Legal
Privacy Policy
Last updated: August 8, 2026
Pocket Chief (“we”, “us”) is a product of Thrive Labs, Vancouver, BC, Canada. This policy explains what we collect, why, and the choices you have. The short version: we collect what the service needs to write and publish LinkedIn content on your behalf, we never sell your data, and nothing is ever posted without your explicit approval.
What we collect
- Account details — your name, email, and workspace settings.
- LinkedIn connection — when you connect LinkedIn, we receive your basic profile (name, photo, member ID, email) and an access token that lets us publish posts you approve. Tokens are encrypted at rest. We request only these permissions: sign-in (openid, profile, email) and posting on your behalf (w_member_social). We cannot read your messages, connections, or feed.
- Content you give us — voice notes, notes, previous posts you import (by paste or LinkedIn data export), source feeds you add, photos and videos you attach, and the drafts and posts created with you.
- Usage data — product events (drafts created, approvals, errors) used to operate and improve the service.
How we use it
- To build and maintain your voice profile so drafts sound like you.
- To transcribe your voice notes into text.
- To research topics and verify sources for your drafts.
- To publish posts to LinkedIn — only after you approve each one.
- To notify you (e.g., a draft is ready, a post went live, your LinkedIn connection needs renewal).
- To operate, secure, and improve the service.
We do not sell your personal information. We do not use your content to train models for other customers. Your voice profile serves you alone.
Service providers (subprocessors)
We use a small set of infrastructure providers to run Pocket Chief:
- Vercel (hosting) and Supabase (database, authentication, file storage)
- Anthropic (AI drafting) and Perplexity (research)
- AssemblyAI (voice-note transcription)
- Kie.ai (image generation, when you use AI images)
- LinkedIn (publishing, via its official API)
- Telegram or email (notifications, if you enable them)
Each receives only what its function requires (for example, AssemblyAI receives the audio of a voice note to return its transcript).
Storage, security, and retention
- Media, voice recordings, and reference photos live in private storage buckets, served only through short-lived signed links.
- LinkedIn tokens are encrypted at rest and are never exposed to your browser.
- We retain your data while your account is active. When you cancel, you may request an export; we delete your data — including LinkedIn tokens — within 30 days of a deletion request.
Your rights and choices
- Access, correct, export, or delete your data at any time by emailing us.
- Disconnect LinkedIn at any time — in the app, or from LinkedIn's side under Settings & Privacy → Data privacy → Other applications → Permitted services.
- Canadian residents: we handle personal information in line with PIPEDA. EU/EEA users: we honor GDPR access, portability, and erasure requests.
Contact
Questions or requests: suhaas@thrivelabs.ca. We'll reply within a few business days.