Privacy policy

La Pochette - Last updated: 18 July 2026

Language of this document

This is a courtesy translation. The French version is the reference text and prevails in the event of any discrepancy.

In short

La Pochette is designed so that your documents are encrypted on your device before any backup. We cannot read the content of your documents, nor their titles, categories or text: we only host encrypted data that is unreadable to us ("zero-knowledge"). We do not sell any data and we use no advertising trackers.

Data controller

The data controller is Damien DIEP, sole trader operating under the trade name Hermitech, registered at 1970 Territoriale 40, 20131 Pianottoli-Caldarello, France (SIRET 821 372 133 00024).
Contact: contact@la-pochette.fr

Data we process

What we never see

The content of your documents, their images, their text (OCR), their titles and categories are encrypted on your device. The encryption key never leaves your device and is never transmitted to us. A consequence we own up to: if you lose your recovery key ("backup code"), no one - not even us - can restore your documents.

Image processing on your device

Before being encrypted, each document (photo, imported image, PDF page) is converted on your device into an image format: it is resized and re-encoded as JPEG to limit the space it takes up, and its technical metadata (EXIF) is removed - including, where applicable, the geolocation of the shot. This information is therefore neither kept nor backed up. This processing happens entirely on your device; the original file is not kept (see article 3 of the terms of use).

Importing from a computer (transfer)

The "Import from a computer" feature (page la-pochette.fr/envoyer) lets you send a file from your computer to your phone. Your browser encrypts each file on your computer with a single-use key transmitted to your phone through the QR code only - never to our servers. The encrypted file passes through a temporary relay, for as long as it takes your phone to fetch it.

Transparency: during this transfer, the imported file exists in the clear for a brief moment inside the web page we serve (it is your computer that encrypts it). This is the only moment when content is decrypted outside your phone, limited to that one file. The rest of your documents and your key never leave your phone.

Purposes and legal bases

Hosting and processors

Some of these providers (notably RevenueCat, Apple, Google and Cloudflare) may process data outside the European Union. These transfers are governed by appropriate safeguards (European Commission standard contractual clauses or the EU-US Data Privacy Framework).

Retention period

Your account data and your encrypted backups are kept for as long as your account exists. Deleting the account (or your vault) erases your encrypted blocks, the encrypted index and the associated metadata. Email verification codes expire within minutes and are purged. Transfer relay files are deleted at the end of the transfer and within 24 hours at the latest.

After any deletion, technical safety copies (storage safety versions and database backups, which protect us against mistakes and failures) may remain temporarily: they are purged automatically, within 30 days at the latest. They remain encrypted and unreadable to us, like everything else.

Deleting your account

You can delete your account and your encrypted backup at any time, in two ways:

Deletion is permanent and takes effect immediately: it erases your account, your encrypted blocks, the encrypted index and the associated metadata from our servers. It is irreversible. Only technical safety copies (encrypted and unreadable) may remain temporarily; they are purged automatically within 30 days at the latest (see "Retention period").

Deleting part of your data (without deleting your account)

You do not have to delete your account in order to erase your data from our servers.

These deletions are permanent: the encrypted block is removed from storage and its metadata row from the database, and nothing in the app can restore them. As with account deletion, technical safety copies (encrypted and unreadable) are purged automatically within 30 days at the latest (see "Retention period").

You can also, at any time, export all of your documents in the clear from the app (Settings → export), before deleting them.

Your rights

Under the GDPR, you have a right of access, rectification, erasure, restriction, objection and portability. Portability of your documents is also available directly from the app (export as an archive). To exercise your rights: contact@la-pochette.fr. You may also lodge a complaint with the French data protection authority, the CNIL.

Security

Encrypted communications (HTTPS), hashed passwords (Argon2id), encryption of documents at rest on the device, access protected by biometric authentication, and end-to-end encryption of backups.

Trackers

The app uses no advertising trackers and no third-party tracking cookies. The la-pochette.fr website only uses cookies strictly necessary for its operation (for example the temporary session for importing from a computer); no audience measurement or tracking cookies.

Minors

The Service is not intended for minors. We do not knowingly collect data concerning minors.

Changes

This policy may change. In the event of a significant change, we will inform you in the app.