Legal
Privacy Policy
Last updated: 1 July 2026
We built My Pookie for personal, emotional moments — so privacy is not optional. This policy explains what we collect, why, and what your rights are.
1. Data we collect
- Account: email, display name, avatar (via Google or email sign-up).
- Page content: titles, messages, images, audio, timeline entries you create.
- Payments: order records and Cashfree transaction IDs. We never see your card or UPI details.
- Usage: page views, visitor country (via IP header), device type. Aggregated only.
2. How we use it
- To run the service — store, render, and share your pages.
- To generate AI messages (Google Gemini via Lovable AI Gateway) and voice (ElevenLabs). Prompts are sent, results returned — providers do not retain your content for training.
- To send transactional emails (receipts, password reset, page notifications). No marketing emails without opt-in.
- To detect abuse and enforce our terms.
3. What we don't do
- We do not sell your data.
- We do not use your content to train AI models.
- We do not run third-party ad trackers on public pages.
4. Storage & security
Data is stored on Supabase infrastructure with row-level security. Media and audio live in private buckets accessed via signed URLs. Passwords for password-protected pages are hashed.
5. Your rights
- Access and export your data from your dashboard.
- Delete any page or your entire account — this permanently wipes content.
- Request a copy of everything we hold about you by emailing us.
6. Children
My Pookie is not intended for children under 13. If you believe a child under 13 has created an account, email us and we'll remove it.
7. Changes
We'll notify you before material changes take effect.
8. Contact
Privacy questions: privacy@mypookie.app