PoCats Privacy Policy

Effective 10 August 2026 · Last updated 14 September 2026

PoCats is a game about photographing real cats you meet and collecting them as cards. This policy explains exactly what the app collects, why, who processes it on our behalf, and how to get it deleted. It covers the PoCats mobile app for iOS and Android (bundle and package id com.pocats.app) and nothing else.

PoCats is made by Vega Digital, an independent studio. You can reach a human at hello@vegadigital.app.

The short version. We collect your email (or nothing at all, if you play as a guest), your in-game progress, your cat photos, and a deliberately blurred location for the sightings map. Your photos are sent to an AI vision service to confirm they show a real cat and to cut the cat out of the background. We run no advertising and no tracking of any kind. Unless you switch it off in Settings, the app sends counts of what worked and what failed, a catch succeeded or a purchase failed, along with a report when the app crashes, so faults get found. None of it ever includes your photos, your location or your name, and one switch turns all of it off. We do not sell your data. You can delete your account and everything in it from inside the app.

1. What we collect

DataWhenWhy
Email address If you sign in with an email link, with Google or with Apple To create and secure your account and to send the sign-in link. If you use Apple's Hide My Email, the relay address Apple gives us is the one we hold. Guests do not provide one.
Name Only if you sign in with Google or with Apple Supplied by Google as part of the sign-in, or by Apple on your first sign-in only, and only if you choose to share it. Used to pre-fill your profile.
Account identifier Always, including guest sessions The internal ID that ties your album, wallet and purchases to you.
Profile you choose During setup Username, trainer picture, country and language, so the app can address you and localise content.
Photos you take in the app Each time you attempt a catch To verify the photo shows a real, live cat, to cut the cat out of the background, and to become your card art.
Approximate location Each catch, when you open the map, and while the app is open to measure how far you walk for the yarn feature. Only if you grant location permission. To place a sighting on the community map and to find sightings near you. Coordinates are rounded to two decimal places (roughly a kilometre) before they leave your device. The walk is measured on your phone: the position readings never leave it, and only the day's total in metres is saved with your progress. We never store your precise position.
Gameplay data As you play Your album, cards and their rarity, snack cans, treats, coins, XP, streaks, daily rewards, battle results, the distance walked today in metres, and sighting records, so your progress survives reinstalling.
Purchase records and device identifiers Only if you buy something Handled by RevenueCat and by the store you bought through, Google Play or the Apple App Store, so we can unlock what you bought, restore it on a new device, and prevent fraud. We never see or store your card number, bank details or billing address. The store handles payment entirely.
Usage counts As you play, unless you switch “Share usage data” off in Settings Counts of in-app events (catches, paywall views, purchase attempts and failures) and error messages from failures, sent to our own PostHog instance so faults get found and the game gets better, along with facts about the phone: operating system and version, device model, screen size, language and time zone setting, and the app version running. PostHog derives a country and city from the connection address and then discards the address. While you are signed in these events are tied to your account id, so they are not anonymous; they never include your photos, your GPS location, your email or your name. Switching it off stops the sending immediately and discards anything not yet sent. There is no analytics SDK in the app: no Google Analytics, Firebase, Amplitude, Mixpanel or Segment.
Crash reports When the app crashes, unless the same switch is off The error and the stack trace that produced it, with which app version and which update were running, sent to Sentry. Configured not to send the identifying extras it can send by default: no IP address and no device name. No session tracking and no performance monitoring. Switching it off stops new reports at once; a crash deep in the native layer during that same session may still be reported until the app is restarted, and nothing is reported from the next launch on. Crash reports never include your photos, your location, your email or your name. There is no Crashlytics in the build.

What we deliberately do not collect

2. Your photos, in detail

This is the part most worth reading, so we are being specific.

When you take a catch photo, the image is sent over an encrypted connection to our server function, which forwards it to xAI (the Grok vision service) to answer one question: is this a genuine, live cat, rather than a photo of a screen, a poster or a printout? The verification result comes back and the photo becomes your card.

On phones that support on-device subject segmentation (iOS 17 and newer, or Android devices with Google ML Kit subject segmentation), the cat is cut out of the background entirely on your phone and the image never leaves it for that step. On phones without that capability, the image is sent to Replicate to perform the same cut-out.

Your photos are stored on your device as card art and are associated with your account so your album can be restored. Your photos are never shown to other players, never posted publicly, and never used for advertising. We do not use your photos to train any model of our own.

3. The community sightings map

When you catch a cat, PoCats can add a marker to a shared map that other players can see. That marker contains only: a blurred coordinate rounded to about a kilometre, a rarity tier, and a location label drawn from a fixed list built into the app. It does not contain your name, your username, your photo, your account identifier or your exact position. Markers are player reports: a marker means another player says they saw a cat roughly there. We do not verify them, and a marker is never an assurance that a place is safe, open to the public, or lawful to enter. Markers expire automatically. If you decline location permission, no markers are created and the rest of the game works normally.

4. Who processes data for us

We use a small number of service providers. They process data on our instructions, for the purposes below, and for nothing else.

ProviderWhat it handles
SupabaseAccount sign-in, the database holding your profile, album, wallet and sightings, and the server functions the app calls.
xAIVision check on each catch photo to confirm it shows a real, live cat.
ReplicateBackground removal on catch photos, on devices that cannot do it locally.
RevenueCatSubscription and purchase management, entitlement checks and restore-purchases.
PostHogProduct analytics, unless you switch “Share usage data” off in Settings. Receives counts of in-app events and error messages from failures, together with facts about the phone: operating system and version, device model, screen size, language and time zone setting, and which version of the app is running. It derives a country and city from the connection address of each request and then discards the address, so the address itself is never stored. Never receives your photos, your GPS location, your email or your name.
SentryCrash reporting, unless you switch “Share usage data” off in Settings. Receives the error and stack trace of a crash with the app version and update that were running. No IP address, no device name, and never your photos, your location, your email or your name.
Google Play Billing and the Apple App StoreTake the payment on their platform. We never receive your payment details.
Google Maps SDK (Android) and Apple Maps (iOS)Draw the map. Governed by Google's and Apple's own privacy policies.

We do not sell your personal information, we do not share it with data brokers, and we do not use it for advertising or marketing profiling.

5. Legal bases

Where the GDPR or similar laws apply: we process your account data and gameplay data to perform our contract with you (running the game you asked to play); we process catch photos and approximate location on the basis of your consent, given through the camera and location permission prompts, which you can withdraw at any time in your device settings; and we process purchase and fraud-prevention data under our legitimate interests in delivering what you paid for and preventing abuse.

6. How long we keep it

7. Deleting your data

In the app: open your Profile (tap your avatar and name on the Home screen), tap Delete account, type DELETE and tap Delete forever. This permanently removes your account, profile, album, wallet, purchase records and sightings from our servers. It cannot be undone. Guest accounts can be deleted the same way.

By email: write to hello@vegadigital.app from the address you signed up with, or tell us your username, and we will delete everything within 30 days.

Deleting your PoCats account does not cancel a subscription. Cancel that separately where you bought it: on Android in Google Play → Subscriptions, on iPhone in Settings → your name → Subscriptions.

8. Your other rights

Depending on where you live, you may have the right to access a copy of your data, correct it, restrict or object to processing, port it elsewhere, or complain to your local data protection authority. Email hello@vegadigital.app and we will respond within 30 days. We will not charge you or treat you differently for exercising any of these rights.

9. Security

All data sent between the app and our servers travels over encrypted HTTPS/TLS connections. Sign-in tokens are stored in your device's secure keystore, not in plain app storage. Database access is restricted per-account by row-level security so one player cannot read another player's album, profile or purchases. No system is perfect, and we do not claim otherwise, but we do not collect anything we do not need, which is the strongest protection available.

10. Children

PoCats is not directed at children under 13, and we do not knowingly collect personal information from anyone under 13. Younger players should use the app with a parent or guardian, who accepts the Terms on their behalf. If you believe a child under 13 has given us personal information, email hello@vegadigital.app and we will delete the account promptly.

11. International transfers

Our providers operate servers in the United States and the European Union, so your data may be processed outside your country. Where required, transfers rely on the European Commission's Standard Contractual Clauses or an equivalent safeguard.

12. Changes to this policy

If we change what we collect or who processes it, we will update this page and change the "Last updated" date at the top. Material changes will also be surfaced in the app. Continuing to use PoCats after a change means you accept the updated policy.

13. Contact

Vega Digital, PoCats
Operated by Isaac Efraim
hello@vegadigital.app