Privacy Policy
Effective August 16, 2026 · Last updated August 16, 2026
Pocky turns your product notes into creator briefs. That means you hand us your brand voice, so this page is specific about where it goes.
The short version
- We do not train AI models on your content
- Not our own models, and not Anthropic's. Your briefs, brand documents and campaign inputs are used to run the service for you, and nothing else.
- Your inputs go to Anthropic to generate a brief
- Anthropic is our model provider. Under its commercial terms it may not train on what we send, and it deletes API inputs and outputs within 30 days by default.
- We never see your card number
- Stripe processes payments and holds the card. We store a customer ID, the plan you are on and the invoice history.
- We use product analytics
- PostHog, for understanding which parts of the product work and for catching errors. You can opt out at any time.
- You can get your data out or have it deleted
- Ask us and we will respond within 45 days. Section 10 covers how.
- We do not sell your personal information
- We have never sold it and we do not share it for cross-context behavioral advertising.
This summary is for orientation only. The numbered sections below are the terms that actually apply.
1. Who we are
Pocky is operated by Use Pocky LLC, a New York limited liability company with its place of business at 418 Broadway #6354, Albany, NY 12207. In this policy, "we", "us" and "Pocky" mean that company, and "you" means the person or business using the service at usepocky.com.
This policy covers the Pocky website and application. It does not cover the third-party services we rely on to deliver it, each of which has its own policy. Every one of them is named on our subprocessors page.
2. What we collect
Everything below is either something you give us, something the product generates while you use it, or something your browser sends automatically. We do not buy personal information from data brokers and we do not enrich your profile from third-party sources.
| Category | What it is | Where it comes from |
|---|---|---|
| Account data | Email address, password hash or Google sign-in identifier, account creation date, email verification state. | You, at sign-up. Passwords are hashed by Supabase Auth and are never visible to us. |
| Waitlist submissions | Email address, name, company and where you came from, if you joined the waitlist before there was an account to sign into. | You, on the public waitlist form. A notification also goes to our Slack. |
| Brand and campaign content | Brand names, product descriptions, audience notes, selling points, tone guidance, and any brand documents you paste or upload. | You, as you use the product. |
| Generated briefs | The creator briefs, hooks and scripts Pocky produces for you, plus any you mark as favorites. | Generated by the service from your inputs. |
| Usage and metering data | Briefs generated, model used, token counts, computed cost, outcome of each generation, and a trace identifier that ties a request together across our logs. | Recorded automatically on every generation, so we can meter your plan and control cost. |
| Billing data | Stripe customer and subscription identifiers, plan, subscription status, billing period, invoice and payment history, credit balance and expiry. | Stripe, via webhook. Card numbers are held by Stripe and never reach our servers. |
| Product analytics | Pages viewed, features used, feature-flag assignments, approximate location derived from IP, device and browser type, a session identifier, and session recordings of your interactions with the interface. | PostHog, in your browser and on our servers. See section 6. |
| Error and diagnostic data | Stack traces, request metadata and trace identifiers when something fails. | Generated automatically when an error occurs. |
| Support correspondence | The content of emails you send us and our replies. | You, when you contact us. |
3. How your content reaches Claude
Pocky does not run its own AI model. When you generate a brief, we send the inputs needed to answer, which is your brand profile, your campaign inputs, any brand document excerpt you provided, and our prompt, to Anthropic's API, and Anthropic's Claude models return the brief. That transmission is the only purpose for which the content leaves our systems.
Anthropic processes this content under its Commercial Terms of Service and its commercial data retention policy. Two commitments in those terms matter to you:
- Anthropic may not train its models on the content we send through the API.
- Anthropic automatically deletes API inputs and outputs on its backend within 30 days of receipt, except where content is flagged under its Usage Policy, in which case it may be retained for up to two years, with trust and safety classification scores retained for up to seven years.
We do not send your account email, your billing details or your payment information to Anthropic. We do send a request identifier, so a failed generation can be traced, and a pseudonymous account identifier, which Anthropic uses to enforce its Usage Policy.
4. Training on your content
We do not use your inputs, your brand documents or your generated briefs to train any AI model, and our model provider does not train on them either. There are four narrow exceptions, which are the ones every mature AI company carries:
- Abuse and safety. We and Anthropic may review content flagged by automated safety systems, or reported to us, in order to enforce the Acceptable Use Policy and Anthropic's Usage Policy.
- Aggregated and de-identified data. We use counts, costs and error rates that cannot identify you or your brand to operate, debug and improve the service.
- Feedback you choose to send. If you report a bug or send us an example of a bad brief, we use what you sent to fix it, including keeping it in a test set.
- Legal compliance. We retain and disclose content where the law requires it, as described in section 7.
5. Why we process your information
| Purpose | What we use |
|---|---|
| Providing the service you paid for: generating briefs, storing your brands and campaigns, metering your plan. | Account data, brand and campaign content, generated briefs, usage data. |
| Taking payment, applying your plan allowance and handling refunds and disputes. | Account data, billing data, usage data. |
| Keeping the service up, debugging failures and controlling AI spend. | Usage data, error data, analytics. |
| Preventing abuse, fraud and violations of the Acceptable Use Policy. | Account data, usage data, flagged content, IP address. |
| Understanding how the product is used so we can improve it. | Product analytics, aggregated usage data. |
| Sending service email: verification, password reset, billing notices, and material changes to these policies. | Account data, billing data. |
| Meeting tax, accounting and other legal obligations. | Billing data, correspondence. |
6. Analytics and cookies
We use PostHog for product analytics, session recording and error tracking. It tells us which steps of the brief wizard people abandon, what a visitor saw before they signed up, and what broke when a generation failed. We do not use advertising cookies, and we do not run third-party ad or social tracking pixels.
| Cookie or storage | Purpose | Type |
|---|---|---|
| Supabase auth session | Keeps you signed in and refreshes your session. | Strictly necessary. Cannot be turned off while you are signed in. |
| PostHog analytics identifier | Distinguishes one visitor from another so usage counts and funnels are meaningful, and links a browser session to server-side events and to session recordings. | Analytics. |
Session recording
PostHog records how you move through the interface: pages, clicks, scrolling and the shape of the page as you saw it. We use it to work out why a step failed for a real person rather than guessing from a stack trace. Recordings are stored by PostHog on our plan's retention schedule and are not used for advertising or sold to anyone.
Turning analytics off
Email ops@usepocky.com and we will exclude your account from analytics and session recording, and delete the analytics profile we already hold for you. We will confirm when it is done. This does not limit your access to any feature.
8. How long we keep things
| Data | Retention |
|---|---|
| Brands, campaigns and generated briefs | Until you delete them or close your account. Deleting an item hides it from your account immediately and marks it deleted in our database. If you want it erased outright rather than marked deleted, ask us using section 10 and we will do it. |
| Account record | Until you close your account, then removed as part of the deletion process described in section 10. |
| Usage and metering records | Retained after account deletion with the user identifier removed, so that historical cost and volume totals stay correct. The remaining rows cannot be tied back to you. |
| Billing records, invoices and tax records | Seven years, because tax and accounting law requires it. This survives account deletion. |
| Product analytics | Retained by PostHog on our plan's default schedule. Aggregates persist indefinitely. |
| Error and diagnostic logs | Hosting and function logs are kept for the retention window of our hosting plan, currently measured in days. The same records, which carry an account identifier and a request identifier, are also sent to PostHog and kept on its retention schedule. |
| Content sent to Anthropic | Deleted by Anthropic within 30 days, or up to two years if flagged under its Usage Policy. See section 3. |
| Support email | Two years from the last message in the thread. |
9. Security
Data is encrypted in transit and at rest. Access to production data is restricted to the people who operate the service. Every table holding your content has row-level security enabled in the database, so the ordinary read and write paths cannot reach another account's rows, and the small number of privileged server paths check ownership explicitly. We cap AI spend per account and across the service, which also limits the blast radius of a compromised account.
No system is perfectly secure. If we become aware of a breach affecting your personal information we will notify you and any regulator we are required to notify, without undue delay.
10. Your rights and choices
Depending on where you live, you may have the right to access the personal information we hold about you, to receive a copy in a portable format, to correct it, to delete it, to opt out of sale or sharing (we do neither), and not to be discriminated against for exercising any of these rights. Residents of California, Colorado, Connecticut, Virginia, Texas, Oregon, Montana and other states with comprehensive privacy laws have these rights by statute.
How to exercise them
Email ops@usepocky.com from the address on your account and tell us what you want. We will confirm your identity by that email address, and respond within 45 days. If we need longer we will tell you why before the deadline. There is no charge unless a request is manifestly excessive or repetitive.
Deletion in practice
Deleting your account removes your sign-in record, and your brands, campaigns and briefs go with it. Favorites and any waitlist entry under your email are removed outright. Deleting a single brand, campaign or brief from inside the product marks it deleted rather than erasing it; ask us if you want it erased outright. Usage records are stripped of your identifier rather than deleted, so that our cost and volume totals stay accurate. Billing and tax records are retained for the period in section 8, because the law requires it. You can also ask an authorized agent to make a request on your behalf, with written proof of authorisation.
Appeals
If we decline a request, you may appeal by replying to our decision. We will review and respond within 45 days of the appeal. Some states also allow you to complain to your attorney general.
11. Children
Pocky is a business tool and is not directed to children. You must be at least 18 to use it. We do not knowingly collect personal information from anyone under 18. If you believe a minor has given us information, tell us and we will delete it.
12. Where the service is offered
Pocky is offered to customers in the United States only. Your account, your content and your briefs are stored and processed in the United States. The one exception is the network layer: our hosting provider and the Cloudflare bot check on our sign-in forms both run on global edge networks, so request-level metadata such as your IP address may be handled at an edge location outside the United States before the request reaches us.
We do not currently offer the service to residents of the European Economic Area, the United Kingdom or Switzerland, and we do not target those markets. If you access the service from outside the United States, you do so on your own initiative and you are responsible for compliance with local law.
13. Changes to this policy
We will update this page when the product changes. The effective date at the top always reflects the current version. For a material change, which means one that expands how we use your information or reduces your rights, we will email the address on your account at least 30 days before it takes effect.
14. Contact
Privacy questions, data requests and everything else: ops@usepocky.com. By post: Use Pocky LLC, 418 Broadway #6354, Albany, NY 12207.