Last updated: April 2026
This Privacy Policy describes how PocketBot (“we”, “us”, or “our”) collects, uses, and protects your information when you use the PocketBot mobile application (the “App”). PocketBot is developed and operated by PocketBot Ltd.
By using PocketBot, you agree to the collection and use of information as described in this policy. If you do not agree, please do not use the App.
Contact: For privacy inquiries, email anton.may@new.ox.ac.uk
PocketBot does not require an email address, password, or any personal registration. Your account is created automatically using:
When you use the chat interface to create automations, your messages are sent to our server and forwarded to a third-party AI service (see Section 5.1). We do not retain your chat messages after processing.
When you create automations (“pocks”), we store:
We store your subscription plan tier and Apple transaction identifiers for the purpose of verifying your purchase and determining your plan level. We do not receive or store any payment or billing information (see Section 7).
PocketBot accesses device data only when your automations require it. We do not passively collect device data in the background. Data types that may be accessed include:
| Data Type | What We Access | How It's Used |
|---|---|---|
| Contacts | Names, phone numbers, emails | Look up contacts referenced in automations |
| Calendar | Event titles, times, descriptions | Calendar-based automation triggers |
| Health | Step count, distance, calories | Health-based automation triggers |
| Location | Lat/lon (50m foreground, 500m background) | Location-based automation triggers |
| Messages | SMS compose (iOS); read/send (Android) | Messaging automations |
| Camera & Photos | Photo capture, gallery access, OCR | Image-based automations |
| Bluetooth | Paired device names, connection status | Device-based automation triggers |
| Microphone | Speech-to-text (processed on-device) | Voice input for creating automations |
| Device Info | Battery, network, model, OS version | Device state-based automations |
On iOS, SMS messages cannot be sent programmatically. The App opens the native message compose sheet, and you must manually tap Send.
Background location: Location data may be collected in the background when you have configured a location-based automation trigger. Continued use of GPS running in the background can decrease battery life. You can disable background location at any time in your device's Settings app.
Apple HealthKit data: Health data accessed via Apple HealthKit is used solely to power the automation triggers you configure. HealthKit data is not used for advertising or marketing purposes, is not sold to data brokers or any third parties, is not shared with third parties (including AWS Bedrock or any AI service), and is not used to determine insurance eligibility, lending decisions, or for any purpose other than the automation triggers you configure within the App.
The following data is stored locally and never transmitted to our servers:
Your automation data is stored on our server, organised by your anonymous User ID. Data is encrypted in transit. Server access is restricted to authorised personnel only.
Your automation data is stored on servers located in Europe and the United States. Our third-party service providers (AWS Bedrock, Nango, RevenueCat) may also process data in the United States.
If you are located in the European Economic Area (EEA), transfers of your data to the United States are protected by Standard Contractual Clauses (SCCs) approved by the European Commission, or by the provider's participation in equivalent data protection frameworks. These safeguards ensure that your data receives a level of protection equivalent to that provided within the EEA.
Sensitive data (authentication tokens, OAuth credentials) is stored in iOS Keychain via Flutter Secure Storage, which provides hardware-backed encryption. Non-sensitive preferences use standard app storage.
PocketBot uses a third-party AI service to create automations from your chat messages. Before any data is sent, the app asks for your explicit permission via an in-app consent screen.
Your data is sent to Amazon Web Services (AWS) Bedrock, a cloud AI service operated by Amazon Web Services, Inc. AWS Bedrock hosts the AI models (Anthropic Claude) that process your requests. See AWS Privacy Policy and AWS Service Terms.
When you use the chat feature to create or modify automations, the following data is sent to AWS Bedrock:
The app displays a consent screen the first time you use the chat feature, clearly explaining what data will be sent and to whom. You must tap “I Agree” before any data is sent to the AI service. No data is sent to the AI service until you have reviewed and accepted this consent.
Important: AI processing is a core feature of PocketBot. By accepting the consent screen and using the app, you agree to your chat messages being processed as described above.
When you connect third-party services (Gmail, Slack, GitHub, etc.), PocketBot uses Nango to manage OAuth tokens and proxy API requests. Nango receives:
We do not store your OAuth tokens directly; they are managed by Nango. See Nango's Privacy Policy.
PocketBot uses RevenueCat to verify in-app purchases and manage subscription entitlements. RevenueCat receives:
RevenueCat does not receive your name, email, payment details, or any other personal information. See RevenueCat's Privacy Policy.
When you connect services like Gmail, Google Calendar, Slack, GitHub, Discord, Notion, Linear, Spotify, or others, PocketBot accesses those services through OAuth with the permissions you authorise. Data is accessed only when your automations run, and only within the scopes you granted. Each service has its own privacy policy.
If you sign up via the waitlist form on our website (getpocketbot.com), your email address is collected by Tally.so. This data is separate from the app and is not linked to your PocketBot account. See Tally's Privacy Policy.
PocketBot offers subscription plans managed through Apple's in-app purchase system (StoreKit). All payment information is collected and processed entirely by Apple. We do not receive or store your credit card number, billing address, or other payment details. We receive only a transaction receipt confirming your subscription status and plan tier.
See Apple's Privacy Policy for details on how Apple handles payment data.
PocketBot is not directed at children under the age of 13 (or 16 in the European Economic Area). We do not knowingly collect personal information from children. If we learn that we have collected data from a child under these ages, we will delete it promptly. If you believe a child has provided us with data, please contact us at anton.may@new.ox.ac.uk.
You can view all your automations and execution logs within the App. Contact us to request a full export of your server-side data.
AI processing is a core part of how PocketBot creates automations. By using the app and accepting the in-app data sharing consent, you agree to your chat messages being processed by the third-party AI service described in Section 5.1.
Under Article 6 of the GDPR, we process your data on the following legal bases:
If you are located in the European Economic Area, you have the following rights under the General Data Protection Regulation:
To exercise these rights, contact anton.may@new.ox.ac.uk. We will respond within 30 days.
We may update this Privacy Policy from time to time. When we make material changes, we will update the “Last Updated” date at the top and may notify you through the App. Your continued use of PocketBot after changes constitutes acceptance of the updated policy.
If you have questions about this Privacy Policy or wish to exercise your data rights:
We aim to respond to all inquiries within 30 days.