Article 10 of the Spanish Law 34/2002 on information society services (LSSI-CE) requires every provider established in Spain to publish the following details. They are the same ones shown on our Google Play developer listing.
Name or company name
Pelayo Naredo García
Tax number (NIF/CIF)
15508437C
Registered address
C/ Orán 39, 5.º E · 33211 Gijón, Asturias, España
Registry details
Not applicable — sole trader (autónomo), not entered in the Commercial Registry.
Activity
Development and distribution of the PocketCode application for Android, and operation of the associated online services (accounts, Cloud Sync, marketplace and AI proxy).
Authorisations
Software development is not an activity subject to prior administrative authorisation, nor a regulated profession, so no authorisation number or professional-body details apply (art. 10.1 of the LSSI-CE).
Contact point
[email protected] for legal matters, notices of illegal content and requests from authorities. [email protected] for data protection. We accept communications in Spanish and English.
Digital Services Act
[email protected] is the single point of contact under articles 11 and 12 of Regulation (EU) 2022/2065 for users, Member State authorities, the European Commission and the Board. The reporting procedure is described in section 11 of the Terms of Service.
Hosting
The website is served by Vercel Inc. and the backend runs on Google Cloud Platform. Details of the transfers are in section 9 of the Privacy Policy.
Please read these Terms before using PocketCode. They cover the app, this website and every online service we run around them: accounts, Cloud Sync, the marketplace, the community and the AI features. The English text published at this URL is the authentic version; the other languages are provided for convenience.
1. Who we are, and accepting these Terms
PocketCode is an Android IDE published by the provider identified in the Legal identification section of this page ("PocketCode", "we", "us"). By downloading, installing or using the app, this website or any of our online services, you agree to these Terms. If you do not agree, do not use them. These Terms and the Privacy Policy are the whole agreement between you and us regarding the service.
2. Licence to use PocketCode
PocketCode is proprietary software. We grant you a personal, non-exclusive, non-transferable and revocable licence to install and use the app on compatible Android devices, for the term of these Terms. We do not sell you the software and we transfer no ownership: every right not expressly granted here stays with us. Some features require an active subscription (see section 15). PocketCode incorporates third-party open-source components, listed with their licences at the end of this page; those components keep their own licences, nothing in these Terms restricts the rights those licences grant you, and where these Terms conflict with one of them in relation to that component, the component's licence prevails. In particular, BusyBox is distributed as a separate program under GPLv2 with its complete corresponding source offered on this page, and the LGPL components carry the right to modify and relink described there.
3. Eligibility and age
PocketCode includes accounts, community content and messaging between users, so:
You must be at least 13 years old to use PocketCode
Between 13 and 16 you also need the consent of a parent or legal guardian to use the account, community and messaging features. In Spain, from the age of 14 you may consent yourself to the processing of your personal data (art. 7 LOPDGDD)
We do not knowingly collect personal data from anyone under 13. If we become aware of it, we delete the account and its data
You must have legal capacity to enter into this agreement and must not be prevented from using the service by any applicable law or sanctions list
4. Your account, your alias and its security
An account is only needed for Premium, Cloud Sync, the community and the marketplace. If you create one:
You choose a public alias. It may not impersonate another person, suggest an official role (such as admin or support), or infringe third-party rights
You are responsible for everything done through your account and for keeping your credentials safe
Tell us immediately at [email protected] if you suspect unauthorised access
One account per person. Creating accounts in bulk, sharing them, selling them or automating their creation is not allowed
We may reclaim an alias that impersonates someone, infringes rights or is reserved for the operation of the service
5. Your responsibilities
You are responsible for:
Keeping your API keys, tokens and credentials secure
Complying with the terms of the third-party services you connect (OpenAI, Anthropic, Google, GitHub, deployment platforms, and others)
Any code you write, run, publish or deploy with PocketCode, including code generated by AI
Backing up your work. Projects you do not sync live only on your device and disappear if you uninstall the app or lose the device
The costs you incur with third-party services (AI APIs, hosting, deployments)
The lawfulness of the data you handle with the app. If you use the database tools or the API tester on someone else's personal data, you are the controller of that processing and we are not
Keeping your account secure and telling us about any unauthorised access
6. Acceptable use
You may not use PocketCode to:
Break any local, national or international law or regulation
Infringe intellectual property rights or trade secrets
Create or distribute malware or harmful code, other than in an environment you own and are entitled to test
Abuse the third-party services integrated with the app, or exceed the limits their own terms impose on you
Circumvent plan limits, licence checks, entitlement gates or the payment system, or obtain Premium fraudulently through repeated trials or multiple accounts
Scrape, resell, sublicense or automate access to our API, marketplace or website beyond ordinary use of the app
Mine cryptocurrency, send spam or unsolicited bulk messages, or attack our infrastructure, our providers or other users
Harass, threaten or defame other users, or publish the content prohibited in the AI and safety section of this page
Reverse engineer, decompile or disassemble PocketCode, our backend or our API, or extract their source code — except where applicable law expressly allows it, such as the interoperability exception in Directive 2009/24/EC art. 6 and art. 100.5 of the Spanish TRLPI, or where the licence of an open-source component we include grants you that right
7. Running code, terminal and SSH
PocketCode runs code on your device: a Linux terminal, compilers and interpreters, language servers, an embedded database engine, and SSH and SFTP connections you configure. That capability is the product, and the risk of using it is yours.
You are responsible for every command, script and program you run, wherever it came from — written by you, generated by AI, downloaded from the marketplace or copied from the internet
Running untrusted code can destroy data on your device, expose your credentials or run up costs with third parties. We do not inspect, sandbox or validate what you run
You may only connect to hosts you own or are expressly authorised to access. You are responsible for the credentials you enter and for everything you do on the remote host
Port scanning, intrusion attempts and attacks against infrastructure that is not yours are prohibited, and may be a criminal offence
Local-network collaboration connects devices directly over your own network with end-to-end encryption: the content does not pass through our servers, and you decide who you let into a session
Important: the terminal is a real terminal. Commands such as deleting files are not reversible and there is no undo on our side.
8. Your content and Cloud Sync
Everything you create is yours: your projects, your code, your designs, your queries and your prompts. We claim no ownership over any of it. To make certain features work, you grant us a narrow licence:
A worldwide, non-exclusive, royalty-free licence to host, store, copy, transmit and display your content solely to operate the features you turn on. We do not use it for anything else, we do not sell it, and we do not train AI models on it
Cloud Sync (Premium) copies to our infrastructure what you choose to sync: database schemas, API collections and environments, workflows, visual designs, AI chat sessions, project metadata and usage statistics. The exact list is in the Privacy Policy
Whatever you do not sync stays on your device and is deleted when you uninstall the app
You can export and delete your synced content at any time from Settings, and deleting your account deletes it from our systems
You are responsible for holding the rights over what you upload, and for not uploading other people's personal data without a legal basis
9. Community, messages and user content
PocketCode includes community features — highlights, tips and challenges — a friends list and direct messages between users. When you publish or send something:
Do not post illegal, infringing, harassing, hateful or deceptive content, malware, spam, or any sexual content involving minors
Do not publish other people's personal data without their consent or another legal basis
We may remove content, restrict visibility or suspend accounts that break these rules. When we do, we tell the affected person the reason and how to contest it
Direct messages are private between participants, and we do not read them routinely. We may access the content of a specific conversation when it is reported, when the law requires it, or to investigate a serious safety risk
You can block other users and report content from within the app
10. Marketplace
The marketplace distributes assets, templates and extensions. Some are curated by us; others are published by their authors.
When you download an asset, you receive the licence stated in its listing. Being free of charge does not imply permission to redistribute or resell it
When you publish an asset, you keep ownership and grant us the licence needed to distribute it. You warrant that you hold the rights, that you state its licence correctly and that it contains no malicious code
You must respect the licences of anything the asset incorporates, including open-source components
We may review, reject, delist or remove any asset, in particular following a rights-holder complaint. Copies already downloaded stay on your device
Removing an asset from the catalogue is not a breach of these Terms on our part, and does not by itself give rise to compensation
11. Reporting illegal content, and how we act
If you find content in PocketCode that you consider illegal or in breach of these Terms, notify us at [email protected] or from the report control in the app. That address is also our single point of contact for the purposes of the Digital Services Act (Regulation (EU) 2022/2065), for users, Member State authorities, the Commission and the Board alike; we accept notices in Spanish and in English.
Tell us what the content is and where it is (asset, user, message or URL), why you believe it is illegal or infringing, how to contact you, and confirm that your notice is made in good faith
We acknowledge receipt and decide in a timely, diligent, non-arbitrary and objective manner
If we remove content, restrict its visibility, suspend a service or terminate an account, we give the affected person a statement of reasons: what we did, on what facts, on what legal or contractual basis, and how to contest it
You may reply to us at the same address. If you are not satisfied, you may go to the courts or to the competent authority — in Spain, the CNMC, as Digital Services Coordinator
We suspend, after warning, both users who repeatedly post infringing content and those who repeatedly send manifestly unfounded notices
12. Copyright complaints
If you are a rights holder and believe that content distributed through PocketCode infringes your copyright, send a notice to [email protected] identifying the protected work, the infringing material and where it is, your contact details, a statement that you act in good faith and that the information is accurate, and your signature. We remove infringing material and terminate the accounts of repeat infringers. If your content was removed by mistake, you may send a counter-notice to the same address. This procedure follows section 512 of the US Digital Millennium Copyright Act and the notice-and-action rules of the Digital Services Act.
13. Artificial intelligence and generated code
PocketCode connects to third-party AI models with your own key (BYOK): OpenAI, Anthropic, Google, GitHub Copilot, or any OpenAI-compatible endpoint you configure. We neither host, train nor fine-tune models.
You are interacting with an artificial intelligence system, not a person. Its answers are not professional, legal, medical or financial advice
Generated code is provided 'as is'. We do not guarantee that it is accurate, secure, efficient or error-free, and reviewing it before use is your responsibility
As between you and us, the output is yours: we claim no rights over it. Bear in mind that it may not be protected by copyright, and that another user with a similar prompt may receive a similar answer
Output may resemble third-party code released under its own licence. Checking licence compatibility before you ship is your responsibility
The prompts, code and files you attach are sent to the provider you choose and are subject to its terms and privacy policy. PocketCode does not use your prompts, your code or the answers to train any model, ours or anyone else's
These features make no automated decision producing legal effects concerning you, nor anything similarly significant
You may not use them to generate illegal content, malware, or any of the content prohibited in the AI and safety section of this page
Important: always review and test AI-generated code before putting it into production. Do not trust generated code blindly for critical systems.
14. Third-party services and deployments
PocketCode integrates services operated by other companies. Connecting them is your choice, and your use of each is subject to its own terms:
GitHub, for repositories, version control and Copilot. If you connect your account, we store the access token so the integration can work
Deployment platforms such as Vercel, Railway or Render. The deployment, what it costs and what it publishes are yours
AI providers, when you use your own key
Firebase and Google Cloud, for authentication, analytics, crash reports and Cloud Sync
Google Play and RevenueCat, for subscriptions and purchases
We are not responsible for changes, outages, price rises, data loss or decisions made by those services, and we cannot restore what they delete
15. Subscriptions, billing and refunds
PocketCode is freemium: the IDE works for free, and Premium raises limits and unlocks features listed on the pricing page.
Subscriptions are sold through Google Play. Google is the seller of record, charges you and issues the receipt; we do not process payments and never see your card
The price varies by country. Google Play converts the currency and applies the taxes of your jurisdiction, so what you pay may differ from the reference price shown on the website
Subscriptions renew automatically at the end of each billing period. You can cancel from Google Play settings at any time, and cancelling at least 24 hours before renewal avoids the next charge
Free trials, if offered, turn into a paid subscription when they end unless you cancel first
Cancelling takes effect at the end of the period in progress, and you keep access until that date
Refunds are handled under Google Play's policy. EU consumers have a 14-day right of withdrawal under Directive 2011/83/EU; however, under art. 16(m) of that Directive (art. 103.m of the Spanish TRLGDCU) the right does not apply once delivery of the digital content has begun with your prior express consent — by tapping Subscribe you give that consent and acknowledge that you lose the right of withdrawal
We may change prices with at least 30 days' notice. You will be told before the new price applies and you can cancel before it takes effect
If you go back to the free plan you lose Premium features at the end of the period. Your local projects and data are unaffected, and content already synced remains available for you to export
16. Beta and experimental features
Features labelled beta, experimental or preview are made available for testing. They may change, break or disappear without notice, and they may lose data. Use them at your own risk and do not rely on them for critical work. To the fullest extent permitted by law we accept no liability for them; if you are a consumer, this does not affect your statutory rights.
17. Feedback
If you send us ideas, suggestions, bug reports or improvements, you grant us a perpetual, irrevocable, worldwide and royalty-free licence to use them without obligation or compensation. This does not affect any right over your own code. We treat what you send us as non-confidential, so do not send us information you consider confidential or that belongs to someone else.
18. Our intellectual property
PocketCode, its name, its logo, this website's content and the brand assets belong to us and are protected by intellectual property and trademark law. You may use the name to refer to the product — reviews, tutorials, articles and comparisons are welcome and need no permission. You may not use it to name, brand or promote another product, nor in a way that suggests we built, endorse or support something we do not. The open-source components we incorporate keep their own licences, and none of those licences grants any right over our brand.
19. No warranty
PocketCode is provided 'as is' and 'as available', with no warranty of any kind, express or implied, including merchantability, fitness for a particular purpose and non-infringement. We do not warrant that it will work without interruption or error, that it will be secure, that it will meet your requirements, or that you will not lose data. If you are a consumer in the European Union, this section does not limit the statutory conformity guarantees of Directive (EU) 2019/770 or of the Spanish TRLGDCU.
20. Limitation of liability
To the fullest extent permitted by applicable law:
We are not liable for indirect, incidental, special, consequential or punitive damage, nor for loss of profit, business, data or goodwill
We are not liable for damage caused by AI-generated code, by code you run, by commands executed in the terminal, by actions taken on remote hosts, by third-party services or deployments, or by costs you run up with other providers
Our total aggregate liability for any claim arising from the service is limited to the greater of the amount you paid us in the twelve months before the event, or one hundred euros (100 EUR)
Nothing in these Terms excludes liability for death or personal injury caused by our negligence, for fraud or wilful misconduct, or any other liability that cannot be excluded by law
If you are a consumer, this section applies only to the extent consumer protection law permits, and your statutory rights are unaffected
21. Indemnity
If you use PocketCode outside your capacity as a consumer — professionally, for a business or on behalf of an organisation — you agree to defend, indemnify and hold us harmless from any claim, liability, damage and reasonable expense, including legal fees, arising from your use of the service, from your content, from code you publish or deploy, from your breach of these Terms, or from your infringement of third-party rights. We will notify you promptly of any such claim and you may take over the defence with counsel we reasonably approve. This section does not apply to consumers.
22. Suspension and termination
This agreement may end in the following ways:
You can stop using PocketCode whenever you like, and delete your account and its data from the app settings or at pocketcodeapp.com/account/delete
We may suspend or terminate your account if you breach these Terms, if the law requires it, for abuse or fraud, or where there is a serious risk to the service or to other users
Except where the law or the seriousness of the case prevents it, we notify you first and always give you the reason and how to contest it
On termination you lose access to Premium features, to synced content and to community content. You can export your data beforehand
Files stored locally on your device are not affected by termination
The sections that by their nature should survive do so: intellectual property, disclaimers, limitation of liability, indemnity, and law and jurisdiction
23. Export control and sanctions
You may not use PocketCode, nor let anyone use it through you, in breach of the export control and sanctions rules of the European Union, Spain, the United States or any other applicable jurisdiction. You confirm that you are not located in an embargoed territory, that you are not on any restricted-party list, and that you will not use the service for prohibited end uses. This applies both to the app and to the third-party services you connect to it.
24. Changes to these Terms
We may change these Terms. Substantial changes are announced at least 15 days in advance through an in-app notice, by email or by publication on this page with a new 'last updated' date; changes required by law, and those that merely add optional features, may take effect sooner. If you do not accept the new version, stop using the service and cancel your subscription before it takes effect — continuing to use it means you accept it. Previous versions are available on request at [email protected].
25. Governing law and disputes
These Terms are governed by Spanish law, without prejudice to the mandatory rules of the country where you habitually live.
Before anything else, write to [email protected]. Most matters are settled there, and we undertake to reply in good faith
If you are a consumer in the European Union, you may bring proceedings in the courts of your domicile (Regulation (EU) 1215/2012, arts. 17 to 19). We are not currently signed up to any alternative dispute resolution body; the national ADR bodies are listed at consumer-redress.ec.europa.eu/dispute-resolution-bodies, and in Spain you may also go to the consumer arbitration boards. The European ODR platform ceased operating on 20 July 2025 and no longer accepts complaints
If you live in the United States, you and we agree to resolve any dispute by individual binding arbitration administered by the American Arbitration Association under its Consumer Arbitration Rules, waiving trial by jury and any class or representative action. You keep the right to bring an individual claim in small claims court, and you may opt out of this clause by writing to [email protected] within 30 days of first accepting these Terms
In any other case, the courts of our registered address in Spain have jurisdiction, unless mandatory consumer law in your country gives you a different forum
Nothing in this section prevents either party from seeking interim relief from a court where it is needed to protect a right urgently
26. Miscellaneous
Standard provisions that apply to the whole agreement:
Severability: if a clause is held invalid, the rest remains in force and the invalid clause is replaced by the valid one closest to its purpose
No waiver: not enforcing a right on one occasion does not mean we give it up
Assignment: you may not assign this agreement. We may assign it in a merger, acquisition or sale of the business, telling you in advance, and without your rights being reduced
Force majeure: neither party is liable for failures caused by events beyond its reasonable control, including outages at providers we depend on
Notices: we contact you by email or through the app; you contact us at [email protected]
Entire agreement: these Terms and the Privacy Policy replace any earlier agreement on the same subject
Language: the English version published at this URL is the authentic one; the translations are for convenience and do not create additional rights
27. Data protection
We process your personal data in accordance with the General Data Protection Regulation (Regulation (EU) 2016/679), the Spanish LOPDGDD and, where they apply, the CCPA/CPRA, the UK GDPR and the LGPD. Which data we collect, why, on what legal basis, for how long we keep it, who processes it on our behalf and how to exercise your rights are all set out in the Privacy Policy below. To exercise your rights or ask a question, write to [email protected]; you may also lodge a complaint with the Spanish Agencia Española de Protección de Datos (aepd.es).
At PocketCode, your privacy is our priority. This policy transparently explains how we handle your information when you use our website and application, what data we collect, how we protect it, and what rights you have. We do not sell personal data and we do not train AI models — ours or anyone else's — on your code, prompts or files.
1. Information we collect
What we collect depends on whether you use the website, the app without an account, or an account with Cloud Sync:
Website (pocketcodeapp.com):
Pages visited and time on site (Google Analytics)
Device type and browser
Approximate location (country/city)
Referral source (how you reached the site)
Android app (with your consent):
Anonymous usage analytics: features used, navigation flows and feature popularity (Firebase Analytics). The content of your code is never sent
Crash reports: stack traces, device model and OS version when the app crashes (Firebase Crashlytics)
Push notification token (Firebase Cloud Messaging), so we can deliver the notifications you enable
Account, Cloud Sync and community (only if you sign in):
Authentication data: email address, alias, user ID and sign-in provider (Google, GitHub or email), managed through Firebase Authentication
Subscription data: plan status, purchase history and billing period, managed through RevenueCat and Google Play. We never store payment data (cards or bank accounts)
Content you choose to sync: database schemas, API collections and environments, automation workflows, visual designs, AI chat sessions and their messages, project metadata and usage statistics
GitHub access token, if you connect your account, so the integration can operate
Community and social data: alias, friend requests and friendships, content you publish (highlights, tips), assets you publish in the marketplace, and direct messages you exchange with other users
The first time you open the app you are shown a consent dialog where you choose which categories to share (analytics, crash reports, performance). You can change it at any time in Settings > Privacy. Cloud Sync and the community features are optional and only work if you sign in.
2. How We Use Your Data
Analytics data is used solely to:
Improve user experience on the site and app
Understand which content and features are most useful
Optimize site and app performance
Make informed decisions about new features and improvements
3. What stays on your device, and what does not
PocketCode is local-first: your projects, your code and your files live on your device, and we do not upload them. There is one exception, and it is under your control: what you explicitly turn on in Cloud Sync, listed in section 1. Everything else — the projects you work on, the files you open, the output of the terminal — never reaches our servers.
Important: if you use the AI features, you provide your own provider keys (OpenAI, Anthropic, Google, GitHub Copilot or an OpenAI-compatible endpoint). Those keys are encrypted on your device with the Android Keystore and are NEVER transmitted to our servers: the app talks to the provider directly. We do not use your prompts, your code or the AI answers to train any model — and as of 2026 the API endpoints of the major providers do not use customer prompts for training by default, though you should check your specific plan with each of them.
4. Third-Party Services
When you use integrations in the app, you are subject to their respective privacy policies:
GitHub: For repositories, version control, and GitHub Copilot
Deployment platforms (Render, Vercel, Railway): For application deployment
AI Services (OpenAI, Anthropic, Google): When you use your API key for the copilot
Firebase (Google): Analytics, authentication, crash reporting, and cloud storage
RevenueCat: Subscription and in-app purchase management
Google speech recognition: when you use voice input in AI chat, the recorded audio is sent to Google's speech-to-text service to transcribe it. We do not receive or store that audio.
5. Data Security
We implement multiple security measures to protect your information:
API keys are stored encrypted on your device using Android Keystore
Communications with third-party services use TLS/SSL encryption
We do not store passwords or credentials on our servers
We perform regular security audits of our code and dependencies, and use StrongBox-backed AES-256-GCM where the device supports it; if a personal data breach occurs we notify the Spanish AEPD within 72 hours per art. 33 GDPR and affected users without undue delay where the risk is high
6. Cookies and Tracking Technologies
Our website uses cookies and similar technologies to enhance your experience:
Essential cookies: required for site functionality (language preference, session)
Analytics cookies: Google Analytics for anonymous usage statistics
You can manage or disable cookies from your browser settings at any time
7. Your Rights
Under data protection legislation (including GDPR for EU users), you have the right to:
Access: request a copy of the data we hold about you
Rectification: correct inaccurate or incomplete data
Erasure: request that we delete your personal data
Portability: receive your data in a structured, machine-readable format
Objection: object to the processing of your data in certain circumstances
Disable cookies and tracking in your browser settings — and lodge a complaint with the Spanish Agencia Española de Protección de Datos (AEPD) at aepd.es. We respond to verified rights requests within 30 days, extendable by two months for complex cases (art. 12(3) GDPR). For users in California (CCPA/CPRA), Brazil (LGPD), the UK (UK GDPR) and other jurisdictions, equivalent rights apply — write to [email protected]
8. Data Retention
We retain your data only for as long as necessary for the purposes described in this policy:
Website analytics data: maximum 24 months, then automatically deleted
App analytics data (Firebase): maximum 14 months, then automatically deleted
Local app data: stored on your device, under your full control. Deleted when you uninstall the app
Crash reports: anonymized and retained for 90 days to improve stability
Authentication data: retained while your account is active. You can request deletion at any time
Subscription data: retained as required by tax legislation and Google Play policies
9. International Transfers
Some sub-processors (e.g. RevenueCat in the US) may process data outside the EU. Transfers are covered by the European Commission's Standard Contractual Clauses (Decision 2021/914) and, where the sub-processor self-certifies, the EU-US Data Privacy Framework (Decision (EU) 2023/1795). A copy of the SCCs in force is available on request at [email protected].
10. Children's privacy
PocketCode requires you to be at least 13 years old, because it includes messaging and user-generated content. Between 13 and 16 you need the consent of a parent or legal guardian to use the account, community and messaging features; in Spain, from the age of 14 you may consent yourself to the processing of your personal data (art. 7 LOPDGDD). The app includes an age check during onboarding. We do not knowingly collect data from anyone under 13: if you are a parent or guardian and believe your child under 13 has given us personal information, write to [email protected] and we will delete it.
11. Changes to This Policy
We may update this privacy policy from time to time. We will notify you of any significant changes by posting the new policy on this page with an updated date, and through in-app notifications for important changes. We recommend reviewing this policy periodically.
12. Legal basis for each purpose
Article 6 of the GDPR requires us to state why each processing operation is lawful:
Providing the app, the account, Cloud Sync, the marketplace and the community: performance of the contract between you and us (art. 6.1.b)
Analytics, crash reports and performance metrics: your consent, given in the initial dialog and revocable at any time (art. 6.1.a)
Push notifications: your consent, revocable from the system settings (art. 6.1.a)
Preventing fraud and abuse, keeping the service secure and defending our rights: legitimate interest (art. 6.1.f)
Handling reports of illegal content and complying with authority requests: legal obligation (art. 6.1.c)
Billing and tax records for subscriptions: legal obligation (art. 6.1.c)
13. Automated decisions and profiling
We make no automated decision producing legal effects concerning you or similarly significantly affecting you, and we do not profile you for advertising. AI answers are generated at your request by the provider you choose and do not decide anything about you. Suspending an account for abuse is always reviewed by a person before it takes effect, except where an automatic measure is needed to stop an ongoing attack, in which case you can ask for a human review at [email protected].
14. Who is responsible for your data
The controller of the processing described in this policy is the provider identified in the Legal identification section at the top of this page, whose full details, tax number and address are published there as required by article 10 of the Spanish LSSI-CE. For anything relating to data protection, including exercising your rights, the contact address is [email protected]. If you believe we are not handling your data correctly you may lodge a complaint with the Spanish Agencia Española de Protección de Datos (aepd.es) or with the supervisory authority of the country where you live.
Open Source Licenses
PocketCode stands on the shoulders of giants. We thank the open source community for making this project possible. Below are the licenses of the main libraries we use.
Automatically generated from the source repository on 5/20/2026. 82 components under 14 distinct licenses.
Provides TLS and crypto primitives (libssl.so + libcrypto.so). Bundled both inside the PostgreSQL engine tarball and under assets/nodejs-runtime/lib for the Node.js runtime (libssl.so.3 / libcrypto.so.3). OpenSSL relicensed to Apache-2.0 as of 3.0.
The PostgreSQL binaries and supporting shared libraries are sourced from Termux's Android port (build scripts and patches). Termux build configuration is Apache-2.0; upstream sources are unmodified.
libnode_binary.so is a custom Android build of Node.js (Termux aarch64). It runs the AI provider CLIs (Claude Code, Gemini, Codex) and the on-device dev server / linters. Its dynamically-linked shared libraries ship under assets/nodejs-runtime/lib and are extracted to the app's private files dir at first launch: libz (zlib), libcrypto/libssl (OpenSSL 3 / Apache-2.0), libicui18n/libicuuc/libicudata (ICU), libc++_shared (LLVM libc++ / Apache-2.0 w/ LLVM exception), libcares (c-ares / MIT), libsqlite3 (SQLite / public domain). All are permissive — no GPL/LGPL. The official Node.js LICENSE bundles many third-party components; their notices are reproduced in this app's notice.txt.
GNU Lesser General Public License v2.1 (LGPL-2.1)1 component
Component
Version
Type
URL
TinyCC (TCC)
Linked statically into libpocketcode_tcc.so. Per LGPL-2.1 §6, you have the right to relink against a modified TinyCC. The vendored source is in frontend/core/tcc/tcc-vendor/.
Public Domain (SQLite Blessing) (Public-Domain-SQLite)1 component
Component
Version
Type
URL
SQLite
Ships as libsqlite3.so under assets/nodejs-runtime/lib — a runtime dependency of the bundled Node.js binary (node:sqlite). SQLite is dedicated to the public domain, with no licensing restrictions.
Used by the optional 'Local PostgreSQL' database connection. Binaries ship as both bundled tarball assets and renamed lib*.so files. Sourced from the Termux Android port of PostgreSQL; the original PostgreSQL source is at git.postgresql.org/git/postgresql.git tag REL_18_2. All databases live entirely on the user's device — no PostgreSQL data is sent to any server we control.
Unicode collation and locale handling. Bundled both inside the PostgreSQL engine tarball and under assets/nodejs-runtime/lib for the Node.js runtime (libicui18n.so.78 / libicuuc.so.78 / libicudata.so.78).
The official PostgreSQL JDBC Driver. PocketCode uses it to talk to the embedded local PostgreSQL server over 127.0.0.1 loopback. PgJDBC is BSD-2-Clause — fully compatible with commercial distribution. Replaces a previous shell-out to psql, which transitively depended on GNU readline (GPL-3).
This list includes the main dependencies. For the complete list of dependencies, check the package.json file in our GitHub repository.
AI-generated content & safety
PocketCode displays responses generated by third-party AI models (OpenAI, Anthropic, Google and GitHub Copilot) that you connect to with your own API key (BYOK model). PocketCode does not host, train or fine-tune any model: your messages and any code or files you attach are sent to the provider you choose, which enforces its own safety and moderation policies on both input and output.
Every AI response includes a control to report it. Reports reach our team and are reviewed; you can also send them by email.
Zero tolerance for child sexual abuse and exploitation (CSAE)
Child sexual abuse and exploitation material is strictly prohibited in PocketCode. Reports flagged as CSAE are prioritized, reviewed immediately and escalated to the relevant authorities (e.g. NCMEC) and providers where applicable. PocketCode ships no feature that solicits, searches for, generates or organizes such content.
To report AI content or any safety concern, contact [email protected].
Anthropic Claude
PocketCode does not bundle or download Claude Code (the proprietary CLI tool owned by Anthropic PBC). Claude works exclusively through Anthropic's official API with your own key (BYOK model): no binary is downloaded or executed at runtime, in any version of the app.
PocketCode does not relicense or redistribute any Anthropic software; it only sends your messages and the code you attach to the API with your key.
Your use of Claude is governed by Anthropic PBC's terms:
PocketCode is not a party to that agreement. It does not store the models or response content on its servers; your API key is kept encrypted on your device.
Source code offer: BusyBox (GPLv2)
PocketCode ships BusyBox v1.34.1-meefik as a separate native library (libbusybox.so) inside the Android terminal module. BusyBox is free software under the GNU General Public License version 2 (GPLv2).
GPLv2 §3 obliges us to deliver the complete corresponding source. We satisfy this obligation in two complementary ways:
1. Inside the app (GPLv2 §3(a) — source accompanying the binary)
Every PocketCode APK includes the same source tarball, its SHA-256 and the full GPLv2 text under assets/legal/. To copy them to your Downloads folder, open the app and go to Settings → Open-source licenses → BusyBox source (GPL-2.0) → “Save source to Downloads”. The files land under Download/PocketCode-GPL/ and can be verified with sha256sum -c busybox-source-1.34.1-meefik.tar.gz.sha256.
No internet connection required — the source travels with the binary.
2. From this website (GPLv2 §3(b) — written offer)
The same package is permanently hosted here, byte-for-byte identical to the one bundled in the APK:
SHA-256 sums of all of the above and of the shipped binaries
This offer is valid for at least three (3) years from the date the corresponding binary was last distributed, per GPLv2 §3(b). Alternatively you may request the source on physical media by writing to [email protected].
Right to modify and relink (LGPL-2.1 §6)
PocketCode incorporates components under the GNU Lesser General Public License version 2.1. Per LGPL §6, you have the right to modify the LGPL library and to relink PocketCode against the modified version.
Tiny C Compiler (TCC) — vendored from upstream without modification; ask us and we send you the exact snapshot we build
To exercise this right, download the upstream sources and follow the build instructions documented upstream. You may also request the corresponding source of the version you received from us, free of charge, at [email protected]; we will send it within 30 days. PocketCode does not expose proprietary interfaces that would prevent relinking against a modified version.