Last updated: April 12, 2026 · Effective: April 12, 2026
This Privacy Policy explains how Poggle(“we,” “us,” or “our”) collects, uses, discloses, and protects personal information when you use Poggle(the “Service”). By using the Service, you consent to the practices described here. If you do not agree, do not use the Service.
1. Information We Collect
Information you provide
- Account data: email address, password hash, display name, and optional profile details.
- Billing data: name, billing address, and payment method details (processed and stored by our payment processor; we do not store full card numbers).
- Content: notes, files, skills, agents, folders, boxes, links, imports, exports, and any other content you create or upload.
- Communications: support tickets, emails, and feedback you send to us.
- Connection tokens: the name and scope you set for external API or MCP connections you create.
Information collected automatically
- Usage data: pages viewed, actions taken, timestamps, approximate location derived from IP, device type, browser, and operating system.
- Log and diagnostic data: IP address, request headers, error traces, and performance metrics.
- Audit events: an append-only record of writes, lifecycle changes, rollbacks, proposal approvals, and similar actions performed on your account.
- Cookies and similar technologies: authentication cookies, preference cookies, and limited analytics tracking as described in our Cookie Policy.
Information from third parties
We may receive limited information from third-party services you choose to use, such as authentication providers, payment processors, and AI model providers. We only receive what is necessary to provide the Service and never receive the content of your communications with AI providers unless you send it through the Service.
2. How We Use Information
We use the information we collect to:
- operate, maintain, secure, and improve the Service;
- authenticate you and prevent unauthorized access;
- process payments, renewals, cancellations, and refunds;
- respond to your requests, provide support, and communicate important service notices;
- detect, investigate, and prevent fraud, abuse, and security incidents;
- comply with legal obligations and enforce our Terms;
- with your consent, send product updates, tips, and marketing communications (which you can opt out of at any time).
We do not use your Content to train machine learning models. We do not sell your personal information. We do not share your Content with third parties except as strictly necessary to operate the Service, as described below, or as required by law.
3. Legal Bases (EEA/UK)
If you are in the European Economic Area, the United Kingdom, or Switzerland, we rely on one or more of the following legal bases to process your personal data under the GDPR or UK GDPR:
- Contract: to provide the Service you requested.
- Legitimate interests: to secure, improve, and operate the Service, provided these interests do not override your rights.
- Consent: for optional communications and certain cookies.
- Legal obligation: to comply with applicable law and respond to lawful requests.
4. How We Share Information
We share personal information only as described in this policy. We do not sell personal information.
- Service providers (processors): we use trusted third parties to provide hosting (Supabase), authentication, email delivery, payment processing, analytics, and customer support. They are contractually bound to protect your data and use it only on our instructions.
- Legal and safety: we may disclose information if required by law, subpoena, court order, or government request, or to protect the rights, property, or safety of Poggle, our users, or the public.
- Business transfers: if we are involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, your information may be transferred as part of that transaction. We will notify you of any change in ownership or use of your personal information.
- With your direction: when you connect the Service to third-party services (such as AI agents over MCP or API), we share the data you direct us to share within the scope you authorize.
- Aggregated or de-identified data: we may share aggregated or de-identified data that cannot reasonably be used to identify you.
5. International Data Transfers
We may process personal data in the United States and other countries that may have different data protection laws than your country. When we transfer personal data from the EEA, UK, or Switzerland, we rely on lawful transfer mechanisms such as the European Commission’s Standard Contractual Clauses, supplemented by additional safeguards where required.
6. Data Retention
We retain personal data for as long as your account is active or as needed to provide the Service. When you delete Content, we delete it from our active systems promptly and from backups in the ordinary course. We may retain certain information longer where required by law, for audit and security purposes, to resolve disputes, or to enforce our agreements. Version history and audit logs are retained according to the retention windows described in the Service.
7. Security
We implement reasonable administrative, technical, and physical safeguards designed to protect personal data, including encryption in transit, encryption at rest for stored content, access controls, audit logging, and regular security reviews. No system is perfectly secure, however, and we cannot guarantee the security of information transmitted to or stored by the Service. You are responsible for keeping your account credentials confidential and for the security of your own devices.
8. Your Rights
Depending on where you live, you may have the following rights with respect to your personal data:
- Access the personal data we hold about you.
- Correction of inaccurate or incomplete data.
- Deletion of your personal data, subject to legal exceptions.
- Portability: receive your data in a structured, commonly used, machine-readable format (export is built into the Service).
- Restriction or objection to certain processing.
- Withdraw consent where processing is based on consent.
- Lodge a complaint with a data protection authority.
To exercise these rights, contact us at privacy@poggle.app. We may verify your identity before fulfilling your request. We will respond within the timeframe required by applicable law.
9. California Residents (CCPA/CPRA)
If you are a California resident, you have the right to know what personal information we collect, use, disclose, and retain, to request deletion, to correct inaccurate information, to opt out of any “sale” or “sharing” of personal information (we do neither), and to limit the use of “sensitive personal information.” You also have the right not to be discriminated against for exercising these rights. To exercise them, contact us at privacy@poggle.app.
10. Children
The Service is not directed to children under 16. We do not knowingly collect personal information from children under 16. If you believe a child has provided us with personal information, contact us at privacy@poggle.app and we will take steps to delete it.
11. Automated Decision-Making
We do not use automated decision-making that produces legal or similarly significant effects on you without human involvement.
12. Do Not Track
We do not currently respond to “Do Not Track” browser signals because no consistent industry standard has been adopted. You can control cookies through your browser settings; see our Cookie Policy for details.
13. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email or through the Service. Your continued use of the Service after the effective date constitutes acceptance of the updated policy.
14. Contact
For privacy questions or to exercise your rights, contact us at privacy@poggle.app.