1. Who We Are
Summary
Pocodot Labs, Inc. is a Delaware corporation and data controller for your personal data.
Pocodot Labs, Inc. is a Delaware corporation operating a cloud-based AI agent platform at pocodot.ai. We are the data controller for personal data we collect directly from you. For enterprise customers, we act as a data processor - see Section 6.
For questions about this policy or to exercise your rights, contact us at privacy@pocodot.ai.
2. What Data We Collect
Summary
We collect account info, usage data, communications, technical data, and payment data - nothing more.
We collect the following categories of personal data:
| Category | What We Collect | Why |
|---|---|---|
| Account data | Name, email, password hash | Account creation & authentication |
| Usage data | Agent configurations, prompts, actions taken | Platform operation & improvement |
| Communication data | Messages sent to/from agents | Delivering the service |
| Technical data | IP address, device type, browser, logs | Security & performance |
| Payment data | Billing info (processed by Stripe) | Subscription management |
We do not sell your personal data. We do not share your personal data for cross-context behavioral advertising.
3. AI Agent Data - Special Notice
Summary
Your prompts and agent data are processed to run the service; we never train models on your content.
- Prompts and instructions you provide are processed to operate the service
- Third-party data your agents access (emails, files, contacts, etc.) is processed on your behalf - you are responsible for having a lawful basis to process that data
- Agent action logs are retained for 90 days to support debugging and audit
- We do not use your agent data or configurations to train AI models without your explicit opt-in consent
3A. Browser Sessions and Stored Logins
Summary
Logins you store in the Vault are encrypted with a key specific to your workspace and used only when Cole signs in for you. Location pins you choose to share are stored until you delete them. We do not record your screen, keyboard, microphone, or background location, and none of this is used to train models.
Site logins you store. If you add a login to your workspace Vault, we store the site, the username and the password. Passwords are encrypted with a key specific to your workspace; our staff cannot read them, and they are decrypted only at the moment Cole signs in to that site for you. We keep a log of when each stored login was used and on which site, which you can view in your workspace. When you delete a stored login it is removed immediately and is not retained in backups beyond our standard retention window.
Browser activity. When Cole visits websites for you, we process the pages it visits, the text it reads, and screenshots it takes to show you its work. Screenshots you receive are stored so the link keeps working; you can ask for them to be deleted. We do not record your own screen, keyboard, microphone, or device location in the background, and we do not use any of this content to train models.
Locations you share. If you send Cole a location pin in a chat, or tap its request to share your location, we store that pin (coordinates, and the place name or address if you included one) with the time you shared it so Cole can help with things nearby and remember where you were. We never read your device location in the background and Cole cannot track you. You can see and delete shared locations in your workspace under Account, Config, Locations, and deletion is immediate.
1Password vault sharing. If you connect 1Password, we store the service account token you provide, encrypted with a key specific to your workspace, and use it only to read the single vault you chose to share. Cole reads a login from that vault, including its one-time code, only at the moment it signs in to that site for you, and each use is recorded in your workspace activity. Disconnecting deletes the token immediately.
Payment cards you store. If you add a card, we store the card number and security code encrypted with a key specific to your workspace, together with the card brand, the last four digits, the expiry and the cardholder name. Cole enters the card only at the moment of a payment you approved in chat, and only once per approval. Each payment is recorded with the amount, currency and merchant so you can see it in your workspace, and your monthly spending cap is enforced before the card is used. Deleting a card removes it immediately.
Watches. When you ask Cole to watch a web page, we store the page address, what to look for, and the last value we saw, and we fetch that page on the interval you chose until the watch fires, expires or you cancel it. A trigger you set up (for example from a Shortcut on your phone) stores only its name; the address we give you contains a token specific to your workspace, so treat it like a password.
4. How We Use Your Data
Summary
Your data is used to provide the service, secure your account, improve features, and comply with law.
We use your data for the following purposes:
- To provide, operate, and maintain the Platform
- To authenticate and secure your account
- To improve platform features using aggregated, non-identifiable data only
- To comply with legal obligations
- To communicate service updates, security notices, and (where consented) marketing
5. Automated Decision-Making
Summary
Our platform uses ADMT; you'll receive a pre-use notice and can opt out of profiling.
Pocodot's platform uses automated decision-making technology (ADMT) as part of its AI agent infrastructure. Before deploying agents that use ADMT, you will receive a pre-use notice describing what decisions are being automated and their significance. You have the right to opt out of ADMT used for profiling purposes - see your Privacy Preference Center in account settings.
6. Data Controller / Processor Roles
Summary
Pocodot is controller for your data, processor for enterprise customers, and you're controller for third-party data your agents process.
- Consumer users: Pocodot is the data controller for your account and usage data.
- Enterprise customers: Where you use Pocodot to process personal data on behalf of your organization, Pocodot acts as your data processor. A Data Processing Agreement (DPA) is available at legal@pocodot.ai.
- Your agents processing third-party data: You become the data controller for any personal data your agents collect or process about individuals outside your account.
7. Your Rights
Summary
You have rights to access, correct, delete, port, restrict, and object - plus opt-out of ADMT.
Depending on your location, you have the following rights:
| Right | What It Means |
|---|---|
| Access | Request a copy of your personal data |
| Correction | Fix inaccurate data |
| Erasure | Request deletion of your data |
| Restriction | Limit how we process your data |
| Portability | Receive your data in a portable format |
| Objection | Object to certain processing activities |
| Opt-out of ADMT | Opt out of automated decision-making (CCPA 2025) |
| Non-discrimination | Exercising rights will not affect your service level |
To exercise your rights: privacy@pocodot.ai. We will respond within 30 days (GDPR) / 45 days (CCPA) / 30 days (other applicable US state laws).
Under the General Data Protection Regulation (GDPR), EU residents have the following rights:
- Access:Request a copy of the personal data we hold about you.
- Rectification:Ask us to correct inaccurate or incomplete data.
- Erasure:Request deletion of your personal data ('right to be forgotten').
- Restriction:Ask us to limit how we process your data in certain circumstances.
- Portability:Receive your data in a structured, machine-readable format.
- Object:Object to processing based on legitimate interest or direct marketing.
- Automated decisions:Not be subject to decisions based solely on automated processing, including profiling.
- Withdraw consent:Withdraw consent at any time where processing is based on consent.
8. Data Retention
Summary
Account data is retained 90 days after deletion; agent logs for 90 days; payment records for 7 years.
We retain your data according to the following schedule:
| Data Type | Retention |
|---|---|
| Account data | While account is active + 90 days after deletion |
| Agent action logs | 90 days rolling |
| Payment records | 7 years (legal/tax requirement) |
| Backup systems | Purged within 180 days of deletion request |
9. International Data Transfers
Summary
EU/UK data is transferred to the US under the Data Privacy Framework or Standard Contractual Clauses.
Pocodot Labs, Inc. is a US-based company. If you are located in the EU or UK, your personal data is transferred to the United States under one of the following safeguards:
- EU-US Data Privacy Framework (DPF) - Pocodot will self-certify under the DPF program
- Standard Contractual Clauses (SCCs) - available upon request for enterprise customers
10. Security
Summary
We use TLS, AES-256 encryption, RBAC, and will notify you of breaches within 72 hours.
We implement industry-standard security measures including:
- TLS encryption in transit
- AES-256 encryption at rest
- Role-based access controls
- Regular security audits
We will notify affected users of a data breach within 72 hours of discovery where required by law.
12. Third-Party Processors (Sub-Processors)
Summary
We use a limited set of sub-processors for AI, payments, and hosting - enterprise customers are notified of changes.
| Sub-Processor | Purpose |
|---|---|
| AI model providers | AI model inference |
| Stripe | Payment processing |
| DigitalOcean | Cloud hosting & infrastructure |
We maintain an up-to-date sub-processor list and will notify enterprise customers of changes per their DPA. See our full Subprocessors page.
12A. Third-Party Advertising Platform Data
Summary
Users connect their own ad accounts via OAuth; we also use ad APIs for internal reporting. Google data subject to Limited Use requirements.
Pocodot integrates with third-party advertising platforms — including TikTok Business API, Meta Marketing API, and Google Ads API — in two ways:
- User-connected accounts: Users may connect their own advertising accounts via OAuth 2.0 so that Cole, our AI assistant, can read performance data and execute user-approved management actions (e.g., pausing campaigns, adjusting bids, adding keywords) on their behalf.
- Internal reporting: Pocodot also receives aggregated ad performance metrics for accounts it owns or is authorized to manage, used for internal analytics and cross-platform campaign performance reporting.
OAuth tokens for user-connected accounts are encrypted at rest, stored server-side only, and are never exposed to the AI model or any third party. Users can disconnect any integration at any time, which deletes the stored credentials.
Pocodot does not sell, share, or redistribute advertising data obtained from these platforms. Pocodot does not access individual user data from advertising platforms and does not use advertising platform data for profiling, cross-context behavioral advertising, or any purpose beyond providing the requested features to the account owner.
With whom we share, transfer, or disclose Google user data
Pocodot shares, transfers, or discloses Google user data (such as Google Ads account, campaign, and performance data accessed via the Google Ads API) only with the following limited categories of recipients, and only as necessary to provide the user-facing features you request:
- Cloud infrastructure provider (DigitalOcean): hosts Pocodot's servers and stores Google user data encrypted at rest on our behalf as a sub-processor.
- AI model provider (Anthropic): when you ask Cole to read, summarize, analyze, or act on your Google Ads data, the relevant data is transmitted to our AI model provider solely to generate your requested response. It is processed under terms that prohibit using it to train their models.
- Legal or corporate successors: where required to comply with applicable law or valid legal process, or as part of a merger, acquisition, or asset sale, in which case we will provide notice and honor prior user consent.
Pocodot does not share, sell, transfer, or disclose Google user data to advertising networks, data brokers, data aggregators, or any other third party, and does not use it for serving advertising, retargeting, or profiling. We do not allow humans to read Google user data except as described in the Limited Use disclosure below.
Google API Services — Limited Use Disclosure
Pocodot's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, Pocodot:
- Only uses Google user data to provide and improve user-facing features that are visible and apparent to the user.
- Does not transfer Google user data to third parties, except as necessary to provide or improve user-facing features, to comply with applicable law, or as part of a merger, acquisition, or asset sale with prior user consent.
- Does not use Google user data for serving advertisements, including retargeting, personalized, or interest-based advertising.
- Does not allow humans to read Google user data unless the user has provided affirmative consent, it is necessary for security purposes, it is necessary to comply with applicable law, or the data is aggregated and anonymized for internal operations.
For details on our TikTok Business API integration specifically, see our TikTok Business API Integration Disclosure.
13. Minors
Summary
Pocodot is not intended for users under 18; we delete accounts of minors promptly.
Pocodot is not intended for users under 18. We do not knowingly collect personal data from minors. If we become aware that a minor has created an account, we will delete the account and associated data promptly. Contact privacy@pocodot.ai if you believe a minor has accessed the platform.
14. US State Privacy Rights
Summary
Residents of CA, VA, CO, CT, TX, OR, MT, and other states have privacy rights similar to those in Section 7.
In addition to CCPA/CPRA, residents of Virginia, Colorado, Connecticut, Texas, Oregon, Montana, and other states with applicable privacy laws have rights substantially similar to those described in Section 7. Contact privacy@pocodot.ai to exercise any state privacy rights.
15. Changes to This Policy
Summary
Material changes will be communicated at least 30 days before taking effect.
We will provide 30 days' notice of material changes to this Privacy Policy via email or platform notice before they take effect. Your continued use of the Platform after the notice period constitutes acceptance of the updated Policy.
16. Contact
Summary
Reach us at privacy@pocodot.ai for privacy inquiries or legal@pocodot.ai for legal questions.
- Data Controller: Pocodot Labs, Inc. · 765 Market St, San Francisco, CA 94103, USA
- Thailand operations: POCODOT Ltd. (บริษัท โพโคดอต จำกัด) · Bangkok, Thailand
- Privacy inquiries: privacy@pocodot.ai
- Legal inquiries: legal@pocodot.ai
EU residents may also lodge a complaint with your local data protection authority if you believe your rights have not been adequately addressed.
Related Policies
Questions about this policy? Email us at privacy@pocodot.ai