Privacy Policy
Effective date: October 8, 2026. Last updated: October 8, 2026.
Pokit Note is an iPhone app for to-do lists, shopping lists, notes, and recipes, built to work with your own AI assistant, with a companion website for managing your account. This Privacy Policy explains what information we collect, why we collect it, who we share it with, how long we keep it, and the choices and rights you have.
This policy applies to the Pokit Note iPhone app, the Pokit Note website at https://pokitnote.com, the Pokit Note MCP connector, and related services (together, the "Service"). It should be read together with our Terms of Service. The Service is offered only in the United States. Your lists, notes, and recipes live in the iPhone app; the website doesn't show or store them and is used only for signing in, your account, sessions, and password, assistant setup, support, and account deletion. There is no Pokit Note Android app.
Summary
- What we collect. Your account details (email address and a hashed password), the lists, notes, and recipes you create in the app, your signed-in sessions, things you share to Pokit Note from your iPhone (including your iPhone model name), your subscription status from Apple, support messages you send us, and technical data such as IP addresses used to run and protect the Service.
- Your assistant, your choice. If you connect an AI assistant (Grok Bot today; others coming soon), Pokit Note sends it the shares and change notices you choose and lets it read and edit your lists, notes, and recipes. Your assistant is a third-party service, and data sent to it is subject to that assistant's own terms and privacy policy.
- Short retention. Shared photos are deleted after 7 days; share records, assistant delivery logs, and server logs after 30 days; and "recently bought" items and stored support submissions after 90 days.
- Face ID stays on your phone. Face ID unlocks a sign-in key kept in your iPhone's Keychain. Nothing biometric leaves your phone.
- Apple handles payments. Subscriptions are purchased through the App Store. We receive only your subscription status, never your card number or other payment details.
- No ads, no analytics, no selling, no AI training. We don't show ads, use analytics or crash-reporting tools, sell personal information, share it for cross-context behavioral advertising, or use your data to train AI models.
- Delete anytime. You can delete your account in the app or on the website. Deletion from our live database is immediate and permanent; residual copies remain in database backups for up to 7 days and in server logs for up to 30 days.
1. Who We Are
The Service is operated by BotRelay LLC, a North Carolina limited liability company with its mailing address at 4030 Wake Forest Road, STE 349, Raleigh, NC 27609, USA ("BotRelay," "Pokit Note," "we," "us," or "our"). BotRelay LLC is responsible for the personal information described in this policy and is the "business" for purposes of U.S. state privacy laws.
If you have questions, contact us at support@botrelay.ai or through the form at https://pokitnote.com/support.
2. Information We Collect
2.1 Account Information
You create an account with your email address and a password. We don't ask for your name at signup. We store your password only as a one-way hash, never in readable form. Signing up requires you to confirm your email address by following a link we send you. If you don't confirm, the unconfirmed account is deleted within 3 days.
2.2 Your Content
We store the content you create in the Pokit Note iPhone app so we can keep it in your account and make it available to your connected assistant:
- lists (such as to-do lists and shopping lists) and list items;
- notes;
- recipes;
- "recently bought" items; and
- due dates and flags you add to items.
2.3 Sessions
Each phone or browser where you're signed in has a session. We keep a record of each session, including when it was last used and a label so you can recognize it: for a browser, the browser and operating system taken from its user agent; for the iPhone app, your phone model. You can view your sessions and sign any of them out on the website or in the app. Browser sessions last up to 14 days and end sooner after 24 hours of inactivity. Phone sessions expire after 60 days of inactivity.
2.4 Face ID
If you turn on Face ID in the iPhone app, Face ID unlocks a sign-in key stored in your iPhone's Keychain. Face ID is handled entirely on your device by Apple, and nothing biometric leaves your phone. We never receive, collect, or store your face data or any other biometric data.
2.6 Connected Assistant Settings and Delivery Log
If you connect an AI assistant, we store the webhook URL and optional authorization header you enter, the signing secret we issue for your webhook, your share and change-notice settings, and the authorization you approve for your assistant to use the Pokit Note MCP connector. We also keep a delivery log of the webhook messages (payloads) we send to your assistant, so we can retry failed deliveries and troubleshoot. See Sections 3 and 7.
2.7 Subscription Information
Pokit Note subscriptions are purchased through the Apple App Store, and Apple handles all billing. We receive only your subscription status (for example, whether you're in your free trial or have an active subscription, and when it renews or expires). We don't receive or store your card number or other payment details.
2.8 Support Form
If you contact us through the support form, we collect your name, email address, the topic, your message, and, if you choose to provide them, your device and app version. If you're signed in when you submit the form, we also attach your account ID and account email. Submissions are emailed to support@botrelay.ai.
2.9 Technical and Abuse-Protection Data
- Rate limits. To protect the Service from abuse, we count attempts by IP address for sign-in, signup, password reset, and the support form, and use these counts to apply rate limits. These counters are held in memory only and expire within 15 minutes to 24 hours.
- Server access logs. Our servers keep access logs that include the IP address, user agent, and URL of each request. Sign-in tokens and similar secrets are stripped from URLs before they are logged.
2.10 What We Don't Collect
We don't use analytics, crash-reporting, or advertising tools in the iPhone app or on the website, and we don't use advertising pixels or cross-app tracking. We don't buy personal information from data brokers.
3. Your Connected AI Assistant
The main feature of Pokit Note is working with your own AI assistant. Today you can connect Grok Bot; support for other assistants is coming soon. Your assistant is a third-party service. Connecting it is optional and fully under your control.
How you connect. Connecting an assistant has two steps:
- Webhook. You enter your assistant's webhook URL and, optionally, an authorization header. Pokit Note issues a signing secret your assistant can use to verify our messages. You can rotate the signing secret at any time.
- MCP connector. You approve your assistant's access to the Pokit Note MCP connector through an OAuth authorization screen.
What Pokit Note sends to your assistant. Pokit Note pushes these events to your assistant's webhook:
- Shares: links and photos you share from the iPhone share sheet, along with any optional note or prompt you add and your iPhone model name. You can turn off shares for each assistant.
- Change notices: notices when you change a list in the iPhone app. Change notices are sent only for changes made in the app. They include list titles and up to 10 item names. They never include note text, recipe steps, or quantities. You can switch off change notices for an individual list, note, or recipe, or turn them off entirely.
Shared photos. Your assistant receives a private link to a shared photo that expires after 1 hour. Anyone who has that link can open the photo during that hour, so treat it like a password. Until the photo is deleted from our storage after 7 days, your assistant can also fetch the photo, and new 1-hour links to it, through the Pokit Note MCP connector.
What your assistant can do. Your assistant can read and edit your lists, notes, and recipes through the Pokit Note MCP connector. It can do so only after you approve its access through an OAuth authorization screen.
Your assistant's own privacy policy applies. Once data is sent to your assistant or read by it, that data is handled by your assistant's provider and is subject to that assistant's own terms and privacy policy, not this one. We don't control, and aren't responsible for, how your assistant or its provider uses, stores, or shares that data. Please review your assistant's privacy policy before connecting it.
Not a sale. We send data to your assistant only at your direction. This is not a sale of personal information.
4. How We Use Information
We use information only to:
- Provide the Service. Create and maintain your account, store your lists, notes, and recipes for the iPhone app, check your subscription status, and deliver shares and change notices to your connected assistant at your direction.
- Keep your account and the Service secure. Confirm your email, manage sessions, apply rate limits, detect and prevent abuse, and investigate security issues.
- Send you service emails. For example, email confirmation, password reset, a notice when someone tried to sign up with your email address, and replies to support requests. These messages are part of the Service.
- Respond to you. Answer support requests and questions.
- Operate and fix the Service. Diagnose problems, such as failed deliveries to your assistant, using server logs and the assistant delivery log.
- Comply with the law and enforce our terms. Meet legal obligations, respond to lawful requests, and protect our rights and the rights and safety of our users and others.
We don't send marketing emails today. If we start, every marketing email will include an unsubscribe link, and opting out won't stop service emails.
We don't use your data to train artificial-intelligence or machine-learning models. Your connected assistant's provider may have its own practices, which are governed by its own terms and privacy policy.
7. How Long We Keep Information
- Account information and content (lists, list items, notes, recipes, due dates, and flags) are kept while your account is active, until you delete them or delete your account.
- Unconfirmed accounts. If you don't confirm your email address, the unconfirmed account is deleted within 3 days of signing up.
- "Recently bought" items are deleted automatically after 90 days.
- Sessions. Browser sessions last up to 14 days and end after 24 hours of inactivity. Phone sessions expire after 60 days of inactivity. You can sign out any session at any time.
- Share records for links and photos you share from your iPhone (including the URL, page title, iPhone model name, and your note) are deleted after 30 days.
- Shared photos are deleted from our storage after 7 days. Each private link given to your assistant expires after 1 hour; until the photo is deleted, your assistant can request new links through the MCP connector.
- Assistant delivery log. Webhook payloads we send to your assistant are kept for 30 days.
- Subscription status is kept while your account is active.
- Support requests. The copy of a support form submission that we store in the Service is deleted after 90 days, or immediately if you delete your account. Emails sent to support@botrelay.ai are kept only as long as needed to handle your request.
- Rate-limit counters are held in memory only and expire within 15 minutes to 24 hours.
- Server access logs (IP address, user agent, and URL, with sign-in tokens and similar secrets stripped) are kept for 30 days.
- Database backups may contain copies of your information for up to 7 days after it is deleted from our live database.
- "Why are you leaving" feedback, if you choose to give it when deleting your account, is stored without a link to your account. Because it's free text, it may contain personal information if you choose to write it.
We may also keep information longer when needed to comply with the law, resolve disputes, or enforce our agreements.
8. Deleting Your Account
You can delete your account at any time in the iPhone app or on the website. Deletion is immediate and permanent and can't be undone. When you delete your account, we immediately delete from our live database:
- your account information;
- your lists, notes, and recipes;
- your connected assistants and the access you granted them;
- your shares and shared photos;
- your sessions; and
- your support messages.
Copies of this information may remain in our database backups (DigitalOcean Managed Postgres) for up to 7 days and in our server logs for up to 30 days, until they are deleted in the normal course. We don't use these copies to restore deleted accounts.
When you delete your account, we may ask why you're leaving. Answering is optional. Any answer is stored without a link to your account, but because it's free text, it may contain personal information if you choose to include it.
Deleting your Pokit Note account doesn't cancel your App Store subscription; cancel it in your Apple ID settings. Deleting your account also doesn't delete data that was already sent to your connected assistant. To delete that data, contact your assistant's provider.
9. How We Protect Information
Measures include:
- storing passwords only as one-way hashes;
- requiring email confirmation at signup;
- encrypted connections (HTTPS/TLS);
- a secure, HttpOnly session cookie, session expiration, and the ability to view and sign out your sessions;
- rate limits on sign-in, signup, password reset, and the support form;
- stripping sign-in tokens and similar secrets from URLs before they are logged;
- optional Face ID lock in the iPhone app, which unlocks a sign-in key in your iPhone's Keychain, with nothing biometric leaving your phone;
- signing webhook messages to your assistant with a secret you can rotate;
- removing location and other metadata from shared photos, storing them in a private bucket, and giving your assistant only short-lived private links; and
- restricting access to production systems to authorized personnel.
No system is perfectly secure. If we learn of a security breach affecting your personal information, we'll notify you and the relevant authorities as required by law.
10. Where We Store and Process Data
The Service is offered only in the United States. BotRelay is based in the United States, and we store and process your information in the United States. Our servers and database are hosted by DigitalOcean in its NYC1 and NYC3 data centers in New York.
11. Your Rights and Choices
Depending on the state where you live, you may have some or all of these rights:
- Access and portability. Ask what personal information we hold about you and get a copy. Pokit Note doesn't offer a self-service export tool; to request a copy, contact us as described below.
- Correction. Ask us to correct inaccurate information.
- Deletion. Delete your account yourself in the app or on the website, or ask us to delete your personal information.
- Opt out of certain processing. Ask us to limit certain processing, or object to it, where your state's law gives you that right.
- Withdraw consent where we rely on consent, such as by turning off shares or change notices for your assistant.
- Opt out of sale, sharing, or targeted advertising. We don't do these, so there's nothing to opt out of, but you may still make a request.
- Appeal. If we decline your request, you can appeal by replying to our decision or emailing support@botrelay.ai with the subject "Privacy request appeal."
How to make a request. Email support@botrelay.ai from the address on your account with the subject "Privacy request," or use the form at https://pokitnote.com/support. We'll verify your identity, usually by confirming control of your account email. We'll respond within the time required by law (for example, within 45 days under the CCPA) and tell you if we need more time. You may use an authorized agent where the law allows; we'll ask for proof of their authority. We won't treat you differently for exercising your rights.
12. Additional Information For U.S. State Residents (Including California)
This section supplements the rest of this policy for residents of California and other U.S. states with comprehensive privacy laws.
Categories of personal information we collect (in the past 12 months, or since launch if less):
- Identifiers: email address, account ID, IP address, and your name if you give it in the support form. Disclosed for business purposes to: Google Workspace (email), our hosting provider (DigitalOcean), and your connected assistant at your direction.
- Customer records: email address, and support form details (name, topic, message, device and app version). Disclosed to: Google Workspace and our hosting provider (DigitalOcean).
- Commercial information: subscription status received from Apple. Disclosed to: our hosting provider (DigitalOcean).
- User content: lists and list items, notes, recipes, "recently bought" items, due dates and flags, shared links and notes, and shared photos (with location and other metadata removed). Disclosed to: our hosting provider (DigitalOcean) and your connected assistant at your direction.
- Internet or network activity and device information: session records (session labels showing browser and operating system or phone model, and last used), iPhone model name on shares, server access logs (IP address, user agent, and URL), the assistant delivery log, and in-memory rate-limit counters. Disclosed to: our hosting provider (DigitalOcean), and, for iPhone model name on shares, your connected assistant at your direction.
- Sensitive personal information: account login credentials (password stored only as a one-way hash). Disclosed to: our hosting provider (DigitalOcean), in hashed form only. We don't collect biometric data.
Sources: you and your devices, and Apple (subscription status). Purposes: as described in Section 4. Retention: as described in Section 7.
We don't sell personal information or share it for cross-context behavioral advertising, and we haven't done so in the past 12 months. Sending data to your connected assistant at your direction is not a sale. We don't knowingly collect, sell, or share the personal information of anyone under 18, including consumers under 16. We use sensitive personal information only to provide the Service and keep it secure, as permitted by law, so we don't offer a "limit the use of my sensitive personal information" option.
You have the rights described in Section 11, including the rights to know, delete, and correct, and the right not to be discriminated against for using them.
13. Children
The Service is intended only for adults 18 and older and is not directed to children or teens. We don't knowingly collect personal information from anyone under 18. If we learn that we've collected personal information from someone under 18, we'll delete the account and its data. If you believe someone under 18 has given us personal information, contact us at support@botrelay.ai.
14. Changes to This Policy
We may update this policy from time to time. We'll change the "Last updated" date at the top. If we make material changes, we'll notify you by email or through the Service at least 30 days before they take effect. We'll keep previous versions available on request.
15. Contact Us
Questions, requests, or concerns:
- Email: support@botrelay.ai (for privacy requests, use the subject "Privacy request")
- Support form: https://pokitnote.com/support
- Mail: BotRelay LLC, Attn: Privacy, 4030 Wake Forest Road, STE 349, Raleigh, NC 27609, USA