HeyPoko info@disrex.nl

Privacy Policy

What HeyPoko collects, why we need it, who we share it with, and how you get it back or have it deleted.

Last updated: 5 September 2026

HeyPoko is a product of Disrex V.O.F. We are the data controller for the information described here.

Disrex V.O.F.
Egbert Gorterstraat 6
7607 GB Almelo
Netherlands
Chamber of Commerce (KvK) 92470157
info@disrex.nl

This policy covers heypoko.com and the HeyPoko application, including its PokoBlog app. It is written to be read, not to protect us. If something here is unclear, ask and we will explain it.

What we collect

Your account. Your name, email address, and the company name you choose. If you sign in with Google, we receive your name, email address and profile picture from Google, and nothing else.

Your websites. The addresses of the sites you connect, their titles and descriptions, the topics and keywords you or we propose for them, and the articles we draft and publish.

The pages we read. To learn what you sell and who you sell it to, we fetch the public pages of the websites you connect, the way any visitor or search engine would. We read what is published. We do not log in, we do not touch pages behind a password, and we do not go near your customer records.

Search Console data, if you connect it. Read-only performance figures for a site you own: the queries it appears for, impressions, clicks, average position, and which pages Google has indexed. We never receive your Google password, and we cannot change anything in your Search Console account.

Usage and errors. Which pages you open and what fails, through PostHog and Sentry. We use this to find broken things, not to build a profile of you.

Payments. Stripe handles your card details. We never see or store them. We keep the invoice record and your subscription status.

Support messages. What you write to us, so we can answer and find the conversation again later.

Google user data

This section exists because Google asks for it, and because you deserve a plain answer about the account you are about to connect.

What we request. One scope: https://www.googleapis.com/auth/webmasters.readonly. Read-only access to Search Console for the properties you select.

Why. To show you how a site is actually performing in search, to spot queries you already rank for but have not written about, and to tell you whether an article we published has been indexed. That is the whole purpose.

What we do with it. We store the figures against your website in our own database so a screen can render without calling Google every time. We do not sell it, we do not use it for advertising, and we do not use it to train any AI model. Nobody outside the people who need it to run and support HeyPoko can see it.

Limited Use. HeyPoko's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Taking it back. Disconnect the site inside HeyPoko, and we delete the stored figures and the token. You can also revoke our access directly at myaccount.google.com/permissions, which works whether or not you still have a HeyPoko account.

How the writing actually works

The articles are written by AI models under our instruction. You should know what that means for your data.

What we send. The brief for one article: your keyword, what we learned from your public pages, the sources we found, and the draft as it is revised. Your account details, your billing data and your Search Console figures are not sent to a model.

What the model does not do with it. Anthropic, who write the text, and the image provider both operate under terms that forbid training on what we send. Your article is not folded into a model somebody else will use.

What we do not automate. Nothing here makes a decision that has a legal or similarly significant effect on you, so the GDPR's rules on solely automated decisions do not bite. If you switch on automatic publishing, the article goes out without a person reading it, and that is a choice you make and can undo.

When we publish. We write the article to the website you connected, using the connection you set up. We touch nothing on that website except the posts we create for you.

Linking your sites to each other

If your company has several websites with us, we can suggest links between them, so an article on one can point at a relevant page on another.

Only your own. A link is only ever proposed between two sites belonging to the same company in HeyPoko. We never link your site to another customer's, and we never show one customer anything about another customer's site. That boundary is checked in the database query itself rather than trusted to the screen above it.

Why we are allowed to hold it

Under the GDPR we rely on three grounds. Most of what we hold is there because we cannot deliver the service without it, which is performance of a contract: your account, your websites, your articles, your Search Console figures. Billing records we keep because Dutch tax law requires it, which is a legal obligation. Error and usage measurement rests on our legitimate interest in a product that works, and you can object to it.

Who else processes it

We use other companies to run HeyPoko. Each one only receives what its job requires, and each is bound by a processing agreement.

WhoWhat they getWhat for
AnthropicThe brief and the draft textWriting and reviewing your articles
ReplicateThe image promptGenerating article images
DataForSEOKeyword phrasesSearch volume and competition
GoogleKeyword phrases, and your Search Console requestSearch volume, and the figures you asked us to read
Trigger.devJob payloadsRunning scheduled work
StripeYour email address and what you boughtTaking payment and issuing invoices
PostHog, SentryUsage events, error reportsFinding and fixing faults
Our hostEverything stored, at restRunning the database and the application
Email providerYour address and the messageSending you sign-in links and notices

Two of those need a word of explanation. Anthropic receives your article text to write and check it, and does not use it to train models. Google receives two separate things for two separate reasons: keyword phrases, to tell us how often they are searched, and your own Search Console request, to return the figures you asked us to read on your behalf.

Beyond this table we share nothing, except where a Dutch or EU authority compels us by law. If we add a processor that handles your personal data, we update this table before it starts, and we email you if the change is significant.

Where it lives and how long we keep it

Data is stored in the European Union. Where a processor above operates outside the EU, the transfer runs on the European Commission's Standard Contractual Clauses.

We keep your account and content for as long as your account is open. Delete your account and we remove it within 30 days, apart from invoices, which Dutch law requires us to keep for seven years. Search Console figures go as soon as you disconnect the site.

Your rights

You can ask us for a copy of what we hold, correct it, delete it, take it elsewhere in a portable format, object to processing based on legitimate interest, or ask us to pause processing while a dispute is settled. Write to info@disrex.nl and we will answer within a month.

Two of those you can do yourself, without asking. Your articles export from the app in a portable format at any time, and deleting your account from the settings screen starts the deletion described above. We would rather you had the button than had to write us a letter.

If you think we have handled this badly, you can complain to the Dutch data protection authority, the Autoriteit Persoonsgegevens. We would rather you told us first.

Security

Traffic runs over TLS. Credentials and access tokens are encrypted at rest. Access to production data is limited to the people who need it and is logged. No system is perfect, and we will tell you and the regulator if a breach affects you, within 72 hours of finding it.

Children

HeyPoko is a business product and is not for anyone under 16. We do not knowingly collect their data.

Changes

When we change this policy we update the date at the top. If a change affects what we do with your data in a way you would not expect, we email you before it takes effect.