1. Who is responsible for data
Pomlet is responsible for the data it processes to operate the website, accounts, subscriptions, security, support and product. For quizzes, classroom games, employee training, participant answers and organization content, the customer, host, school, employer or organization may also be responsible for deciding what data is collected and why. In those cases, Pomlet may act as a service provider or processor where applicable law recognizes that role.
Privacy questions and rights requests may be sent to support@pomlet.com.
2. Data we collect
Depending on how you use Pomlet, we may collect:
- account data: name, email address, password hash, email verification status, login method and plan;
- authentication and session data: session tokens, device identifiers, account identifiers, reset tokens and verification tokens;
- quiz content: titles, descriptions, questions, answers, explanations, settings, themes, folders, images and slide content;
- whiteboard content: names, backgrounds, sticky notes, text, shapes, connectors, drawings, positions, votes and snapshots needed for persistence and synchronization;
- collaboration and access data: whiteboard and session identifiers, owner, admin, editor or viewer roles, guest links, email invitations, presence and contributions;
- AI input data: prompts, instructions, source URLs and extracted document or PDF text submitted for AI quiz generation;
- AI output data: generated quiz titles, descriptions, questions, answers, explanations and image search keywords;
- organization data: organization name, roles, members, invitations, license assignments and billing status;
- MCP data: authorized OAuth clients, client identifiers, granted permissions, authorized organization, connections, timestamps and action logs for Pomlet objects;
- player data: game PIN, nickname, answers, score, rank, streak, team, connection state and game progress;
- reports: session summaries, player names, question statistics, answer distributions and scores;
- billing data: customer identifiers, subscription identifiers, plan, seat count, payment status, invoice status and billing portal events from our payment provider;
- communications: emails, support requests, legal notices, feedback and related metadata;
- technical data: IP address, request metadata, browser/device information, timestamps, security logs, rate-limit records and error information.
Pomlet does not intentionally store full payment card numbers. Card details are handled by the payment provider. For AI PDF generation, the browser extracts text from the PDF. Pomlet intends to transmit and process extracted text, not to store the original PDF file as a server-side upload for that feature.
3. How we use data
We use data to:
- provide, maintain, secure and improve Pomlet;
- create accounts, verify emails, authenticate users and prevent abuse;
- store, edit, organize, launch, share, embed and display sessions, quizzes and whiteboards;
- synchronize real-time collaboration, apply roles and access settings, store contributions and create related reports;
- operate live and self-paced sessions, teams and elimination modes, leaderboards, QR codes and reports;
- process AI quiz generation requests and return generated quiz drafts;
- manage organizations, members, roles, invitations, seats and licenses;
- process subscriptions, renewals, prorations, cancellations, invoices and billing support;
- send transactional emails, account notices, security messages, invitations and billing confirmations;
- monitor service health, enforce limits, detect fraud, prevent attacks and comply with law;
- respond to support, privacy, legal and abuse requests.
4. Legal bases
Where laws such as the GDPR, UK GDPR, Swiss FADP or similar rules apply, we rely on legal bases that may include contract performance, legitimate interests, consent, compliance with legal obligations and, where applicable, the instructions of a customer acting as controller.
Examples: account and subscription processing are generally needed to perform a contract; security logging and abuse prevention are based on legitimate interests and legal obligations; marketing or optional cookies, if introduced, would rely on consent where required.
5. AI features and OpenRouter
If you use AI features, you instruct Pomlet to send relevant prompts, instructions, source material and extracted document text to OpenRouter, which routes the request to third-party model endpoints. Those providers process data under their own systems, policies and contractual terms.
Separately, the remote Model Context Protocol (MCP) server lets you authorize an external client you control (for example Cursor, Codex or Claude Code) to create and manage Pomlet content through structured tools. Pomlet processes the OAuth identifiers, permissions, authorized organization and action logs needed to secure those actions. You remain responsible for what the client sends, reviewing created content and revoking MCP connections from your account. Access and rate limits apply.
Pomlet does not control the independent retention, abuse monitoring, security or policy decisions of AI providers. You are responsible for ensuring that you have the right to send the content to an AI provider and that the content is appropriate for AI processing. Do not submit trade secrets, confidential documents, personal data, student records, health data, financial data, regulated data or other sensitive information unless you are authorized and accept the third-party processing risk.
As of the date above, Pomlet configures OpenRouter calls to use only endpoints that declare Zero Data Retention (ZDR), so prompts and outputs are not retained after processing on those endpoints. Provider policies can change, and OpenRouter's ZDR documentation is available at OpenRouter's Zero Data Retention docs.
AI output is stored in Pomlet as quiz content until you delete it or your account is deleted. Source text used for AI generation is not intentionally stored as a separate source document after generation, but it may appear in generated questions, answers, explanations, logs, provider systems or support/security records.
6. Sharing and disclosure
We may share data with:
- service providers that help us host, process, secure, email, bill, support or operate Pomlet;
- AI providers when you use AI generation features;
- payment providers for checkout, subscriptions, invoices, fraud prevention and billing support;
- image providers when you search or import public images, or when AI-generated cover keywords are used to find cover images;
- organization admins and members according to their workspace role and access rights;
- participants and collaborators according to the session mode, whiteboard role and settings;
- anyone who can access an embed, public PIN, QR code, whiteboard guest link or shared page that you publish;
- law enforcement, regulators, courts, advisors or other parties where legally required or needed to protect rights, safety and security;
- successors in connection with a merger, acquisition, financing, reorganization or sale of assets.
Where data lives and who processes it. As of the date above, Pomlet runs on Cloudflare Workers. Core relational data (accounts, quizzes, reports, organizations, affiliate attribution and ledger records, and durable snapshots) is stored in Cloudflare D1; uploaded images and other media in Cloudflare R2; and active game and collaborative-whiteboard state in Cloudflare Durable Objects. Cloudflare may also process technical logs through Workers Observability and, when enabled, usage data through Cloudflare Web Analytics.
Depending on the features you use, Resend processes email delivery, Stripe processes payments, subscriptions and Stripe Connect payout accounts, subscriptions, Google processes Google sign-in, OpenRouter (and the model endpoints it routes to) processes AI-generation requests and Pixabay processes image searches and imports. Card details are entered and processed by Stripe and are not stored by Pomlet. Affiliate bank details, identity documents and verification data are also processed by Stripe; Pomlet stores only the connected-account identifier and status. These providers may operate infrastructure in multiple countries, so Pomlet does not promise a single storage country unless separately agreed by contract. You may contact support@pomlet.com for the current provider list and available location information.
7. Retention
We keep data for as long as reasonably necessary for the purposes described in this Policy, including to provide the service, maintain accounts, comply with law, resolve disputes, enforce agreements, maintain security and keep business records.
- Account data is generally kept while the account exists.
- Sessions expire automatically according to their validity period; revoked sessions and revoked devices are purged no later than 30 days afterwards.
- Sessions, quizzes, whiteboards, images and organization content are kept until deleted by an authorized user or account deletion process.
- Session and whiteboard reports are kept until deleted by an authorized user or account deletion process.
- Billing records may be retained as needed for accounting, tax, fraud prevention and legal compliance.
- Security logs and the technical webhook ledger are purged after 30 days; rate-limit counters are removed when their window expires.
- MCP authorizations are kept until revocation, expiry or account deletion. MCP idempotency responses are purged after 24 hours and MCP action logs after 90 days.
- Uploads that are never saved are deleted after about 24 hours. Abandoned game state is removed no later than 48 hours; a removed image may remain for up to 72 hours when an active game still uses it and while the next daily cleanup is pending.
8. International processing
Pomlet and its providers may process data in countries other than where you live. Those countries may have different data protection laws. Where required, we use appropriate safeguards such as contractual commitments, transfer mechanisms or provider terms.
9. Your rights
Depending on your location and role, you may have rights to access, correct, delete, restrict, object to or port personal data, withdraw consent and complain to a supervisory authority. You may also have rights to opt out of certain processing.
To exercise rights, contact support@pomlet.com. We may need to verify your identity and may direct player, student or employee requests to the relevant host, school, employer or organization where they control the data.
10. Children and students
Pomlet is not intended for children to create accounts without appropriate authorization. Players can join games without accounts, but hosts should avoid collecting unnecessary personal information from minors. Schools, teachers and organizations are responsible for obtaining any required notices, consents, approvals or data processing terms before using Pomlet with children or students.
11. Security
We use reasonable technical and organizational measures designed to protect data. No internet service is completely secure. You are responsible for using strong passwords, limiting who receives game PINs and embeds, managing organization roles and avoiding unnecessary sensitive content.
12. Cookies and local storage
Pomlet uses necessary cookies and browser storage to keep users signed in, remember player names for a game, maintain demo return paths and operate the service. See the Cookie Policy for details.
13. Changes
We may update this Privacy Policy as the product, providers, laws or practices change. The updated date above shows when the page was last changed. Continued use of Pomlet after an update means the updated Policy applies.