Poquito Privacy Policy

Effective date: 7 October 2026

Last updated: 7 October 2026

Poquito is operated by Odd Potato. This policy explains what Poquito stores and sends when you use the Android app. It is a source document; before publication, review it against the release build and keep the dates above updated when it changes.

Accounts and information stored on your device

Poquito does not require an account. The app stores some information in its private app storage so its features work:

These items are stored on the device. Poquito does not claim that app-private files are encrypted at rest. You can remove saved remotes, scans, and queued feedback from their respective features; favorites can be removed in the app. The app does not currently provide a single control to erase every local setting and recent-tool entry. Uninstalling Poquito removes its app-private data. Android cloud backup and device transfer are disabled for Poquito app data. Files you export, save elsewhere, or share are outside Poquito's control and may remain with the destination you choose.

Camera, scanning, and files

The TV Size Visualizer requests camera access when you use its AR view. The camera image is used for the on-device AR experience; Poquito does not upload camera frames to a Poquito server. The feature uses Google Play Services for AR (ARCore), which may send its own device, identifier, API-usage and diagnostic information to Google as described in Google's documentation. Poquito does not use ARCore Geospatial or Cloud Anchors.

Document Scanner uses Google's Google Play services document-scanning flow. Its scanning flow runs on-device, and you choose which scan results are returned to Poquito. Poquito stores the returned scan copies and any OCR text locally. The app also runs bundled ML Kit text recognition on-device; the document image and recognized text are not sent to a Poquito server by that implementation. Google documents that ML Kit may send SDK diagnostics and usage metrics to Google. The scanner's camera flow is provided by Google Play services; the Android camera permission declared by Poquito is used by the TV Size Visualizer.

File and media tools process files you select on-device. Android's system picker grants access to selected files rather than Poquito requesting broad media-library access. If you choose to export or share a result, Android and the destination app handle that transfer. The Media Converter can request a direct media URL from the host in the URL you enter. That host receives the request and ordinary network information such as your IP address; Poquito does not route that download through its feedback service. Use an HTTPS URL when you need an encrypted connection to the remote host. The app also allows some local-network TV communication over HTTP as required to control compatible devices.

Advertising and privacy choices

Poquito uses Google Mobile Ads (AdMob) for banner ads and optional rewarded ads. Google Mobile Ads may collect or share IP address, ad and app interaction information, diagnostics, and device or account identifiers for ad delivery, measurement, analytics, and fraud prevention, as described by Google. Depending on your region and choices, Google may use information to provide and measure ads. Google's User Messaging Platform (UMP) presents consent and privacy choices where required; when Google reports that privacy options are available, you can reopen them in Settings under Ad privacy choices.

Buying Remove Ads suppresses Poquito's ad display. The app may still initialize Google advertising components as part of startup, so this purchase should not be understood as a guarantee that every Google SDK process or data flow is disabled. Google and Android settings provide additional controls for advertising identifiers and privacy choices.

Value conversion services

When you request current values, Poquito may contact Frankfurter for currency rates, Gold API for metal values, and CoinGecko for cryptocurrency lists and prices. Requests contain the selected currency pair, metal symbol, or asset and quote currency needed for the query. These services and their hosting providers receive normal network metadata, such as an IP address, as applicable to their own service. Some responses are cached locally. Their logging, retention, and privacy practices are controlled by those providers, not by Poquito. Review their current privacy information before using these features.

TV Remote and your local network

TV Remote discovers compatible devices on your local Wi-Fi network and communicates with the TV you select to pair or control it. Depending on the TV, the app sends commands and pairing information such as a PIN, token, client key, or other credential to that TV over your local network. Saved device and pairing details stay in Poquito's app-private storage. TV Remote is not a Poquito cloud service; the selected TV and your local network receive the communications needed for discovery, pairing, and control.

Purchases

Poquito uses Google Play Billing for Remove Ads and optional one-time support purchases. The support purchases are consumable; Remove Ads is a non-consumable purchase that can be restored through Google Play. Google handles the payment transaction and payment credentials. Poquito does not access your card number or other payment credentials. The app receives purchase product and status events needed to apply or restore the feature, and stores the Remove Ads entitlement locally. See Google's Privacy Policy and Google Payments Privacy Notice for Google's handling of Play and payment data.

Feedback

Sending feedback is optional. When you submit feedback, Poquito sends your message and these fields: a random submission ID, product (poquito), source (Home, a tool, or Settings), optional tool identifier, feedback type, app version, and timestamp. The production route is Poquito → Poquito's feedback service on Google Cloud Run → Resend → Odd Potato's recipient inbox. The service uses request information for rate limiting and short-lived duplicate protection. It has no feedback database, but email and service-provider systems may process or retain copies under their own settings and policies; no fixed retention period is promised here.

If delivery fails, a copy can remain in the local feedback queue until you retry or delete it. You can delete queued messages in the app. Poquito cannot recall a message after it has been delivered to the recipient inbox. You can contact Odd Potato about a privacy or deletion request using the address below.

Analytics, diagnostics, and service providers

Poquito does not include a separate product-analytics SDK or dedicated crash-reporting SDK. This does not mean that no usage or diagnostic information leaves the device: Google Mobile Ads, ARCore, ML Kit, Google Play Billing/Google Play services, Android, Cloud Run, Resend, and external API providers may process the information described in this policy to provide their services, diagnose them, prevent abuse, or handle transactions. Their own policies apply to their processing.

Security

Poquito stores its app data in Android app-private storage and disables Android backup and device transfer for that data. Feedback is sent to the configured production service over HTTPS. Value-conversion API requests use HTTPS. A direct media URL can use HTTP or HTTPS as entered, and local TV communication may use HTTP on your Wi-Fi network. Do not include sensitive information in a URL or feedback message unless you are comfortable sending it to the destination described above. Poquito does not claim encryption at rest for local files; provider security practices are described by the providers themselves.

Android permissions and network access

The verified Android release requests camera permission for the TV Size Visualizer, and network/Wi-Fi permissions for online features and local-network discovery/control. Google advertising and Android platform libraries may contribute advertising-related permissions such as the Advertising ID and Android Ad Services permissions in the merged release manifest. The release manifest does not request broad media/storage, location, microphone, contacts, SMS/phone, or notification permissions. System pickers and Android/Google-provided flows may have their own permissions outside Poquito's app permission set.

Third-party information

The services currently used include Google Mobile Ads, Google Play services for AR / ARCore, ML Kit, Google Play Billing and Google payments, Google Cloud, Resend, Frankfurter, Gold API, and CoinGecko. Their services and disclosures can change; consult each provider's current policy for details.

Children

Poquito is not represented here as designed for children. Its intended target audience and age groups must be set in Google Play Console by the developer. This policy does not make a target-age or age-threshold declaration.

Changes and contact

Odd Potato may update this policy when the app or its data practices change. The effective and last-updated dates at the top will be maintained explicitly. For privacy questions or requests, contact Odd Potato at odd.potato.labs@gmail.com.