Skip to main content
Roscommon Group
Menu
Home
Apps
All appsRenewlistHN RelayPouch
Contact

Pouch

Privacy Policy

Effective September 10, 2026

Pouch is designed so your durable AI memory belongs to you. This policy explains the limited information needed to make that work.

1. Scope

This policy applies to the Pouch iPhone and iPad app, Pouch's remote connection gateway, and the Pouch pages on this website. Pouch is operated by Roscommon Group LLC ("Pouch", "we", or "us"). Read it with our Terms of Use.

2. The short version

Your vault's canonical contents live in your private iCloud database. We do not maintain a separate copy of your memory, sell it, use it for advertising, or train models on it.

When you authorize an assistant, our gateway briefly processes requested vault data in transit so it can perform file operations against your iCloud database. The gateway does not perform AI inference, create embeddings, or persist your files, prompts, search terms, or conversation transcripts.

3. Information Pouch handles

Vault documents

Your Markdown documents, paths, revision records, and document metadata are stored in the CloudKit private database associated with your Apple account. The app keeps an offline cache on your device. Pouch processes requested records transiently when syncing or servicing an authorized assistant.

Credentials and connection state

To connect assistants, Pouch stores an encrypted CloudKit web authentication credential, OAuth grants, revocation status, and request-sequencing and abuse-prevention state. Access tokens are short-lived and may rotate. These are operational secrets and are not memory content.

Minimal operational metadata

We may process an opaque vault identifier, request identifier, tool name, time, latency, status code, byte count, and record count to secure and operate the gateway. We design application logs not to contain vault content, search queries, file paths, titles, summaries, tokens, or conversation text.

Support and website information

If you contact us, we receive the information you choose to send. These website pages are hosted by Vercel and use Google Analytics; those providers may process ordinary website data such as IP address, browser information, page interactions, cookies, and referral information. Analytics on this website are separate from the Pouch app and vault gateway.

4. How information is used

We use information only to provide requested vault access and synchronization, authenticate and authorize connections, prevent abuse, diagnose reliability or security problems, provide support, comply with law, and protect Pouch and its users. Pouch does not make automated decisions about you or score the importance of your memories.

5. Providers and connected assistants

Apple provides iCloud and CloudKit. Cloudflare hosts the stateless gateway and its per-vault encrypted credential and connection state. Vercel, Google Analytics, and our support-form provider operate parts of this website. Their processing is governed by our arrangements with them and their applicable terms.

When you connect ChatGPT, Claude, Codex, or another assistant, that provider receives the vault information the assistant requests through Pouch. The provider's own privacy policy governs what it does with that information. Disconnect an assistant to revoke its Pouch access. Pouch does not control an assistant provider's independent retention of information already disclosed to it.

6. No sale, advertising, or model training

We do not sell or rent personal information. We do not share personal information for cross-context behavioral advertising, use vault contents for advertising, or use vault contents to train machine-learning models. We do not install session replay or screen-recording analytics in the app.

7. Retention and deletion

Vault records remain in your private iCloud database until you delete or archive them. The local cache remains until removed through the app or by deleting the app. Connection credentials and grants remain until you disconnect the integration, delete the vault, or they expire or are revoked. Security and operational metadata may be retained only as reasonably needed for security, reliability, legal compliance, and dispute prevention. Infrastructure providers may retain limited service logs under their own policies.

Export creates a portable ZIP archive on your device for you to save or share. After export, you control that copy and the destination's privacy practices apply.

8. Your choices and rights

You can browse, edit, archive, and delete documents; export the vault as Markdown; disconnect assistants; and delete the vault from Pouch. Depending on where you live, you may also have rights to access, correct, delete, or restrict certain personal information. Submit a request through Pouch Support. We may need to verify your request and cannot retrieve records that only Apple can associate with your private iCloud account.

9. Security

We use measures intended to protect Pouch data, including encrypted transport, CloudKit private databases, encrypted remote credentials, scoped authorization, tenant isolation, revocation, rate limiting, and log minimization. No storage or transmission system is perfectly secure. Protect your Apple account and connected-assistant accounts, keep devices updated, and promptly disconnect access you no longer recognize or need.

10. Children and international processing

Pouch is not directed to children under 13, and we do not knowingly collect their personal information. If you believe a child has provided information, contact us. Providers may process information in the United States and other countries, subject to applicable safeguards and law.

11. Changes and contact

We may update this policy as Pouch changes. We will post the revised policy and update its effective date. Material changes will receive additional notice when required.

Roscommon Group LLC
P.O. Box 389
Issaquah, WA 98027
United States
Phone: (971) 264-3654
Contact: Pouch Support

Pouch by Roscommon Group

TermsPrivacySupport

© 2026 Roscommon Group LLC