Legal

Pockt Privacy Policy

Effective 2026-06-09, last updated 2026-06-09

1. Who we are

Pockt is a service operated by AYEYE IO LTD (trading as "Pockt"), a company registered in England and Wales under company number 05113299, with its registered office at Millhouse, 32-38 East Street, Rochford, Essex SS4 1DB ("Pockt", "we", "us", or "our").

For the personal data described in this policy, AYEYE IO LTD is the data controller. This policy explains what personal data we collect, how and why we use it, who we share it with, how long we keep it, and the rights you have under the UK GDPR and the Data Protection Act 2018.

If you have any question about this policy or want to exercise your rights, contact us at simon.jennings@ayeye.io.

We are registered with the UK Information Commissioner's Office (ICO) under registration number ZB226962.

2. Scope

This policy covers personal data we process when you visit pockt.studio, create an account, and use the Pockt application and its features (Pipelines, collections, the Inbox, Drop In, Backstage, Brand, Media, and Settings). It does not cover third-party websites or platforms you connect to or publish to, which have their own privacy policies.

3. The personal data we collect

3.1. Account data. When you register, we collect your name, email address, and either a password (stored only as a secure hash, never in plain text) or, if you sign in with Google, the basic profile and email information Google provides.

3.2. Workspace and billing data. Your workspace name; your plan and billing period; your Credit balance and Credit transaction history; and payment records (the amount, currency, VAT, the associated Stripe invoice or charge identifiers, and invoice links). We do not store your full card number - card details are entered directly with our payment processor, Stripe, and we never see or hold them.

3.3. Content you submit and generate. The reference photos you upload, and the images, videos, audio, and other Output the Services generate from them, together with collections, capsules, tags, captions, and related metadata about your Content. The AI models Pockt generates for casting are synthetic and do not depict real people, and the Looks and Collections you create use only the clothing and attire from the photos you upload, not the face or identity of anyone shown in them. A reference photo you upload may nonetheless contain a real, identifiable person, in which case that uploaded image is personal data that we handle as described in this policy.

3.4. Usage and technical data. Job and step logs, administrative audit logs, error reports, performance traces, device and browser information, IP address, and similar technical data generated when you use the Services.

3.5. Error and diagnostic data. When the Services encounter an error, we use Sentry to capture the error and basic technical context (such as the type of error, the page involved, and device/browser information) so we can fix it and keep the Services reliable and secure.

3.6. Communications. Messages you send us (for example support or abuse reports) and our replies.

We do not intentionally collect special-category data (such as health, biometric, or financial-account data). You must not submit such data as Input except where expressly permitted and where you have a lawful basis.

4. How we use your data, and our legal bases

PurposeLegal basis (UK GDPR)
Create and administer your account; provide the Services; run Pipelines and produce Output; process your ContentPerformance of our contract with you (Art. 6(1)(b))
Take payment, manage Subscriptions, Credits, top-ups, refunds, and renewalsPerformance of our contract; compliance with a legal obligation (tax/accounting)
Keep the Services secure, prevent abuse, run content-safety and moderation checks, investigate incidentsOur legitimate interests in operating a safe, lawful service (Art. 6(1)(f)); compliance with legal obligations
Monitor errors and performance to keep the Services secure and reliable, and improve them using aggregated/anonymised operational dataOur legitimate interests in a secure, reliable service (Art. 6(1)(f))
Send service and transactional emails (e.g. password resets, billing notices)Performance of our contract
Send marketing or product updates (if any)Your consent, which you may withdraw at any time
Comply with legal obligations and respond to lawful requestsCompliance with a legal obligation (Art. 6(1)(c))

We do not use your Input to train publicly released foundation AI models, and we require our providers not to do so where such controls are available. We may use aggregated, anonymised, or pseudonymised operational data to operate, secure, and improve the Services.

5. Cookies and similar technologies

We use only essential cookies and technologies - to sign you in, keep the Services secure, and detect and fix errors. We do not use advertising cookies, so we do not show a cookie-consent banner. Full detail, including names and durations, is in our Cookie Policy (https://pockt.studio/cookies).

6. Who we share information with

We do not sell your personal data, and we do not share it for advertising. We share information only with the service providers ("processors" and "sub-processors") necessary to run Pockt, and only the information each one needs to do its job. Each acts under contract and on our instructions, except where a provider is an independent controller for its own compliance purposes (for example Stripe for payments).

6.1. AI generation and processing. To produce and check the content you ask us to create, the reference photos you submit for a job and the resulting Output are sent to specialist AI providers that run each step. These providers receive only the content needed to perform the generation; they do not receive your name, email address, password, or payment details. The AI models Pockt generates for casting are synthetic and are not images of real people, and a generated Look or Collection uses only the clothing and attire from the photos you upload, never the face or identity of any real person. If a photo you choose to upload contains a real, identifiable person, that uploaded image is still personal data under the UK GDPR while we process it to extract the clothing. So you know where such content may be processed, we set out below the categories of provider involved:

  • providers of AI image, video, and audio generation;
  • vision and large-language-model providers, used for image analysis, tagging, captioning, and text generation;
  • video composition and captioning providers;
  • text-to-speech and music generation providers.

These providers are located in the United Kingdom and elsewhere, including the United States (see Section 7). The specific providers used depend on the Pipeline you run and may change over time. If you want to know the specific providers that have processed your content, you can request that information by emailing simon.jennings@ayeye.io.

6.2. Infrastructure and operations.

  • Stripe - payment processing, invoicing, and tax calculation (Stripe is an independent controller for payment data; see Stripe's privacy policy);
  • Google Cloud - storage of your uploaded and generated media;
  • Railway - application hosting and the database that holds your account and workspace data;
  • Resend - delivery of transactional emails;
  • Sentry - error monitoring and performance tracing;
  • Google - sign-in (OAuth) if you choose to sign in with Google.

6.3. Legal and corporate. We may disclose personal data where required by law, to enforce our Terms, to protect our rights, users, or the public, or in connection with a merger, acquisition, or sale of assets (in which case we will notify you of any change of controller).

7. International transfers

Several of the providers listed above are located outside the United Kingdom, including in the United States. Where we transfer personal data outside the UK, we rely on an appropriate safeguard recognised under UK data protection law - typically the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or a UK adequacy decision - so that your data continues to receive an essentially equivalent level of protection. You can ask us for more detail about the safeguards that apply.

8. How long we keep your data

  • Account and workspace data: for as long as your account is active.
  • Content (Input, Output, media, lineage): while your account is active; after account closure it is deleted, subject to routine backup cycles (permanent deletion from backups may take up to 90 days) and any legal hold.
  • Billing and tax records: retained for as long as required by UK tax and accounting law (generally around six years), even after account deletion - see Section 9.
  • Logs and error data: for a limited period necessary for security, debugging, and improvement, after which they are deleted or anonymised.

9. Your rights, and deleting your account

Under the UK GDPR you have the right to: access your personal data; have inaccurate data corrected; have your data erased; restrict or object to certain processing; data portability; and withdraw consent at any time where we rely on consent. You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk, although we would welcome the chance to resolve any concern first.

Deleting your account. You can permanently delete your account at any time from your Settings. When you do, we erase your account, workspace, Content, generated media, and associated personal data from the Pockt application and its storage. The only data we retain is the billing and tax records held by our payment processor and in our accounting records, which UK law requires us to keep for a number of years; this retention is permitted under Article 17(3)(b) of the UK GDPR (compliance with a legal obligation). You can also ask us to action a deletion or any other request by emailing simon.jennings@ayeye.io; we will respond within one month.

10. Security

We use technical and organisational measures appropriate to the risk, including encryption in transit, hashed passwords, access controls, automated content-safety screening, and monitoring. No service can be guaranteed perfectly secure; you are responsible for keeping your credentials safe and for notifying us promptly of any suspected compromise.

11. Children

The Services are intended for users aged 18 and over and are not directed at children. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us and we will delete it.

12. Changes to this policy

We may update this policy from time to time. When we do, we will update the "Last updated" date above and, for material changes, notify you through the Services or by email. Continued use of the Services after the effective date constitutes acceptance of the updated policy.

13. Contact

  • Data controller: AYEYE IO LTD (trading as Pockt)
  • Registered office: Millhouse, 32-38 East Street, Rochford, Essex SS4 1DB
  • Email: simon.jennings@ayeye.io
  • Company number: 05113299 (England and Wales) - UK VAT: GB839353696
  • Supervisory authority: Information Commissioner's Office (ICO), ico.org.uk
Sign in