HomeThe People Pocket

Privacy

Privacy Policy

Last updated July 2026. This policy explains how The People Pocket ("we," "us," or the "Service") collects, uses, discloses, and retains personal information when you use the Service or visit our marketing site. It sits alongside our Terms & Disclaimers and the standalone Not-Legal-Advice notice.

1. Roles: controller vs. processor

For workforce data your organization enters, uploads, or generates through the Service, including situation facts, employee identifiers, documentation drafts, policies, and HR records, your organization is the controller and The People Pocket is the processor. We handle that data on your instructions under our Terms and any executed data processing addendum (DPA).

For account, billing, product-analytics, and marketing-site data associated with the individual using the Service (name, email, company, IP, device, log data), we act as an independent controller.

2. What we collect

Account data: name, work email, password hash or OAuth identifier, company name, role.

Customer content: situations you describe, messages exchanged with Tova, uploaded policies and handbooks, generated drafts, reminders, and follow-up notes. This may include personal information about your employees (identifiers, employment status, leave, performance, protected-class references your users enter).

Usage data: pages viewed, features used, request timestamps, error diagnostics, coarse device and browser metadata, IP address.

Billing data: handled by our payment processor; we receive a customer identifier and status, not full card numbers.

Communications: messages you send to support and responses.

3. Sources of information

Directly from you and from users at your organization; automatically from your use of the Service; from our subprocessors (auth, hosting, payments, email, analytics, AI inference); and from publicly available sources for anti-fraud and account safety.

4. How we use information

  • Provide, operate, secure, and improve the Service.
  • Generate AI responses, drafts, risk analysis, scripts, and documents you request.
  • Authenticate users, manage accounts, and process payments.
  • Detect, prevent, and respond to abuse, fraud, and security incidents.
  • Comply with legal obligations and enforce our Terms.
  • Send service, billing, and, where permitted, product update communications.
  • Aggregate and de-identify data for internal analytics and product research.

5. AI models and training

Customer content is used to generate responses for you and to operate features you invoke (retrieval over your uploaded policies, chunking, embeddings, reminders, document generation). We do not use identifiable customer content to train third-party foundation models, and we contractually require our AI inference subprocessors not to train their base models on your inputs or outputs.

We may use aggregated, de-identified signals (e.g., which prompts fail, latency, feature usage) to improve prompts, guardrails, and internal evaluation sets.

6. When we share information

  • Subprocessors that host, secure, or power the Service (see §7).
  • Your organization, administrators may see users, activity, and content on the account.
  • Legal and safety, to comply with law, respond to lawful requests, enforce our Terms, or protect rights, safety, and property.
  • Corporate transactions, in a merger, acquisition, financing, or asset sale, with appropriate confidentiality protections.
  • With your consent, where you direct us to share.

We do not sell personal information and we do not share personal information for cross-context behavioral advertising.

7. Subprocessors

Current material subprocessors used to operate the Service:

  • Supabase (AWS us-east-1): managed Postgres database, object storage, authentication.
  • Cloudflare Workers: serverless application runtime and edge delivery.
  • Lovable AI Gateway routing to model providers (OpenAI, Anthropic, Google) for chat completions, embeddings, and document generation, with no-training terms in place.
  • Stripe: subscription billing and payment processing.
  • Resend (via Lovable email): transactional email delivery.
  • Firecrawl: retrieval of publicly published state agency guidance for the state-law reference library.

A current, dated subprocessor list, with advance notice of material changes, is available on request at privacy@backpockethr.com. Enterprise customers may subscribe to notifications of subprocessor additions.

8. Retention & deletion

We retain account data for the life of the account and customer content per your organization's instructions. Absent contrary instructions, we delete or de-identify customer content within 30 days of account termination, subject to legal-hold, backup-cycle, and dispute-preservation exceptions. Billing and tax records are retained as required by law.

Administrators can request export or deletion of an account's content at any time via privacy@backpockethr.com.

9. Security

We use encryption in transit (TLS) and at rest for data stored in our managed cloud database and object storage; role-based access controls; least-privilege internal access; audit logging on privileged operations; and vendor security review for subprocessors. No system is perfectly secure, you are responsible for your users' credentials and for calibrating what workforce data your team enters into the Service.

Report suspected vulnerabilities to security@backpockethr.com. Report incidents affecting your account to the same address; where The People Pocket is a processor, we will notify your designated administrator without undue delay after becoming aware of a personal data breach affecting your data.

10. International transfers

The Service is operated from the United States and personal information is processed in the United States and in regions our subprocessors operate. Where required, we rely on Standard Contractual Clauses and equivalent transfer mechanisms.

11. Your rights

Depending on your jurisdiction (including US state privacy laws such as CCPA/CPRA, VCDPA, CPA, CTDPA, UCPA, and comparable regimes; and, where applicable, GDPR/UK GDPR), you may have rights to access, correct, delete, port, restrict, or object to processing of your personal information, and to appeal a denial.

For account/controller data: submit requests to privacy@backpockethr.com and we will verify your identity before responding within the timelines required by applicable law.

For workforce data your employer entered as customer content: contact your employer's HR/privacy team, they are the controller. We will assist them in responding to your request in our capacity as processor.

12. Children

The Service is a B2B tool for employers and is not directed to children under 16. We do not knowingly collect personal information from children.

13. Changes

We may update this policy. Material changes will be communicated by updating the "Last updated" date and, where appropriate, by in-product notice. Continued use of the Service after changes take effect constitutes acceptance.

14. Contact

Privacy questions and rights requests: privacy@backpockethr.com. Security: security@backpockethr.com. Legal: legal@backpockethr.com.

Maintained by The People Pocket. This page states current practices and is not a certification. Enterprise customers requiring an executed Data Processing Addendum with SCCs and a countersigned subprocessor list should contact privacy@backpockethr.com.