pocket.ceo
  • Why?
  • How?
  • Login
EN PL

pocket.ceo Privacy Policy

Version date: 2026-06-21


This Privacy Policy explains how the personal data of users of the pocket.ceo service is processed. pocket.ceo is a platform in which each user is paired with an AI persona acting as their “boss”/accountability operator. This document constitutes an information notice within the meaning of Article 13 of Regulation (EU) 2016/679 (the “GDPR”) and fulfils the information obligations under Polish law on the provision of electronic services.

Please read the whole document carefully — in particular Section 6 (Transfers outside the EEA) — because the service currently relies on AI model providers whose infrastructure is located outside the European Economic Area (in the USA).


1. Data controller

The controller of your personal data is VALITY Łukasz Wątroba, a sole proprietorship (jednoosobowa działalność gospodarcza, JDG) with its registered seat at Kretowskie 44, 43-436 Górki Wielkie, Poland, NIP (Polish tax ID): 5472086879, REGON (Polish business register no.): 24361592800000, registered in CEIDG (the Polish Central Register and Information on Economic Activity).

Controller contact details:

  • Postal address: Kretowskie 44, 43-436 Górki Wielkie, Poland
  • Data-protection e-mail address: hi@pocket.ceo

Data Protection Officer (DPO): The controller has not appointed a Data Protection Officer, as appointing one is not mandatory at this stage — the processing does not involve large-scale systematic monitoring within the meaning of Article 37 GDPR. For all data-protection matters, please contact: hi@pocket.ceo.

Representative in the European Union (Article 27 GDPR): Not applicable. An EU representative is not required because the controller is established in Poland — that is, within the European Economic Area.


2. Scope of this Policy

This Policy covers data processing within:

  • the pocket.ceo web application (SPA) — in preparation; it will initially cover login, onboarding, selecting and paying for a plan, linking the Account with a messenger, and account settings and a usage overview;
  • the Telegram communication channel (Telegram bot — active channel);
  • the waitlist sign-up on the landing page;
  • AI memory and inference processes running in the background (memory processing and consolidation, delivery of proactive messages).

Planned but INACTIVE channels: Discord, WhatsApp, Signal, Slack. These channels are not currently implemented and do not process any data. Should they be introduced in the future, this Policy will be updated before they go live.


3. What data we process

The service relies on the AI persona’s persistent memory, so the scope of processed data is broader than in a typical application. We process the following categories of data:

3.1. Account data

Name, e-mail address, time zone, language preferences and — where you sign in via Google or GitHub — the identity provider’s OAuth token (a scope covering your e-mail address). Stored in the platform database.

3.2. Conversation content (transcripts)

All chat messages, task and project content, and “proofs” of completed commitments. Stored in an isolated data store assigned to your account.

3.3. AI memory (long-term)

So that the persona can act as a “boss”, it maintains persistent memory built from your interactions. It includes, among other things, records and summaries of conversations, retained information about you, and the context and overall tone of the user–persona relationship. This memory serves to personalise support, tone and proactive messages and — taken together — constitutes profiling within the meaning of the GDPR. See Section 9 (Profiling and automated decisions).

3.4. Tasks, projects and proactive messages

Commitments, schedules, and scheduled reminders and proactive messages (follow-ups). Used for accountability tracking and delivery of proactive notifications.

3.5. Attachments

Files you upload (images, PDFs). Stored in Cloudflare R2 object storage and — where technically supported and needed — analysed by a multimodal AI model from the provider Together AI (USA) (see the table in Section 5).

3.6. Waitlist sign-up data

Name, e-mail address and optionally a Twitter/X handle. This data is sent to the e-mail service provider (Resend) for list management and for sending service-related messages — including the welcome email, project-status updates, surveys and other communications about pocket.ceo. By signing up, you consent to receiving these messages by electronic means, including commercial information (Art. 10 of the Polish Act on the provision of services by electronic means). You may unsubscribe from these messages at any time (an “unsubscribe” link is included in every message).

3.7. Technical data and cookies

Session identifiers, landing-page analytics data, and cookies — see the Cookie Policy (https://pocket.ceo/legal/cookie-policy).

3.8. Special categories of data (sensitive data)

The service does not require you to provide special categories of data within the meaning of Art. 9 GDPR (e.g. health, beliefs, sexual orientation, biometric data). However, given the nature of the service (conversations about personal and professional goals with persistent memory), you may voluntarily disclose such data in the content of your messages. The service is not intended to process such data, does not require you to provide it, and we advise against entering it — in particular data you do not wish to entrust to the AI inference provider (a provider located in the USA; see Section 6). If you nonetheless knowingly include special-category data in your conversations, you do so on your own initiative; we do not use it for purposes other than providing the service, and you may delete it at any time by clearing the persona’s memory or by asking us to delete the data (see Section 10). Once an interface with an active consent mechanism is launched, the processing of special-category data will be based on explicit consent given by a separate, affirmative statement (Art. 9(2)(a) GDPR).


4. Purposes and legal bases for processing

We process data for the following purposes and on the following legal bases:

PurposeCategories of dataLegal basis
Provision of the service — chat, persona memory, tasks, projects, proactive messages, delivery of responses and notificationsTranscripts, AI memory, tasks, projects, proactive messages, attachmentsArt. 6(1)(b) GDPR — necessity for performance of the service contract
AI inference — including creation of vector representations of memory and attachment analysis, as a technical element of providing the serviceMemory content, attachment contentArt. 6(1)(b) GDPR
Building the persona’s persistent memory and a profile (profiling) — to personalise support, tone and proactive messages; see Section 9AI memory, transcriptsArt. 6(1)(b) GDPR — profiling is the essence of the requested “boss” persona service; you control the memory/profile by clearing the persona’s memory or deleting your account (see Section 9)
Authentication, account and session management, Telegram channel linkingAccount data, sessions, OAuth tokensArt. 6(1)(b) GDPR
Usage metering (credit model) and management of subscription tiersAccount data, usage data — tokens/costArt. 6(1)(b) GDPR
Service security, abuse prevention, protection against jailbreak/prompt extractionTechnical data, content to the extent necessaryArt. 6(1)(f) GDPR — legitimate interest (security)
Waitlist sign-up and delivery of service-related messagesName, e-mail, optionally Twitter/XArt. 6(1)(a) GDPR — consent (for commercial information, also Art. 10 of the Act on the provision of services by electronic means)
Landing-page analytics (Google Analytics)Cookie identifiers, traffic dataArt. 6(1)(a) GDPR — consent; GA4 loads only after consent is given, via the consent-management mechanism (Google Consent Mode v2) — see Section 7
Legal obligations (e.g. responding to authorities’ requests)Data necessary to complyArt. 6(1)(c) GDPR

What we do NOT do with your data:

  • we do not sell your personal data;
  • we do not use your conversation content for advertising profiling;
  • we do not disclose conversation content for third-party marketing.

For the use of user content to train AI models, see Section 6.3.


5. Recipients of data — processors (subprocessors)

To provide the service we use external providers acting as processors. The table below lists the current recipients, their role and the location of their infrastructure.

ProviderRoleLocationWhat it receives
Together AIAI inference provider for chat and memory cycles, creation of vector representations of memory, and attachment analysis (models hosted on Together AI’s own infrastructure in the USA, not as a proxy routing data to China)USAConversation content, memory content, tasks, attachment content/images during analysis
Stripe (planned)Payment processor — once paid sales launch: handling subscriptions (billing, recurring payments). Until launch, billing data is not transmittedUSA (stripe.com)Billing and identifying data necessary to process subscription payments
TursoDatabase hosting — platform database (accounts, sessions, subscriptions) and isolated data of individual users (all memory, transcripts, tasks, projects, proactive messages)EU (Ireland) — databases hosted in the European Union; no third-country transfer for the database layerEffectively all stored data
Cloudflare R2Object storage for attachmentsEU (Eastern Europe, EEUR) — bucket hosted in the European Union; no third-country transfer for the attachment storage layerAttachment files
TelegramCommunication channel (the only active external communication channel)Telegram servers (EU/international)Content of messages exchanged via Telegram
GitHub / GoogleSocial sign-in providers for the web application (OAuth; a scope covering the e-mail address)USA (github.com, google.com)Authentication data within the OAuth flow
ResendE-mail delivery to waitlist members (welcome, status updates, surveys)USA (resend.com)Name, e-mail, optionally Twitter/X (waitlist contacts)
Google Analytics (GA4)Landing-page analyticsUSACookie identifiers, site traffic data

Note: for authentication we use our own mechanism running on our own infrastructure (it is not a third-party SaaS provider).

Status of data processing agreements (Article 28 GDPR): Together AI — an Art. 28 DPA is available, with transfers to the USA based on Standard Contractual Clauses (SCC); the Zero Data Retention (ZDR) setting is enabled on the pocket.ceo account and a no-training principle applies; see https://www.together.ai/terms-of-service and https://www.together.ai/privacy. Cloudflare — DPA in place; transfers based on SCC and/or DPF (R2 data hosted in the EU). Resend — DPA in place; SCC + DPF. GitHub (Microsoft) — DPA in place; SCC and/or DPF. Google (sign-in and Google Analytics) — transfers to the USA based on the Data Privacy Framework (DPF); Google LLC holds an active DPF certification (see the dataprivacyframework.gov list). Stripe (planned) — DPA available; once paid sales launch, transfers to the USA based on SCC and/or DPF. Turso — DPA in place (SOC 2 / HIPAA), data hosted in the EU (Ireland) with native at-rest encryption, so there is no — or only minimal — third-country transfer; see https://turso.tech/pricing.


6. Transfers outside the European Economic Area (EEA)

This is a key section of this Policy. Providing the service requires transferring data to third countries.

6.1. Transfers to the USA — AI inference (Together AI) and other providers

AI inference for chat and memory cycles (language models), the creation of vector representations of memory, and attachment analysis is performed by Together AI, a provider established in the United States that hosts models on its own infrastructure in the USA (it is not a proxy routing data to China). Data for AI inference is not transferred to China.

Transfers of data to Together AI (USA) are based on Standard Contractual Clauses (SCC) approved by the European Commission (Art. 46(2)(c) GDPR). A copy of the clauses used is available on request (contact: hi@pocket.ceo).

We additionally apply the following measures that reduce the risk of secondary use of the data:

  • Zero Data Retention (ZDR) — the ZDR setting is enabled on the pocket.ceo account in Together AI (in accordance with the Together AI Terms): content sent for inference is not stored, retained, or used for any purpose other than fulfilling the request;
  • a no-training principle — content is not used to train or fine-tune models.

Please note that these measures reduce but do not eliminate the risk associated with possible access by US public authorities to data during its processing, and they do not constitute an adequacy decision within the meaning of Art. 45 GDPR. Language-model inference requires processing content in cleartext at the provider in the USA.

Sources: https://www.together.ai/privacy and https://www.together.ai/terms-of-service.

Other providers with infrastructure in the USA rely on the following transfer mechanisms:

  • Google / Google Analytics — the EU–US Data Privacy Framework (DPF): Google LLC holds an active DPF certification (https://policies.google.com/privacy/frameworks);
  • Stripe (planned) — once paid sales launch: SCC and/or DPF;
  • Resend — SCC + DPF;
  • GitHub (Microsoft) — DPA in place; SCC and/or DPF.

Database in the EU. The isolated user data stores and the platform database (Turso) are hosted in the European Union (Ireland) — storage in the database layer does not involve a transfer to a third country.

6.2. Background memory processing on the platform key

Background memory processing — the consolidation and processing of your memory (including the extraction of generated memory from your conversations) and the creation of vector representations of memory content (which enable related memories to be retrieved) — is performed using the Together AI (USA) service on the platform key, for every user, based on Standard Contractual Clauses (SCC), Zero Data Retention (ZDR), and the provider’s no-training principle. This means that transcript and memory content — not only vector representations — is processed by Together AI as part of this background memory work, on the platform key, regardless of the AI model otherwise used for interactive chat, and including for users who supply their own API key (whose background memory work runs on the platform key rather than their own).

6.3. Training models on your content

User content is not used to train or fine-tune AI models. On the pocket.ceo account, Zero Data Retention (ZDR) is enabled in Together AI and a no-training principle applies; we apply these commitments to AI inference within the service (see https://www.together.ai/privacy). For other providers (e.g. analytics), the rules set out in their agreements (DPAs) apply.


7. Cookies and analytics

A detailed list of cookies is set out in the Cookie Policy (https://pocket.ceo/legal/cookie-policy). In short, we use:

  • _ga, _ga_<id> (Google Analytics, GA4) — analytics cookies, provider: Google (USA), basis: consent. The GA4 script is loaded only after consent is given via a consent-management mechanism (CMP) with Google Consent Mode v2 in place (equivalent “Accept”/“Reject” options and the ability to withdraw consent). Transfer to the USA: the EU–US Data Privacy Framework (DPF) — Google LLC holds an active DPF certification (https://policies.google.com/privacy/frameworks). The lifetime of the _ga cookie is shortened to approximately 13 months (from the default 24), in line with electronic-communications privacy guidance.
  • session cookie (first-party) — necessary to maintain a logged-in session; does not require consent (technical cookie).

8. Data retention period

Data categoryPeriod / criteria
Conversation transcriptsRetained for the duration of your use of the service; not deleted automatically — deleted upon account deletion
AI memory — current records and summariesRetained for a limited time and automatically rotated (older records are replaced by newer summaries)
AI memory — persistent elements (retained information, relationship context and tone)Maintained for the duration of the user–persona relationship; deleted when the persona’s memory is cleared or the account is deleted
Tasks, projects, proactive messagesFor the duration of your use of the service; deleted upon account deletion
Attachments (Cloudflare R2)Automatically deleted after 90 days; also deleted when the user deletes their account
Account dataWhile the account exists; deleted after account deletion
Waitlist data (Resend)Until the service launches or until unsubscribe/withdrawal; if the service does not launch — at the latest 24 months after sign-up

The automated memory housekeeping covers only system-generated memory records and does not delete conversation transcripts.


9. Profiling and automated decisions

So that the AI persona can act as a “boss”, it builds a persistent profile of the user from your memory and analyses your behaviour, commitments and progress to adjust tone, content and proactive messages. This constitutes profiling within the meaning of the GDPR.

Significance and consequences: profiling serves to personalise support (accountability, coaching, reminders) and affects how the persona communicates with you and when it initiates contact.

No solely automated decisions producing legal effects: the service does not make decisions about you based solely on automated processing that would produce legal effects concerning you or similarly significantly affect you within the meaning of Art. 22 GDPR. AI responses and notifications are supportive and informational in nature.

Your rights: because the persona’s memory and profile are necessary to provide the requested service (Art. 6(1)(b) GDPR), we provide control over profiling primarily through the ability to clear the entire persona memory or delete your account (which removes the associated memory) — as part of the right to erasure (Art. 17 GDPR). You may also exercise your other rights, including requesting deletion of your data, by contacting us (see Section 10). The right to object (Art. 21 GDPR) applies instead to processing based on legitimate interest (service security, abuse prevention).


10. Your rights

You have the following rights under the GDPR:

  • Right of access to your data (Art. 15);
  • Right to rectification (Art. 16);
  • Right to erasure — the “right to be forgotten” (Art. 17);
  • Right to restriction of processing (Art. 18);
  • Right to data portability (Art. 20) — in a structured, commonly used, machine-readable format;
  • Right to object to processing, including profiling, based on legitimate interest (Art. 21);
  • Right to withdraw consent at any time (without affecting the lawfulness of processing before withdrawal) — where consent is the basis;
  • Right to lodge a complaint with a supervisory authority — in Poland: the President of the Personal Data Protection Office (UODO), ul. Stawki 2, 00-193 Warsaw.

How to exercise your rights: send your request to the e-mail address given in Section 1. We will respond without undue delay and within one month of receiving the request; where the matter is complex or there are numerous requests, this period may be extended by a further two months, of which we will inform you.

Account deletion: when your account is deleted, account data is cascade-deleted and all isolated User data is deleted from the Turso infrastructure. Attachments stored in Cloudflare R2 are deleted. The fate of any data previously sent to AI providers for inference depends on their retention policies and DPAs; for Together AI an enabled Zero Data Retention (ZDR) setting and no-training principle apply — inference content is not persistently retained for purposes beyond fulfilling the request itself.

Data export / portability: you may request a copy of all your data — transcripts, persona memory, tasks, projects, proactive messages, and account data — by contacting hi@pocket.ceo. The copy is provided in a commonly used, machine-readable format within one month of your request.


11. Data security (Article 32 GDPR)

We apply, among others, the following technical and organisational measures:

  • Isolation of individual users’ data — each user’s data is kept isolated; one user’s data contains no other users’ data;
  • Databases located in the EU — the databases are hosted in the European Union (Ireland), with no transfer of the database layer to a third country;
  • Minimised retention at the AI providers — AI inference is performed at Together AI (USA) with an enabled Zero Data Retention (ZDR) setting and a no-training principle;
  • Session management — sessions expire after a defined period or on logout;
  • Validation and filtering of user content;
  • Access control over application configuration and confidential data;
  • Minimised logging of content and sensitive data;
  • Authentication of the messenger integration;
  • data in transit secured with TLS;
  • Encryption at rest — stored data is encrypted at rest by default on the Cloudflare R2 and Turso side.

12. Use of the service by minors

The service is not directed at persons under the age of 18 and we do not knowingly collect such persons’ data. If we learn that data of a person below the required age has been provided to us without the required basis, we will delete it without undue delay.


13. California / US users

The service is also directed at users in the United States, including residents of California. This section describes the rights available to California residents under the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA).

Scope. This section applies to residents of the State of California. Where the CCPA/CPRA concepts map to the categories described elsewhere in this Policy, the disclosures below reflect the same processing.

Categories of personal information collected:

  • identifiers — account data, e-mail address, Google/GitHub login (authentication);
  • user content — conversations (transcripts), AI memory, tasks, projects, attachments;
  • usage / analytics data — technical data and landing-page analytics;
  • payment / billing data — once paid sales launch, processed via Stripe (planned).

Sources of the information:

  • directly from you (the content you enter and the data provided at registration);
  • automatically from your use of the service (technical and analytics data);
  • from the Google/GitHub authentication providers (the OAuth flow).

Business and commercial purposes for processing: providing the service, security, analytics, and billing.

Categories of recipients (service providers). We disclose personal information to the following service providers acting on our behalf: Together AI, Turso, Cloudflare, Telegram, Resend, GitHub and Google (sign-in), Google Analytics, and — once paid sales launch — Stripe (for a full description of roles and locations, see Section 5).

Sale / sharing. We do NOT sell personal information for money. We do, however, disclose that the use of Google Analytics may constitute “sharing” of personal information for cross-context behavioral advertising under the CCPA. California residents may exercise the right to opt out via the cookie-consent mechanism (a “Do Not Sell or Share My Personal Information” / consent control), by rejecting analytics cookies or withdrawing consent.

Your rights (California residents):

  • right to know / access — the categories and specific pieces of personal information collected;
  • right to delete personal information;
  • right to correct inaccurate personal information;
  • right to opt out of the sale or sharing of personal information;
  • right to limit the use of sensitive personal information;
  • right to non-discrimination for exercising any of these rights.

How to exercise your rights. You may submit a request by e-mailing hi@pocket.ceo (and, where available, using the relevant in-app controls). We will respond within 45 days (extendable as permitted by law). Requests may also be submitted by an authorized agent acting on your behalf.

For more information on California consumer rights, see the California Attorney General’s CCPA page: https://oag.ca.gov/privacy/ccpa.


14. Changes to this Privacy Policy

We may update this Policy, in particular where there are changes in law, in the scope of the service, in providers (subprocessors) or for security reasons. We will inform you of material changes in a manner appropriate to the nature of the change (e.g. an in-app notice or e-mail), with reasonable advance notice. The current version is always available at https://pocket.ceo/legal/privacy-policy.


15. Contact

For any matters concerning personal data protection, contact us at: hi@pocket.ceo.

Binding version: The binding version of this document is the Polish version. The English version is provided for convenience only; in the event of any discrepancy, the Polish version prevails.
pocket.ceo

© 2026 pocket.ceo

Blog Terms Privacy Cookies