Privacy Policy
Note: This is a courtesy translation. The German version (Datenschutzerklärung) is legally binding.
Note: Draft version during the closed pre-alpha. The full text will undergo legal review before the public beta.
1. Controller
Markus Thaier, Fischerweg 9, 5400 Hallein, Austria
Email: pouch@agentmail.to
2. The essentials in brief
- This website sets no cookies and no trackers, and loads no analytics scripts. Your light/dark choice and dismissed notices are remembered locally by your browser (localStorage) — these entries never leave your device and are not read by us. Only what you actively click is stored; simply visiting a page writes nothing.
- Your full Pouch file (memory, skills, projects) lives on your device. One exception, named here rather than hidden: if you create a recovery backup, the file is additionally stored encrypted on our server — openable only with your password, which we do not know (section 5). What you release for an AI chat goes to your chosen provider (e.g. ChatGPT or Claude) in readable form — that choice is yours alone, request by request.
- For the waitlist sign-up (waitlist) we store your email address encrypted and use it only for manual approval by us and to send your download link.
3. Hosting of this website
This website is served as a static site via Cloudflare Pages (Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA). On each visit, Cloudflare technically processes connection data required for delivery (IP address, timestamp, requested resource) to provide and secure the service. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in secure, performant delivery). Transfer to the USA is based on Standard Contractual Clauses and/or the EU-US Data Privacy Framework.
In addition, we increment a simple counter on our own server on every page view (anonymous reach measurement). No cookies are set, and no IP addresses or other identifiers are stored — there is no personal reference and no way to recognize individual visitors. Alongside the plain view count, we also record the language of the page viewed and a rough referral category (e.g. "via Discord") — still without cookies, IP storage, or recognition. If your browser sends the Do-Not-Track signal, the count is skipped. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in a rough overview of how this page is used).
4. Waitlist sign-up ("Become a tester")
Waitlist sign-up happens on a separate page, and you can choose between two routes:
- With your email address — you enter it and confirm with a code we send you. No third party is involved.
- With your Google account (Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland). We receive your verified email address from Google — and nothing else. This route loads a script from Google; it is the only external script on the entire site.
Both routes lead to the same result: we know your email address and process it for exactly one purpose — running the waiting list and granting access to the closed pre-alpha.
We also ask you eight questions — all of them optional. You can submit the form without answering a single one; they only help us decide who gets access next. We ask: how often and with which AI chat you work, which device you use, whether a web app would be an option for you, what you would use Pouch for, whether you know someone who would also like to test, whether you would send us feedback, and whether you are willing to install an app from outside the Play Store. Your answers are stored encrypted on the same server as your address and are read by us to decide who is next — they feed into no analysis and are not passed on.
Two of these questions are free-text fields. If you name another person there ("Do you know someone who would join?"), we process that entry solely in order to invite them — and you should ask them first. We never contact anyone unprompted if you leave the field empty.
- Storage: encrypted or as a cryptographic hash, on a server located in Austria. The daily backup of that database is additionally stored, encrypted, on Google Drive — readable only by us, kept for 30 days (section 5).
- Notifications: You receive transactional emails about your request (received, approved, or declined) — no advertising, no newsletter. Sent via AgentMail (USA, Standard Contractual Clauses).
- Analysis with AI: If you write to us, the text of your message may be analysed with a language model by Anthropic, or used to draft a reply. Only what you wrote is transmitted. If you would rather it were not, say so in the message and it stays between us.
- Legal basis: Art. 6(1)(b) GDPR (performing the beta program at your request).
- Retention: until the end of the beta program or until you request deletion; declined requests are deleted after 6 months at the latest.
5. The Pouch app
The app stores your dossier locally on your device — encrypted with a key that lives in the Android Keystore and never leaves the device. The relay service passes requests between your AI chat and your device and stores as little as possible; it accepts shares to friends, sensor answers and recovery backups only encrypted and rejects unencrypted content (the optional recovery backup can be decrypted only by you, with your password). The full privacy policy for the app is available in the app under Settings → Updates & help → Legal — at any time, in the version you agreed to.
Some metadata the service needs in order to work is not encrypted there: your email address and display name as the identifier of your account, the names of your CrewPouches along with membership and release level, the file names and types of attachments, the labels you give your AI connections yourself, the sender label on a share, name and email address in a friend request, the names you give binding codes for additional devices, and the sender details of a feedback report. Your facts, projects and skills are not among them — they never reach the relay service.
So that a hardware failure on our machine does not take your access with it, we back up the relay database off-site to Google Drive every day. The backup is encrypted before upload; only we hold the key, and Google cannot read the contents. What is backed up is the account data and metadata just described — not the contents of your dossier, which live on your device and never appear there. The copies are kept for 30 days: deletion takes effect in live operation immediately, but in the older backups only once that period has elapsed.
6. Friends feature and sensor permissions
In the app you can confirm other Pouch users as friends and grant them individual permissions — for example the right to query your device's battery level or location. These permissions can be granted as standing permissions, so that no individual confirmation is required for each query.
- The legal basis is your consent (Art. 6(1)(a) GDPR). You grant every permission yourself and can withdraw it at any time in the app; withdrawal takes effect for the future.
- Queries are only possible between mutually confirmed friends and only for the data types you have explicitly released to that friend.
- The requested value is encrypted on your device for the requesting friend. The relay service only passes it through and cannot read it. If the requester's key is not verified, nothing is sent at all.
- Entries marked secret are excluded from sharing — there is no way to send them along.
- In a CrewPouch your permission is time-limited: when contributing you set how long presence counts as consent. After that your device no longer answers by itself.
- If you share the location of a device that other people also use, you are deciding about their data too. Only grant such permissions with their knowledge.
7. Availability: questions instead of data
Since version 0.44 a connected AI chat can ask whether you have time at a given moment. The answer is yes, no or unclear — nothing else. Titles, locations, participants and notes of your events are never read in the first place, and the computation happens on your device only: no calendar query goes to any server, ours or anyone else's.
- The legal basis is your consent (Art. 6(1)(a) GDPR). The calendar permission is not requested during setup, only when such a question is actually asked.
- Without a calendar you selected, Pouch does not answer at all.
- Times are rounded to 15 minutes and the number of questions is capped — so your calendar cannot be reconstructed through many small questions.
- Stated honestly: even with these limits every answer reveals something. Far less than the calendar itself, but not nothing.
7z. Standing rules: decide once instead of every time
From version 0.47.4 you can grant a standing rule for these three kinds of question instead of confirming each one on your device.
- What a rule covers: one specific connection, one specific kind of question, an expiry date and a maximum count. Both are mandatory — there is no open-ended and no unlimited rule.
- What it never covers: anything that releases raw data (your location itself, a sensor reading), and any change to your dossier. For private and secret entries, on-device approval remains mandatory without exception.
- The legal basis is your consent (Art. 6(1)(a) GDPR). You can revoke a rule at any time; revocation takes effect immediately, even in the middle of an ongoing conversation.
- Traceable: every use of a rule is logged and counts against its maximum.
- To be honest: a rule is a convenience, not a blank cheque — but it moves a decision forward in time. Whoever draws it widely decides once for many cases they do not yet know.
7a. Budget: questions instead of your balance
From version 0.46.33 a connected AI chat can also ask whether an amount fits within a limit you set yourself. The answer is yes, no or unclear — nothing else. Pouch has no access to accounts, cards, banks or payment services: the limit is a number you enter in the app, and it stays encrypted on your device.
- The legal basis is your consent (Art. 6(1)(a) GDPR). Without a limit set, Pouch does not answer at all.
- The limit itself never leaves and cannot be found out — only yes/no/unclear along with the requested purpose goes out.
- Answers are rounded to money steps, and the number of questions is capped — so your limit cannot be narrowed down through many small questions.
- Stated honestly: ask often enough and you learn the rounding step your limit falls into. Not the amount itself.
7b. Places: questions instead of your location
From version 0.46.33 a connected AI chat can also ask whether you are currently at a place you saved yourself. The answer is yes, no or unclear — nothing else. A place is created by being there: there is no map and no address search, because both would send data to a third-party service. Everything is computed on your device.
- The legal basis is your consent (Art. 6(1)(a) GDPR). The location permission is not requested during setup, only when you save a place.
- Coordinates, radius and distance never leave and cannot be found out. The asker also cannot pass a radius of their own — otherwise your location could be narrowed down across several answers.
- At most eight places, and the number of questions is capped. If your location is too old or less accurate than the radius, the answer is unclear rather than a guess.
- Stated honestly: ask often enough over a day and a movement pattern emerges — not your location, but the sequence of "there" and "not there".
7c. Places for contacts: asking without locating
From version 0.47.4 you can ask a friend whether they are at a place — and they can ask you. The answer is yes, no or unclear, nothing else. The calculation happens exclusively on the device of the person being asked, against their own stored places.
- It is a separate permission. Someone who shared their location with you has not thereby allowed place questions, and someone who allows place questions does not release any coordinates. That is precisely the point: you can let someone know you have arrived without being located.
- Coordinates, distance and the other person's list of places never leave the device; even the place name in the answer is the one the asker supplied.
- The legal basis is the consent of both sides (Art. 6(1)(a) GDPR). The permission can be revoked in the app at any time, with effect for the future.
- The number of questions is limited twice over — per asking connection and per contact. An answer of “I do not know that place” counts too, otherwise the other person's list of places could be probed for free.
- To be honest: as with 7b, every answer reveals something — and unlike there, here it is another person it reveals something about.
8. Your rights
Under the GDPR you have the right to access, rectification, erasure, restriction of processing, data portability, and objection. Contact the email address above informally to exercise these rights. You also have the right to lodge a complaint with a supervisory authority; in Austria: Datenschutzbehörde, Barichgasse 40–42, 1030 Vienna, dsb.gv.at.
← Back to homepage