Trupocket

Privacy Policy

Last Updated: November 17, 2025

📋 Quick Summary

What We Collect: Email, name, financial transactions you enter, API usage data

How We Use It: Only to provide Trupocket services - we NEVER sell your data

Your Rights: Access, delete, and export your data anytime

Third Parties: Stripe (payments), AWS (hosting), Cloudflare (security). Future: Plaid (bank sync)

Data Retention: Based on your plan (90 days free, 2 years premium, unlimited for developer)

Contact: legal@trupocket.app for privacy questions

This summary is for convenience only. The full policy below is legally binding.

Table of Contents

1. Introduction

Welcome to Trupocket, an API-first personal finance platform operated by ForceCore LLC. This Privacy Policy explains how we collect, use, store, and protect your personal information.

By using Trupocket, you agree to the collection and use of information in accordance with this policy. If you do not agree with our policies and practices, please do not use our service.

2. Services & Data Collection

Third-Party Services We Use

Trupocket relies on the following third-party services to operate:

Core Services

AWS Infrastructure Services

Future Services (Not Yet Implemented)

We plan to integrate the following services in the future:

We will notify you via email when these services are introduced and update this Privacy Policy accordingly.

Data We Collect

Cookie Policy

Current Implementation: Trupocket API is completely cookie-free. We use Bearer token authentication via the Authorization header instead of session cookies.

No Cookies Used

Third-Party Cookies

While Trupocket doesn't set cookies, third-party services may:

Future Web Applications

If we launch web applications in the future:

Metrics Collection

We collect basic performance metrics to improve our service, including:

Important: Metrics are aggregated and anonymized. We do not sell or share individual user metrics with third parties.

3. How We Use Your Data

Your data is used only for providing and improving the Trupocket service:

Marketing Communications (Future)

In the future, we may send marketing emails about new features, updates, and promotions. You will be able to:

What We NEVER Do

4. Data Retention & Deletion

Transaction Data Retention

Your transaction data is retained based on your subscription plan:

Important: Data older than your plan limit is not deleted, it is simply not calculated, processed, or accessible via the API or reports. If you upgrade your plan, historical data becomes accessible again.

Specific Retention Periods by Data Type

Different types of data are retained for different periods:

Account Deletion

You may request account deletion at any time by contacting support@trupocket.app.

Subscription Lapse & Downgrade

5. Your Rights

California Residents (CCPA Compliance)

If you are a California resident, you have the right to:

To exercise these rights, contact us at legal@trupocket.app.

Automated Opt-Out Signals (Global Privacy Control)

Effective January 1, 2026: We honor Global Privacy Control (GPC) browser signals as required by California law.

Note: Currently, we do not sell or share personal data, so GPC primarily serves as a future protection mechanism.

Nevada Residents

Nevada law allows residents to opt-out of the "sale" of personal information:

Data Export Process

You have the right to receive a copy of your personal data in a portable format:

Financial Regulation Exemptions (GLBA)

Important disclosure about regulatory exemptions:

US-Only Service (No GDPR Compliance at Launch)

Trupocket is currently available only to US residents. We are not GDPR-compliant at launch. International support may be added in the future, at which time we will comply with applicable international privacy laws.

6. Data Ownership

7. Security & Data Breaches

Security Measures

We implement industry-standard security measures to protect your data:

Important: No system is 100% secure. While we implement industry-standard security practices, we cannot guarantee absolute security. You are responsible for protecting your account credentials.

Data Breach Notification

In the event of a data breach affecting your personal information:

Our Response Procedure

What We Will Tell You

Our breach notification will include:

Your Responsibilities

8. Future Integrations

Open Banking & Data Portability (Section 1033 CFPB Rule)

Compliance Date: April 1, 2026 (for covered financial institutions)

Under the Consumer Financial Protection Bureau's Personal Financial Data Rights Rule, you have the right to:

How to Exercise These Rights

Third-Party Access Protections

When you authorize a third party to access your Trupocket data:

Bank Account Synchronization (Planned)

When we introduce bank account synchronization via Plaid, Yodlee, or similar services:

9. Compliance & Legal

Age Restriction

You must be 18 years or older to use Trupocket.

Children's Privacy (COPPA Compliance)

Trupocket is not intended for children under 18 years of age:

Third-Party Links

Trupocket may contain links to third-party services (Stripe, AWS, Plaid, etc.). We are not responsible for the privacy practices of these external services. Please review their privacy policies before using them.

Policy Updates

We may update this Privacy Policy from time to time. When we make material changes:

Legal Requests & Compliance

We may disclose your information if required by law, court order, or government request, including:

10. Contact Information

If you have any questions or concerns about this Privacy Policy, please contact us:

Response Time: We will respond to privacy inquiries within 45 days as required by CCPA.