POCKET EA · LEGAL
Privacy Policy
Last updated September 7, 2026
Pocket EA is operated by Alpha Code LLC ("Pocket EA," "we," or "us"). This policy explains what we collect through the Pocket EA mobile app and website, why we use it, who processes it, how long we keep it, and the choices available to you. Pocket EA is currently offered only to adults in the United States.
Information we collect
- Account information: email address, adult self-attestation, legal-consent versions, and authentication records. Supabase verifies your password; Pocket EA does not receive it in plain text. We validate your age from the birth date you enter but do not retain the birth date.
- Assistant content: conversations, onboarding answers, tasks, commitments, memories, planning history, and files or images you choose to provide.
- Sensitive and consumer health information: personal, emotional, wellness, relationship, disability, or health-related information you intentionally share. See our Consumer Health Data Privacy Policy.
- Voice: microphone audio sent through Pocket EA’s servers to ElevenLabs for live speech-to-text and text-to-speech, plus resulting transcripts. Live audio is used to provide the current conversation, not as a hidden recording feature.
- Connected services: if you connect Google or Microsoft, the account email, permissions granted, encrypted authorization credentials, and calendar or email information required for your request.
- Notifications and calls: device push tokens, chosen accountability-call schedule, quiet hours, delivery preferences, and delivery status.
- Billing: subscription provider, customer and entitlement identifiers, plan, renewal status, and transaction status. We do not receive or store your full payment-card number.
- Usage and diagnostics: feature usage, approximate provider cost, app version, device and operating-system details, request identifiers, IP-derived security signals, and bounded technical logs.
- Support reports: your submitted description and the diagnostics shown before submission. Conversations, files, audio, and transcripts are never attached automatically.
Sources of information
We receive information directly from you, from your device and use of Pocket EA, from services you choose to connect, and from service providers that process authentication, billing, delivery, security, and support events for us.
How we use information
- Provide continuous conversation, memory, task and commitment management, live voice, and scheduled in-app accountability calls.
- Prepare calendar or email actions for your review and execute them only after the required confirmation.
- Deliver notifications, administer subscriptions, enforce plan limits, prevent abuse, investigate security events, and improve reliability.
- Provide crisis-safety responses when content indicates possible self-harm. Pocket EA does not automatically contact emergency services.
- Respond to support, privacy, access, correction, export, consent-withdrawal, appeal, and deletion requests.
AI processing
Pocket EA clearly uses artificial intelligence. OpenAI processes the content and context needed to generate responses, interpret requests, extract candidate memories, process supported attachments, and moderate content. During live voice conversations, microphone audio passes through Pocket EA’s servers to ElevenLabs, which transcribes speech to text and converts Pocket EA’s responses back to speech; OpenAI then generates the response from that transcript. Connected- service passwords and authorization tokens are not sent to OpenAI or ElevenLabs.
OpenAI states that API data is not used to train its models by default. Its standard abuse-monitoring logs may retain certain API content for up to 30 days unless different approved data controls apply. We do not represent that an AI response is human-authored, professional advice, or guaranteed accurate.
Service providers and disclosures
We do not sell personal information, share it for cross-context behavioral advertising, or sell consumer health data. We disclose information to contracted service providers only for defined business purposes, subject to confidentiality, security, and use restrictions, and when legally required or necessary to protect users or the public.
- Supabase: authentication, PostgreSQL database, and private file storage.
- Resend: transactional account-verification and security email delivery.
- OpenAI: AI responses, interpretation, memory extraction, attachment processing, and moderation.
- ElevenLabs: real-time speech-to-text and text-to-speech during live voice conversations, processed through Pocket EA’s servers rather than directly between your device and ElevenLabs.
- Render: authenticated API hosting and bounded operational logs.
- Expo: app builds, app delivery, and push-notification infrastructure.
- Cloudflare: website hosting, delivery, request security, and abuse protection.
- Stripe, RevenueCat, Apple, and Google: subscription checkout, entitlement management, renewal, cancellation, and platform billing.
- Google and Microsoft: optional calendar and email access that you explicitly connect.
Retention
- Account and assistant content: retained while your account is active, then deleted when you delete the content or account, subject to a short backup and legal-compliance window.
- Uploaded files: retained until you delete the file, assistant data, or account. Deletion removes the private storage object and its record.
- OAuth sign-in state: expired state records are removed after one day.
- Voice-session, usage, support, notification, and external-action records: retained for up to 24 months.
- Billing-event records: retained for up to seven years where needed for tax, accounting, fraud, and dispute obligations.
- OpenAI abuse-monitoring logs: may be retained by OpenAI for up to 30 days under its standard API data controls.
Backup copies and records subject to a legal hold may persist for a limited additional period and remain protected until deletion. We periodically remove records that pass the applicable retention period.
Your privacy choices and rights
- Ask what Pocket EA remembers, correct it, or delete it in conversation.
- Export assistant data, delete assistant data, or permanently delete the account from Settings.
- Disconnect Google or Microsoft capabilities independently and revoke provider access.
- Reject a proposed external action before anything is created, changed, or sent.
- Withdraw sensitive-data consent by deleting the relevant content or contacting us. Withdrawal does not affect processing already completed with valid consent.
- Request access, correction, deletion, portability, or an appeal of a denied request, and use an authorized agent where state law permits.
Submit requests to hello@pocket-ea.app. We will verify the request and respond within the period required by applicable law. You may appeal a denial by replying with "Privacy Appeal" in the subject line. We do not discriminate for exercising privacy rights.
Account deletion and subscriptions
Use the account-deletion page if you no longer have the app. Account deletion does not itself cancel a subscription managed by Stripe, Apple, or Google; Pocket EA provides a direct route to the provider that billed you so cancellation is no more difficult than enrollment.
Security and incident response
We use authenticated APIs, server-only provider keys, least-privilege database access, private file storage, encrypted connected-service credentials, rate limits, secret-redacted logs, and account-level deletion. We investigate suspected incidents and notify affected people and regulators when applicable law requires it. No online service can promise absolute security.
Children
Pocket EA is not directed to anyone under 18. Account creation requires an adult self-attestation, and we do not knowingly collect personal information from children.
Changes and contact
We may update this policy as Pocket EA changes. We will provide reasonable advance notice in the app or by email before material changes take effect when required. Questions or privacy requests can be sent to hello@pocket-ea.app.