Introduction
MachFlow, Inc. dba Pomo ("Pomo", "we", "us", or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website https://usepomo.ai and use our services (collectively, the "Services").
We reserve the right to make changes to this Privacy Policy at any time and for any reason. We will alert you about any changes by updating the "Last Updated" date of this Privacy Policy. Any changes or modifications will be effective immediately upon posting the updated Privacy Policy on our website, and you waive the right to receive specific notice of each such change or modification.
You are encouraged to periodically review this Privacy Policy to stay informed of updates. You will be deemed to have been made aware of, will be subject to, and will be deemed to have accepted the changes in any revised Privacy Policy by your continued use of the Services after the date such revised Privacy Policy is posted.
Information We Collect
Personal Data
Personally identifiable information, such as your name, email address, telephone number, and demographic information that you voluntarily give to us when you register with the Services or when you choose to participate in various activities related to the Services. You are under no obligation to provide us with personal information of any kind, however your refusal to do so may prevent you from using certain features of the Services.
Derivative Data
Information our servers automatically collect when you access the Services, such as your IP address, browser type, operating system, access times, and the pages you have viewed directly before and after accessing the Services.
Data From Social Networks
User information from social networking sites, such as Facebook, Google+, Instagram, Pinterest, Twitter, including your name, social network username, location, gender, birth date, email address, profile picture, and public data for contacts, if you connect your account to such social networks. This information may also include the contact information of anyone you invite to use and/or join the Services.
Generated Content
We may collect information about the content you create, upload, or receive from others when using our Services. This includes the prompts you provide to our AI tools, the responses generated, and any feedback you provide about the quality of these responses.
Use of Your Information
Having accurate information about you permits us to provide you with a smooth, efficient, and customized experience. Specifically, we may use information collected about you via the Services to:
- Create and manage your account
- Deliver targeted advertising, newsletters, and other information regarding promotions to you
- Email you regarding your account or order
- Enable user-to-user communications
- Generate a personal profile about you to make future visits to the Services more personalized
- Increase the efficiency and operation of the Services
- Monitor and analyze usage and trends to improve your experience with the Services
- Notify you of updates to the Services
- Offer new products, services, features, and/or recommendations to you
- Perform other business activities as needed
- Process payments and refunds
- Prevent fraudulent transactions, monitor against theft, and protect against criminal activity
- Request feedback and contact you about your use of the Services
- Resolve disputes and troubleshoot problems
- Respond to product and customer service requests
- Solicit support for the Services
- Improve and train our AI models using aggregated, de-identified data derived from your interactions, subject to any restrictions in your service agreement. This does not include raw, aggregated, anonymized, or derived Google Workspace API data, or any content or data received from Slack (see Slack Integration), or any data received from Shopify (see Shopify Integration)
Disclosure of Your Information
We may share information we have collected about you in certain situations. Your information may be disclosed as follows:
By Law or to Protect Rights
If we believe the release of information about you is necessary to respond to legal process, to investigate or remedy potential violations of our policies, or to protect the rights, property, and safety of others, we may share your information as permitted or required by any applicable law, rule, or regulation. This includes exchanging information with other entities for fraud protection and credit risk reduction.
Third-Party Service Providers
We may share your information with third parties that perform services for us or on our behalf, including payment processing, data analysis, email delivery, hosting services, customer service, and marketing assistance.
Marketing Communications
With your consent, or with an opportunity for you to withdraw consent, we may share your information with third parties for marketing purposes, as permitted by law.
Interactions with Other Users
If you interact with other users of the Services, those users may see your name, profile photo, and descriptions of your activity.
Online Postings
When you post comments, contributions or other content to the Services, your posts may be viewed by all users and may be publicly distributed outside the Services in perpetuity.
Business Transfers
We may share or transfer your information in connection with, or during negotiations of, any merger, sale of company assets, financing, or acquisition of all or a portion of our business to another company.
Affiliates
We may share your information with our affiliates, in which case we will require those affiliates to honor this Privacy Policy. Affiliates include our parent company and any subsidiaries, joint venture partners or other companies that we control or that are under common control with us.
Connected AI Assistants
You may connect a third-party AI assistant you use (for example Claude, ChatGPT or Codex) to Pomo through our Model Context Protocol (MCP) connector. When you do, Pomo shares data only from the company profiles you select on the consent screen, and only within the permissions you approve there. The assistant's provider receives the results Pomo returns for the requests you make in that assistant, and handles them under its own privacy policy. Pomo receives the requests the assistant sends on your behalf and the arguments they carry; Pomo does not otherwise receive your conversation with the assistant.
Every request is recorded in the profile's activity history, visible to the connecting user and to the profile's administrators, without storing request arguments or provider credentials in that history. Actions that change something in Pomo require your confirmation in the assistant or in Pomo. You can disconnect an assistant at any time from the profile's MCP connections settings in Pomo or from the assistant itself; disconnecting revokes its access immediately. If the data permissions a connection covers change, the connection stops until you consent again. A profile administrator can disable assistant access for the whole profile.
Images and video that Pomo generates while drafting a campaign or a post are saved to your Asset Library in Pomo as part of that draft. A connected assistant receives a reduced-size preview and a link to the saved file that expires after one hour, not a standing copy of the original; the original stays in your Asset Library.
Results an assistant requests can include information about people found through marketing research. See People Found Through Marketing Research for where that information comes from and how those people can have it removed.
People Found Through Marketing Research (Prospects, Journalists and Creators)
Pomo's customers are businesses. They use Pomo to plan outreach to other businesses, to the press and to creators. To do that, Pomo processes information about people who are not Pomo customers and have no account with us. This section explains what we hold about those people, where it comes from, why it is used, who receives it, how long it is kept, and how any of them can have it removed. If you are one of these people, you do not need a Pomo account to use the removal route below.
Who This Covers and What We Hold
- Business contacts (growth leads). People who hold a role at a company a customer wants to reach. We hold the person's name, job title and employer, the company's location, a link to a public professional profile or company page (for example a LinkedIn profile address or a team page), a short quoted excerpt from the public page that states the role together with that page's address, and the reason the customer's search matched. Where a customer asked for it inside Pomo, we also hold a work email address at the employer's domain and a record of how it was checked. An outreach email the customer drafts to the person is stored with the record.
- Journalists, editors and outlets. For a customer's PR story we hold the outlet, the subject area it covers, and the contact route the outlet itself publishes. That route can be a newsroom or tips address, a submission form, or a named journalist or editor with their published role, professional email address or author page. We also hold the address of the page where the route appears and a pitch the customer drafts.
- Creators and influencers. Public profile information for Instagram, TikTok and YouTube accounts: handle, display name, profile link, bio, profile picture, country, follower and engagement figures, recent public posts, and contact routes the creator has published for business enquiries (for example an email address in a bio, a link-in-bio page, a website contact page or a management contact). We also hold outreach messages a customer drafts to the creator.
- Authors of public social posts (social prospects). For public Reddit, Instagram and TikTok posts and comments that match topics a customer follows, we hold the author's handle, display name, profile link and public bio, the text of the post or comment and its link, and a reply the customer drafts. Posts whose author says they are under 18 are left out.
Where It Comes From
- Business contacts. Public web pages found by a web search that runs when a customer asks for it, such as company websites, team pages, press releases and public professional profiles. The search is carried out through OpenAI's search-enabled model, and Pomo then retrieves the cited company and role pages itself to check that the quoted text is on them. Pomo rejects results from people-search and contact-database sites. The search does not collect a person's email address or phone number, and quoted text that contains one is rejected. When a customer asks for a work email address inside Pomo, Pomo sends the person's name, employer and the employer's web domain to Hunter (hunter.io), an email-finding service, and keeps an address only when Hunter reports it as valid with a confidence score of at least 80, the address is at the employer's domain, it is not a shared mailbox such as info@ or sales@, and the name matches.
- Journalists and outlets. Public web pages found by web search through an AI model provider's search feature: outlet mastheads, staff and author pages, contact pages, submission guidelines and published articles. Pomo keeps only contact routes the outlet itself publishes for press, tips or submissions, records the page each one came from, and does not guess or construct email addresses.
- Creators. The creator's public profile on Instagram, TikTok or YouTube, found by web search and read through Apify, a service that retrieves public profile pages, together with public pages the profile links to, such as a link-in-bio page or the creator's own website. Pomo also keeps an index of creator profiles that it uses to recommend creators for a customer's influencer campaign.
- Social prospects. Public posts and comments returned by third-party data services for Reddit, TikTok and Instagram, for the keywords a customer sets.
Why It Is Used
The information is used so that a customer can decide which companies, outlets and creators are relevant to its business, see the public evidence behind each suggestion, and prepare a business-to-business outreach message, a press pitch or a creator partnership proposal. Pomo does not contact these people on its own initiative. The customer decides whether to contact someone and is responsible for its own outreach. An email to a saved business contact is sent from the customer's own connected mailbox after the customer has reviewed and approved that message.
Legal Basis and Your Right to Object
Where data protection law requires a legal basis, for example under the GDPR and the UK GDPR, Pomo and its customers rely on legitimate interests: the customer's interest in business-to-business outreach, press relations and creator partnerships, and Pomo's interest in providing the tools for that work. We balance those interests against yours by limiting research to information published for professional or public purposes, recording the source of each item, and offering the removal route below. You have the right to object to this processing at any time, and you do not have to give a reason.
If you live in a US state with a consumer privacy law, such as California, you can use the same route to ask what personal information we hold about you and to have it deleted or corrected. We will not treat you differently for making a request.
Who Receives It
- The customer workspace whose research found the information, and an AI assistant that customer has connected, when the customer asks the assistant for it (see Connected AI Assistants). Creator profile records can be used to answer creator searches from any Pomo customer. Business contact, journalist and social prospect records are visible only to the customer workspace whose research produced them.
- Service providers that carry out the research and drafting for us: the AI model providers Pomo uses (depending on the request and our configuration, these may include OpenAI, Anthropic and Google), Hunter for work email lookups, Apify and the social data services for public profiles and posts, Databricks for the creator index, and our hosting providers.
How Long We Keep It
- Business contact research that a customer does not save is deleted automatically 30 days after the search last ran.
- Saved business contacts, PR contact lists, creator shortlists and social prospects have no automatic expiry. They are kept in the customer's workspace while that customer's account is active, or until they are removed on request.
- Pomo's own creator profile records are kept until they are removed on request.
How to Be Removed
Email [email protected], or follow the instructions for people who are not Pomo customers on our data deletion page. There is no charge and you do not need a Pomo account. Please include:
- your name;
- what we should look for: the work email address, employer, outlet, or social handle and profile link that identifies you;
- if someone contacted you using Pomo, a copy of the message or the sender's name, so we can find the workspace it came from;
- whether you also want a copy of what we hold about you.
When we receive a request, we:
- confirm it comes from you or someone acting for you, for example by asking you to reply from the address concerned. We use what you send only to handle the request;
- search Pomo's records for the identifiers you gave us;
- delete the matching records Pomo holds: business contact research and saved contacts with their draft emails, PR contact entries, creator records with their saved contact details, and social prospect entries, including copies saved in customer workspaces on Pomo;
- reply within 30 days to say what we deleted or that we found nothing.
Removal deletes what Pomo holds. It does not change the public pages the information came from, and it does not reach a message already delivered to you or data held by the third-party services named above. If a Pomo customer has emailed you, you can also reply to that sender and ask them to stop. Pomo does not currently keep a permanent do-not-contact list, so a later search could find the same public information again. If that happens, tell us and we will delete it again.
Google Workspace API Data and Limited Use
The use of raw or derived user data received from Google Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements.
Gmail Send-Only Access
Pomo requests only the Gmail send scope
(https://www.googleapis.com/auth/gmail.send). Pomo uses this permission solely to send
a message that you compose and approve in Pomo. It does not permit Pomo to read, modify, or manage
your Gmail mailbox, messages, drafts, contacts, or other Google Workspace content. After delivery,
Gmail returns a message identifier, which Pomo does not retain. Pomo does not access Google Photos
API data.
Artificial Intelligence and Machine Learning
Pomo does not send Google Workspace API data to third-party AI/ML providers or use it to create, train, fine-tune, or improve foundational or generalized AI/ML models.
Pomo does not use content or data received from Slack to create, train, fine-tune, or improve AI models. See Slack Integration for how Slack content is processed.
Pomo does not use data received from Shopify to create, train, fine-tune, or improve AI models. See Shopify Integration for how Shopify data is processed.
Shopify Integration
If you install the Pomo AI app on your Shopify store, Pomo reads your store's product catalog so it can prepare marketing for your products. This section describes what Pomo receives from Shopify, why we use it, how long we keep it, and how it is deleted.
What We Receive From Shopify
- Store details. Your store's name, its myshopify.com and primary domains, the store contact email, currency, time zone, Shopify plan name, and the country and region of the store address.
- Product catalog. Product titles, descriptions, types, vendors, handles, status and publication dates, product images, and variant titles, SKUs, prices and inventory quantities. The app is granted read-only access to products, inventory and store locations.
- Your Pomo AI subscription. The plan, trial and status of the subscription you choose in Shopify. Shopify bills the subscription; Pomo does not receive your payment details.
Pomo does not request access to your store's orders, customers or checkouts and does not read your customers' information from your store. When Shopify forwards a privacy request from one of your customers, the request includes that customer's identifiers, such as their email address and phone number. We keep them only to fulfill and record that request; for a deletion request they are removed once the deletion is carried out. Pomo cannot change your store.
Why We Use It
We use this data to connect your store to your Pomo company profile, to import and keep your product catalog up to date within your plan's product limit, to prepare the marketing work you ask for, and to check which plan you have chosen.
AI Processing
To prepare the work you ask for, Pomo sends the relevant product and store information to the AI model providers it uses, under those providers' API terms for business customers. Depending on the request and our configuration, these may include OpenAI, Anthropic, Google (Gemini), and models served through Databricks. Pomo uses Shopify data only to produce results for you and does not use it to create, train, fine-tune, or improve AI models.
How Long We Keep It
We keep the store details and imported catalog while the app is installed and your Pomo account is active. Marketing work you create in Pomo stays in your account like any other Pomo work.
Deletion
When you uninstall the app, Pomo stops accessing your store and removes its access token as soon as Shopify notifies Pomo. Shopify then asks Pomo to delete your store's data 48 hours after the uninstall. Pomo then removes the store's connection details automatically, and our privacy team deletes the store details and imported catalog and completes the request within 30 days. If Shopify forwards a request from one of your customers to view or delete their data, our privacy team responds within 30 days. You or your customers can also contact us about Shopify data at [email protected].
Slack Integration
If your Slack workspace installs the Pomo app for Slack, you can ask Pomo questions and give it work by mentioning it in a channel or by sending it a direct message. If an administrator turns it on, Pomo can also send some messages on its own (see below). This section describes what Pomo receives from Slack, what it sends there, why we use it, how long we keep it, and how it is deleted.
What We Receive From Slack
- Messages addressed to Pomo. The text of a message that mentions Pomo or is sent to it as a direct message, together with the Slack identifiers of the workspace, channel, thread, message, and sender. Pomo receives channel messages only when it is mentioned, together with the thread that mention is in (next item).
- The thread a mention is in. When Pomo is mentioned inside a thread, it reads the earlier messages of that thread (up to fifteen messages people wrote, plus the message that opened the thread) so it can understand what the request refers to. A later mention in the same thread reads the opening message and what was written since the previous one. Pomo does not read a thread it is not mentioned in.
- Files attached to a mention. Images are added to your company's Asset Library in Pomo, and documents are stored as attachments of the Pomo conversation for that thread. Files of other types are not stored, and the thread is told they were skipped. An image you have already placed in a campaign or other work in Pomo stays with that work.
- Who you are. Your Slack user ID and username, and the work email address on your Slack profile, which we look up to match you to your Pomo account. Pomo checks that the sender is allowed to use that company profile before it answers. If Pomo's own messages are turned on, Pomo also reads the time zone on your Slack profile so a morning summary arrives during your working day.
- Direct-message sessions. When you open Pomo's Messages tab, rename a session or press Stop, Slack tells Pomo so it can show suggested prompts, keep the session's title in step with your Pomo conversation, and stop the work in progress. Pomo sends Slack a session title taken from the beginning of your first message, and the session's status.
- Reactions and button clicks on Pomo's messages. A thumbs-up on an update you asked for (see below) is recorded only as an acknowledgement; it never approves anything. Reactions on Pomo's other messages are not recorded. Buttons on Pomo's cards (for example Approve, Reject or Cancel work) act only for a person Pomo has matched to their Pomo account and who is allowed to make that decision.
- Workspace and channel settings. The workspace ID and name, the channels an administrator has pinned to a company profile, and the access token Slack issues to the app, which is stored encrypted.
Pomo does not answer in Slack Connect channels or in channels shared with other workspaces or organizations, and does not read those threads.
Messages Pomo Sends On Its Own
These are off until an owner or administrator of your Pomo organization turns on "Let Pomo post on its own in this workspace" for a company profile, and they can be turned off there at any time. When it is on, Pomo can send:
- Decision cards. When a decision or an approval is waiting in Pomo, a card in the direct messages of the people who can decide, with buttons to decide from Slack. While the channel the administrator chose is still pinned to the company profile, the card is also posted there (visible to everyone in that channel); otherwise it goes to direct messages only.
- Account alerts. When a data connection or an ad account stops working, a direct message to the organization's owners and administrators, and a message in the chosen channel while it is still pinned to the company profile.
- A morning summary. On workdays, a direct message listing what is waiting on you and work that finished since the last summary, sent only when there is something to list. You can stop it from the message.
- Finished work. A direct message when work you started from Slack finishes later. You can stop these from the message.
- Updates you asked for. If you ask Pomo to keep you posted about a piece of work and choose Slack, a direct message to you with what changed or what it suggests next.
Why We Use It
We use this information to answer your request, to continue the conversation in the same thread, to match the Slack user to their Pomo account and permissions, to run and report on the work you ask Pomo to do, and to send the messages an administrator has turned on.
AI Processing
To answer a request, Pomo sends the message, the thread context, and any attached files to the AI model providers it uses to generate the answer, under those providers' API terms for business customers. Depending on the request and our configuration, these may include OpenAI, Anthropic, Google (Gemini), and models served through Databricks. Pomo does not use content or data received from Slack to create, train, fine-tune, or improve AI models.
How Long We Keep It
- The conversation Pomo holds with you in a thread or direct message, including your messages, Pomo's answers, and attached files, is kept while your Pomo account and the workspace's connection to Pomo are active, like any other Pomo conversation.
- Thread messages read for a request are kept only as part of that request's processing record and are removed from it 72 hours after the work completes.
- Records of inbound Slack events, which we keep only so the same event is not processed twice, contain identifiers and timestamps but not the message, and are deleted after 72 hours.
- The job and delivery records used to process a request and post the answer are reduced to non-identifying status records 72 hours after the work completes; their Slack content and identifiers are removed.
- Identity links, channel pins, and the workspace's access token are kept while the workspace is connected to Pomo.
- Records of decision cards, account alerts, morning summaries and finished-work messages (what the message was about, whom it went to, and where it was posted in Slack) are kept while the matter is open and deleted 90 days after it closes.
- An update you asked for is part of your Pomo conversation and is kept like it. The record of its Slack delivery, including the message text and where it was posted, is reduced to a non-identifying status record 72 hours after delivery finishes.
Deletion
Uninstalling the Pomo app from your Slack workspace or revoking its token in Slack deletes, as soon as Slack notifies Pomo, the Slack-derived data of every company profile connected to that workspace: the Slack conversations with their messages and attached files, the identity links, the channel pins, pending deliveries, Slack-related notifications and settings, Pomo's record of where its own messages were posted in Slack (their buttons stop working; the messages themselves stay in Slack), scheduled morning summaries, and the app's access token. Disconnecting Slack from a company profile in Pomo, or deleting that profile, deletes the same data for that profile immediately; other company profiles connected to the same workspace keep theirs, and the app's access token is removed once no company profile remains connected. An image from Slack that you had already placed in a campaign or other work in Pomo stays with that work. A person can also ask us to delete data about them by emailing [email protected]. Messages already posted in Slack, including Pomo's answers, remain in your workspace under Slack's own retention settings.
Security of Your Information
We use administrative, technical, and physical security measures to help protect your personal information. While we have taken reasonable steps to secure the personal information you provide to us, please be aware that despite our efforts, no security measures are perfect or impenetrable, and no method of data transmission can be guaranteed against any interception or other type of misuse. Any information disclosed online is vulnerable to interception and misuse by unauthorized parties. Therefore, we cannot guarantee complete security if you provide personal information.
Data Retention and Storage
We store your information on infrastructure located in the United States, operated by us and by the third-party service providers described above. If you access the Services from outside the United States, your information is transferred to and processed there.
We retain personal information for as long as your account is active and as needed to provide the Services to you, and thereafter only as long as necessary for the purposes described in this Privacy Policy. In particular:
- Account, company profile and marketing data you create in Pomo is retained while your account is active. When you terminate your account or ask us to delete your data, we delete or de-identify it from our active systems within a reasonable period, except where we must keep it to comply with law, resolve disputes, prevent fraud or enforce our agreements.
- Access credentials for connected platforms and AI assistants are deleted or invalidated when you disconnect the integration or terminate your account.
- Security, audit and activity records, including the activity history of connected AI assistants, are retained for a limited period for security, troubleshooting and compliance purposes and then deleted.
- Backups are retained for a limited period on a rolling schedule and are overwritten as that schedule advances.
- Aggregated or de-identified data that no longer identifies you may be retained for analytics and service improvement.
To request deletion of your data, see our data deletion instructions or contact us using the information below. If you are not a Pomo customer and were found through a customer's marketing research, see How to Be Removed.
Policy for Children
We do not knowingly solicit information from or market to children under the age of 13. If you become aware of any data we have collected from children under age 13, please contact us using the contact information provided below.
California Privacy Rights
California Civil Code Section 1798.83, also known as the "Shine The Light" law, permits our users who are California residents to request and obtain from us, once a year and free of charge, information about categories of personal information (if any) we disclosed to third parties for direct marketing purposes and the names and addresses of all third parties with which we shared personal information in the immediately preceding calendar year. If you are a California resident and would like to make such a request, please submit your request in writing to us using the contact information provided below.
If you are under 18 years of age, reside in California, and have a registered account with the Services, you have the right to request removal of unwanted data that you publicly post on the Services. To request removal of such data, please contact us using the contact information provided below, and include the email address associated with your account and a statement that you reside in California. We will make sure the data is not publicly displayed on the Services, but please be aware that the data may not be completely or comprehensively removed from our systems.
Options Regarding Your Information
Account Information
You may at any time review or change the information in your account or terminate your account by:
- Logging into your account settings and updating your account
- Contacting us using the contact information provided below
Upon your request to terminate your account, we will deactivate or delete your account and information from our active databases. However, some information may be retained in our files to prevent fraud, troubleshoot problems, assist with any investigations, enforce our Terms of Use and/or comply with legal requirements.
Emails and Communications
If you no longer wish to receive correspondence, emails, or other communications from us, you may opt-out by:
- Noting your preferences at the time you register your account with the Services
- Logging into your account settings and updating your preferences
- Contacting us using the contact information provided below
If you no longer wish to receive correspondence, emails, or other communications from third parties, you are responsible for contacting the third party directly.
Users in India
If you are located in India or your use of the Services involves the personal data of individuals located in India, the following applies: (a) with respect to Authorized User account data, billing data, usage telemetry, fraud prevention data, security logs, and aggregated data, Pomo acts as a Data Fiduciary and processes such data in accordance with this Privacy Policy; (b) with respect to personal data that Pomo processes on a customer's behalf in connection with the Services, Pomo acts as a Data Processor and the customer is the Data Fiduciary, as further described in the applicable service agreement; (c) personal data may be transferred to and stored in the United States; and (d) for grievances or inquiries relating to the personal data of Indian data principals processed by Pomo as a Data Fiduciary, contact us at [email protected]. For personal data processed by Pomo as a Data Processor on behalf of a customer, data principals should contact the customer directly as the Data Fiduciary. This section will be updated to reflect the requirements of the Digital Personal Data Protection Act, 2023 as its provisions come into force.
Contact Us
If you have questions or comments about this Privacy Policy, please contact us at:
Email: [email protected]
Address:
MachFlow, Inc. dba Pomo
2261 Market Street STE 85781
San Francisco, CA 94114
United States