legal

Privacy Policy

Last updated July 13, 2026

Pokobot (“Poko”, “we”, “us”) is a reminder assistant you talk to inside WhatsApp. This policy explains what data we collect, why, and how we protect it — with a dedicated section on the Google user data we access when you connect Google Calendar.

Who we are

Pokobot is operated as an independent service reachable at our WhatsApp number and at pokobot.com. For any privacy question, email sudhanshu@radicallabs.io.

What we collect

Website click measurement

When you tap a WhatsApp button, we record the page, original landing page, referral and campaign information, browser information, language, and timezone. We use this to understand how people find Poko. A random identifier in your browser tab's session storage helps us distinguish repeat clicks and preserve the original source as you navigate. It renews after 30 minutes without a page change or tap and is not sent to WhatsApp. Our click log does not store your IP address.

Google Calendar integration & Google user data

Connecting Google Calendar is optional and initiated by you through a Google sign-in screen. When you connect, we request the following scopes:

We only access your calendar in direct response to a message you send — for example “what’s on my calendar tomorrow?” or “set up a meeting with Priya at 3pm.” We do not access, scan, or sync your calendar in the background.

How Google data is stored

Limited Use disclosure

Pokobot’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, we do not:

How your data is used

Solely to operate the service: parse your requests, schedule and send reminders, and — if connected — read and manage your calendar as you direct. To interpret your natural-language messages we send the relevant message text to our language-model provider for processing; your Google refresh token is never shared with them.

Sharing

We do not sell your data. We share it only with the infrastructure providers needed to run Poko (messaging, hosting, database, and the language-model provider that parses requests), each acting on our instructions.

Retention & deleting your data

Security

Sensitive credentials such as Google refresh tokens are encrypted at rest. Access to production systems is restricted, and data is transmitted over encrypted connections.

Children

Pokobot is not directed to children under 13.

Changes

We may update this policy; material changes will be reflected by the “last updated” date above.

Contact

Questions? Email sudhanshu@radicallabs.io or say hi on WhatsApp.

← Back to Pokobot