Privacy Policy and Terms of Service
Last updated 6 September 2026
This page sets out the two documents that govern your use of PocketPass. Part A is the Privacy Policy, which describes the personal data we process and the rights you have in respect of it. Part B is the Terms of Service, which are the conditions on which the Service is made available to you. By creating an account or otherwise using the Service you confirm that you have read and agree to both documents.
Capitalised terms have the meaning given to them in Part B, section 1. Where this page refers to the "Service", it means the PocketPass application for Android (the "App"), the website at pocketpass.xyz (the "Website"), the developer portal at developer.pocketpass.xyz and the account, messaging, encounter and API services that support them.
Part A. Privacy Policy
A1. Controller and contact
The Service is operated by the PocketPass team (referred to in this Policy as "PocketPass", "we", "us" or "our"), an independent group of individuals and not a commercial company. We are the controller of the personal data described in this Policy. The Service is hosted on a single cloud server rented from Oracle Cloud and administered by us. Enquiries concerning this Policy, including requests to exercise the rights described in section A9, may be submitted through the PocketPass Discord server.
A2. Categories of personal data processed
Account data. There are three ways to hold an account. If you sign in with an email address, we store that address; sign-in uses a six-digit code that expires ten minutes after it is issued and no password is involved. If you sign in with Discord, we store the Discord account identifier and display name supplied by Discord. If you create a username account, we store the username you chose and a salted hash of your password produced by the authentication service; no email address is held for such an account, and internally it is identified by a reserved address of the form username@users.pocketpass.xyz that receives no mail. Because no address is on file, a forgotten password cannot be reset by you or by us. You may later link a verified email address to a username account from Settings, after which that address is stored as described above and the account may also sign in with a code sent to it. For every account we record the date and time of registration and of your most recent sign-in.
Profile data. Your display name, username, biography, Piip designs (comprising the cosmetic parameters and the rendered portrait image), an optional age, and the country you selected during setup. Age and country are displayed to other users exactly as you entered them. The App does not access the location services of your device; the country shown is solely the one you selected. We also record an approximate "last active" timestamp so that your friends can see whether you are available.
Social data. Your friend code, your friendships, pending friend requests sent and received, and the users you have blocked.
Messages. The text of your conversations, images you attach, replies, edit history, and read status. Deleting a message replaces its text with the words "Message deleted" for every participant. Attached images are held in private storage that can be opened only by members of the conversation concerned.
Encounter data. The identity of each user you have encountered, the time of the encounter, and whether both parties confirmed it. Encounter records are retained for the lifetime of your account because World Tour, the leaderboards and several achievements are calculated from them.
Activity data. Your token balance, shop purchases, achievements, Bingo progress and supporter status. If you enable Step Rewards, the App transmits only a daily step total for the current day and the previous day, never raw sensor readings, and only for as long as the setting remains enabled.
Notifications. In-app notifications are retained for 90 days and are then deleted automatically.
Connected applications and developer data. The third-party applications you have authorised to access your account and the permissions you granted to each. If you register an application in the developer portal, we hold the details of that application and a count of the requests it makes per day.
Technical data. Our servers keep ordinary access logs, which include IP addresses, for a short period for the purposes of troubleshooting and security. The Website sets no cookies, contains no analytics or tracking code, and keeps no record of its visitors beyond those server logs. The App contains no advertising, analytics or crash-reporting components.
A3. Nearby Encounters
Nearby Encounters is disabled until you enable it. While it is enabled, the Bluetooth radio of your device broadcasts only a protocol version number and a random identifier that changes frequently. Your name, Piip, account identifier and all other personal data are never broadcast.
When two devices running the App come within range, they establish an encrypted connection and exchange single-use passes issued by our server. Passes expire seven days after issue and are deleted from our systems approximately one day after they are used. The cryptographic keys involved never leave your device, and the records of the exchange itself are discarded together with the passes. An encounter, and the resulting disclosure of your profile to the other user, comes into existence only once both users have confirmed it in the App.
On Android 11 the operating system requires the location permission in order to scan for Bluetooth devices. The App requests that permission on Android 11 for that purpose alone and does not read your position. On Android 12 and later the App uses the dedicated Bluetooth permissions instead.
A4. Purposes and legal bases
We process personal data (a) to provide the Service you have requested, including creating and operating your account, delivering messages, recording encounters and calculating tokens and achievements, which is necessary for the performance of our agreement with you; (b) to keep the Service secure, to prevent abuse and to maintain records of administrative actions, which is in our legitimate interests and those of other users; (c) to comply with legal obligations to which we are subject; and (d) in the case of optional features such as Nearby Encounters, Step Rewards and third-party application access, on the basis of your decision to enable the feature, which you may reverse at any time. We do not use personal data for advertising, we do not build profiles for marketing purposes, and we do not sell personal data.
A5. Recipients of personal data
Other users. Your profile data is visible to users who are permitted to view your profile, such as your friends and users with whom you have a confirmed encounter. Messages are visible to the participants in the conversation.
Service providers. Resend delivers the sign-in and verification code emails and therefore processes your email address whenever an address is held for your account. Discord is contacted only if you choose to sign in with Discord, in which case we receive your Discord identity and the display name associated with it. Ko-fi sends us a notice for each payment containing the payer's email address, name, tier, amount and any message so that the associated benefits can be applied to the account registered with the same email address or to the account whose username or friend code appears in the message; those notices are retained as payment records even if the account is subsequently deleted. A username account without an email address receives benefits when the payer names it in the message, or once it links the email address used at Ko-fi. GitHub hosts the App's release files, and your device downloads updates directly from GitHub, which receives the download request like any other. Pretendo Network is contacted only when you import a Mii, and receives only the Pretendo Network ID you enter.
Third-party applications. An application you connect to your account receives only the data covered by the permissions you approved on the consent screen. Connected applications never receive your email address or Discord identity. You may review and revoke every connected application at links.pocketpass.xyz/oauth/apps or in the App under Settings.
Legal disclosures. We may disclose personal data where we are required to do so by law or by a binding order of a competent authority.
The App does not include Google Play Services, Firebase, CAPTCHA services or any advertising component.
A6. Storage, security and international transfer
All personal data described above is stored in a database on a single cloud server rented from Oracle Cloud and administered by us. Connections to the server are encrypted, access controls ensure that each account can read only its own data and data that has been shared with it, and the server exposes only the interfaces the App requires. Encrypted backups are taken nightly; seven days of backups are kept on the server and one further copy is kept off the server. If you access the Service from a country other than the one in which the server is located, your personal data will be transferred to and processed in that location.
A7. Retention
Account, profile, social, message, encounter and activity data are retained for as long as your account exists. Notifications are retained for 90 days. Passes are retained for no more than seven days after issue and for approximately one day after use. Server access logs are retained for a short period only. Ko-fi payment notices are retained as payment records for as long as is necessary to account for the payment. Data you delete is removed from live systems immediately but may remain within encrypted backups for up to approximately seven days before those backups are overwritten.
A8. Administrative access
To operate and support the Service, members of the PocketPass team may look up an account (including its email address or username), correct token balances and achievements, and link a Ko-fi payment to an account. Every such action is recorded in an audit trail. No other person has this access.
A9. Your rights and choices
You may at any time, from within the App: enable or disable Nearby Encounters, encounter alerts and Step Rewards; edit your profile and Piips; link an email address to a username account and, once an address is on the account, change your password; block other users, which removes you from their view entirely; disconnect any third-party application; and delete your account, which takes effect immediately and is described in detail on the account deletion page.
Depending on the law that applies to you, you may also have the right to request access to, rectification or erasure of, or restriction of or objection to the processing of, your personal data, the right to receive a copy of your data in a portable format, and the right to withdraw consent where processing is based on consent. Requests may be made through the Discord server referred to in section A1. You also have the right to lodge a complaint with the supervisory authority responsible for data protection in the country where you live.
A10. Children
The Service is not directed at children under the age of 13, or under the higher minimum age that applies in your country, and we do not knowingly collect personal data from them. If you believe that a child has created an account in breach of this section, please contact us so that the account and its data can be removed.
A11. Changes to this Policy
We may amend this Policy when the Service changes. The date at the top of this page indicates when it was last revised. Material changes will be announced in the App or on the Discord server before they take effect.
Part B. Terms of Service
B1. Agreement and definitions
These Terms of Service (the "Terms") form a binding agreement between you and the PocketPass team ("PocketPass", "we", "us" or "our") governing your access to and use of the Service. By creating an account, installing the App or otherwise using the Service you accept these Terms and the Privacy Policy in Part A. If you do not accept them, you must not use the Service. In these Terms, "Content" means any text, image, Piip design, profile information or other material that you submit to or transmit through the Service, and "Virtual Items" means tokens, hats, achievements and any other digital item made available within the App.
B2. Eligibility and accounts
You must be at least 13 years of age, or the higher minimum age required in your country, to use the Service. If you are under the age of majority where you live, you confirm that a parent or guardian has reviewed and agreed to these Terms on your behalf. You may hold one account only. You are responsible for maintaining control of the email address or Discord account used to sign in, and for all activity that takes place under your account. If you create a username account you choose a password of at least eight characters. PocketPass holds no email address for such an account, cannot verify your identity in any other way, and therefore cannot reset or recover the password. Losing the password means losing access to the account permanently, unless you linked a verified email address to it beforehand, in which case you may sign in with a code sent to that address and set a new password from Settings. You must notify us promptly through the Discord server if you become aware of any unauthorised use of your account.
B3. Nature of the Service and alpha status
The Service is provided free of charge and is currently in an alpha stage of development. Features may be added, changed, suspended or withdrawn at any time, data may be lost, and the Service may be interrupted without notice. The App checks for updates automatically and installs them after verification. We may designate a minimum supported version of the App, and versions below it may cease to function until updated. We may discontinue the Service in whole or in part at any time.
B4. Acceptable use
You agree not to use the Service to harass, threaten, defame or abuse any person; to publish or transmit Content that is unlawful, hateful, pornographic, or that sexualises minors; to impersonate any person or misrepresent your affiliation; to send unsolicited or bulk messages; to collect or harvest data about other users; to distribute malware or otherwise interfere with the operation or security of the Service; to forge, replay, tamper with or otherwise manipulate passes, encounters, tokens or any other record held by the Service; to access the Service by automated means other than through the documented API; or to circumvent rate limits, permission checks or other technical restrictions. You further agree not to reverse engineer, decompile or attempt to derive the source code of the App except to the extent that applicable law expressly permits it notwithstanding this restriction.
B5. Your Content
You retain ownership of your Content. You grant us a non-exclusive, worldwide, royalty-free licence to store, reproduce, transmit and display your Content solely to the extent necessary to operate, maintain and provide the Service, including displaying your profile and Piip to other users as described in the Privacy Policy. You are solely responsible for your Content and warrant that you hold the rights necessary to grant this licence. We may remove or restrict access to Content, and suspend or terminate accounts, where we reasonably believe these Terms have been breached. Content that concerns you may be reported through the Discord server, and you may block any user at any time.
B6. Nearby Encounters and interactions with other users
Nearby Encounters relies on the Bluetooth radio of your device and on the proximity of other devices running the App. We do not guarantee that any encounter will occur or be recorded. We do not verify the identity of users. You are solely responsible for your interactions with other users, whether within the Service or in person, and you should exercise appropriate caution before arranging to meet anyone you have encountered through the Service.
B7. Virtual Items and memberships
Virtual Items have no monetary value, are not your property, cannot be transferred to another account or person, and cannot be exchanged for money or anything of value outside the Service. We may adjust, reset or remove Virtual Items, including to correct errors or to address abuse. Memberships are purchased through Ko-fi and are subject to Ko-fi's own terms and payment policies; we do not process payments and do not issue refunds. A membership payment unlocks all hats for 36 days per payment on the PocketPass account registered with the same email address as the Ko-fi payment or, where no such account exists, on the account whose username or friend code the payer writes in the Ko-fi message. A payment that identifies no account is held until we can link it; a username account can be named in the message or can link the email address used at Ko-fi. Membership benefits may change, and the unlocking of hats does not constitute the sale of goods.
B8. Third-party services and connected applications
The Service interoperates with services operated by third parties, including Discord, Ko-fi, GitHub and Pretendo Network, each of which is governed by its own terms and privacy policy. Applications that connect to PocketPass accounts through the developer platform are provided by their respective developers and not by us. You connect an application at your own discretion, you may revoke its access at any time, and we are not responsible for the conduct of any third-party application or service.
B9. Developers
Use of the developer portal and the API is subject to these Terms, to the documentation published at developer.pocketpass.xyz, and to any rate limits or technical restrictions we impose. Developers must request only the permissions their application requires, must use data obtained from the Service solely for the purpose disclosed to the user on the consent screen, must not misrepresent their application, and must delete data obtained from a user when that user disconnects the application or deletes their account. We may suspend or revoke an application's access at any time.
B10. Intellectual property
The PocketPass name, logos, artwork, sounds and software are owned by us or licensed to us. Subject to these Terms, we grant you a limited, personal, non-transferable and revocable licence to install and use the App on Android devices you own or control. The App and the Website incorporate components licensed by third parties, including the Rubik typeface under the SIL Open Font License, emoji artwork from Sudofont under the MIT License, and Mii rendering technology by ariankordi. Mii is a trademark of Nintendo. PocketPass is not affiliated with, sponsored by or endorsed by Nintendo, Discord, Ko-fi, GitHub or Pretendo Network.
B11. Suspension and termination
You may terminate this agreement at any time by deleting your account from within the App. The consequences of deletion are described on the account deletion page. We may suspend or terminate your access to the Service, with or without notice, if we reasonably believe that you have breached these Terms, if we are required to do so by law, or if we discontinue the Service. Sections B5 (to the extent of Content already shared with other users), B7, B10, B12, B13 and B14 survive termination. Records retained after termination are described in the Privacy Policy.
B12. Disclaimer of warranties
The Service is provided "as is" and "as available", without warranty of any kind. To the maximum extent permitted by applicable law, we disclaim all warranties, whether express, implied or statutory, including warranties of merchantability, fitness for a particular purpose, non-infringement, availability, accuracy and the absence of errors or loss of data.
B13. Limitation of liability
To the maximum extent permitted by applicable law, PocketPass and the individuals who operate it shall not be liable for any indirect, incidental, special, consequential or punitive damages, or for any loss of data, profits, goodwill or opportunity, arising out of or in connection with the Service, however caused and under any theory of liability, even if advised of the possibility of such damages. To the same extent, our aggregate liability for all claims arising out of or in connection with the Service shall not exceed the amount, if any, that you have paid to us for the Service in the twelve months preceding the event giving rise to the claim. Nothing in these Terms excludes or limits any liability that cannot be excluded or limited under applicable law, including liability for death or personal injury caused by negligence or for fraud, and nothing in these Terms limits the rights you have as a consumer under mandatory law in the country where you live.
B14. Indemnity
To the extent permitted by applicable law, you agree to indemnify and hold harmless PocketPass and the individuals who operate it from and against any claims, liabilities, damages and reasonable expenses arising from your Content, your use of the Service or your breach of these Terms.
B15. Changes to these Terms
We may amend these Terms from time to time. The revised Terms will be published on this page with an updated date, and material changes will be announced in the App or on the Discord server before they take effect. Your continued use of the Service after the revised Terms take effect constitutes acceptance of them. If you do not accept the revised Terms, you must stop using the Service and may delete your account.
B16. General
These Terms, together with the Privacy Policy, constitute the entire agreement between you and us regarding the Service. If any provision of these Terms is held to be invalid or unenforceable, the remaining provisions remain in full force and effect. Our failure to enforce any provision is not a waiver of our right to do so later. You may not assign or transfer your rights under these Terms; we may assign ours to any successor operator of the Service. These Terms are written in English, and any translation is provided for convenience only.
B17. Contact
Questions about these Terms or the Privacy Policy may be raised on the PocketPass Discord server.