Privacy Policy
Last updated: 9 June 2026
1. Controller
The entity responsible for the processing of personal data described here is:
PocketPhantom
Switzerland
Not registered for VAT
Contact: open a support ticket
This policy is based on the Swiss Federal Act on Data Protection (revFADP/nFADP, in force since 1 September 2023). Where visitors or customers in the European Union or EEA are concerned, the EU General Data Protection Regulation (GDPR) applies in addition.
2. Your rights
You have the right to request information about the personal data we hold about you, to have inaccurate data corrected, and to request its erasure, subject to any legal retention obligations. You may object to processing based on a legitimate interest, request data portability, and — where processing is based on consent — withdraw that consent at any time with effect for the future. To exercise any of these rights, open a support ticket.
You also have the right to lodge a complaint with the Swiss Federal Data Protection and Information Commissioner (FDPIC, edoeb.admin.ch). EU residents may contact the supervisory authority in their member state.
3. Hosting & Cloudflare
The website, the licensing/account server, and the installer downloads run on a dedicated server located in the European Union. Traffic to pocketphantom.com and its subdomains is routed through Cloudflare, Inc. (San Francisco, USA), which provides DNS, TLS termination, caching, DDoS mitigation, and bot protection. To do this, Cloudflare processes request metadata such as IP address, URL, user-agent, and a country-level location. Cloudflare is certified under the EU–US Data Privacy Framework and offers Standard Contractual Clauses. Legal basis: our legitimate interest in a secure, performant service (Art. 6(1)(f) GDPR; Art. 31 para. 2 lit. a revFADP).
4. Data collected by the website
Server log files
When you visit the website, the server automatically records browser type, operating system, referrer URL, the time of the request, and the IP address. This is used only for the secure, error-free operation of the site and is not used to identify you. Log files are deleted after a short period (typically 7 days).
Account & checkout
When you buy a licence or manage your subscription, we process the email address tied to your licence and your subscription/payment status. This is necessary to deliver and verify your licence (see Sections 7 and 9).
5. Cookies & local storage
pp-cookie-consent(localStorage, first-party) — stores your cookie choice. Strictly necessary; persists until you clear it.pp_fid(localStorage, first-party) — a random, per-browser identifier used to de-duplicate anonymous funnel/conversion events (see Section 7). It contains no name, email, or other personal identifier. Persists until you clear your browser's storage for this site.__cf_bm/cf_clearance(Cloudflare) — bot management and security-challenge clearance. Strictly necessary._ga,_ga_*(Google Analytics) — loaded onlyafter you click “Accept” on the cookie banner. See Section 6.
You can withdraw analytics consent at any time via “Cookie settings” in the footer, which re-opens the banner.
6. Analytics
With your consent, this website uses Google Analytics 4, a web-analytics service provided by Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland). Google Analytics is loaded only after you accept analytics cookies on the cookie banner, and is not loaded at all if you decline.
When active, it collects aggregate usage data such as the pages you view, time on page, approximate location (country/city level), device and browser type, and the source that referred you. IP addresses are anonymised (anonymize_ip) before processing. It sets the _ga and _ga_* cookies described in Section 5. Data may be transferred to Google servers in the United States under the EU–US Data Privacy Framework.
Legal basis: your consent (Art. 6(1)(a) GDPR; Art. 31 para. 1 revFADP). You can withdraw it at any time via “Cookie settings” in the footer, which re-opens the banner. For details on Google's processing, see policies.google.com/privacy.
7. Funnel & conversion events
To understand how visitors move through the purchase flow and to measure how well it converts, PocketPhantom records a small number of funnel events on its own admin backend. We log pay_visited, pay_form_submitted, download_visited, manage_visited, checkout_completed and activation_completed.
These events are keyed by pp_fid, a random per-browser identifier stored in your browser's localStorage (see Section 5). The identifier lets us de-duplicate and sequence events from the same browser. From pay_form_submitted onwards these events also record the email address you entered at checkout, together with the originating IP address and the country derived from it, so that a completed purchase can be matched to the visit that produced it. Earlier events carry no email. Legal basis: our legitimate interest in measuring and improving the conversion of our own website (Art. 6(1)(f) GDPR; Art. 31 para. 2 lit. a revFADP). You can stop and reset this at any time by clearing your browser's storage for this site, which removes the pp_fid value.
8. Payments — Stripe
Subscriptions are processed by Stripe Payments Europe Ltd. (Dublin, Ireland). When you pay, you are handled on Stripe's secure checkout; we never receive or store your full card details. Stripe processes your name, email, billing details, and card data under its own privacy policy. We receive your subscription status and a customer/subscription identifier to grant and renew your licence. Legal basis: performance of the contract (Art. 6(1)(b) GDPR).
At checkout we also store a short consent record alongside the payment as Stripe metadata: a withdrawalWaiver flag (recording that you asked for the licence to be made available immediately and acknowledged the effect of that request on your right of withdrawal) and a consentAt timestamp. We keep this so that we can evidence the consent you gave at the time of purchase. Legal basis: compliance with our legal obligations and our legitimate interest in keeping accurate records of consent (Art. 6(1)(c) and (f) GDPR).
9. Email — Resend
We use Resend (Resend, Inc., San Francisco, USA) to send transactional emails such as your activation key and payment confirmations, and to send and receive support correspondence (see Section 10). Only your email address and the relevant transaction or support data are transmitted. Legal basis: performance of the contract and our legitimate interest in reliable delivery (Art. 6(1)(b) and (f) GDPR).
10. Support & contact data
When you contact us for support — either through the support formon this website or from within the PocketPhantom desktop application (Settings → Support) — we collect and process the information you submit so that we can answer you and keep a record of the request:
- your first and last name and your email address;
- the category, subject, and message content you provide, together with any further correspondence in the same conversation;
- when you write from the desktop application, basic technical context — the application version and your operating-system version — to help us diagnose the issue.
We store the support ticket and the full conversation thread so that we can handle your request, follow up, and refer back to it if you contact us again. To send our replies and to receive and attach your email responses back to the ticket, we use our email provider Resend (see Section 9). Before submitting the form you confirm that you have read this Privacy Policy and our Terms of Service. Legal basis: performance of the contract where your request relates to your subscription, and otherwise our legitimate interest in responding to enquiries and providing support (Art. 6(1)(b) and (f) GDPR; Art. 31 revFADP). Support records are retained as described in Section 15, and you may request erasure of correspondence that is not subject to a retention obligation.
11. The desktop app — licence verification
The PocketPhantom desktop application communicates with our licensing server to verify your subscription and bind your licence to your device(s). For this purpose it sends and we store:
- your activation key;
- a device identifier (a stable hardware/installation identifier derived from your Windows installation) and a device label (typically your computer's host name);
- the IP address of the verification request and timestamps (kept as licence-event logs for fraud and abuse prevention);
- your entitlements and subscription status, mirrored from Stripe.
This is used solely to confirm a valid subscription, enforce the per-licence device limit, and detect key sharing or abuse. Legal basis: performance of the contract and our legitimate interest in protecting against unauthorised use (Art. 6(1)(b) and (f) GDPR).
Your AI provider API keys / sign-in tokens are stored locally and encrypted on your own device (via the operating system's secure storage) and are never transmitted to or stored by PocketPhantom.
12. Where your prompts go — included AI vs. your own key
There are two paths and they are materially different for your privacy. Which one is in use is shown in the app's model picker.
Included AI (the default on a new installation). The screenshots, text, and any Context you have saved are sent from your device to PocketPhantom's servers, which relay them to an upstream AI provider using our own credentials and stream the answer back to you. On this path our servers do receive the content you analyse, in order to forward it. We do not store that content. We retain only metering metadata for each request — the model used, input and output token counts, a timestamp, the activation key, and the originating IP address — which we need in order to debit your allowance and to detect abuse. Legal basis: performance of our contract with you (Art. 6(1)(b) GDPR; Art. 31 para. 2 lit. a revFADP). The upstream recipients are named in Section 13.
Your own key. If you supply your own API key, the content is sent directly from your device to the provider you selectand does not reach PocketPhantom's servers at all. Your key is stored encrypted on your device and is never transmitted to us. On this path the data is processed solely by your chosen provider under their privacy policy and terms:
- OpenAI — openai.com/policies
- Anthropic — anthropic.com/legal/privacy
- Google — policies.google.com/privacy
Features such as the on-screen answer display and screen-capture exclusion run entirely on your device and transmit nothing to us.
13. Third-party processors — summary
- Cloudflare — DNS, proxy, TLS, caching, security (Section 3).
- Stripe — subscription payments (Section 8).
- Resend — transactional email and support correspondence (Sections 9 and 10).
- Google Analytics 4 (Google Ireland Limited) — website analytics, only with consent (Section 6).
- Discord (Discord Inc., USA) — operational notifications to a private staff channel. These include your email address, the subject and an excerpt of any support message you send us, and, for security alerts, an IP address and browser user-agent (Sections 9, 10 and 11).
- Anthropic PBC (USA) — processes the content you analyse on the included AI path, as our processor, on our own account (Section 12).
- API relay endpoint — the included-AI pool can be configured to route through a reseller that speaks the same API, in which case that reseller receives the content you analyse before it reaches the model provider. No reseller is in the path today — the pool routes directly to Anthropic. This page is updated if that changes (Section 12).
- Your chosen AI provider (OpenAI / Anthropic / Google) — on the your own key path only; processes the content you analyse under your own account and their policy (Section 12).
We do not sell or rent your personal data.
14. International data transfers
Some of the processors above are located in, or transfer data to, the United States, and your chosen AI provider may be a US company. As a result, personal data may be processed outside Switzerland and the EU/EEA. Where that happens we rely on recognised transfer mechanisms:
- Cloudflare (USA) — certified under the EU-US Data Privacy Framework and offers Standard Contractual Clauses.
- Stripe (EU entity in Ireland, with group processing in the USA) — Standard Contractual Clauses and the EU-US Data Privacy Framework.
- Resend (USA) — Standard Contractual Clauses.
- Your chosen AI provider(OpenAI, Anthropic, or Google, US-based) — the content you analyse is sent by you, from your device, to that provider under your own account; the provider's own Data Privacy Framework certification and/or Standard Contractual Clauses, as set out in their privacy policy, govern that transfer (see Section 12).
For transfers from Switzerland, the equivalent Swiss safeguards apply (the Swiss-US Data Privacy Framework and the Swiss addendum to the Standard Contractual Clauses, recognised by the FDPIC). You can request a copy of the relevant safeguards by opening a support ticket.
15. Retention
Licence and subscription records (including device bindings and licence-event logs) are retained for the duration of your subscription and for as long as required to comply with statutory bookkeeping obligations (up to 10 years under Art. 958f of the Swiss Code of Obligations). Support tickets and their correspondence are kept after a ticket is resolved, so it can be reopened or referenced if you contact us again, and are retained until you ask us to delete them. Server logs are deleted after a short period. You may request erasure of data not subject to a retention obligation at any time.
16. Encryption
All connections to the website and the licensing server use TLS encryption (the https:// padlock in your browser). Licence-server responses are additionally signed so the desktop app can verify their authenticity.