1. What we collect
We keep the minimum needed to run the product:
- Account: your email address (for sign-in and your account).
- Usage:counts of how many plans you’ve generated (to enforce quotas) and your paid status.
- Pack recovery: for a signed-in generation, a random pack identifier and one-way digest of the accepted pack context. This temporary proof lets us recover the same paid result without accepting different content; it does not contain your idea or generated files.
- Paid saved projects:your idea and other project inputs, the generated pack, and reference-file descriptors needed to reopen and hand off the project. Uploaded reference-file bytes are held separately in private storage. We record their private storage keys temporarily while a pack is assembled and, for a saved project, for as long as needed to keep that project’s reference files available.
- In-progress planning drafts: your idea, Builder choice, how the app earns, the canonical questions and answers you commit, and the plan so far. We also keep bounded, content-free command and recovery identifiers needed to prevent a retry or another browser from applying the same planning change twice. A provider’s latest display-only reply is not saved or reconstructed.
- Unpromoted visual references: bounded file metadata, a private storage locator, and content-free upload and deletion status needed to finish or clean up an upload. Reference-file bytes are not sent to our AI provider, and a reference URL is not fetched. The URL or private file locator is used only as the visual-reference pointer you chose.
- Completion recovery: content-free operation, project, revision, lease, reservation, and one-way digest bindings used briefly to recover the exact result after a lost response. These records contain no idea, answer, generated file, reference byte, or model reply.
- GitHub drift monitoring: when you connect it, we store the GitHub App installation ID, the GitHub account or organization login where it is installed, the numeric GitHub user ID GitHub identifies as the installer, and the link between a repository’s full name and the saved project you choose. A one-time OAuth token is used only to ask GitHub for that numeric user ID and is discarded after that lookup.
- GitHub delivery retries: for reliable signed-webhook processing, we keep the delivery identifier, event name, retry status, attempt count, lease and retry timing, and a safe error code. We also keep only the small actionable projection needed to retry: the installation ID; for an installation, its account login and installer ID; or for a pull request, the repository owner and name, pull-request number, and head commit SHA. The raw signed webhook body is never stored.
- Consent records: which version of the Terms and this Policy you accepted, and when.
- Payment: handled by Stripe; we receive confirmation and limited billing metadata, not your card number.
- Technical / security: your IP address and request metadata, used transiently for rate-limiting and bot protection — not stored in our database or analytics.
If you do not save a paid project, each generation request is processed transiently and is not retained by us as a saved project after the pack is returned. The content-free recovery proof described above may remain briefly as described in Sections 3 and 6.
When monitoring is on for a mapped repository, we retrieve the full pull-request diff from GitHub and process it transiently on our server against your saved plan. The diff is not stored or logged, is not sent to our AI provider, and makes no model call. We send only a generic result back to GitHub; it does not copy your saved-plan wording into the repository.
2. What we don’t do
We don’t sell your personal information, and we don’t “share” it for cross-context behavioural advertising (as defined by California law). We don’t use your content to train, develop, or improve any AI or machine-learning models — we don’t train models at all. Your idea text, answers, and email are kept out of our logs and analytics by design.
3. AI processing & international transfer (please read)
To create your plan, we send your idea text and answers to a single third-party AI provider — Cerebras (running GPT-OSS-120B) — for both your clarifying questions and your plan synthesis. Cerebras processes your input under its own terms and privacy policy. The generation request is processed transiently by our generation service. If you use paid saved projects, the separate project record described in Sections 1 and 6 persists so you can reopen it.
EU/UK users: our legal basis for this processing is performance of our contract with you (and, for the transfer, your explicit request to use the Service); where available, we rely on Standard Contractual Clauses with providers. You can avoid the transfer by not using the Service.
4. Third parties that process your data
Each provider uses your data only to provide its service to us, under a data-processing agreement where offered:
- Cerebras — AI (clarifying questions and plan synthesis) — the United States.
- Stripe — payments / hosted checkout (handles card data directly; we never receive it).
- Supabase — authentication and the database that stores your account.
- Vercel — website hosting and delivery.
- GitHub — GitHub App installation, repository access, pull-request delivery, and check results when you opt in to drift monitoring.
We may also use content-free, cookieless product analytics and PII-scrubbed error monitoring to keep the Service reliable; these carry no idea content.
6. Data retention
Account data (email and usage) is kept while your account is active and removed through the account-deletion process, subject to the exceptions below. Consent records are kept for up to 3 years to evidence compliance. Payment and tax records are kept as required by law (typically up to 7 years) and by Stripe. Saved-project content remains stored while the account is active. Project-level deletion archives the project and removes it from the product view rather than immediately erasing it. Tier retention limits may archive older projects; those archived records, including their reference-file descriptors and privately stored file bytes, remain stored until account deletion or another applicable retention process removes them.
In-progress planning drafts expire 30 days after the last committed planning change. Opening or viewing a draft does not extend that period. Deleting the draft removes its planning content and command records, and account deletion removes any remaining owner-scoped draft records.
An unpromoted reference upload is available for seven days unless you remove it sooner or it becomes unavailable. Expiry makes it unavailable for a new plan and starts bounded cleanup; the private bytes and content-free deletion record may remain longer only until storage deletion is confirmed or an operator resolves failed cleanup. To prevent a late upload from becoming untracked, we retain content-free deletion tracking for at least 24 hours after its five-minute upload lease ends. Once a reference is promoted into a completed saved project, the saved-project retention above applies instead.
Content-free completion-recovery records are usable for up to 24 hours and are then eligible for bounded cleanup. They do not extend draft, reference, saved-project, or generated-content retention. Security counters use short, fixed windows. A content-free pack-recovery identifier and one-way digest are usable for up to 7 days. They then expire and are removed by bounded cleanup.
For GitHub drift monitoring, we keep the installation ID and GitHub account or organization login and installer’s numeric GitHub user ID while the GitHub App remains installed. Repository-to-project mappings remain until you unlink them or uninstall the App. When you uninstall, the account or organization login, your account link, the installer’s numeric GitHub user ID, and repository mappings are removed immediately. Only the installation ID and removal time remain for 30 days to reject delayed installation messages; after that, they are eligible for removal on the next bounded cleanup pass.
A retry worker’s claim lasts at most five minutes so another worker can recover after a crash. The small actionable retry projection described in Section 1 is eligible for retry for up to 12 attempts or 24 hours from first receipt. After that, the next worker pass marks it failed and erases the projection. Success or a permanent failure erases it immediately. The delivery identifier, event, final status, attempt count, safe error code, and timing metadata are kept for seven days to prevent duplicate work and support operations. After that, they are eligible for removal on the next bounded cleanup pass. The full pull-request diff is not retained after that request finishes.
7. Your rights
You can request to access, correct, delete, or port your data, and to object to or restrict certain processing. California (CCPA/CPRA): you may know, access, delete, and correct your information and opt out of the sale or sharing of personal information — we do notsell or share it — and you won’t be discriminated against for exercising these rights. To exercise any right, email contact@pogoprompt.ai; we verify your request and respond within the time the law allows. EU/UK users may also lodge a complaint with their local data-protection supervisory authority.
8. AI-training disclosure
We do not use your personal information or content to train, develop, or improve AI or machine-learning models. Cerebras, the provider that processes your input, states that it does not train on customer inputs (see Section 3).
9. Children
The Service is for adults (18+). We don’t knowingly collect data from children; if you believe a child has given us data, email us and we’ll delete it.
10. Security
Managed authentication, HTTPS in transit, Stripe for card data, secrets kept in server-side environment variables, database row-level security, and PII-scrubbed logs. No method of transmission or storage is 100% secure.
11. Changes
We’ll post any update with a new effective date and record your acceptance of material changes.
12. Contact
PogoPrompt Co · contact@pogoprompt.ai