pocket.ceo
  • Why?
  • How?
  • Login
EN PL

pocket.ceo Privacy Policy

Version: 1.0 · Effective date: 2026-08-31


This Privacy Policy explains how the personal data of users of the pocket.ceo service is processed. pocket.ceo is a platform in which each user is paired with an AI Boss — an AI-based assistant acting as their “boss” and accountability partner. This document constitutes an information notice within the meaning of Article 13 of Regulation (EU) 2016/679 (the “GDPR”) and fulfils the information obligations under Polish law on the provision of electronic services.

Please read the whole document carefully — in particular Section 6 (Transfers outside the EEA) — because the service currently relies on AI model providers whose infrastructure is located outside the European Economic Area (in the USA).


1. Data controller

The controller of your personal data is VALITY Łukasz Wątroba, a sole proprietorship (jednoosobowa działalność gospodarcza, JDG) with its registered seat at Kretowskie 44, 43-436 Górki Wielkie, Poland, NIP (Polish tax ID): 5472086879, REGON (Polish business register no.): 24361592800000, registered in CEIDG (the Polish Central Register and Information on Economic Activity).

Controller contact details:

  • Postal address: Kretowskie 44, 43-436 Górki Wielkie, Poland
  • Data-protection e-mail address: hi@pocket.ceo

Data Protection Officer (DPO): The controller has not appointed a Data Protection Officer, as appointing one is not mandatory at this stage — the processing does not involve large-scale systematic monitoring within the meaning of Article 37 GDPR. For all data-protection matters, please contact: hi@pocket.ceo.

Representative in the European Union (Article 27 GDPR): Not applicable. An EU representative is not required because the controller is established in Poland — that is, within the European Economic Area.


2. Scope of this Policy

This Policy covers data processing within:

  • the pocket.ceo web application — login, onboarding, starting a free Trial or selecting and paying for a plan (subscription), linking the Account with a messenger, and account settings and a usage overview;
  • the communication channels offered for linking with an Account: Telegram, Slack and Discord;
  • the pocket.ceo website — including the site analytics described in Section 7;
  • AI memory and inference processes running in the background (memory processing and consolidation, delivery of proactive messages).

3. What data we process

The service relies on the AI Boss’s persistent memory, so the scope of processed data is broader than in a typical application. We process the following categories of data:

3.1. Account data

Name, e-mail address, time zone and language preferences. An Account is created by signing in via GitHub or Google (OAuth; a scope covering your e-mail address); we process your account identifier at the sign-in provider and the tokens issued within the OAuth flow. We also process the messenger identity of the channel linked to your Account: your user id and username on Telegram, Slack or Discord. This data is stored in the platform database (tokens and other confidential data in encrypted form).

3.2. Conversation content (transcripts)

All chat messages, task and project content, and “proofs” of completed commitments. Stored in an isolated data store assigned to your account.

3.3. AI memory (long-term)

So that the AI Boss can play its role, it maintains persistent memory built from your interactions. It includes, among other things, records and summaries of conversations, retained information about you, and the context and overall tone of your relationship. This memory serves to personalise support, tone and proactive messages and — taken together — constitutes profiling within the meaning of the GDPR. See Section 9 (Profiling and automated decisions).

3.4. Tasks, projects and proactive messages

Commitments, schedules, and scheduled reminders and proactive messages (follow-ups). Used for accountability tracking and delivery of proactive notifications.

3.5. Attachments

Files you upload (images, PDFs). Stored in Cloudflare R2 object storage (a bucket in the European Union) and analysed by an AI model through the AI inference provider described in Section 5 — under the same zero data retention and no-collection regime as all other model calls (see Sections 5 and 6).

3.6. E-mail delivery

For transactional messages necessary to provide the Account service — welcome, trial-started and trial-ended e-mails — we pass to Resend the recipient e-mail address, the transactional message content (including the Trial end date where applicable), and domain event/idempotency identifiers used to deliver the message and prevent an immediate duplicate attempt. These messages concern the Account lifecycle and are not marketing. We do not send conversation content, the AI Boss’s memory, or payment-card data to Resend.

3.7. Technical data and cookies

Session identifiers, pocket.ceo website analytics data, and cookies — see the Cookie Policy.

3.8. Special categories of data (sensitive data)

The service does not require you to provide special categories of data within the meaning of Art. 9 GDPR (e.g. health, beliefs, sexual orientation, biometric data). However, given the nature of the service (conversations about personal and professional goals with persistent memory), you may voluntarily disclose such data in the content of your messages. The service is not intended to process such data, does not require you to provide it, and we advise against entering it — in particular data you do not wish to entrust to the AI inference provider (a provider located in the USA; see Section 6). If you nonetheless knowingly include special-category data in your conversations, you do so on your own initiative; we do not use it for purposes other than providing the service, and you may delete it at any time by clearing the AI Boss’s memory or by asking us to delete the data (see Section 10). Once an interface with an active consent mechanism is launched, the processing of special-category data will be based on explicit consent given by a separate, affirmative statement (Art. 9(2)(a) GDPR).


4. Purposes and legal bases for processing

We process data for the following purposes and on the following legal bases:

PurposeCategories of dataLegal basis
Provision of the service — chat, the AI Boss’s memory, tasks, projects, proactive messages, delivery of responses and notificationsTranscripts, AI memory, tasks, projects, proactive messages, attachmentsArt. 6(1)(b) GDPR — necessity for performance of the service contract
AI inference — generating the AI Boss’s responses, background memory processing, creation of vector representations of memory (embeddings), and attachment analysis, as a technical element of providing the serviceTranscripts, memory content, attachment contentArt. 6(1)(b) GDPR
Agent tools — searching for information on the internet (Google Search) and fetching an indicated page where this is needed to provide a response or complete a taskThe content of the search query composed by the model on the basis of the conversationArt. 6(1)(b) GDPR
Building the AI Boss’s persistent memory and a profile (profiling) — to personalise support, tone and proactive messages; see Section 9AI memory, transcriptsArt. 6(1)(b) GDPR — profiling is the essence of the requested AI Boss service; you control the memory/profile by clearing the AI Boss’s memory or deleting your account (see Section 9)
Authentication, account and session management, linking of the communication channel (Telegram/Slack/Discord)Account data, sessions, OAuth tokens, channel identifiersArt. 6(1)(b) GDPR
Usage metering (credit model) and management of subscription tiersAccount data, usage data — tokens/costArt. 6(1)(b) GDPR
Transactional Account e-mail — welcome, Trial-started confirmation and Trial-ended noticeE-mail address, transactional message content, Trial end date where applicable, domain event/idempotency identifiersArt. 6(1)(b) GDPR — necessary to perform the service contract; these messages are not marketing
Service security, abuse prevention, protection against jailbreak/prompt extractionTechnical data, content to the extent necessaryArt. 6(1)(f) GDPR — legitimate interest (security)
pocket.ceo website analytics (Google Analytics)Cookie identifiers, traffic dataArt. 6(1)(a) GDPR — consent; GA4 loads only after consent is given, via the consent-management mechanism (Google Consent Mode v2) — see Section 7
Legal obligations (e.g. responding to authorities’ requests)Data necessary to complyArt. 6(1)(c) GDPR

What we do NOT do with your data:

  • we do not sell your personal data;
  • we do not use your conversation content for advertising profiling;
  • we do not disclose conversation content for third-party marketing.

For the use of user content to train AI models, see Section 6.3.


5. Recipients of data — processors (subprocessors)

To provide the service we use external providers acting as processors. The table below lists the current recipients, their role and the location of their infrastructure.

ProviderRoleLocationWhat it receives
OpenRouter (OpenRouter, Inc.)AI inference provider — performs all model calls within the service: the AI Boss’s chat responses, proactive messages, background memory processing, creation of vector representations of memory (embeddings), and attachment analysis. OpenRouter does not host models itself — it routes every request to an infrastructure provider described in the row belowUSAConversation content, memory content, tasks and projects, attachment content and images
Inference infrastructure providers — sub-processors selected by OpenRouter separately for each requestExecution of a single request to an AI model. The selection is limited by a policy enforced on every request: zero data retention (ZDR) and a prohibition on collecting and using content, including to train models (see Section 6.1). A list of the entities currently used is available on requestUSA and other third countriesThe content of a single request — only for the time needed to execute it, with no storage
Google (Search)Agent tool — as part of a response, the model may run a Google search and fetch an indicated pageUSAOnly the content of the search query composed by the model. No transcripts, AI Boss memory or account data
StripePayment processor — handling subscriptions (billing, recurring payments, self-service checkout and subscription-management portal)USA (stripe.com)Billing and identifying data necessary to process subscription payments (card data is processed solely by Stripe)
TursoDatabase hosting — platform database (accounts, sessions, subscriptions) and isolated data of individual users (all memory, transcripts, tasks, projects, proactive messages)EU (Ireland) — databases hosted in the European Union; no third-country transfer for the database layerEffectively all stored data
CloudflareObject storage for attachments (R2) and hosting of the website and the web application (edge network)EU for the R2 bucket (EEUR region) — no third-country transfer for the attachment storage layer; the edge network operates globallyAttachment files; HTTP traffic to the website and the web application
Railway (Railway Corp.)Hosting of the server application (API)EU — the application is deployed in an EU region; the provider is established in the USA, so SCC remain the transfer basisData processed while application requests are being served (with no separate persistent store — data is kept in the Turso databases and in Cloudflare R2)
Telegram / Slack / DiscordCommunication channels (a bot in the chosen messenger); each messenger operates under its own terms and privacy policyProvider servers (USA/international)Message content, user id and username in the given messenger
GitHub (Microsoft) / GoogleSign-in providers for the web application (OAuth; a scope covering the e-mail address)USAAuthentication data within the OAuth flow
ResendDelivery of transactional Account e-mail (welcome, Trial-started, Trial-ended)USA (resend.com); the sending domain uses the eu-west-1 sending region, but Resend account data is stored in the USARecipient e-mail address, transactional message content (including the Trial end date where applicable), and domain event/idempotency identifiers. No conversation content, AI Boss memory, or payment-card data
Google Analytics (GA4)pocket.ceo website analytics (site-wide) — loaded only after consent is givenUSACookie identifiers, site traffic data

Note: for authentication we use our own mechanism running on our own infrastructure (it is not a third-party SaaS provider).

Why the infrastructure providers are not named individually. The AI model executing a single request is hosted by an entity selected dynamically, at the moment the request is sent, from among those that satisfy the zero-retention and no-collection policy described above. That set changes over time, which is why we identify it as a category of recipients within the meaning of Article 13(1)(e) GDPR, and the current list of the specific entities is available on request at hi@pocket.ceo.

Status of data processing agreements (Article 28 GDPR):

  • OpenRouter — a processing agreement forms part of the terms of service; transfers to the USA based on Standard Contractual Clauses (SCC); every request is subject to the zero data retention (ZDR) and no-collection-or-use-of-content policy described in Section 6.1;
  • Inference infrastructure providers — as sub-processors, they are bound by the processing terms concluded by OpenRouter and by the same policy, enforced on every request; transfers based on SCC;
  • Cloudflare — DPA in place; transfers based on SCC and/or DPF (R2 data hosted in the EU);
  • Railway — DPA in place; transfers to the USA based on SCC;
  • Turso — DPA in place (SOC 2 / HIPAA); data hosted in the EU (Ireland) with native at-rest encryption, so there is no — or only minimal — third-country transfer;
  • Telegram / Slack / Discord — communication channels operating under their own terms and privacy policies;
  • Resend — DPA in place; SCC + DPF;
  • GitHub (Microsoft) — DPA in place; SCC and/or DPF;
  • Google (Google sign-in, Google Search and Google Analytics) — transfers to the USA based on the Data Privacy Framework (DPF); Google LLC holds an active DPF certification (see the dataprivacyframework.gov list);
  • Stripe — DPA in place; transfers to the USA based on SCC and/or DPF.

6. Transfers outside the European Economic Area (EEA)

This is a key section of this Policy. Providing the service requires transferring data to third countries.

6.1. Transfers to the USA — AI inference and other providers

All AI model calls within the service — the AI Boss’s chat responses, proactive messages, background memory processing, the creation of vector representations of memory (embeddings), and attachment analysis — are performed by a single AI inference provider: OpenRouter (USA). OpenRouter does not host models itself: it routes every request to an infrastructure provider, which executes it and returns the result. That provider is selected separately for each request, and its infrastructure may be located in the USA or in another third country.

Transfers of data to OpenRouter and to the infrastructure providers acting as sub-processors are based on Standard Contractual Clauses (SCC) approved by the European Commission (Art. 46(2)(c) GDPR). A copy of the clauses used and the current list of the entities used are available on request (contact: hi@pocket.ceo).

Every request sent to an AI model is subject to a fixed routing policy, enforced on our application’s side:

  • zero data retention (Zero Data Retention, ZDR) — a request may go only to an infrastructure provider committed to not storing the transmitted content beyond the time necessary to execute the request;
  • prohibition on collecting and using content — a request may go only to a provider committed to not collecting the transmitted content and not using it for its own purposes, including to train or fine-tune models;
  • disabling the router’s additional services — the request is not enriched or processed by the provider’s ancillary services.

This policy is part of the application code and cannot be weakened by an individual call: a request that cannot be covered by it is not sent by the application. If no infrastructure provider meeting these conditions is available for a given model, the request fails with an error — it is not served on weaker terms.

For completeness, we state the limit of that mechanism: the classification of individual infrastructure providers as meeting the above conditions comes from the router operator and rests on commitments made by those providers, not on our separate verification of each of them. The mechanism narrows the set of recipients to those who have made such commitments — it does not replace their own responsibility for honouring them.

Please note that these measures reduce but do not eliminate the risk associated with possible access by US public authorities to data during its processing, and they do not constitute an adequacy decision within the meaning of Art. 45 GDPR. Language-model inference requires processing content in cleartext at the provider executing the request.

Internet search is performed by Google Search (USA) — it receives only the content of the search query composed by the model, with no transcripts, AI Boss memory or account data. Transfers are based on the Data Privacy Framework (DPF) — Google LLC holds an active certification. Search is not covered by the zero-retention policy described above — it operates under the terms of the Google service.

Other providers with infrastructure in the USA rely on the following transfer mechanisms:

  • Google / Google Analytics — the EU–US Data Privacy Framework (DPF): Google LLC holds an active DPF certification (https://policies.google.com/privacy/frameworks);
  • Stripe — SCC and/or DPF;
  • Resend — SCC + DPF; Resend account data is stored in the USA. The configured eu-west-1 sending region controls sending infrastructure and does not provide EU account-data residency;
  • GitHub (Microsoft) — DPA in place; SCC and/or DPF;
  • Cloudflare — SCC and/or DPF; the bucket storing attachments is hosted in the EU.

Processing and storage in the EU. The isolated user data stores and the platform database (Turso) are hosted in the European Union (Ireland) — storage in the database layer does not involve a transfer to a third country. Attachments are stored in a Cloudflare R2 bucket in the European Union. The server application (API) runs at the hosting provider in an EU region. The providers of these layers are, however, established in the USA and may access data in the course of operating and maintaining the service, so Standard Contractual Clauses (SCC) remain the transfer basis.

6.2. Background memory processing

Background memory processing — the consolidation and processing of your memory (including the extraction of generated memory from your conversations) and the creation of vector representations of memory content, which enable related information to be retrieved — is performed in the same way and by the same AI inference provider as interactive chat, under the same zero-retention and no-collection rules. This means that transcript and memory content — not only vector representations — is sent to the AI model as part of background memory processing.

6.3. Training models on your content

Content transmitted for AI inference — conversations, memory, tasks and attachments — is not used to train or fine-tune AI models. The router operator commits not to use it for model training, and the policy described in Section 6.1, enforced on every request, narrows the set of infrastructure providers to those that have made the same commitment; a request that cannot be covered by it is not sent.

For other recipients, the rules set out in their terms and data processing agreements apply. We do not pass conversation transcripts, AI Boss memory or account data to Google Search — only the content of a single query reaches it.


7. Cookies and analytics

A detailed list of cookies is set out in the Cookie Policy. In short, we use:

  • _ga, _ga_<id> (Google Analytics, GA4) — analytics cookies, provider: Google (USA), basis: consent. The GA4 script is loaded only after consent is given via a consent-management mechanism (CMP) with Google Consent Mode v2 in place (equivalent “Accept”/“Reject” options and the ability to withdraw consent). Transfer to the USA: the EU–US Data Privacy Framework (DPF) — Google LLC holds an active DPF certification (https://policies.google.com/privacy/frameworks). The lifetime of the _ga cookie is shortened to approximately 13 months (from the default 24), in line with electronic-communications privacy guidance.
  • authentication session cookie (better-auth.session_token, first-party) and short-lived technical cookies for the OAuth login flow — necessary to log in and to maintain the session; they do not require consent (technical cookies).

8. Data retention period

Data categoryPeriod / criteria
Conversation transcriptsRetained for the duration of your use of the service; not deleted automatically — deleted upon account deletion
AI memory — current records and summariesRetained for a limited time and automatically rotated (older records are replaced by newer summaries)
AI memory — persistent elements (retained information, relationship context and tone)Maintained for the duration of your relationship with the AI Boss; deleted when the AI Boss’s memory is cleared or the account is deleted
Tasks, projects, proactive messagesFor the duration of your use of the service; deleted upon account deletion
Attachments (Cloudflare R2)Automatically deleted after 90 days; also deleted when the user deletes their account
Account dataWhile the account exists; deleted after account deletion
Billing data (subscriptions, invoices)Retained for the period required by mandatory law (including tax and accounting law — as a rule 5 years); payment-card data is processed solely by Stripe
Transactional e-mail delivery data (Resend)Processed in the context of welcome, Trial-started and Trial-ended delivery under Resend’s provider terms and DPA; Resend account data is stored in the USA. pocket.ceo does not maintain a separate delivery-status store or promise a provider-retention period beyond those terms

The automated memory housekeeping covers only system-generated memory records and does not delete conversation transcripts.


9. Profiling and automated decisions

So that the AI Boss can play its role, it builds a persistent profile of the user from your memory and analyses your behaviour, commitments and progress to adjust tone, content and proactive messages. This constitutes profiling within the meaning of the GDPR.

Significance and consequences: profiling serves to personalise support (accountability, coaching, reminders) and affects how the AI Boss communicates with you and when it initiates contact.

No solely automated decisions producing legal effects: the service does not make decisions about you based solely on automated processing that would produce legal effects concerning you or similarly significantly affect you within the meaning of Art. 22 GDPR. AI responses and notifications are supportive and informational in nature.

Your rights: because the AI Boss’s memory and profile are necessary to provide the requested service (Art. 6(1)(b) GDPR), we provide control over profiling primarily through the ability to clear the entire AI Boss memory or delete your account (which removes the associated memory) — as part of the right to erasure (Art. 17 GDPR). You may also exercise your other rights, including requesting deletion of your data, by contacting us (see Section 10). The right to object (Art. 21 GDPR) applies instead to processing based on legitimate interest (service security, abuse prevention).


10. Your rights

You have the following rights under the GDPR:

  • Right of access to your data (Art. 15);
  • Right to rectification (Art. 16);
  • Right to erasure — the “right to be forgotten” (Art. 17);
  • Right to restriction of processing (Art. 18);
  • Right to data portability (Art. 20) — in a structured, commonly used, machine-readable format;
  • Right to object to processing, including profiling, based on legitimate interest (Art. 21);
  • Right to withdraw consent at any time (without affecting the lawfulness of processing before withdrawal) — where consent is the basis;
  • Right to lodge a complaint with a supervisory authority — in Poland: the President of the Personal Data Protection Office (UODO), ul. Stawki 2, 00-193 Warsaw.

How to exercise your rights: send your request to the e-mail address given in Section 1. We will respond without undue delay and within one month of receiving the request; where the matter is complex or there are numerous requests, this period may be extended by a further two months, of which we will inform you.

Account deletion: when your account is deleted, account data is cascade-deleted and all isolated User data is deleted from the Turso infrastructure. Attachments stored in Cloudflare R2 are deleted. Content previously sent for AI inference does not require separate deletion: the policy described in Section 6.1 allows a request to be executed only by a provider bound to zero retention, so that content is not stored at the provider beyond the time needed to serve the individual request.

Data export / portability: you may request a copy of all your data — transcripts, the AI Boss’s memory, tasks, projects, proactive messages, and account data — by contacting hi@pocket.ceo. The copy is provided in a commonly used, machine-readable format within one month of your request.


11. Data security (Article 32 GDPR)

We apply, among others, the following technical and organisational measures:

  • Isolation of individual users’ data — each user’s data is kept isolated; one user’s data contains no other users’ data;
  • Databases located in the EU — the databases are hosted in the European Union (Ireland), with no transfer of the database layer to a third country;
  • Zero retention at the AI providers, enforced in code — every request to an AI model carries a policy of zero data retention (ZDR) and a prohibition on collecting and using content; a request that cannot be covered by it is not sent by the application (see Section 6.1);
  • Session management — sessions expire after a defined period or on logout;
  • Validation and filtering of user content;
  • Access control over application configuration and confidential data;
  • Minimised logging of content and sensitive data;
  • Authentication of the messenger integration;
  • data in transit secured with TLS;
  • Encryption at rest — stored data is encrypted at rest by default on the Cloudflare R2 and Turso side.

12. Use of the service by minors

The service is not directed at persons under the age of 18 and we do not knowingly collect such persons’ data. If we learn that data of a person below the required age has been provided to us without the required basis, we will delete it without undue delay.


13. California / US users

The service is also directed at users in the United States, including residents of California. This section describes the rights available to California residents under the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA).

Scope. This section applies to residents of the State of California. Where the CCPA/CPRA concepts map to the categories described elsewhere in this Policy, the disclosures below reflect the same processing.

Categories of personal information collected:

  • identifiers — account data, e-mail address, the identifier at the sign-in provider (GitHub or Google), and the user id and username in the linked messenger (Telegram, Slack or Discord);
  • user content — conversations (transcripts), AI memory, tasks, projects, attachments;
  • usage / analytics data — technical data and pocket.ceo website analytics;
  • payment / billing data — processed via Stripe (payment-card data is processed solely by Stripe);
  • transactional e-mail data — recipient e-mail address, Account lifecycle message content (including a Trial end date where applicable), and domain event/idempotency identifiers processed via Resend.

Sources of the information:

  • directly from you (the content you enter and the data provided at registration);
  • automatically from your use of the service (technical and analytics data);
  • from the authentication provider — GitHub or Google (the OAuth flow).

Business and commercial purposes for processing: providing the service (including transactional Account e-mail), security, analytics, and billing.

Categories of recipients (service providers and the communication channel). We disclose personal information to the following recipients: the AI inference provider OpenRouter and the inference infrastructure providers it selects; Google Search; the database provider Turso; Cloudflare (file storage and website hosting); Railway (server application hosting); the communication channels Telegram, Slack and Discord; the e-mail provider Resend; the sign-in providers GitHub and Google; Google Analytics; and the payment processor Stripe (for a full description of roles and locations, see Section 5).

Sale / sharing. We do NOT sell personal information for money. We do, however, disclose that the use of Google Analytics may constitute “sharing” of personal information for cross-context behavioral advertising under the CCPA. California residents may exercise the right to opt out via the cookie-consent mechanism (a “Do Not Sell or Share My Personal Information” / consent control), by rejecting analytics cookies or withdrawing consent.

Your rights (California residents):

  • right to know / access — the categories and specific pieces of personal information collected;
  • right to delete personal information;
  • right to correct inaccurate personal information;
  • right to opt out of the sale or sharing of personal information;
  • right to limit the use of sensitive personal information;
  • right to non-discrimination for exercising any of these rights.

How to exercise your rights. You may submit a request by e-mailing hi@pocket.ceo (and, where available, using the relevant in-app controls). We will respond within 45 days (extendable as permitted by law). Requests may also be submitted by an authorized agent acting on your behalf.

For more information on California consumer rights, see the California Attorney General’s CCPA page: https://oag.ca.gov/privacy/ccpa.


14. Changes to this Privacy Policy

We may update this Policy, in particular where there are changes in law, in the scope of the service, in providers (subprocessors) or for security reasons. We will inform you of material changes in a manner appropriate to the nature of the change (e.g. an in-app notice or e-mail), with reasonable advance notice. The current version is always available at https://pocket.ceo/legal/privacy-policy.


15. Contact

For any matters concerning personal data protection, contact us at: hi@pocket.ceo.

Binding version: The binding version of this document is the Polish version. The English version is provided for convenience only; in the event of any discrepancy, the Polish version prevails.
pocket.ceo

© 2026 pocket.ceo

Blog Terms Privacy Cookies