Will Pokor store another password?
Passwordless account access
Sign in with a one-time email code or an approved OAuth provider. One-time codes expire, while OAuth tokens and connected AI keys are encrypted at rest.
Planning data should not disappear into a black box. Here is how Pokor handles access, connected backlogs, optional AI requests, payments, and retention.
Each answer names the control and points to the policy or evidence behind it. For procurement documents and service status, use the trust center.
Will Pokor store another password?
Sign in with a one-time email code or an approved OAuth provider. One-time codes expire, while OAuth tokens and connected AI keys are encrypted at rest.
Can Pokor charge or see a card directly?
Stripe handles subscription and AI-credit payments. Pokor stores the billing identifiers and lifecycle records it needs, not card numbers, CVCs, or bank details.
Does every integration receive broad access?
Connected tools use provider-approved OAuth scopes. Content enters a room when someone imports it, and estimate write-back runs only when an organizer configures it.
Is data encrypted?
Connections use TLS. Sensitive integration tokens and connected AI-provider keys are encrypted at rest.
Pokor connects the planning room to the tools your team already uses. Import and write-back actions remain deliberate rather than becoming an invisible background sync.
Bring selected backlog items into a session. When the organizer enables and configures it, finalized estimates can be written back to supported source fields.
The browser parses the file first. Only the rows selected for import are sent to Pokor.
The bots respond where a team invokes the Pokor command; they do not silently read every conversation in a workspace or server.
An eligible signed-in participant or organizer must explicitly trigger an AI action. Story explanation and session summary are available to eligible signed-in participants; estimate suggestions and disagreement analysis remain organizer-controlled.
Only the content required for that action is sent to the model provider. Voter identities are anonymized before vote data leaves the browser. Hosted AI traffic goes through Cloudflare AI Gateway and is not used to train third-party models.
Organizer customers can connect an OpenAI, Anthropic, Google, or Grok API key. That key is encrypted at rest and requests then go directly to the selected provider under its terms.
Review AI data handling in the privacy policyEphemeral state such as pending join requests expires automatically after 10 minutes.
Guest participation uses a random token, not an email account. Signing out removes the guest cookie and data associated with that token.
Pokor application infrastructure is hosted in Europe, and connections are encrypted in transit with TLS.
We prefer specific, reviewable claims. The trust center brings the supporting documents and live service evidence together.
Privacy policy
Collected data, third-party services, retention, and user rights.
Read the privacy policyData Processing Addendum
GDPR processor obligations, subprocessors, transfers, and notification terms.
Download the DPASend the details to [email protected]. We review every report.
Essential cookies keep Pokor working. Optional analytics only load if you say yes. Privacy policy