# Privacy Policy · Pokobot

> How Pokobot handles your data across WhatsApp, the ChatGPT plugin, and the optional Google Calendar integration.

Last updated September 9, 2026.

Pokobot (“Poko”, “we”, “us”) is a reminder assistant you talk to inside WhatsApp, operated by Radical Labs. Contact: sudhanshu@radicallabs.io, or reply in the WhatsApp thread your reminders arrive in.

## Who we are

Pokobot is reachable [on WhatsApp](https://wa.me/917722891195?text=Remind%20me%20to%20drink%20water%20in%202%20minutes) and at https://www.pokobot.com.

## ChatGPT plugin

Connecting Poko to ChatGPT is optional. Poko uses the WhatsApp number you enter on its OAuth page to find your account and send a one-time verification code through Meta's WhatsApp service. The number is not included in Poko's tool inputs or responses to ChatGPT.

Poko issues opaque OAuth credentials to the authorized ChatGPT client. We store only cryptographic digests of authorization codes, one-time codes and tokens, together with their account binding, scopes, expiry and revocation state. Raw one-time codes and raw OAuth tokens are not stored.

Poko receives only the tool request ChatGPT sends, not the full ChatGPT conversation. Depending on the request, Poko returns: timezone, current local time and reminder-creation availability; or a reminder's ID, task text, due time, timezone, recurrence, optional active-window times and status; and whether cancellation succeeded. The plugin returns only the authenticated account's private self-reminders. It does not return the phone number, reminders addressed to other people, OAuth secrets, internal account identifiers, or unrelated account data.

Reminders created through ChatGPT are stored in the same Poko account as WhatsApp reminders so they can be delivered, listed or cancelled. Operational logs may include tool name, outcome, duration and reminder ID, but omit phone numbers and reminder text. Poko's plugin server makes no additional AI-model call. ChatGPT processes prompts and tool results under the user's OpenAI account terms and settings.

Disconnect Poko in ChatGPT's plugin settings to stop future access, or contact us to revoke the connection and delete Poko data. App reviewers use a clearly labelled isolated sandbox with no real user data and no WhatsApp delivery.

## Google Calendar

When you connect Google Calendar we use these scopes, only in response to a WhatsApp message you send:

- `openid` and `email` — to identify your Google account.
- `https://www.googleapis.com/auth/calendar.events` — to view and manage events on your behalf (read agenda, create events and meetings you dictate, delete events you cancel).

We do not access, scan, or sync your calendar in the background. The OAuth refresh token is stored encrypted at rest with AES-256-GCM. We do not keep a copy of calendar events; they are fetched live when you ask.

### Limited Use

Use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including Limited Use. We do not: use Google user data for ads; sell or transfer it to third parties or data brokers unrelated to the features you requested; allow humans to read it except with consent, to comply with law, or as strictly necessary for security; use it to train generalized AI/ML models.

## How your data is used

Solely to operate the service: parse WhatsApp requests, schedule and send reminders, return self-reminder information requested through ChatGPT, and — if connected — read and manage your calendar as directed. Relevant WhatsApp message text is sent to our language-model provider for processing. Google refresh tokens and ChatGPT OAuth tokens are never shared with them.

## Sharing

We do not sell your data. We share it only with infrastructure providers needed to run Poko (messaging, hosting, database, and the language-model provider), each acting on our instructions. When the ChatGPT plugin is connected, requested reminder fields are returned to OpenAI so ChatGPT can complete the action and show the result.

## Retention

Disconnect Poko in ChatGPT's plugin settings to stop future access, or contact us to revoke the connection. Disconnect Google Calendar by asking Poko or revoking at https://myaccount.google.com/permissions — we then delete the stored refresh token. Delete everything by messaging Poko or emailing sudhanshu@radicallabs.io.

## Other

Sensitive credentials are encrypted at rest. Data is transmitted over encrypted connections. Pokobot is not directed to children under 13.