legal

Privacy Policy

Last updated September 9, 2026

Pokobot (“Poko”, “we”, “us”) is a reminder assistant you talk to inside WhatsApp. This policy explains what data we collect, why, and how we protect it — including dedicated sections on the data handled when you connect Poko to ChatGPT or Google Calendar.

Who we are

Pokobot is operated as an independent service reachable at our WhatsApp number and at pokobot.com. For any privacy question, email sudhanshu@radicallabs.io.

What we collect

Website click measurement

When you tap a WhatsApp button, we record the page, original landing page, referral and campaign information, browser information, language, and timezone. We use this to understand how people find Poko. A random identifier in your browser tab's session storage helps us distinguish repeat clicks and preserve the original source as you navigate. It renews after 30 minutes without a page change or tap and is not sent to WhatsApp. Our click log does not store your IP address.

ChatGPT plugin

Connecting Poko to ChatGPT is optional and initiated by you. The connection uses OAuth authorization. On Poko's authorization page, you enter the WhatsApp number already connected to your Poko account and verify it with a one-time code sent through WhatsApp.

Authentication data

Data processed and returned

Poko receives only the tool request ChatGPT sends, not your full ChatGPT conversation. Depending on what you ask, Poko may return:

The plugin is limited to your own private self-reminders. It does not return your phone number, reminders addressed to other people, OAuth secrets, internal account identifiers, or unrelated Poko account data. Pokobot's plugin server does not send these tool requests or reminder results to an additional language-model provider. ChatGPT itself processes your prompt and the tool result under your OpenAI account's terms and data settings.

Storage, logs, and disconnection

Reminders created through ChatGPT are stored in the same Poko account as reminders created through WhatsApp so they can be listed, delivered, or cancelled. Security and reliability logs are limited to operational metadata such as the tool name, outcome, duration, and reminder ID; they omit phone numbers and reminder text. Disconnecting Poko in ChatGPT stops future access. You may also contact us to revoke the connection and delete your Poko data.

Review sandbox

App reviewers may use a clearly labelled, isolated demo account. Its reminders are kept in a separate sandbox that contains no real user data and is never read by Poko's WhatsApp scheduler, so demo reminders are not delivered.

Google Calendar integration & Google user data

Connecting Google Calendar is optional and initiated by you through a Google sign-in screen. When you connect, we request the following scopes:

We only access your calendar in direct response to a message you send — for example “what’s on my calendar tomorrow?” or “set up a meeting with Priya at 3pm.” We do not access, scan, or sync your calendar in the background.

How Google data is stored

Limited Use disclosure

Pokobot’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, we do not:

How your data is used

Solely to operate the service: parse your requests, schedule and send reminders, return the self-reminder information you request through ChatGPT, and — if connected — read and manage your calendar as you direct. To interpret messages sent directly to Poko on WhatsApp, we send the relevant message text to our language-model provider for processing; your Google refresh token and ChatGPT OAuth tokens are never shared with them.

Sharing

We do not sell your data. We share it only with the infrastructure providers needed to run Poko (messaging, hosting, database, and the language-model provider that parses WhatsApp requests), each acting on our instructions. When you connect the ChatGPT plugin, we also return the requested reminder fields to OpenAI so ChatGPT can complete the action and show you the result.

Retention & deleting your data

Security

Sensitive credentials such as Google refresh tokens are encrypted at rest. Access to production systems is restricted, and data is transmitted over encrypted connections.

Children

Pokobot is not directed to children under 13.

Changes

We may update this policy; material changes will be reflected by the “last updated” date above.

Contact

Questions? Email sudhanshu@radicallabs.io or say hi on WhatsApp.

← Back to Pokobot