Last Updated: September 9, 2026
Pockit is an iOS app that helps App Store creators view Apple App Store Connect sales, revenue, downloads, ratings, reviews, widgets, and related business insights in one place. We design Pockit around local storage and user control.
To connect to App Store Connect, you may enter Apple Connect API information: Issuer ID, Key ID, Vendor Number, and a .p8 private key. You may also choose app filters, currency, widget preferences, Face ID settings, notification settings, and display preferences.
The .p8 private key is stored only in the on-device Keychain and is limited to this device. It does not sync through iCloud Keychain and is not included in device backups. Issuer ID, Key ID, and Vendor Number are stored on your device. Pockit never uploads your .p8 key to any server. Login credentials used to call Apple APIs stay in memory only and are not saved to disk or uploaded.
Pockit does not operate a separate user-account login to collect, store, or process your App Store Connect credentials.
After you connect your account, Pockit may request data from Apple's App Store Connect APIs and related Apple services, including app metadata, sales and proceeds reports, downloads, ratings, reviews, territories, currencies, and app status information.
This data is used only to display analytics inside Pockit and its widgets. Cached data is stored locally on your device to improve speed and reduce repeated network requests.
Pockit does not collect or sell personal data for advertising or tracking. The app includes a PrivacyInfo.xcprivacy manifest declaring that it does not track users and does not collect data linked to your identity for tracking. We do not collect contacts, live camera or microphone recordings, precise location, browsing history, or device identifiers for third-party tracking.
When you create a share poster, you may use the system photo picker to choose an image already on your device, and you may save the generated poster to Photos. Those images remain on your device unless you choose to share them yourself. Pockit does not upload your photos to our servers.
If you copy sensitive values such as an order passcode, notification URL, or export password, Pockit writes them only to the on-device pasteboard. They expire after about two minutes and are not synced to other devices.
If you enable Face ID, unlock happens entirely on your device. Biometric data is not sent to us or to any third party.
Pockit may contact the following services as needed for app functionality:
We do not include advertising or third-party analytics SDKs, and we do not share your data with advertising networks or analytics providers.
If Pockit shares data with Apple services or any permitted third-party service required for app functionality, those services are expected to protect user data according to their own privacy and security standards and provide protections consistent with this policy and Apple's requirements.
If you enable order notifications, Pockit saves on this device a set of identity information used only to receive order alerts.
After you enter the matching notification URL in App Store Connect, Apple sends order events to Pockit's order notification service (orders.pockitkit.cn).
That service is used only to push your order alerts to devices you have authorized. It never receives your .p8 private key, and it is not a separate cloud account you need to register for.
You can destroy this notification link in the app at any time. After you destroy it, the related passcode on this device is cleared, and that address will no longer receive or push new order alerts. The next time you open the Orders page, a new link is created.
The order notification service keeps only the information needed to show orders on your devices and send alerts, and isolates it from other users by your unique link. We cannot access your order contents, and we do not use them for advertising or analytics.
Pockit may write selected summary data to the App Group container so iOS widgets can display your chosen metrics.
If you enable notifications, order alerts are delivered as remote notifications through Apple Push Notification service (APNs), not as local-only notifications. The app may also use background refresh so widgets and on-device summaries can update when the system allows. Notification permission can be managed in iOS Settings.
Pockit may use Apple's StoreKit framework to process purchases or subscriptions. Purchase processing is handled by Apple. We receive only the information needed to unlock app features and restore purchases.
Pockit is not directed to children under 13 and does not knowingly collect information from children.
Locally stored credentials, settings, cached analytics, and the local order ledger remain on your device until you delete them in the app, reset the app, or uninstall the app.
Deleting local App Store Connect credentials in Pockit removes them from this device. It does not revoke the corresponding API key in App Store Connect. If you believe a key may be compromised, you must revoke it yourself in App Store Connect.
If you used order notifications, destroying the order link is a separate action. It stops that address from receiving and pushing new order alerts, and it clears the related passcode on this device. Deleting local API credentials does not by itself destroy the order link.
iOS may retain Keychain items after you uninstall the app. On a later install, if the app no longer has your previous Issuer ID, Key ID, and Vendor Number, Pockit attempts to clear leftover .p8 material and order-notification credentials so a previous user's key is not restored automatically.
Pockit does not provide a separate cloud login or user-account system. The only server-side data associated with you is the information needed to deliver order notifications to your devices, which you can invalidate by destroying the order link.
We may update this Privacy Policy from time to time. Any changes will be posted on this page with an updated date.
If you have questions about this Privacy Policy, please contact us at: jason2k@126.com
最后更新日期:2026年9月9日
Pockit 是一款帮助 App Store 开发者查看 Apple App Store Connect 销量、收入、下载量、评分、评价、小组件及相关经营数据的 iOS 应用。我们围绕本地存储和用户控制来设计 Pockit。
为了连接 App Store Connect,您可能会填写 Apple Connect API 信息:Issuer ID、Key ID、Vendor Number 和 .p8 私钥。您也可以设置 App 筛选、货币、小组件偏好、Face ID、通知和显示偏好。
.p8 私钥只保存在本机钥匙串中,且仅限此设备:不会通过 iCloud 钥匙串同步,也不会随设备备份迁移。Issuer ID、Key ID 和 Vendor Number 保存在您的设备本机。Pockit 不会把您的 .p8 上传到任何服务器。用于连接 Apple 的登录凭证只短暂留在内存中,不会保存到本机或上传。
Pockit 不提供单独的云端登录账号,也不会用独立账号系统来收集、保存或处理您的 App Store Connect 凭证。
连接账号后,Pockit 可能会向 Apple 的 App Store Connect API 及相关 Apple 服务请求数据,包括 App 元数据、销量和收入报告、下载量、评分、评价、地区、货币和 App 状态信息。
这些数据仅用于在 Pockit 应用内和小组件中展示数据分析。缓存数据会保存在您的设备本机,以提高打开速度并减少重复网络请求。
Pockit 不会为了广告或追踪目的收集或出售个人数据。应用包含 PrivacyInfo.xcprivacy 清单,声明不做用户追踪,也不为追踪目的收集可关联到您身份的数据。我们不会收集联系人、实时相机或麦克风录音、精确位置、浏览历史,或用于第三方追踪的设备标识符。
当您制作分享海报时,可以使用系统相册选择器选取设备上已有的图片,也可以把生成的海报保存到相册。这些图片会留在您的设备上,除非您自己选择分享。Pockit 不会把您的照片上传到我们的服务器。
如果您复制订单口令、通知地址或导出密码等敏感内容,Pockit 只会写入本机剪贴板,约两分钟后失效,且不会同步到其他设备。
如果您开启 Face ID,解锁完全在本机完成。生物识别数据不会发送给我们或任何第三方。
为完成应用功能,Pockit 可能会连接以下服务:
我们不内置广告或第三方分析 SDK,也不会把您的数据分享给广告网络或分析服务商。
如 Pockit 因应用功能需要与 Apple 服务或其他被允许的第三方服务共享必要数据,这些服务应按照其自身隐私与安全标准保护用户数据,并提供与本隐私政策及 Apple 要求一致的保护。
若您开启订单通知,Pockit 会在本机保存一组仅用于接收订单提醒的身份信息。
您在 App Store Connect 里把通知地址填成该身份对应的专属链接后,Apple 会把订单事件发到 Pockit 的订单通知服务(orders.pockitkit.cn)。
该服务只用来把属于您的订单提醒推送到您已授权的设备。它不会收到您的 .p8 私钥,也不是一个需要单独注册的云端账号。
您可以随时在应用内销毁这条通知链接;销毁后本机相关口令会被清除,该地址将不再接收并推送新的订单提醒。下次打开订单页会生成新的链接。
订单通知服务只会保存向您的设备展示订单、发送提醒所需的信息,并按您的专属链接与其他用户隔离。我们无法获取订单内容,也不会用于广告或分析。
Pockit 可能会将您选择的摘要数据写入 App Group 容器,以便 iOS 小组件展示对应指标。
如果您开启通知,订单提醒会通过 Apple 推送通知服务(APNs)以远程通知下发,而不是仅使用本地通知。应用也可能使用后台刷新,以便在系统允许时更新小组件和本机摘要。通知权限可以在 iOS 设置中管理。
Pockit 可能会使用 Apple 的 StoreKit 框架处理购买或订阅。购买流程由 Apple 处理。我们仅接收用于解锁功能和恢复购买所需的信息。
Pockit 并非面向 13 岁以下儿童的应用,也不会有意收集儿童信息。
本地存储的凭证、设置、缓存分析数据和本机订单账本会保留在您的设备上,直到您在应用内删除、重置应用或卸载应用。
在 Pockit 中删除本机 App Store Connect 凭证,只会从这台设备移除这些信息,并不会在 App Store Connect 中撤销对应的 API Key。如果您怀疑密钥可能泄露,需要自行到 App Store Connect 撤销该 Key。
如果您使用过订单通知,销毁订单链接是单独操作。销毁后该地址将不再接收并推送新的订单提醒,本机相关口令也会被清除。仅删除本机 API 凭证并不会同时销毁订单链接。
卸载应用后,iOS 仍可能保留钥匙串条目。再次安装时,如果应用里已经没有此前的 Issuer ID、Key ID 和 Vendor Number,Pockit 会尝试清除残留的 .p8 和订单通知相关凭证,避免自动填回上一任用户的私钥。
Pockit 不提供单独的云端登录或用户账号系统。与您相关的服务端数据,仅包括向您的设备投递订单通知所需的信息;您可以通过销毁订单链接使其失效。
我们可能会不时更新本隐私政策。任何变更都会发布在本页面,并更新日期。
如果您对本隐私政策有任何问题,请通过以下邮箱联系我们:jason2k@126.com