Legal
Privacy Policy
What personal data Pogama handles, why, where it goes, how long it stays and what you can do about it.
Last updated:
This document was written to describe how Pogama actually works and to meet the laws of the EU, the United States and Uruguay. If something is unclear, write to soporte@pogama.xyz.
In short
- The desktop app is local-first: your projects, files, settings and API keys stay on your computer, and we don't have a copy. Your chats too — unless Chat sync is on, which keeps them in your Pogama account so they continue on the website and your other devices.
- When you send a message to an AI provider you chose (OpenAI, Anthropic, Google, a local model…), it goes from your device straight to that provider, under its own policy.
- If you have a Pogama account, we store what's needed to run it: your email, profile, licenses, and the things you choose to keep in the cloud (Work tasks, Teams messages, Client Hub and Cobros records — with client credentials encrypted on your device so we can't read them).
- Usage data (which features you use, errors) is only sent if you say yes, never includes your content, and can be turned off in Settings → Privacy.
- We don't sell or share your personal data for advertising, we don't use it to train AI models, and the website only uses cookies that are strictly necessary.
- You can access, correct, export or delete your data, and object to some uses, by writing to soporte@pogama.xyz.
1.Who we are
Pogama (the desktop app, the website pogama.xyz and the online services behind them) is owned and operated by GS Team 2026, which is the data controller ("responsible" under Uruguayan law) for the personal data described here. Pogama is developed under the Pocho.dev brand.
Contact for anything about privacy, including exercising your rights: soporte@pogama.xyz. Postal address: a postal address for formal notices is available on request at soporte@pogama.xyz.
We have not appointed a data protection officer, because we are not required to. Every privacy request is handled by the same team through the address above.
2.What this policy covers
This policy applies to the Pogama desktop app, the website pogama.xyz (including the account area and its chat), Pogama accounts, and the emails we send. Our Cookie Policy explains in detail what the website stores in your browser.
It does not cover services you connect yourself — AI providers, MCP servers, Git hosts, block explorers, music players or websites you open. Those receive data directly from your device and their own policies apply.
3.What we collect and where
Pogama is built so that as little as possible leaves your computer. Below, product by product, is what stays with you and what reaches us.
The desktop app, on your computer
Projects, files, chats and their history, agents, memory, knowledge, settings, your profile, captures and recordings, schedules, crypto wallet lists, Security Lab reports and the app's audit log are stored on your computer. API keys and passwords you save in Pogama are kept in your operating system's credential store; the interface can save them but never read them back. We cannot see any of this — except your chats while Chat sync is on (see “Synced chats” below).
AI providers and services you choose
When you send a message, the text and any files you attach go from your device directly to the provider and model you selected (Pogama asks before sending files to a cloud provider). Local models (such as Ollama or LM Studio) never send anything off your computer. These providers are not our subprocessors: you have your own relationship with them and their terms and privacy policies apply. The same goes for MCP servers, Git hosts and websites you connect, music players you load, and block explorers and price services the crypto feature reads public wallet addresses from (for example mempool.space, TronGrid, Blockscout and CoinGecko). Those requests come from your device, and the explorers see the public addresses you add.
Usage data (optional)
If you're signed in, Pogama asks once whether to share usage data. Nothing is sent before you answer, and nothing is sent if you say no or aren't signed in. If you agree, the app sends usage facts linked to your account: this device's installation ID, app version, operating system and processor type, language and a few settings (theme, space, reasoning level), when you use the app, which screens and commands you use, message counts, which provider answered, token counts and response times (the model name only for well-known providers), how many providers and projects you have, your plan, update progress, and error reports.
It never includes the text of your messages or answers, prompts, knowledge entries, Client Hub and Cobros data, attached or project files, file paths, API keys, or terminal commands and their output. Error reports are cleaned twice — on your device and again on our server — to remove quoted text, emails, links, paths and keys. You can turn usage data off at any time in Settings → Privacy; anything not yet sent is discarded.
Update checks
Unless you turn off automatic checks in Settings → Updates, the app asks our server whether a new version exists. The check carries the app version, operating system and processor type, update channel and a random update ID. It is not linked to your account, your files or your activity.
Your Pogama account
You need an account to use the desktop app and the website's account area (it's also what Work, Teams, Client Hub sync and licenses are tied to). We store your email address, your password (as a one-way hash managed by our authentication provider — we never see it), your display name, language and optional avatar, your email preferences, and security information about your sessions (sign-in times, the IP address and browser or device type recorded by our authentication provider).
Work and Teams
Tasks, workspaces, members and invitations you create in Work are stored on our servers so that the people you share them with can see them. In Teams we store your public username (if you choose one), friends and blocks, your privacy choices (presence, read receipts, who can contact you), and the messages, reactions, files and images you send in conversations. Those are visible to the other participants of each conversation — that is the purpose of the feature. Teams messages are not end-to-end encrypted: they are protected in transit and on our servers, and only participants can read them through the app.
Client Hub and Cobros sync (Pro)
Client Hub works offline on your computer and, when you're signed in with a Pro license, backs up and syncs your records (clients, contacts, services, domains, renewals, billing notes, documents, notes and activity) to your account, together with your Cobros finance records (accounts, categories and income and expense movements, with their amounts, dates, descriptions and links to your clients). Client credentials are sealed on your device with a key derived from a passphrase only you know, before they're uploaded; we cannot decrypt them, and if you forget the passphrase they can't be recovered on a new device. Every other Client Hub and Cobros record — finance records included — is not end-to-end encrypted: it's protected in transit, encrypted at rest on our servers, and guarded by access rules that only let your account read it. Cobros never stores bank passwords, PINs, card security codes or tokens.
Licenses and plans
When a license is issued to you we keep its plan, the installation it is bound to, the email it was issued to, its dates and a fingerprint of the signed license (not the license itself). Paid plans can't be purchased yet: there is no checkout and no payment provider. When that changes, this policy will say which payment provider receives your payment details and what we keep.
Invitation passes
If you invite someone or accept an invitation, we record the invitation, who invited whom, its status and any reward. To prevent abuse, an automatic score built only from account activity — never IP addresses or device fingerprints — can hold a reward for a person to review. The person you invite only sees your public Teams username, and only if you chose to show it.
The website chat
The chat in the website's account area is different from the app: here Pogama runs the model for you. Your message and the conversation so far are sent through our server to Anthropic (Claude) to produce the answer. That request isn't logged; we count how many messages and tokens you used each day, to apply your plan's daily limit. Anthropic processes the request in the United States and may retain inputs and outputs for a limited period under its commercial terms; it does not use them to train its models by default.
Your own keys and MCP servers on the website
In the website chat you can also use your own AI provider (for example Anthropic, OpenAI, Google Gemini, OpenRouter, or a model server on your own computer) and remote MCP servers. Their API keys and access tokens stay only in the memory of that browser tab: they're never stored in your browser or your account, never sent to our servers, never logged and never part of usage data, and they're forgotten when you reload, leave the chat page, close the tab or sign out. Your messages then go from your browser directly to that provider or server — not through Pogama — and their terms and privacy policies apply. Pogama asks you before every MCP tool call. Those conversations sync like any other chat while Chat sync is on (text only; tool inputs and outputs are never stored).
Synced chats
While Chat sync is on (the default; you can turn it off in Settings → Account in the app or on the website), your Chat and Co-Work conversations from the app and the website are stored in your Pogama account so they continue wherever you sign in. They're private to you — nobody else can read them through Pogama — protected in transit and encrypted at rest on our servers, but not end-to-end encrypted. What's stored is the conversation text (including the model's reasoning when the app shows it), the names and status of tools the AI used (never their input or output) and the names of attached files (never their contents). You can turn sync off at any time — nothing more is uploaded — and delete the cloud copy; each device keeps its own.
The website itself
Our hosting provider processes your IP address and standard request data (page, time, browser) to deliver the site and protect it from abuse. The website does not use advertising or third-party trackers. If enabled, it records anonymous product events (such as "download clicked") with no cookies and no identifiers, and not at all if your browser sends Do Not Track or Global Privacy Control. Details in the Cookie Policy.
Emails and support
We send account and security emails (sign-in codes, password changes, license notices) whenever needed. Product news and marketing emails follow your preferences (on by default, one click to turn off) — in Settings → Account → "Emails from Pogama". We keep a record of each email sent (template, status, dates) and delivery events, never the codes or tokens inside them. If you write to soporte@pogama.xyz, we keep your message and our replies to handle your request.
Staff access
A small number of Pogama staff can look at account information to provide support and keep the service safe, according to their role (least privilege). Every look at a person's data and every change is written to an internal audit log.
4.Why we use it and our legal bases
Under the GDPR and UK GDPR we must tell you the legal basis for each use. Under Uruguayan law, we process data with your consent or under its exceptions (such as data needed to perform a contract with you).
| Purpose | Data | Legal basis (GDPR Art. 6) |
|---|---|---|
| Create and run your account, sign you in, keep sessions secure | Account and session data | Contract (6(1)(b)) |
| Provide Work, Teams, Client Hub sync, licenses and the website chat | The data of each feature described above | Contract (6(1)(b)) |
| Understand usage and fix errors | Usage data and error reports | Consent (6(1)(a)) — asked once, withdraw anytime in Settings → Privacy |
| Offer updates and keep installed versions secure | Update checks | Legitimate interests (6(1)(f)) — you can turn automatic checks off |
| Account and security emails | Email address, language | Contract (6(1)(b)) |
| Product news emails | Email address, preferences | Legitimate interests (6(1)(f)) — opt out anytime |
| Marketing emails | Email address, preferences | Legitimate interests (6(1)(f)) — opt out anytime |
| Answer your messages and requests | What you send us | Contract or legitimate interests (6(1)(b), (f)) |
| Prevent abuse, fraud and attacks; enforce limits; staff audit log | Session data, request logs, counters, invitation signals | Legitimate interests (6(1)(f)) |
| Anonymous website events | Event name, page path, a few non-identifying values | Legitimate interests (6(1)(f)) |
| Meet legal obligations and defend legal claims | What the obligation or claim requires | Legal obligation (6(1)(c)) or legitimate interests (6(1)(f)) |
Where we rely on legitimate interests, they are running a secure, reliable product and telling our users about it, and we have checked that they don't override your rights. You can object at any time (see Your rights). Where we rely on consent, withdrawing it doesn't affect what was done before.
We do not use your content or personal data to train AI models. Pogama does not have its own models.
5.Who receives your data
We use a few service providers ("processors" or "subprocessors") who handle data only on our instructions and under data processing terms:
| Provider | What they do for us | Data involved | Where |
|---|---|---|---|
| Supabase, Inc. | Accounts and sign-in, database, file storage, server functions (website chat, emails, usage data, licenses, updates) | Account, Work, Teams, Client Hub, licenses, usage data, update checks, email records, support messages | The hosting region of our Supabase project (details on request); Supabase is a US company |
| Vercel, Inc. | Hosting and delivery of the website | IP address and request data of visitors | Global network; US company |
| Resend | Sending our emails and receiving mail sent to our support address | Email address, email content, delivery events, support messages | United States |
| Anthropic, PBC | AI model for the website chat only | Messages you send in the website chat | United States |
Other people also receive data when that is the point of a feature: members of your Work workspaces and Teams conversations see what you share there, and other users can see your public Teams username and online status according to your settings.
We may disclose data if the law requires it (for example a valid order from a court or authority), to protect the rights, safety or property of our users or others, or as part of a merger or acquisition — in which case this policy keeps applying to your data and we will tell you before it becomes subject to a different one.
The AI providers and services you connect yourself (see What we collect) receive data directly from you, not from us, and are not on this list.
6.International transfers
GS Team 2026 operates from Uruguay, a country the European Commission recognizes as providing an adequate level of data protection. Some of our providers are in the United States or process data in other countries.
When personal data from the EU/EEA, the UK or Uruguay is transferred to a country without an adequacy decision, we rely on the safeguards in our providers' data processing terms: the European Commission's Standard Contractual Clauses (and the UK Addendum), and, where a provider is certified, the EU–US Data Privacy Framework. For transfers from Uruguay, we rely on those contractual safeguards as permitted by Ley 18.331 (art. 23). You can ask us for a copy of the relevant safeguards at soporte@pogama.xyz.
7.How long we keep it
We keep personal data only as long as needed for the purposes above. Where we can't give a fixed period, we say what decides it.
| Data | How long |
|---|---|
| Data on your computer (desktop app) | Under your control: until you delete it. We never have a copy. |
| Account and profile | While your account exists. When you ask us to delete your account, we delete it and the data linked to it, except what is listed below. |
| Work tasks, Client Hub and Cobros records | Until you delete them or your account. |
| Teams messages and files | Until you delete them (the content is erased) or the conversation is deleted. If your account is deleted, messages you sent in conversations with others stay visible to them but are no longer linked to you, unless you deleted them first. |
| Usage data and error reports | 90 days, then deleted automatically. |
| Update checks | A pseudonymous record per installation (version, channel, platform, dates), kept while needed for release statistics. It is not linked to any account. |
| Website chat | Synced chats are kept until you delete them, delete the cloud copy, or delete your account. Daily usage counters are kept while your account exists. |
| Email records | Delivery events 90 days; records of the facts that triggered an email 180 days; records of sent emails 13 months. When an account is deleted its email address is removed from these records. Addresses that bounced or reported spam stay on a do-not-send list so they don't get mail again. |
| Support messages | As long as needed to handle your request and follow-ups, or until you ask us to delete them. |
| License records | As a record of licenses issued, including after account deletion (a license keeps working offline until it expires). We'll tell you what we must keep when you ask us to delete your data. |
| Staff audit log | Kept as a security record of who accessed or changed what. It stores ids and the parameters of each action. |
| Website request logs | Kept by our hosting provider for a short period under its own retention for security and reliability. |
We may keep data longer when the law requires it or to establish, exercise or defend legal claims, and only for that purpose.
8.Your rights
Wherever you live, you can ask us to tell you what personal data we have about you, give you a copy, correct it, or delete it. Your local law may give you more rights, described below. Using them is free, and we won't treat you differently for doing so.
EU, EEA and United Kingdom
- Access your data and get a copy (Art. 15).
- Rectify inaccurate data (Art. 16).
- Erasure ("right to be forgotten") (Art. 17).
- Restrict processing (Art. 18).
- Data portability — receive the data you gave us in a structured, machine-readable format (Art. 20).
- Object to processing based on legitimate interests, and to direct marketing at any time (Art. 21).
- Withdraw consent at any time, without affecting earlier processing (Art. 7(3)).
- Lodge a complaint with a supervisory authority, in particular where you live or work — see the list of EU authorities, or the ICO in the UK. We'd appreciate the chance to address your concern first.
Uruguay (Ley 18.331 and Decreto 414/009)
- Access: know what data about you we hold, free of charge, at intervals of six months unless you show a legitimate interest to ask sooner (art. 14).
- Rectification, update, inclusion and suppression of your data (art. 15).
- Information about the purpose of the processing and its recipients (art. 13).
- We answer access requests within 5 business days, and rectification, update, inclusion or suppression requests within 5 business days (arts. 14 and 15).
- If we refuse or don't answer in time, you can file a complaint with the Unidad Reguladora y de Control de Datos Personales (URCDP) or bring a habeas data action.
California and other US states
If you live in California, Virginia, Colorado, Connecticut, Utah, Texas, Oregon or another US state with a consumer privacy law, you have — depending on your state — the right to:
- Know and access the personal information we collect, use and disclose, and get a portable copy.
- Correct inaccurate personal information.
- Delete personal information we collected from you.
- Opt out of the sale or sharing of personal information, targeted advertising and profiling with significant effects — we do none of these (see below).
- Limit the use of sensitive personal information — we only use it to provide the service, as the law allows.
- Not be discriminated against for exercising your rights.
- Appeal our decision on your request: reply to our answer asking for an appeal. If we deny the appeal, you can contact your state's Attorney General.
We honor these rights for all US residents, whether or not a given state law applies to us.
How to exercise them
Write to soporte@pogama.xyz, preferably from the email address of your Pogama account, and tell us what you want. To protect you, we confirm your identity before acting — usually by replying to your account's email address, or by asking for a code we send there — and we ask only for what we need to do that. In California you can use an authorized agent; we'll ask for your signed permission and may confirm your identity directly with you. Data on your computer is already in your hands: you can export or delete it from the app (Settings → Storage & backup).
When we answer
- EU/EEA and UK: within one month; up to two more months for complex or numerous requests, and we'll tell you within the first month if so.
- California and other US states: we confirm receipt within 10 business days and answer within 45 days; up to 45 more days when reasonably necessary, and we'll tell you if so. Appeals are answered within the period your state's law sets.
- Uruguay: within 5 business days (see above).
If you're in more than one of these situations, we apply the shortest period.
9.US state privacy notice (notice at collection)
This table describes, using the categories of the California Consumer Privacy Act, the personal information we have collected in the last 12 months. Sources: you, your device (usage data and update checks, if enabled) and other users (for example someone inviting you to a workspace). Retention is described in How long we keep it.
| Category | Examples | Purposes | Disclosed to |
|---|---|---|---|
| Identifiers | Email address, account ID, installation ID, public Teams username, IP address | Account, security, support, features you use | Our service providers |
| Customer records | Name you choose, email address | Account, support, emails | Our service providers |
| Commercial information | Plan and licenses | Licenses and plan limits | Our service providers |
| Internet or network activity | Usage data (if you agree), session and request logs | Improving and securing the service | Our service providers |
| Audio, visual or similar | Avatar, images and files you share in Teams | Providing Teams | Our service providers; the participants you share with |
| Professional information | Client Hub and Cobros records you choose to sync | Providing Client Hub sync on your behalf | Our service providers |
| Sensitive personal information | Account login (email and password) | Only to sign you in and secure your account | Our service providers |
We do not collect precise geolocation, and we do not draw inferences to build a profile about you.
10.No selling, no sharing, no advertising
We do not sell personal information, and we do not "share" it for cross-context behavioral advertising, as those terms are defined in US state laws. We have not done so in the last 12 months. We do not show ads, use advertising trackers, or let third parties track you across sites. We have no actual knowledge of selling or sharing data of anyone under 16.
Because of that, there is nothing to opt out of — but if your browser sends a Global Privacy Control signal, we treat it as a valid opt-out request, and our website stops its anonymous events too.
11.Automated decisions
We don't make decisions based solely on automated processing that produce legal effects on you or similarly significantly affect you (GDPR Art. 22).
Some automatic checks do run: daily limits in the website chat, rate limits that stop spam and abuse, and the invitation-pass abuse score that can hold a reward for a person to review. If you think one of them affected you wrongly, write to soporte@pogama.xyz and a person will look at it.
12.Children
Pogama is not directed to children. You must be at least 16 years old to create an account, everywhere in the world. We do not knowingly collect personal data from children under 16 (including children under 13 as defined by the US COPPA). If you believe a child has given us personal data, write to soporte@pogama.xyz and we'll delete it.
13.How we protect your data
No system is perfectly secure, but we design for it from the start. Among the measures in place:
- Local-first design: most of your data never leaves your computer.
- API keys and passwords in the app live in your operating system's credential store; the interface can't read them back, and they are only sent to the site they belong to.
- Client Hub credentials are encrypted on your device before syncing; we cannot decrypt them.
- Provider keys and MCP tokens you use on the website stay in that browser tab's memory, are only sent to the address they were entered for, and never reach our servers.
- Encrypted connections (HTTPS/TLS) between the app, the website and our servers.
- Database access rules that let each account read only its own data, and server functions that check your session and permissions on every request.
- Passwords stored only as one-way hashes by our authentication provider.
- Usage data and error reports cleaned of content on your device and again on the server.
- Staff access by role (least privilege), with every access to personal data recorded in an audit log.
- Signed licenses and signed app updates, verified on your device.
If a personal data breach is likely to put your rights at risk, we will notify the competent authority and, where required, you, within the periods the law sets. To report a security issue, write to soporte@pogama.xyz.
14.Data you store about other people
If you keep information about other people in Pogama — for example your clients in Client Hub, or members you invite to Work or Teams — you decide why and how it is used. For the copy that syncs to your account, we act as your processor (service provider): we store it only to provide the feature to you. You are responsible for having a lawful basis to keep it and for answering those people's requests; we'll help you if you need us to.
15.Changes to this policy
When we change this policy, we update the date at the top. If a change materially affects how we use your data, we'll announce it in advance in the app's What's new and, for account holders, by email. Where the law requires your consent to a change, we'll ask for it.
16.Contact
Questions, requests or complaints about privacy: soporte@pogama.xyz. We answer in English or Spanish.
Data controller: GS Team 2026. Postal address: a postal address for formal notices is available on request at soporte@pogama.xyz.