Privacy Policy
Last updated September 9, 2026
Pokobot (“Poko”, “we”, “us”) is a reminder assistant you talk to inside WhatsApp. This policy explains what data we collect, why, and how we protect it — including dedicated sections on the data handled when you connect Poko to ChatGPT or Google Calendar.
Who we are
Pokobot is operated as an independent service reachable at our WhatsApp number and at pokobot.com. For any privacy question, email sudhanshu@radicallabs.io.
What we collect
- Your WhatsApp number and messages to Poko. We use these to understand your reminder requests and reply to you. We do not read messages you send to anyone else — only what you send to Poko.
- Reminders and preferences you create — the text, time, recurrence, and timezone of each reminder, so we can poke you at the right moment.
- Google account data — only if you explicitly connect Google Calendar (see below). This is entirely optional; reminders work without it.
- ChatGPT plugin connection data — only if you explicitly connect Poko in ChatGPT. This includes the authorization records needed to keep that connection secure and the reminder data described in the ChatGPT section below.
Website click measurement
When you tap a WhatsApp button, we record the page, original landing page, referral and campaign information, browser information, language, and timezone. We use this to understand how people find Poko. A random identifier in your browser tab's session storage helps us distinguish repeat clicks and preserve the original source as you navigate. It renews after 30 minutes without a page change or tap and is not sent to WhatsApp. Our click log does not store your IP address.
ChatGPT plugin
Connecting Poko to ChatGPT is optional and initiated by you. The connection uses OAuth authorization. On Poko's authorization page, you enter the WhatsApp number already connected to your Poko account and verify it with a one-time code sent through WhatsApp.
Authentication data
- Your WhatsApp number is used by Poko to find your account and by Meta's WhatsApp service to deliver the one-time code. It is not included in Poko's tool inputs or responses to ChatGPT.
- Poko issues opaque access and refresh tokens to the authorized ChatGPT client. Our database stores only cryptographic digests of authorization codes, one-time codes, and tokens, together with the account binding, requested scopes, expiry, and revocation state. We do not store the raw one-time code or raw OAuth tokens.
Data processed and returned
Poko receives only the tool request ChatGPT sends, not your full ChatGPT conversation. Depending on what you ask, Poko may return:
- your Poko timezone, current local time, and whether reminder creation is available;
- pending self-reminders, including reminder ID, task text, due time, timezone, recurrence, optional active-window times, and status;
- the same fields for a reminder you create or cancel, plus whether a cancellation succeeded.
The plugin is limited to your own private self-reminders. It does not return your phone number, reminders addressed to other people, OAuth secrets, internal account identifiers, or unrelated Poko account data. Pokobot's plugin server does not send these tool requests or reminder results to an additional language-model provider. ChatGPT itself processes your prompt and the tool result under your OpenAI account's terms and data settings.
Storage, logs, and disconnection
Reminders created through ChatGPT are stored in the same Poko account as reminders created through WhatsApp so they can be listed, delivered, or cancelled. Security and reliability logs are limited to operational metadata such as the tool name, outcome, duration, and reminder ID; they omit phone numbers and reminder text. Disconnecting Poko in ChatGPT stops future access. You may also contact us to revoke the connection and delete your Poko data.
Review sandbox
App reviewers may use a clearly labelled, isolated demo account. Its reminders are kept in a separate sandbox that contains no real user data and is never read by Poko's WhatsApp scheduler, so demo reminders are not delivered.
Google Calendar integration & Google user data
Connecting Google Calendar is optional and initiated by you through a Google sign-in screen. When you connect, we request the following scopes:
openidandemail— to identify your Google account and show you which account is connected.https://www.googleapis.com/auth/calendar.events— to view and manage events on your calendar on your behalf, entirely in response to your WhatsApp requests: reading your agenda when you ask, creating events and meetings you dictate, and deleting events you tell Poko to cancel.
We only access your calendar in direct response to a message you send — for example “what’s on my calendar tomorrow?” or “set up a meeting with Priya at 3pm.” We do not access, scan, or sync your calendar in the background.
How Google data is stored
- We store the OAuth refresh token Google issues so you don’t have to reconnect each time. It is encrypted at rest using AES-256-GCM.
- We do not keep a copy of your calendar events. Event data is fetched from Google live when you ask and used only to form the reply — it is not stored in our database.
Limited Use disclosure
Pokobot’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, we do not:
- use Google user data for serving advertisements;
- transfer or sell Google user data to third parties, data brokers, or for any purpose unrelated to providing the reminder and calendar features you requested;
- allow humans to read your Google data, except with your explicit consent, to comply with law, or as strictly necessary for security (e.g. investigating abuse);
- use Google user data to train generalized AI/ML models.
How your data is used
Solely to operate the service: parse your requests, schedule and send reminders, return the self-reminder information you request through ChatGPT, and — if connected — read and manage your calendar as you direct. To interpret messages sent directly to Poko on WhatsApp, we send the relevant message text to our language-model provider for processing; your Google refresh token and ChatGPT OAuth tokens are never shared with them.
Sharing
We do not sell your data. We share it only with the infrastructure providers needed to run Poko (messaging, hosting, database, and the language-model provider that parses WhatsApp requests), each acting on our instructions. When you connect the ChatGPT plugin, we also return the requested reminder fields to OpenAI so ChatGPT can complete the action and show you the result.
Retention & deleting your data
- Disconnect ChatGPTin ChatGPT's plugin settings to stop future access. You can also email us to revoke the connection. Expired or revoked OAuth records are removed through routine cleanup.
- Disconnect Google Calendar anytime by asking Poko to disconnect, or by revoking access at myaccount.google.com/permissions. On disconnect we delete your stored refresh token.
- Delete everything — message Poko or email sudhanshu@radicallabs.io and we will remove your reminders and account data.
Security
Sensitive credentials such as Google refresh tokens are encrypted at rest. Access to production systems is restricted, and data is transmitted over encrypted connections.
Children
Pokobot is not directed to children under 13.
Changes
We may update this policy; material changes will be reflected by the “last updated” date above.
Contact
Questions? Email sudhanshu@radicallabs.io or say hi on WhatsApp.