Data supports the workflow
Pokor stores account, session, vote, billing, and integration data needed to run the service.
What Pokor collects, where it goes, how long it stays, and the choices available to you. Last updated July 23, 2026.
Pokor stores account, session, vote, billing, and integration data needed to run the service.
Personal data is not sold or shared with third parties for their own marketing.
Analytics, connected integrations, browser push, and AI involve data only when enabled or triggered.
Access, export, correction, deletion, and other applicable privacy requests are supported.
This summary helps you find the relevant section. The full policy below controls if the summary and policy ever differ.
Pokor ("we", "us", "our") operates the planning poker service at pokor.dev. This policy explains what data we collect, how we use it, and your rights, including how anonymous session data is removed when you sign out.
When you sign in via email, Google, GitHub, Atlassian, Notion, Discord, or Microsoft, we receive and store:
We do not store passwords. Email sign-in uses a one-time confirmation code sent to your email address; the code is ephemeral and deleted after use or expiry. OAuth authentication is handled entirely by the respective provider (Google, GitHub, Atlassian, Notion, Discord, or Microsoft).
If you subscribe to our newsletter (on the landing page or via Settings → Notifications), we collect your email address and store your marketing opt-in preference. For registered users this preference is stored on your account; for guests it is stored only with Brevo (see Section 4). You can unsubscribe at any time from Settings → Notifications or via the unsubscribe link in any marketing email.
You can use Pokor without creating an account. When you choose a display name, we store:
If you sign out as an anonymous user, we clear the related cookies and delete the anonymous participation data linked to that token.
When you participate in planning sessions, we store:
If you create or join a team, we store the team name and settings, its membership (including the email addresses invited to it and who invited them), and a shared AI credit pool balance. Inviting someone sends an invitation email to the address entered; removing a member or deleting a team sends that person a notification email. Team admins can generate AI summaries and insights from the team's sessions — see Section 4 for what is sent to AI providers and how identities are anonymized.
Pokor offers optional AI features. We store an AI credit balance on your account (a monthly free allowance plus any credits you purchase) so we can meter usage. If you connect your own AI provider on the Organizer plan, we store your provider API key encrypted at rest until you disconnect it; we never display it again after you save it. What is sent to AI providers when you use these features is described in Section 4.
If you subscribe to the Organizer plan, payment processing is handled entirely by Stripe. We do not store your payment card information. We store:
If you use the Pokor Slack integration, we store:
This data is used solely to link Pokor sessions to the originating Slack workspace and channel.
If you use the Pokor Discord integration, we store:
This data is used solely to link Pokor sessions to the originating Discord server and channel.
If you connect your Notion workspace to Pokor, we access:
Notion data is fetched on demand when you use the import feature and is not continuously synced. Imported story titles, descriptions, and Notion page links are stored as part of your Pokor session data. If estimate write-back is enabled, Pokor can send the finalized estimate to a configured database property, a page comment, or both. You can disconnect Notion at any time from Settings, which revokes our access to your workspace.
If you connect GitHub to Pokor via the GitHub App, we access:
GitHub data is fetched on demand when you use the import feature and is not continuously synced. We store an encrypted access token and refresh token, plus your write-back preference. Imported issue titles, descriptions, labels, and GitHub issue links are stored as part of your Pokor session data. If estimate sync is enabled for a session, Pokor can write the finalized estimate back to the source issue as a comment, an estimate label, or both. You can disconnect GitHub at any time from Settings.
If you connect Jira to Pokor, we access:
Jira data is fetched on demand when you use the import feature and is not continuously synced. We store an encrypted access token, refresh token, selected Jira Cloud site identifier, and selected story points field ID. Imported issue summaries, descriptions, and Jira issue links are stored as part of your Pokor session data. If estimate sync is enabled for a session, Pokor writes numeric finalized estimates back to the configured Jira story points field. You can disconnect Jira at any time from Settings.
While you have a planning session open, your browser reports whether you are currently looking at it, so the rest of the room can see who is present and so we only send "voting started" notifications to people who aren't already watching. We store, against your participant record for that session:
"Away" is determined entirely inside your browser: it checks whether the tab is in the background and whether there has been any mouse or keyboard activity in the last few minutes. Only the resulting online/away/offline value is sent to us — we never receive what you type, what you click, or where you move your pointer. Nothing is recorded while you don't have a session open, no history of past states is kept, and the data is deleted with the participant record when you leave the session or it is removed.
Separately from session presence, we record a single last active timestamp on your account, so we can tell an account that is still in use from one that has been dormant. This is updated at most once per minute while you are signed in and using Pokor.
It is a timestamp and nothing else — we do not store which page you were on, what you clicked, or a history of past visits. Only the most recent value is kept, each update overwrites the last, and it is deleted along with the rest of your data when you delete your account. Leaving a session tab open in the background does not keep it fresh; it reflects deliberate use of the app.
When a session organizer removes or bans a participant, we store:
When a session requires join approval, pending requests are stored temporarily (up to 10 minutes) and include the applicant's display name, requested role, and IP address. This data is automatically deleted after the request is resolved or expires.
Our server automatically collects:
We use essential cookies to run Pokor. Optional analytics and external-widget cookies or scripts only load after you accept those categories in the cookie banner. You can change your choices from the Cookie Settings link in the footer.
| Cookie | Purpose | Duration |
|---|---|---|
| pokor_cookie_consent | Remembers your cookie consent choices (analytics, external widgets). Set on the parent domain so your preference is shared between landing and app. | 1 year |
| pokor_session | Keeps you signed in | 2 hours |
| XSRF-TOKEN | Security (prevents cross-site request forgery) | 2 hours |
| anonymous_token | Identifies anonymous users | 1 year |
| anonymous_name | Remembers your display name | 1 year |
| pokor_theme | Remembers light/dark theme preference | 1 year |
| pokor_a11y | Remembers your accessibility preferences (motion, contrast, link underline, text size) | 1 year |
| ph_* | PostHog analytics, only if analytics cookies are accepted | 1 year |
Browser push notifications (optional). If you turn on browser push notifications in your settings, your browser creates a push subscription tied to your device and registers a service worker. We store the resulting subscription (its endpoint URL and encryption keys) on our server so we can send you notifications — such as team invitations, new team sessions, and voting reminders — even when the Pokor tab is closed. You can turn this off at any time from your notification settings or your browser's site settings; doing so removes the stored subscription. See Section 4 for the push delivery services involved.
We use your data solely to provide and improve the planning poker service:
We do not sell or share your personal data with third parties for their own marketing purposes.
You can sign in with your email address using a one-time confirmation code. Pokor generates and verifies the code; our transactional email provider may deliver the message. Alternatively, you can sign in via:
We use Brevo for transactional messages such as one-time sign-in codes, billing notices, team invitations, and service emails. Brevo receives the email address and message content required to deliver each message. If you separately opt in to product updates or newsletters, Brevo also receives your name, plan tier, signup timestamp, and marketing subscription status. We do not send marketing email unless you opt in. For more details, see the Brevo Privacy Policy.
We use PostHog for product analytics to understand how the service is used. PostHog initializes only after analytics consent. When enabled, it collects usage data such as page views, feature interactions (e.g., session creation, voting), and basic device information. Data is processed in the EU. For more details, see the PostHog Privacy Policy.
We use Sentry to detect and diagnose errors. When an error occurs, Sentry may collect error details (stack traces, error messages), the request URL and method, browser and device information, and your user ID and email (if you are signed in). You may also be prompted to submit optional feedback when an error occurs. Data is processed in the EU. For more details, see the Sentry Privacy Policy.
We use Laravel Nightwatch to monitor application health and performance. Nightwatch collects request and response data, database query performance, background job execution, and application logs. This data is used solely to identify and resolve performance issues. For more details, see the Nightwatch Terms of Service.
Pokor offers an optional Slack integration that lets teams start planning poker sessions directly from Slack using the /pokor command. When you install the app, we store a bot access token (encrypted), workspace metadata, and channel/user identifiers to link sessions to your Slack workspace. For more details, see the Slack Privacy Policy.
Pokor offers an optional Discord integration that lets teams start planning poker sessions directly from Discord using the /pokor command. When the bot is added to your server, we store the server (guild) ID, channel identifiers, and the username of the session creator to link sessions to your Discord server. For more details, see the Discord Privacy Policy.
Pokor offers an optional Notion integration that lets you import stories from your Notion databases into a planning poker session and, if enabled, write finalized estimates to a configured database property, a page comment, or both. When you connect your Notion workspace, we store an encrypted access token, your workspace identifier, write-back mode, and any database property mappings you configure. During import, we read database and page data from databases shared with the integration. Imported content is stored as session stories. You can disconnect Notion at any time from Settings. For more details, see the Notion Privacy Policy.
Pokor offers an optional GitHub integration that lets you import issues from your GitHub repositories into a planning poker session and, if enabled, write finalized estimates back as issue comments or labels. When you install the Pokor GitHub App, we store an encrypted access token, refresh token, your GitHub user ID, and your write-back preference. During import, we read repository names and issue data from repositories where the app is installed. Imported content is stored as session stories. You can disconnect GitHub at any time from Settings. For more details, see the GitHub Privacy Statement.
Pokor offers an optional Jira integration that lets you import issues from your Jira projects into a planning poker session and, if enabled, write finalized numeric estimates back to the configured story points field. When you connect Jira, we store an encrypted access token, refresh token, the identifier of your selected Jira Cloud site, and the selected story points field ID. During import, we read project names and issue data from your connected site. Imported content is stored as session stories. You can disconnect Jira at any time from Settings. For more details, see the Atlassian Privacy Policy.
Payments for the Organizer plan are processed by Stripe. When you subscribe, Stripe receives your email address, name, and payment information. Stripe may set cookies for fraud prevention. We do not store your card details. For more details, see the Stripe Privacy Policy.
Pokor offers optional AI features (estimate suggestions, story enrichment, disagreement summaries, retrospective narratives, story explanations, AI-suggested story order, analytics insights, and session summaries). These run only when a session member explicitly triggers them — never automatically. The first time you use an AI feature we ask you to confirm, via a one-time consent prompt, that the relevant story text may be sent to our AI provider; you should avoid pasting passwords, API keys, or other secrets into stories or notes. When you use a hosted AI feature, the relevant content is sent through the Cloudflare AI Gateway to our AI model provider. Depending on the action, this may include a story title and description, the titles and descriptions of the session's stories (when suggesting an order), text from your own similar past stories, and vote rationales with confidence scores. Voter identities are anonymized (e.g. “Voter A”) before any votes are sent — display names are never transmitted. Retrospective narratives and session summaries also include anonymized per-voter votes, confidence scores, and notes; analytics insights send only aggregate statistics. Team admins can also generate cross-session summaries and per-member insights over their team's sessions; as with every other feature, member identities are anonymized (e.g. “Member A”) before anything is sent, and the real names are restored only locally for the admin. This data is used solely to generate the requested output and is not used to train third-party models. If you connect your own provider API key (Organizer plan), those requests go directly to the provider you chose (OpenAI, Anthropic, Google, or Grok) under their respective privacy policies. See the Cloudflare Privacy Policy.
When a team admin uploads a team logo, the cropped image is stored on Cloudflare R2 object storage and served from our content delivery domain so it can be shown across the app. Only the image you upload is stored; the file name is a content hash and carries no personal data. Removing the logo deletes the stored image. See the Cloudflare Privacy Policy.
If you enable browser push notifications, delivery is handled by the push service built into your browser and operating system — for example Google (FCM) for Chrome and Android, Mozilla for Firefox, Apple for Safari, or Microsoft for Edge. When we send a notification, that service receives the subscription endpoint for your device and the encrypted notification payload, which it relays to your browser. We do not choose or control which service your browser uses; it is determined by the browser and platform you run. This only happens if you have turned push notifications on.
The third-party services described above are used for authentication, analytics, error tracking, application monitoring, integrations, optional AI features, payments, and — if you opt in — push notification delivery.
You have the right to:
All connections to Pokor are encrypted via HTTPS/TLS. Session data is stored in a secured database. We do not store passwords. Secrets such as integration OAuth tokens and your bring-your-own AI provider API key are encrypted at rest.
We may update this policy from time to time. Changes will be posted on this page with an updated date.
If you have questions about this privacy policy or your data, please contact us at [email protected].
Essential cookies keep Pokor working. Optional analytics only load if you say yes. Privacy policy