Privacy Policy
Last updated: September 17, 2026
1. Overview
poitoko consists of a web app, an iOS app and its extensions, a Chrome extension, and a
connector for AI assistants that support the Model Context Protocol (MCP). This policy covers
all of them.
2. What We Collect
Content you explicitly save:
- The selected text you choose to save
- The URL and title of the page where you saved it
- Page metadata: article title, author, and preview image, sourced from the page's meta tags
- Kindle highlights when you use the Kindle Sync feature
- Notes saved through an AI assistant you connect using MCP: the note text and optional link
the assistant sends when you ask it to save to poitoko, plus the assistant's name. We do not
receive the rest of your conversation.
Account data:
- Your email address and user ID, obtained at login via Google or Apple
- An authentication token, stored locally on your device
- For each AI assistant you connect: the assistant's registered name, the permissions you
approved, and when the connection was created and last used
Usage metadata attached to each save:
- Timestamp of when the highlight was saved
- How you saved it (context menu, keyboard shortcut, or button)
iOS app analytics:
- Product interactions, such as app lifecycle events, features opened, capture methods,
reading duration, search result counts, and notification or widget opens
- An internal poitoko account ID, a random app-installation ID, and internal content IDs used
to associate events with the correct account, installation, and feature
- App and device information, such as app version, build, operating system, device type,
screen dimensions, language, and whether the app is a debug build
- Coarse account attributes, such as plan, sign-up date, locale, notification status, digest
frequency, and a bucketed—not exact—count of saved fragments
3. What We Do NOT Collect
- We do not read or record pages you merely browse — the extension only accesses page content
when you actively trigger a save
- We do not track your browsing history
- We do not send saved quote text, memo text, or search queries to our analytics provider
- We disable GeoIP enrichment for analytics events and do not use analytics to derive precise
location
- We do not use analytics data for advertising or cross-app tracking
- We do not sell your data to third parties
4. How We Use Your Data
Your data is used solely to provide the poitoko service: storing and organizing your personal
highlights, powering search, and generating AI-assisted features when you request them.
To provide some of these features, your highlight text may be processed by third-party AI
services. This processing is used only to power poitoko features and is not used for
advertising or sold.
If you connect an AI assistant using MCP, it can send notes you ask it to save to your library.
The connector does not let the assistant search, read, or retrieve your saved fragments.
Notes saved this way are part of your library and can appear in search and your digests like
any other save.
We use iOS app analytics to understand whether features are useful, measure reliability and
engagement, identify content gaps, and improve poitoko. Analytics is not used to build
advertising profiles.
5. Third-Party Services
| Service | Purpose |
|---|
| Google Sign-In | Authentication |
| Apple Sign-In | Authentication |
| Third-party AI services | Powering search and AI features, processing your highlight text outside Japan |
| AI assistants you connect using MCP | Only after you connect one: sending notes you ask it to save. The connector does not
provide the assistant with search results or other saved content from your library |
| Product analytics provider | Processing iOS product analytics on our behalf in the United States |
6. Data Storage and Security
- Your data is stored on poitoko's servers
- Your authentication token is stored locally on your device
- Access tokens issued to connected AI assistants are stored on our servers only as hashes and
expire automatically; disconnecting an assistant stops its access immediately
- iOS analytics data is processed and stored by our analytics provider in the United States
under contractual data-protection terms
- Highlight text sent to third-party AI services is processed outside Japan under contractual
data-protection terms, and is not used to train those providers' models. We cannot identify
the destination country in advance, because these providers operate globally distributed
infrastructure and do not commit to a specific processing region for the service we use.
- We retain personal data only for as long as needed to provide, secure, and improve the
service, meet legal obligations, and resolve disputes
- When account deletion succeeds, we remove the account and user-owned data from active
poitoko systems. Limited records may be retained when needed for legal obligations,
security, fraud prevention, dispute resolution, or enforcement of our agreements; they are
deleted or anonymized when no longer needed
- Residual copies may remain temporarily in routine backups and system logs until they are
rotated out
- You can delete any saved highlight at any time from the poitoko web app
7. Permissions We Request and Why
| Permission | Why we need it |
|---|
| storage | Store your authentication token locally |
| activeTab | Access the current page when you trigger a save |
| scripting | Extract selected text and page metadata when you save |
| contextMenus | Add "Save to poitoko" to the right-click menu |
| notifications | Show save confirmation or error notifications |
| tabs | Detect if you have the poitoko web app open to retrieve your auth token |
| host_permissions: <all_urls> | Allow saving highlights from any website |
8. Your Rights
You may:
- Access all your saved data via the poitoko web app
- Delete individual highlights at any time
- Disconnect any AI assistant at any time from the AI assistants page in the poitoko web app,
or from the assistant's own connector settings
- Delete your account in the iOS app under Settings → Account Management → Delete Account;
this deletes your account and user-owned data from active poitoko systems
- Request a manual export of data associated with your account
- Request deletion of analytics data held separately by our analytics provider; deleting your
poitoko account does not delete those analytics records automatically
- Sign out at any time, which clears the locally stored token
For an export, analytics deletion, or account-deletion assistance when you cannot access the
iOS app, email hey@poitoko.com, preferably
from the address associated with your account. We will acknowledge your email within 5
business days, verify your identity if needed, and aim to complete a verified request within
30 days. We will confirm completion by email; if more time or information is required, we will
explain why and provide an updated timeframe.
9. Children's Privacy
poitoko is not directed at children under 13. We do not knowingly collect data from children.
10. Changes to This Policy
We will update this page if our data practices change. Continued use of the extension after
changes constitutes acceptance.