Poucho
How it worksBenefitsProgressFAQ

Privacy Policy

About this policy

This Privacy Policy explains how Poucho collects, uses, stores, and shares information when you use the Poucho website, mobile apps, widgets, account features, subscription features, sync services, and related support services.

Poucho is operated by M4D Solutions. This policy should be read alongside our Terms of Service.

Account and sign-in data

We collect account information such as your name, email address, profile image where provided, account identifiers, sign-in provider, and authentication session information. If you sign in with Apple or Google, those providers may share account information with us according to your choices and their own policies.

Our authentication systems may process session data such as IP address, user agent, access tokens, refresh tokens, identity tokens, and related timestamps to keep your account secure and signed in.

Health-related app data

Poucho collects information you enter during onboarding and app use. This can include gender, birth year, pouch usage, pouch strength, first pouch timing, night use, withdrawal symptoms, quit or reduction goals, motivations, concerns, weekly spend, currency, notification preference, timezone, and review intent.

We treat pouch, nicotine, withdrawal, motivation, and reduction-plan information as health-related data. Poucho is not a medical service, but this information can be sensitive and is used to provide your tracking, plan, progress, and related app features.

Logs, plans, widgets, and local data

We collect pouch logs and related tracking data, including event IDs, dates, times, daily summaries, pouch counts, plan targets, notes you add, device IDs where used for sync, source labels such as manual or widget, and whether entries have been voided.

If you use the Poucho widget or quick actions, those features can read and update local app data on your device and queue changes to sync with your account when available.

Local storage and sync

Poucho stores some information locally on your device, including local database records, cached account state, onboarding progress, plans, pouch logs, pending sync operations, and subscription snapshots. Local storage helps the app work offline and keep the widget up to date.

When you are signed in, Poucho syncs supported account, profile, plan, pouch log, and daily summary data with our backend and sync infrastructure so you can keep your progress across sessions and devices.

Notifications and diagnostics

If you enable reminders, Poucho processes notification permission status and schedules local reminders such as daily check-ins. You can control notifications through your device settings.

Some app events, errors, diagnostics, device information, operating system information, app configuration, timestamps, and usage statistics may be processed to understand reliability, fix issues, and improve Poucho.

Subscriptions and purchases

Poucho uses RevenueCat and app store infrastructure to manage subscriptions. We may process subscription status, entitlement state, app user IDs, aliases, purchase dates, expiry dates, product identifiers, store, billing issue timestamps, renewal state, sandbox status, and webhook event payloads.

Payment, refund, cancellation, and billing details are handled by the app store or payment provider you use. We do not receive full card details from app stores.

Analytics and advertising technologies

We plan to use PostHog for event analytics only, such as understanding feature usage and product performance. This version does not include PostHog session replay or screen recording.

We also plan to use Meta Pixel, TikTok Pixel, and Google tags for advertising measurement, conversion tracking, attribution, and campaign performance across the website and mobile app where applicable.

Cookies, consent, and choices

Non-essential analytics and marketing technologies must not load until you have given the relevant consent. We plan to use the orestbida CookieConsent tool for website consent categories: Necessary, Analytics, and Marketing.

Necessary technologies support core site and app functions. Analytics covers PostHog event analytics and measurement. Marketing covers Meta Pixel, TikTok Pixel, Google Ads, remarketing, and conversion tags. Mobile ad attribution or advertising tracking will be opt-in gated where applicable.

How we use information

We use your information to provide Poucho, create and update reduction plans, show progress, sync data, support widgets, manage accounts, process subscriptions, send reminders, provide support, fix errors, keep Poucho secure, prevent abuse, improve the product, measure campaigns, and comply with legal obligations.

We do not sell your health-related Poucho app data. Advertising technologies may involve sharing identifiers, event data, or usage signals with advertising partners after consent, as described in this policy and your consent choices.

Service providers and sharing

We share information with service providers that help operate Poucho, including Apple, Google, RevenueCat, PowerSync or other sync infrastructure, app stores, hosting providers, database providers, PostHog, Meta, TikTok, Google advertising and analytics services, support tools, and operational providers.

We may also share information where required by law, to protect rights and safety, to investigate abuse, or as part of a business transfer such as a merger, acquisition, or asset sale.

International transfers and security

Poucho is operated from the United Kingdom, but our providers may process information in other countries. Where required, we rely on appropriate safeguards for international transfers, such as contractual protections or other lawful transfer mechanisms.

We use technical and organisational measures intended to protect your information, but no method of transmission or storage is completely secure.

Retention and deletion

We keep account and app data while your account exists or while needed to provide Poucho. If you delete your account, we delete or anonymise account and app data unless we need to keep certain information for legal, security, fraud prevention, accounting, or operational reasons.

Local data may remain on your device until removed by the app, your device settings, or uninstalling the app.

Your privacy rights

Depending on where you live, you may have rights to access, correct, delete, restrict, object to, or receive a copy of your personal information. You may also have the right to withdraw consent where processing is based on consent.

UK and EU users may contact us about these rights at hello@poucho.app. You may also have the right to complain to your local data protection authority, including the UK Information Commissioner's Office.

Children and third-party links

Poucho is intended for users who are at least 18 years old. We do not knowingly collect personal information from children or people under 18. If you believe someone under 18 has provided information to Poucho, contact us so we can take appropriate action.

Poucho may link to third-party services, app stores, websites, or providers. Their privacy practices are governed by their own policies, not this Privacy Policy.

Changes and contact

We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date. If changes are material, we may provide additional notice where appropriate.

To ask a question, exercise privacy rights, or raise a concern, contact M4D Solutions using the details below.

Contact us

M4D Solutions
27 Old Gloucester Street
London
WC1N 3AX
United Kingdom
hello@poucho.app

Last updated July 3, 2026

Poucho

© 2026 Poucho. All rights reserved.

PrivacyTermsContact