Legal

Privacy Policy

1. Who we are

PocketJarvis is a chat-first personal finance assistant for WhatsApp and Telegram, available at pocketjarvis.bornagents.net. The service is operated by MASSA PETRACHE PERSOANA FIZICA AUTORIZATA.

For privacy questions or requests, contact support@bornagents.net.

2. What data we collect

Platform account data. Depending on the channel you use, we may store Telegram identifiers, Telegram chat identifiers, WhatsApp phone identifiers, display names, usernames, language preferences, and message identifiers used for deduplication and routing.

Finance data you provide. We store the expenses, income, budgets, recurring rules, settlements, shopping lists, reminders, merchants, categories, currencies, dates, notes, and group balances needed to run the service.

Documents and receipt data. When you send receipt photos or financial documents, PocketJarvis may store the original file temporarily, an audit record for processing, extracted document fields, invoice metadata, line items, supplier profile data, and pending confirmation state.

Google data. If you connect Google Sheets, we store your Google account email, encrypted OAuth tokens, and the spreadsheet IDs/URLs created or used by PocketJarvis.

Open Banking data. If you opt into the Open Banking pilot, we store data needed for the read-only connection and import: the selected bank and country, consent status and expiry, pseudonymous technical identifiers, accounts, currencies, balances, and transactions. External identifiers, IBAN, names, and sensitive descriptions are encrypted or hashed before storage according to the field's purpose. PocketJarvis does not receive or store your bank credentials.

Subscription and payment data. We store the plan, subscription or trial state, payment channel and cycle, access periods, transaction amount and currency, cancellation or refund state, usage limits, and minimized technical references needed for webhooks, deduplication, reconciliation, and support. To prevent trial reuse, we retain a pseudonymous HMAC proof of the claimed identity. PocketJarvis does not receive or store the full card number or CVV entered in Paddle checkout.

Operational data. We store queue items, outbox events, notification records, idempotency keys, error metadata, and limited logs needed to operate, secure, and debug the service.

3. How we use your data

We do not sell your data and do not use your finance data for advertising or unrelated profiling.

4. Legal bases for processing

We process data needed to provide the Service and the features you request to perform our contract or take requested steps before a contract. We rely on legitimate interests for security, fraud and duplicate prevention, reliability, limited debugging, and support after considering the impact on your rights. We retain certain payment records when required by legal, tax, or accounting obligations. Where processing relies on consent, you may withdraw it for the future without affecting earlier processing.

5. Google API usage

PocketJarvis uses the Google drive.file scope for the Sheets integration. This means PocketJarvis can access files it created or files you explicitly selected for the app. It does not receive broad access to list, read, or modify your entire Google Drive.

Our use and transfer of Google user data complies with the Google API Services User Data Policy, including the Limited Use requirements.

6. Open Banking integration

Open Banking is an optional pilot available only to approved users. ING Bank Romania is the only bank available in the current pilot. PocketJarvis redirects you to the secure flow provided by Enable Banking and ING, where strong customer authentication takes place. Enable Banking provides technical connectivity and sends PocketJarvis only the account, balance, and transaction data required for the feature within the scope of your consent.

Banca Transilvania is not yet available. Export to YNAB is a separate future integration, not a bank; neither has a public launch date, and PocketJarvis does not currently send data to YNAB. Bank access is read-only. PocketJarvis does not initiate payments or transfers, is not a bank, and has no official partnership with ING Bank Romania or Banca Transilvania. You can disconnect the integration in PocketJarvis; we immediately stop local imports and attempt to revoke the provider session. You may also revoke access through your bank or provider. Consent expires and may require reauthorization.

Data may be delayed, incomplete, or temporarily unavailable because of the bank, provider, or maintenance. Disconnecting and account deletion cover Open Banking data and connection references retained by PocketJarvis, subject to applicable legal obligations.

7. Document processing and AI fallback

PocketJarvis is local-first for document extraction. When local extraction is incomplete or configured receipt parsing requires it, the service may send the relevant file or extracted text to Google Gemini through the google-genai API for parsing. The result is used only to provide the PocketJarvis service.

Original receipt and document files are stored in Azure Blob Storage during processing. After a successful processed or duplicate result is committed, PocketJarvis deletes the original blob on a best-effort basis. Failed assets may be kept temporarily for debugging and are expected to be removed by storage lifecycle cleanup.

8. Account linking

If you use both WhatsApp and Telegram, your accounts are linked only when you explicitly use the /link code flow. PocketJarvis does not auto-link accounts by phone number, username, name, or any similar identifier.

9. Storage, security, processors, and transfers

Processors and platforms used to provide the service may include Telegram, Meta/WhatsApp, Google, Enable Banking for Open Banking connectivity, Microsoft Azure, Neon/PostgreSQL hosting, and Sentry-style error monitoring when configured. Your selected bank processes authentication and data under its own duties and policies; GDPR roles may differ by operation. For new subscriptions, Paddle operates checkout and payment services as merchant of record and shares with PocketJarvis the data needed for order fulfilment, fraud prevention, and support.

Some providers may process data outside the European Economic Area. In those cases, as applicable, we rely on adequacy decisions, approved standard contractual clauses, or other safeguards recognized by law. Provider privacy policies also apply to processing performed by those providers.

10. Data retention

Active account data is retained while you use the service unless you request deletion. Temporary queues, expired pending confirmations, purchased or deleted shopping items, processed queue rows, source message records, and original file blobs may be cleaned up by scheduled retention jobs or storage lifecycle rules.

When an account is deleted, checkout sessions, usage counters, and temporary support decisions are deleted. Provider payloads, errors, and sensitive references are deleted or pseudonymized. Strictly necessary subscription and transaction facts are retained for the approved tax and accounting period; retention may continue only as needed for fraud prevention, resolution of an active dispute, or defense of a documented legal claim. The HMAC proof of a trial claim may be retained for abuse prevention without retaining the raw platform identifier.

Telegram group expense records belong to the group context. If you need group data removed, contact support@bornagents.net.

11. Your rights and deletion

You can request deletion of your personal account data by sending /delete_my_data in a private chat. Depending on the platform, PocketJarvis asks for confirmation before destructive deletion.

12. Cookies, local storage, and tracking

The PocketJarvis website does not use advertising cookies or tracking pixels. We use Plausible Analytics for aggregate statistics without cookies or persistent individual profiles. To calculate metrics, Plausible may temporarily process the IP address and user agent into a daily identifier without storing the raw IP. The website uses browser local storage only to remember the selected language. This preference is not used for advertising or tracking.

Telegram, WhatsApp, Google, and other external platforms may process data according to their own policies when you use those services.

13. Children's privacy

PocketJarvis is not directed to children under 13. If you believe a child has provided personal data, contact us and we will take appropriate deletion steps.

14. Changes

We may update this Privacy Policy as the product changes. The latest version will be published on this page with an updated date.