Privacy
Your journal stays on this iPhone.
Last updated — 26 September 2026
Pocket Wombat is built around a single privacy claim: the day lives on the phone you wrote it on. There is no Pocket Wombat account and no Pocket Wombat server holding your pockets. A few things can leave the device — share, Mail, Ask with a cloud key, Apple Speech or Weather if those features run — and only because you asked.
Summary
- No account. No login. No email collection by the app.
- Notes, sketches, photos, voice recordings, settings, and stream rows live in the app sandbox on this iPhone (and in the on-device App Group used by widgets).
- Calendar and Reminders are offered at first launch so today’s pocket can include events and tasks. You can connect now or skip and capture without them. Hide calendars and lists in Settings anytime.
- Health, Bluetooth, Photos, Apple Music, HomeKit, and Weather stay off until you turn them on.
- Now Playing and Device state are on by default. They do not show a permission prompt. You can turn them off in Settings → Stream sources.
- Ask Wombat with Apple Intelligence stays on-device on supported iPhones with iOS 26 or later. A cloud key (BYOK) sends that day’s context to the provider you chose. We never receive the key.
- From version 1.1, the optional Dev inbox can connect to an AI app such as Claude, ChatGPT or Cursor. Only if you turn that on do Dev inbox items — never your journal — go to our small server so the AI app can read them. Turning it off deletes them there.
- No ads, no analytics SDKs, no crash reporters. Delete the app, the journal is gone. That’s the design.
1. What we collect
Nothing that comes to us, unless you email — or you turn on Connect AI agents for the Dev inbox (section 8).
Pocket Wombat does not create user accounts, does not sign you in, and does not operate a backend that stores journal content. We do not receive a copy of your day unless you attach it to a message. There is no Firebase, Sentry, Mixpanel, Amplitude, or Crashlytics dependency in the source.
What this means concretely: we do not collect your name, email, contacts, location, photos, microphone input, calendar, health data, or advertising identifier on our servers, because we do not have servers for that. The one exception is screenshots you attach to Dev inbox items and choose to connect (section 8). The app can read some of those things on the phone, with permission, so they can appear in today’s pocket. That data stays on the device unless a section below says otherwise.
2. What stays on the phone
Unless a later section says otherwise:
- Journal entries you create: writing, sketches, camera photos, files, and voice recordings
- Transcripts of voice notes
- Ask Wombat replies saved into the stream
- Stream rows generated from sources you have enabled
- App settings (theme, filters, which sources are on, Bluetooth allowlist)
- Optional cloud API keys for Ask Wombat, in the iOS Keychain on this iPhone — not in iCloud UserDefaults
- Widget / Live Activity snapshots in the App Group
group.app.pocketwombat.PocketWombaton this device
There is no iCloud sync of the journal in version 1.0.
Dev inbox (from version 1.1, optional, off by default). While you have the Dev tab turned on, its items and their screenshots and voice notes are copied to a Pocket Wombat folder in your own iCloud Drive, so tools on your Mac can read them. The journal is never included. Turning the Dev tab off removes that copy. Nothing from it comes to us.
3. Permissions
iOS shows a system prompt the first time a feature needs access. Denying a permission means that feature does not run. You can change this later in iOS Settings → Privacy & Security, and inside Pocket Wombat → Settings.
Calendar and Reminders
Offered on the last first-run card, and you can skip it. Pocket Wombat reads events and reminders so they appear in today’s pocket, and can write events or reminders you add from the Add sheet. We do not upload your calendar. You can hide specific calendars and reminder lists in Settings → Calendars & Reminders.
Contacts
Used only to resolve names when you add an event or reminder (for example, “Lunch with Sarah”). Contacts are not uploaded to us.
Camera and microphone
Camera captures photos for today’s pocket. The microphone records voice notes. Media stays on this device unless you share it or send it via Ask Wombat with a cloud key.
Photo library
Off by default. If you turn on Photo library in Stream sources, Pocket Wombat notes when a new photo is added so today’s pocket can record it.
Health
Off by default. If you turn Health on, Pocket Wombat may read sleep, workout, and mindful-session data to add rows to the local day stream. This is journaling, not a medical service.
Bluetooth
Off by default. If you turn it on, connection events are logged only for devices whose names match prefixes on your allowlist.
Apple Music
Off by default. If you turn it on and authorise Music, Pocket Wombat may read recently played Apple Music tracks for the local stream.
HomeKit
Off by default. If you turn it on, Pocket Wombat may note when an accessory becomes reachable or unreachable.
Location
Off by default. Used only if you turn Weather on: a when-in-use location read, about once a day, so today’s conditions can be logged. Conditions come from Apple Weather. See Apple’s Weather data sources.
4. Stream sources
Automatic entries Pocket Wombat can write to today’s stream. Nothing that costs a permission prompt is on by default.
On by default (no extra prompt): Now Playing (system now-playing info), and Device state (battery, thermal state, Low Power Mode, and similar signals). Audio-route changes may also appear. Turn any of these off in Settings → Stream sources.
Off until you turn them on: Health, Bluetooth (allowlist), Apple Music, Photo library, HomeKit, Weather (uses location + Apple Weather).
5. Ask Wombat
Apple Intelligence. When you use it, processing stays on-device to the extent Apple provides that for your hardware and system version. We do not receive that request.
Cloud provider (bring your own key). If you paste an API key for Anthropic, OpenAI, or OpenRouter, each Ask may send that day’s notes, calendar context, and stream text to the provider you chose, using your key. We do not operate those services, we do not receive a copy of your key, and we do not see the prompt or the reply.
Those providers process the content under their terms and privacy policies. Do not enable a cloud key if you are not willing to send pocket text to that provider. You can delete a saved key in Settings → Ask Wombat.
6. Voice notes and transcription
Voice notes are stored on this iPhone. Pocket Wombat asks iOS for speech recognition so a transcript can be attached. If on-device recognition is available, the app requires it. If it is not, Apple’s speech recognition may process the audio under Apple’s terms. A failed transcript does not delete the recording.
7. Widgets, pin, share, and this site
Day Pulse and the Lock Screen pin read a local snapshot from the App Group on this device so the widget can update without opening the app. That snapshot does not go to our servers. Pin is a Live Activity: one typed thought at a time, on this phone.
Share today and Email today use the system share sheet or Mail. Content leaves the device only when you send it, to whoever you chose. We are not a party to that message.
pocketwombat.app is a static site (home, privacy, terms, support, connectors). mcp.pocketwombat.app is the Dev inbox connector described in section 8. It does not embed advertising and does not require an account. It uses PostHog for anonymous page analytics (which pages were viewed, roughly where visitors come from). PostHog may store a first-party identifier in the browser (cookie or local storage). We do not use session replay on this site, and we do not send journal content — the site never sees your pocket. Your host or browser may also keep ordinary server or cache logs. To opt out of PostHog on this site, enable a tracking-prevention / “Do Not Track” style blocker, or email matthew.worner@me.com and we can document a clearer opt-out if needed.
The iOS app still has no analytics SDK. App Store Connect is how we see installs and retention for the product itself.
8. Dev inbox and AI agents (optional)
From version 1.1, Settings → Dev inbox has Connect AI agents. It is off until you turn it on, and it needs the Dev tab on too. Turning it on gives you a link you paste into an AI app — Claude, ChatGPT, Cursor, Claude Code — so it can read your Dev inbox and mark items done.
What goes to our server. Dev inbox items only: title and description, type (bug, feature, improvement), status, the optional context you add (screen, steps, expected, what happened), the app version, iOS version, device model and time zone recorded when you captured it, the transcript of an attached voice note, and attached screenshots. Voice recordings themselves stay on the phone. Your Timeline, Thoughts, calendar, reminders, health data and Ask Wombat keys are never sent.
Where. On Pocket Wombat’s server at mcp.pocketwombat.app, hosted by Hostinger. There is no account: your inbox is identified by random keys, and the server keeps only a one-way hash of each key. The host keeps ordinary server logs (IP address, time, address requested).
Who can read it. Anyone who has your connector link — treat it like a password. You can replace it any time with Reset link, and the old one stops working. An AI app you add the link to receives items when it asks for them and handles them under that service’s own terms. We don’t read, analyse, sell or share your items.
How long. Items stay while Connect AI agents is on. Deleting an item on your phone removes it at the next sync. Turning Connect AI agents off deletes your items and screenshots from the server straight away — or the next time your phone is online.
9. Payments
Pocket Wombat is a paid App Store app. There is no subscription and no in-app purchase to unlock the journal. Apple handles payment processing. We receive that you bought the app, not your Apple ID, payment details, or billing address. Refunds are handled entirely by Apple through the App Store; we cannot issue refunds directly.
10. Your rights
Access. Your journal and preferences live in the app; open it to see them.
Delete. Deleting Pocket Wombat from your device removes its sandbox and the App Group snapshot. The journal, settings, and Keychain items for this app go with it, subject to how iOS handles backups you have made. Copies you exported or emailed are untouched. We cannot remotely wipe your journal because we do not hold it. If you turned on Connect AI agents, turn it off before deleting the app so the server copy is deleted; if you forgot, email us and we’ll delete it.
Opt out. Turn stream sources off. Revoke iOS permissions. Delete a cloud Ask key. Turn off Now Playing and Device state. Turn off Connect AI agents. The only network behaviour the app has, besides features you turn on, is what Apple’s frameworks do on your behalf (StoreKit, Weather if enabled, Speech if on-device recognition is unavailable).
Children. Pocket Wombat is not directed to children under 13. We do not knowingly collect data from children because we do not knowingly collect data from anyone, except correspondence you send and Dev inbox items you choose to connect.
We are based in New Zealand. The Privacy Act 2020 applies to personal information we actually hold (for example support email, or Dev inbox items you connect). You may ask for access or correction of that correspondence, or complain to the Office of the Privacy Commissioner. If you are in the EEA, UK, or a similar regime: we are not the processor of your on-device journal. For information we hold in email or on the Dev inbox connector, you may contact us to access, correct, or delete it.
11. Changes
If this policy changes materially — a new data flow, a new third-party SDK, a new destination server — we’ll bump the date at the top of this page and, for substantial changes, surface a notice in the app. Editorial changes that don’t change the actual data flows (clarifying language, fixing typos) won’t be announced.
12. Contact
For any privacy question — including a request to confirm what is or isn’t collected — email matthew.worner@me.com. We don’t have a portal, a web form, or a support team; it’s one person and one inbox. Do not send API keys.