or asset sale. We will provide notice where required before materially different privacy practices apply.

D. Your Direction and Deidentified Data

We disclose information when you direct us to share it. We may also use or disclose aggregated or deidentified information that is not reasonably capable of identifying a person, and we do not attempt to reidentify data maintained as deidentified except to test our protections.

6. No Sale, Advertising or Tracking

Pocket Friends does not sell personal information for money, sell precise location, share personal information for cross-context behavioral advertising, show third-party advertising, or use personal information to track you across other companies’ apps or websites.

If these practices change, we will update this Policy and provide any notice, consent or opt-out required before the new practice begins.

7. Retention and Account Deletion

We retain information only as long as reasonably necessary for the purposes described here, subject to the following release-specific rules:

  • Current Radar coordinates: physically cleared after 15 minutes; a once-per-minute job erases stale and unknown-age values;
  • Account, profile, social and plan data: generally while your account or the shared record remains active;
  • Avatar: until replaced or the account is deleted; object deletion is queued and may finish shortly after the account transaction;
  • Contact-derived hashes and push tokens: while needed for matching or delivery, until replaced, unregistered or the account is deleted;
  • Optional analytics: according to the configured PostHog project retention and only for data sent while consent was active;
  • Reports, blocks and moderation evidence: as reasonably needed for safety, integrity, dispute resolution and repeat-abuse prevention; and
  • Backups and provider logs: removed or overwritten through ordinary security and backup cycles, subject to legal obligations.

You can delete your account in the app. Deletion removes the auth identity, phone, private profile fields, devices, contact-matching rows and current coordinates. It also signs out the account.

Deletion is not an absolute erasure of every shared or safety record in one transaction. A pseudonymous profile tombstone may remain where shared session history references it. Reports, blocks placed by other people, moderation evidence and shared history may be retained for safety, integrity, legal obligations and other users’ records. Copies saved by another person are outside our control.

8. Your Controls and Rights

  • Decline or revoke Contacts, Photos, Location and Notifications permissions in device settings;
  • Use availability, audience, precision, Ghost, block and mute controls;
  • Keep Product analytics off, turn it on, or withdraw consent in Settings;
  • Edit available profile and notification settings;
  • Report a user or content; and
  • Delete your account in the app.

Depending on where you live, you may also request access, correction, deletion or portability; withdraw consent; appeal a privacy-request decision; or exercise other rights provided by law. Contact support@pocketfriends.app. We may verify your identity and authority before acting.

Because Pocket Friends does not sell personal information or use it for targeted advertising, a sale or targeted-advertising opt-out does not change our current practices.

9. Notice at Collection

CategoryExamplesPurposes / recipients
IdentifiersDisplay name, phone number, profile ID, IP address, push tokenAccounts, authentication, delivery and security; processors in Section 5
Internet or electronic activityOptional product interactions, request and delivery recordsService operation and security; PostHog only after analytics opt-in
Precise and coarse geolocationForeground coordinates, timestamps, chosen venues and check-insRadar, nearby places, planning and check-ins; eligible friends, Supabase and Google as described above
Sensory informationOptional avatar photoProfile display and SafeSearch moderation; Supabase and Google Cloud Vision
Communications and user contentPings, plan or RSVP content, report and support notesDeliver the feature, safety and support; intended recipients and Supabase
Social informationFriends, groups, requests, blocks and mutesConnections, audiences and safety; other users as directed and Supabase
Sensitive informationPrecise location and message contentsProvide requested app functionality and safety; no advertising or tracking

We collect these categories from you, your device, other users and the processors listed in Section 5. We retain them according to Section 7.

10. Users Age 13 and Older

Pocket Friends is for people age 13 and older. Account creation requires a checkbox confirming the user is at least 13, but we do not collect a date of birth or age range and do not independently verify age in this release.

Because we do not distinguish teen accounts from adult accounts, location, audience, no-advertising, block and report protections apply to every account. A parent or guardian who believes a child under 13 used the Service should contact support@pocketfriends.app.

11. Security

We use administrative, technical and organizational safeguards designed to protect information, including access controls, encryption in transit, scoped database permissions, monitoring, secure development and incident response. No system is completely secure.

Protect access to your device and verification codes. We will notify affected people and regulators of a security incident when required by law.

12. Changes to This Policy

We may update this Policy when the Service, our practices or the law changes. The Last updated date identifies the current version. We will provide prominent notice or renewed consent when required, including before materially expanding the use of precise location or other sensitive information.

13. Contact Us

Unfold Studio LLC42 West StBrooklyn, NY 11222United Statessupport@pocketfriends.app

Privacy Policy  ·  Terms of Service  ·  Home

© 2026 Unfold Studio LLC, d/b/a Pocket Friends. All rights reserved.