Your data, clearly explained
Privacy Policy
This policy describes what Pomendar collects, how the Service and its providers use it, and the controls available to you.
Last updated: August 26, 2026
1.Scope and who we are
Pomendar is owned, developed, and operated by Pasalica LLC, a New Jersey limited liability company (“Pasalica,” “Pomendar,” “we,” “us,” or “our”). This Privacy Policy describes how Pasalica collects, uses, discloses, and retains personal information when you use Pomendar’s websites, applications, task-management, scheduling, collaboration, artificial-intelligence, voice, subscription, and integration features (collectively, the “Service”).
This Policy applies to the Service worldwide. It does not govern a third-party service that you choose to connect to Pomendar or visit through the Service. That provider processes information under its own terms and privacy notice.
2.Information we collect
Depending on the features you use, we collect the following categories of information:
- Account and identity information: username, email address, display name, password hash, social sign-in provider, provider account identifier, and account-creation date. We do not store the plaintext password you use for a Pomendar password-based account.
- Profile and preference information: time zone, selected AI model, scheduling and workflow settings, notification state, appearance, reward, voice, and other product preferences. Some appearance, voice, conversation-selection, and interface preferences are stored only in your browser.
- Tasks, schedules, and productivity content: task titles and descriptions, notes, comments, priorities, status, estimates, deadlines, dependencies, buckets, sprints, daily plans, focus sessions, momentum activity, scheduled-event records, reminders, and related history and metadata.
- Team and collaboration information: workspace names and state, membership and role, capacity and specialization, assignments, comments, mentions, activity, retrospectives, notifications, and invitation and join records. Invitation tokens are protected by hashing and, where retained for display, encryption.
- AI and approval information: conversation titles, prompts, responses, selected model, tool requests, proposed actions, approvals or rejections, execution results, usage counts, and sanitized operational traces. Do not place sensitive information in an AI conversation unless it is necessary for your use of the Service.
- Connected-service information: the provider, granted capabilities, account identifier or email, display label, selected calendars, repositories or projects, encrypted authorization credentials, sync status and cursor, external record identifiers, sync receipts, conflicts, and error or health information.
- Payment and subscription information: Stripe customer, subscription, price, promotion, status, renewal, and billing-period identifiers and metadata. Payment-card details are collected and processed by Stripe and are not stored in Pomendar’s application database.
- Voice information: an audio recording you choose to submit for speech recognition and text submitted for speech synthesis. Pomendar forwards this material to its AI/voice provider to perform the requested operation. Pomendar does not intentionally persist the source audio or generated audio in its application database. A resulting transcript is stored if you submit or save it as conversation or task content.
- Technical, analytics, and security information: hashed session identifiers, authentication and OAuth state, timestamps, request and provider-response status, latency and retry telemetry, and diagnostic error information. In production, Vercel Web Analytics processes page or route viewed, timestamp, referrer, filtered query parameters, approximate location, browser, operating system, and device type to provide aggregated traffic statistics. Our hosting, database, security, and network providers may also process IP address, browser or device information, and request logs in the ordinary course of delivering and protecting the Service.
3.Sources of information
We obtain information directly from you; automatically from your browser and your use of the Service; from other workspace members who assign, mention, invite, or collaborate with you; from authentication providers; from services you connect; and from service providers such as our payment processor.
If you provide personal information about another person, you are responsible for having authority to provide it and for giving any notice required by law.
4.How we use information
We use personal information to:
- create and secure accounts, authenticate requests, maintain sessions, and prevent misuse;
- provide tasks, scheduling, team workspaces, reminders, progress and reward features, subscriptions, and support;
- read, create, update, or synchronize calendar, task, issue, repository, and project information when you enable an integration or approve an action;
- generate AI-assisted plans, answers, suggested actions, speech transcriptions, and spoken responses;
- remember settings and personalize the Service, including model and time-zone choices;
- process subscriptions, administer promotions, reconcile payments, and maintain financial records;
- monitor reliability, diagnose failures, measure provider performance, enforce limits, and improve the safety and operation of the Service;
- communicate about the Service, security, support, billing, or changes to our terms; and
- comply with law, protect rights and safety, resolve disputes, and enforce our agreements.
Where applicable law requires a legal basis, we process information as necessary to perform our contract with you, based on our legitimate interests in operating and protecting the Service, with your consent, or to comply with legal obligations. You may withdraw consent where consent is the basis, without affecting prior lawful processing.
5.AI and automated features
When you use Pomendar’s AI or server-based voice features, relevant prompts, conversation history, task and schedule context, team-workspace context, approval instructions, audio, or text may be sent to OpenRouter and to the model provider selected or routed through OpenRouter. Those providers process the information to generate the response you request and may process associated technical metadata under their applicable terms and privacy notices.
Pomendar stores AI conversation content, responses, approval records, and sanitized traces so that conversations can be continued, reviewed, secured, and audited. Credentials and common secret fields are redacted from traces by design, but you should not submit secrets or regulated, highly sensitive, or confidential information unless you are authorized to do so and accept the risks of third-party AI processing.
AI outputs and automated suggestions may be inaccurate, incomplete, or inappropriate. Pomendar may rank or suggest tasks based on information such as priority, deadline, dependencies, specialization, workload, and prior completion history. These features assist your decisions; they do not make legal or similarly consequential decisions about you.
6.Connected services and Google user data
Integrations are optional, and Pomendar requests Google permissions according to the features you select. Depending on those selections, Pomendar may:
- use your Google account identifier and email address to authenticate you or identify a connected account;
- read your Google Calendar list and calendar metadata so you can choose which calendars Pomendar uses;
- read free/busy time ranges from selected Google Calendars to calculate availability, scheduling conflicts, workload, or suggested plans;
- read event details—including title, description, location, status, start and end times, calendar identifier, event identifier, and related metadata—from selected Google Calendars, and create or update events only when you enable event access and direct or approve the action; and
- read Google task lists and task titles, notes, status, due dates, hierarchy, identifiers, and related metadata, and create, update, or delete Google Tasks when you enable task synchronization and direct or approve the operation.
Pomendar stores connected-account identifiers, the capabilities you enabled, selected-calendar configuration, synchronization state and cursors, external record links, operation receipts, and encrypted OAuth credentials needed to maintain the connection. Free/busy information used for planning is generally reduced to busy time ranges. Event or task content imported or saved as Pomendar content is retained with the corresponding Pomendar record under this Policy.
When you invoke an AI-assisted planning, scheduling, or task feature, the Google-derived busy ranges, event or task context reasonably necessary to provide your requested result may be transferred to OpenRouter and the model provider selected by you or routed through OpenRouter. That transfer occurs only to provide the user-facing feature you requested. You can avoid this transfer by not using AI features with connected Google context.
Pomendar’s use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including its Limited Use requirements. Google user data is used only to provide or improve the user-facing integration features you request, maintain or enhance those features, protect security, or as otherwise permitted by that policy. We do not sell Google user data, use it for advertising or credit decisions, transfer it to data brokers, or use Google Workspace user data to train a generalized advertising or AI model.
Disconnecting an integration disables Pomendar’s local access and ordinarily deletes its locally stored credentials. Where a provider supports remote revocation, Pomendar attempts it. If remote revocation fails, encrypted credentials may be retained temporarily to permit a retry. Some providers do not support programmatic revocation, so you may also need to revoke Pomendar in that provider’s account settings. Disconnection does not delete records Pomendar previously created in the third-party service or content already imported into Pomendar. You may request deletion of imported Google data and associated Pomendar records by using available deletion controls or emailing contact@pomendar.com, subject to the exceptions described under “Retention and deletion.”
7.How we disclose information
We do not sell personal information, and we do not share personal information for cross-context behavioral advertising. We do not use third-party advertising cookies in the application as reflected by the Service at the date of this Policy.
We may disclose personal information:
- To service providers and processors that provide hosting, database, infrastructure, security, AI and voice processing, payment processing, communications, and technical support, subject to appropriate contractual or other restrictions;
- To connected services such as Google, Apple, Microsoft, Calendly, and GitHub when necessary to authenticate, synchronize, read, or write information at your direction;
- To workspace participants according to the workspace’s roles and features. Workspace content is collaborative and may be visible to other members;
- At your direction or with your consent, including when you approve an AI-proposed action or create an invitation;
- For legal and safety reasons when we reasonably believe disclosure is necessary to comply with law or legal process, enforce agreements, investigate abuse, or protect the rights, safety, and property of Pomendar, our users, or others; and
- In a business transaction involving a merger, financing, reorganization, sale of assets, insolvency, or acquisition, subject to applicable law.
We may use and disclose information that has been aggregated or de-identified so that it cannot reasonably be linked to you, and we will not attempt to re-identify it except to test our de-identification processes or as permitted by law.
8.Cookies, analytics, and local browser storage
Pomendar uses functional cookies and similar browser storage to maintain a signed-in session, preserve interface state, identify the current application workspace, operate the service worker and offline shell, and remember preferences such as appearance, rewards, voice, and the selected conversation. The authentication session is designed to expire after 30 days, although it may end sooner if you sign out or it is revoked.
In production, Pomendar uses Vercel Web Analytics to understand aggregated traffic and product usage. According to Vercel’s documentation, Web Analytics does not use cookies, does not associate analytics with an IP address, and uses a request-derived visitor hash that is discarded after 24 hours. Pomendar does not presently use advertising cookies or cross-site behavioral tracking.
You can clear cookies and local storage through your browser. Blocking them may prevent authentication, offline support, or other features from working. If our analytics or advertising practices materially change, this Policy and any consent controls required by law will be updated before the new use begins.
9.Retention and deletion
We retain information only for as long as reasonably necessary for the purposes described above, taking account of the nature and sensitivity of the information, account status, user instructions, operational needs, security, legal obligations, and limitation periods. Current retention behavior includes:
- account, task, team, schedule, notification, AI conversation, approval, and sync records are generally retained while the account or workspace is active and until the relevant record is deleted or a valid account-deletion request is completed, subject to dependencies, exceptions, and backup cycles;
- active integration credentials are retained while the connection is enabled. On disconnection, credentials are deleted after successful revocation or local disconnection, except encrypted credentials may remain while a failed revocation is retried. Non-credential connection and sync records may remain for security, integrity, troubleshooting, and audit purposes;
- OAuth connection attempts expire after a short authorization window; consumed attempt records are designed to be eligible for cleanup after a seven-day diagnostic period;
- session records contain a hashed identifier and are designed to expire after 30 days; revoked or expired records may remain for a limited security and audit period;
- payment, subscription, transaction, tax, and fraud-prevention records may be retained for the period required by law and legitimate accounting, dispute, and compliance needs;
- technical logs and backups are retained according to operational and provider schedules and are deleted or overwritten in the ordinary course; and
- browser-stored preferences remain on the device until you or the browser removes them.
Deletion from active systems may not immediately remove information from disaster-recovery backups. We may retain information where required by law, needed to establish or defend legal claims, necessary to prevent fraud or abuse, or maintained in de-identified form. A request to delete Pomendar data does not delete information held independently by a connected provider or another workspace member.
10.Security
We use administrative, technical, and organizational measures designed to protect personal information. These measures include hashed password and session values, encrypted integration credentials, access controls, request authentication, credential redaction from AI traces, and scoped integration permissions. No system is completely secure, and we cannot guarantee that unauthorized access, loss, misuse, or alteration will never occur.
You are responsible for protecting your credentials, controlling access to your devices and workspaces, reviewing requested integration permissions, and promptly notifying us of suspected unauthorized use.
11.Your choices and privacy rights
You can update certain profile and preference information in the Service, sign out to revoke the current session, delete individual tasks or buckets where the feature is available, and disconnect integrations. You may request access to, correction of, portability of, or deletion of personal information by emailing contact@pomendar.com. You may also object to or request restriction of certain processing, withdraw consent, or appeal a denied request where applicable law provides that right.
We may need to verify your identity and authority before acting. Rights are not absolute, and lawful exceptions may apply. We will not discriminate against you for exercising a privacy right. An authorized agent may submit a request where permitted by law, subject to proof of authority and identity verification.
Because the Service does not sell personal information or share it for cross-context behavioral advertising, Pomendar does not offer a “Do Not Sell or Share” link. We also do not knowingly sell or share the personal information of people under 16. If our practices change, we will provide the notices and controls required by law.
12.International processing
Pomendar and its service providers may process information in the United States and other countries where they operate. Those countries may have privacy laws different from those where you live. Where required, we rely on an adequacy decision, contractual safeguards, consent, or another lawful transfer mechanism.
13.Children’s privacy
The Service is not directed to children under 13, and we do not knowingly collect personal information from a child under 13. If you believe a child under 13 has provided personal information, contact us so that we can investigate and take appropriate action. The Terms may impose a higher minimum age for creating an account.
14.Changes to this Policy
We may update this Policy to reflect changes in the Service, our practices, or law. We will post the revised Policy and update the “Last updated” date. If required by law, we will provide additional notice or request consent before a material new use of personal information begins. The version in effect when information is processed governs that processing.
15.Contact us
Questions, complaints, and privacy requests may be sent to contact@pomendar.com or mailed to:
Pasalica LLC
Five Greentree Centre
525 Route 73 North, Suite 104
Marlton, New Jersey 08053
United States
Corporate website: www.pasalica.com. Please do not include passwords, access tokens, payment-card information, or other secrets in your message.