App privacy policy

This covers the pouchie app — your account, your photos and videos, and the people you share them with. The marketing website has its own, separate privacy notice.

The short version

  • Your photos and videos are stored encrypted, in the European Union, and decrypted on your own device.
  • Only the people you put in a circle can see what you share with that circle. There is no public feed.
  • Location data is removed from every photo and video before anyone can view it.
  • We never sell your data, never use it for advertising, and never use it to train AI models.
  • Delete your account and your memories are permanently erased after a 30-day grace period.

1. Who we are

pouchie is operated by JR Moreno Ltda ME ("pouchie", "we"), based in São Paulo, Brazil. We are the data controller for the data processed in the app, under Brazil's LGPD (Law 13.709/2018) and, where it applies, the GDPR. Our Data Protection Officer is Gustavo Henrique Moreno, reachable at [email protected].

2. Who this applies to

Anyone who uses the pouchie app. It does not cover the pouchie.app website, which holds no product data and has its own privacy notice. Your use of the app is also governed by our terms.

3. What we collect

  • Account: your phone number, the name you choose to give, and your device's language.
  • Authentication and security: one-time codes (stored hashed, HMAC-SHA256), the device your account is bound to, your IP address and a device identifier (anti-abuse and diagnostics), and append-only access logs.
  • What you create: the photos and videos you upload, plus captions, comments, reactions, and how you've organised them into memories, moments and circles.
  • Technical operation: timestamps, crash and error reports (via Sentry), and strictly operational usage metrics.

We do not collect your location. Photos and videos often carry GPS coordinates in their metadata; we strip that metadata during processing, before any other person can view the file.

4. Why we use it, and our legal basis

  • Creating and running your account, and providing the service — performance of a contract.
  • Delivering your photos and videos to the circles you chose — performance of a contract.
  • Sending login codes and protecting against abuse and fraud — legitimate interest (security).
  • Diagnosing and fixing faults, via Sentry — legitimate interest.
  • Meeting legal obligations, such as retaining logs — legal obligation.

5. How we protect it

  • Media is encrypted at rest and stored and processed in the European Union.
  • Each file has its own key, held in AWS KMS (EU region), and is decrypted on your device — the delivery network only ever handles ciphertext.
  • EXIF and GPS metadata are removed from photos and videos before anyone views them.
  • Screenshots are blocked on media screens (see the limits below).
  • One-time codes and tokens are stored hashed; access logs are append-only.

One honest caveat: this is strong protection and EU data residency, not zero-knowledge encryption. pouchie, via our key service, remains technically able to decrypt your media. We would rather tell you that than over-promise. And no technical measure is absolute — someone you have given access to could always photograph their screen with another device. Choose who joins your circles carefully.

6. Who we share it with

  • The people in your circles — that's the point of the app. You control which circles see each memory; nobody outside them sees it.
  • Service providers who run our infrastructure under our instructions: Twilio (sending login codes), Cloudflare (storage and delivery), Heroku (application hosting), AWS (key management) and Sentry (crash reporting). Each is under a data-processing agreement.

We never sell your data, never use it for advertising, and never use it to train AI models — ours or anyone else's.

7. International transfers

Your data is stored and processed in the European Union. Some of our service providers are headquartered outside the EU; where data moves, those transfers rely on Standard Contractual Clauses and equivalent safeguards.

8. How long we keep it

  • Your data is kept while your account is active.
  • If you delete your account, the memories you hold are soft-deleted for 30 days — a grace period in which they can be restored — and then permanently erased.
  • Security logs and records we're legally required to keep are retained for the period the law requires.

9. Children in the photos

pouchie is built for adults to share pictures of their own family privately, and those pictures often show children. Children do not create accounts and do not use the app — the account holder is an adult, and the sharing happens inside a closed circle that adult chose.

Brazil's LGPD gives children's and adolescents' data special protection in the child's best interest, and the ECA and the Digital ECA (Law 15.211/2025, in force since 17 March 2026) reinforce a child's right to privacy. If you share images of a child, you confirm that you hold parental authority or equivalent legitimacy to do so, and you are responsible for that sharing.

10. Your rights

Under the LGPD (art. 18) and, where it applies, the GDPR, you can: confirm and access the data we hold about you; correct it; request deletion or anonymisation; obtain a portable copy; withdraw consent; and be told who we've shared it with.

To exercise any of these, email [email protected]. We respond within the legal deadlines: up to 15 days for confirmation of processing under the LGPD, and up to 30 days under the GDPR. You can also delete your account directly in the app, at any time.

11. Changes to this policy

We may update this policy. When a change is significant, we'll tell you in the app and update the effective date below.

12. Contact

[email protected] — for any privacy question, request, or complaint.

Effective date: 22 July 2026.