Poco / privacy policy

Privacy Policy

How Poco collects, uses, and protects your data. This complements the Security page, which explains the technical data flows.

Last updated: 14 July 2026

In short

  • We do not use your content to train AI models.
  • Your prompts, commands, and documents are compressed and dropped. If your organization turns content storage on, what is stored is deleted after 30 days.
  • Your data is stored and processed in the EU (AWS in Ireland).
  • We do not sell your data. We share it only with the providers that run Poco.
  • We keep your usage metadata for as long as your account is open, because your dashboard statistics are built from it. Ask us and we will delete your account and that data.

A summary, for orientation only. The full text below is what governs.

.01

Who we are

Poco ("Poco", "we", "us") provides a prompt-compression service for AI coding agents, available at thepoco.io. The service is operated by POCO AI LTD, 14 Charalambou Mouskou, Nicosia, Cyprus.

For privacy questions or to exercise your rights, contact us via the contact form at thepoco.io/contact.

.02

Information we collect

We collect the following categories of data:

  • Account data: your email and authentication identifiers, managed through our identity provider (AWS Cognito).
  • Content you submit: prompt text, shell commands and their output, documents, and session transcripts that the client sends to our server for compression and filtering. Retention of this content is governed by your organization's settings - see the Security page.
  • Usage metadata: project name, working directory, model, token counts, and the AI tools active in your sessions.
  • Local storage: a session token and your theme preference, stored in your browser (see the Cookie Policy).
  • Technical data: your IP address and basic request details (time, path, and response status), written to our server access logs. We use these to rate-limit requests and prevent abuse. The logs are deleted after 30 days.
  • Contact submissions: anything you send us through the contact form.
.03

How we use your data

  • To provide the service: compress prompts, filter commands, convert documents, and populate your dashboard.
  • To operate and secure accounts and authenticate requests.
  • To produce the usage and savings analytics shown in your dashboard.
  • To respond to support and contact requests.
  • To improve the service, using aggregated and de-identified usage information - see "Use of AI and automated processing" below. We do not use your content to train AI models.
.04

Use of AI and automated processing

Compressing your context is the core of what Poco does, and it is automated. When you submit a prompt - and, depending on your settings, commands, command output, and documents - that content is sent to our server and processed by automated systems to compress it, filter it, or convert it before it reaches your AI coding agent.

This processing is mechanical: it shortens and reshapes text. Poco does not use it to make decisions that produce legal or similarly significant effects about you.

To improve Poco and decide what to build, we may analyze aggregated and de-identified information about how the service is used, including patterns in the prompts and commands processed, to understand common scenarios and prioritize our work. We do not use the content you submit to train AI models. If we ever use identifiable submitted content for product development, we will update this policy and obtain consent where required.

.05

Legal bases for processing (EEA/UK)

Where the GDPR or UK GDPR applies, we rely on: performance of a contract (to deliver the service you signed up for), our legitimate interests (to secure and improve the service), your consent (for any non-essential cookies), and compliance with a legal obligation (where the law requires us to retain or disclose data).

.06

How we share data

We do not sell your data. We share it only with service providers that help us run Poco, under contract and only as needed:

We do not use an analytics or advertising provider today, and because Poco is currently free we do not use a payment processor. If either changes, we will name the provider here before it goes live.

  • Amazon Web Services (hosting, database, authentication, content delivery).
  • Authorities where required by law.
.07

Where we process your data

Poco runs on AWS in the eu-west-1 region (Ireland), inside the EU. Your account data, the content you submit, and your usage metadata are stored and processed there.

Our website is delivered through a content delivery network with edge locations in Europe and North America, so a request made from outside the EU may be served from an edge location outside the EEA, which handles the IP address of that request. Where personal data is transferred outside the EEA, we rely on the safeguards our providers have in place, including the European Commission's standard contractual clauses.

.08

Data retention

When content storage is enabled, stored prompts, commands, documents, and transcripts are deleted after 30 days. When it is off, content is processed and dropped, and only metadata and counts are retained.

Usage metadata - token counts, savings, and the project and model names attached to them - is what your dashboard statistics are built from, so we keep it for as long as your account is open, and your account data with it. If we did not, your savings history would disappear from under you.

You can ask us to delete your account at any time: contact us via the contact form and we will delete your account data and your usage metadata. We may keep records for longer where the law requires it.

.09

Your rights

Depending on where you live (e.g. under the GDPR or California's CCPA/CPRA), you may have the right to access, correct, delete, or export your data, to object to or restrict processing, and to opt out of any sale or sharing of personal information. To exercise these, contact us via the contact form at thepoco.io/contact. You also have the right to complain to your local data protection authority.

.10

Cookies and local storage

Poco uses only strictly necessary browser storage today (authentication and theme). If we enable analytics in the future, we will ask for your consent first. See the Cookie Policy for details.

.11

Payments

Not yet active

Poco is currently free. When paid plans launch, billing and payment-card data will be handled by our payment processor; we will update this policy to name the processor and describe what billing data we receive before any charge is taken.

.12

Data security

All data is transmitted over TLS and sent only to our server. For the full technical picture - what leaves your machine, what we keep, and the controls you have - see the Security page.

.13

Children

Poco is not directed to children and is not intended for anyone under 18. We do not knowingly collect data from children. If you believe a child has provided us with personal data, contact us and we will delete it.

.14

Changes to this policy

We may update this policy from time to time. Material changes will be reflected by the "Last updated" date above and, where appropriate, communicated to you.

Questions about this policy? Contact us.