Poliogo
How Poliogo works
Detect & Sync
Code Scanning
Reads package.json and your source to find every service you use.
MCP ServerFor AI editors
Run compliance checks inside Cursor, Claude Code and Windsurf.
No-Code PlatformsNew
Lovable, Bolt.new, v0, Base44, Replit and FlutterFlow.
Drift Monitoring
Add a new service and Poliogo tells you what changed, in plain English.
Automatic Pull RequestsFree plan
Poliogo writes the code and opens a PR. You review and merge.
Generate & Serve
Cookie Banner
Blocks trackers before consent. Geo-aware. Consent Mode v2 and TCF 2.3.
Legal Documents
Privacy Policy, Cookie Policy and Terms of Service.
Privacy Policy
Written from the services your code actually uses — and kept current.
Terms & Conditions
Subscriptions, refunds, liability and user content — fully editable.
Design Customizer
Vibe Presets, brand color auto-detect, and full CSS on Agency.
Accessibility WidgetFree plan
A menu visitors adapt your page with, plus a WCAG 2.2 AA standards scan.
Data Requests (DSAR)
Intake, tracking and deadlines for access and deletion requests.
Trust Center
One public page with your policies. White-label on Agency.
Not sure where to start?Start free — connect a project
Who it's built for
Indie Developers
One subscription covers every side project. MCP built in.
Startups & Product Teams
Daily scans and automatic updates as your product ships.
Agencies & FreelancersWhite-label
Unlimited client sites, your branding, separate client logins.
AI & No-Code BuildersNew
Built for what Lovable, Bolt.new, v0 and Base44 generate.
Managing sites for clients?See agency plans
ConnectorsPricing
Tools & docs
Documentation
MCP setup, CLI commands, config files and API reference.
Setup Guides
Step-by-step instructions for Next.js, Vite, Astro, Remix, SvelteKit and more.
Changelog
What shipped, when — releases, connectors and document updates.
Want us to set it up?Talk to us
About us
About Poliogo
Why we think your policies should keep up with your code.
Security & Trust
What we read, what we keep, and how every clause traces to your code.
Legal Disclaimer
Poliogo is a software tool, not a law firm. What that means for you.
Contact & Support
Real people, same-day replies — and we'll do your setup for you.
Questions from a security team?Get in touch
Sign InStart free — no credit card
Connectors
Pricing
Sign InStart free — no credit card
Contents
  1. Who we are
  2. What personal data we collect
  3. Where the data comes from
  4. Why we process it, and our legal basis
  5. AI and automated decision-making
  6. Cookies and tracking
  7. Who we share data with
  8. International transfers
  9. How we protect your data
  10. How long we keep it
  11. Your rights
  12. Children
  13. Regional information
  14. Changes to this policy

Poliogo · Legal

Privacy Policy

Effective date: August 7, 2026

Last updated: September 11, 2026

1. Who we are

Poliogo ("we", "us", "our") operates poliogo.com — a compliance layer that reads your codebase and keeps your privacy, terms and cookie documents up to date as your stack changes. We decide why and how your personal data is processed, which makes us the data controller under the EU and UK GDPR, a business under the California Consumer Privacy Act, and the equivalent role under other privacy laws that apply to you.

  • Contact for privacy questions and requests: support.polio.ai@gmail.com
  • Where we are based: Israel

If you are in the EEA or the UK and we do not have an establishment there, you may contact us at the address above and we will route your request to our representative.

2. What personal data we collect

CategoryWhat it includesHow the law classifies it
Identity and contact dataFull name, email address, username or handle, company name, profile picture, country and password (kept only as a one-way hash)GDPR personal data · CCPA Category A (identifiers)
Technical and usage dataBrowser and user-agent string and language preference, session logs, pages viewed, referrerGDPR online identifiers · CCPA Category F (internet activity)
Content you give usImages you uploadGDPR personal data — including data about other people you include in it
Support communicationsMessages you send us and their attachmentsGDPR personal data · CCPA Category A

Some of what you give us contains other people's personal data — a document you upload, a name in a message, an address book you share. You need a lawful reason to give it to us, and we handle it under this policy on your behalf.

We do not deliberately collect biometric data, genetic data, precise geolocation or government identification numbers. If you send us any of these in a support message, we delete them once your request is resolved.

3. Where the data comes from

  • Directly from you — when you create an account, fill in a form, make a purchase or contact support.
  • Automatically — through cookies, server logs and the SDKs listed in section 7 when you use the service.
  • From third parties — from the identity provider you sign in with (which tells us your name and email address), and from the payment and infrastructure providers listed below.

4. Why we process it, and our legal basis

PurposeData usedLegal basis (EU/UK GDPR)
Creating and running your accountIdentity, technical dataArt. 6(1)(b) performance of a contract
Keeping the service secure and preventing fraudTechnical data, logsArt. 6(1)(f) legitimate interests
Storing and displaying the content you give usContent you give usArt. 6(1)(b) performance of a contract
Taking payment and running your subscriptionIdentity, transaction recordsArt. 6(1)(b) performance of a contract
Understanding how our public marketing pages are used, and catching errors in themTechnical dataArt. 6(1)(f) legitimate interests

Where another law applies, we rely on the equivalent basis: contractual necessity, legal obligation, legitimate interests, or your consent under the LGPD, PIPL, PIPEDA, the Australian Privacy Act and the US state privacy laws.

5. AI and automated decision-making

We do not use your personal data to train AI models, and we do not make decisions about you by automated means that produce legal or similarly significant effects.

6. Cookies and tracking

We group everything we store on your device into four categories: strictly necessary, functional, analytics and marketing. Only strictly necessary items are set without your permission.

NameSet byCategoryWhat it doesLifespan
__sessionPoliogoStrictly NecessaryCarries the signed token that keeps you signed inUntil you sign out or it expires
__cf_bmCloudflareStrictly NecessaryBot management and abuse prevention30 minutes
firebase:authUser:*FirebaseStrictly NecessaryKeeps you signed in (browser storage, not a cookie)Until you sign out

Beyond cookies we also use data we keep in your browser's local storage. The same consent rules apply to these as to cookies.

Where the law requires your consent, we ask for it before non-essential items are set. You can change your choices at any time by writing to support.polio.ai@gmail.com, and we will apply them to every non-essential technology we use. Our full Cookie Policy explains each item in detail.

7. Who we share data with

We do not sell your personal data for money. We do not share personal data for cross-context behavioural advertising.

ServiceProviderWhy we use itWhat it receivesWhere it processes data
CloudflareCloudflare, Inc.CDN, DNS, security filtering, edge compute, and the AI model that drafts optional clause suggestions from the notes you typeIP addresses, request headers, security events, and — for the drafting step only — the notes you type, the detected service list and your multiple-choice answersEdge locations worldwide
FirebaseGoogle LLCSign-in, app data storage and push messagingEmail, auth tokens, device push tokens, app usage events, stored documentsUnited States
PostHogPostHog, Inc.Product analytics and error monitoring on our public marketing pages only — never on the signed-in dashboard, and never on a customer's Trust CenterIP address, page URL, referrer, clicked element text, error reportsEuropean Union
PayPalPayPal (Europe) S.à r.l. et Cie, S.C.A.Subscription billing and payment processingName, email, billing address, subscription and transaction recordsEuropean Union and United States
GroqGroq, Inc.Drafts the same optional clause suggestions when Cloudflare is unavailableThe notes you type, the detected service list and your multiple-choice answers — never free-text fields holding personal details, never source codeUnited States

A note on the AI drafting step. If you describe how your business operates in your own words, those words are sent to an AI model so it can draft extra clauses for you to review. That model runs at Cloudflare, which already provides our infrastructure; if Cloudflare is unavailable the request goes to Groq instead. We send the notes, the detected service list and your multiple-choice answers. We do not send free-text fields that hold personal details, and we never send your source code. Under the written terms we have with each of them, neither provider is permitted to train a model on what we send. The draft is shown to you before it is added to your document, and it is stored as your own text. Detecting your stack does not use AI at all — that step is pattern matching on our own servers. Nothing is sent unless you type into that box, and the rest of the service works without it.

Google's Gemini API and OpenRouter served this step until September 11, 2026. They were removed on that date and receive nothing.

A note on PostHog. It runs in memory-only mode, which means it stores nothing at all on your device — no cookie, no local storage, no session storage — and a page reload starts a new anonymous session. It is loaded on our marketing pages only: it is switched off inside the product, and it never runs on a Trust Center served from a customer's own domain.

Every provider above is bound by a data processing agreement that limits them to our instructions. We also disclose personal data when a law, court order or regulator requires it, and to a buyer or successor if the business is sold — in which case this policy continues to apply until you are told otherwise.

8. International transfers

Our infrastructure runs in more than one region. Some of the providers above process data outside your country, including in the United States. Where we transfer personal data out of the EEA, the UK or Switzerland we rely on the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, or the provider's certification under the EU–US Data Privacy Framework, and we assess the destination country's laws before we do so. For transfers out of mainland China we rely on the mechanisms permitted by the PIPL.

9. How we protect your data

  • Access to production systems is limited to the people who need it, on the principle of least privilege.
  • Data is encrypted in transit and at rest by our infrastructure providers.
  • Passwords are stored only as one-way hashes — we never hold the password itself.
  • Input is validated on the server before it is stored, to keep records accurate.
  • A documented incident process: if a breach is likely to put you at risk we notify the competent authority within 72 hours and tell you without undue delay.

No system is perfectly secure, so we cannot promise absolute security.

10. How long we keep it

DataRetention
Account dataFor as long as your account is open, then 30 days after deletion
Server and security logs90 days, rolling
Content you uploadedUntil you delete it, then removed from backups within 30 days
Support conversations24 months after the conversation is closed
Analytics and cookie dataAs stated in the cookie table in section 6

When a retention period ends we delete the data or irreversibly anonymise it so it can no longer identify you.

11. Your rights

RightWhat it meansWhere it applies
AccessGet a copy of your data, its sources and who received itGDPR Art. 15 · CCPA § 1798.100 · LGPD · PIPL
DeletionHave your data erased, including at our processorsGDPR Art. 17 · CCPA § 1798.105 · DPDPA
CorrectionFix data that is wrong or out of dateGDPR Art. 16 · CCPA § 1798.106
PortabilityReceive your data in a machine-readable file (JSON or CSV)GDPR Art. 20 · CCPA § 1798.130
Opt out of sale, sharing and targeted adsStop advertising-related sharing, including via GPCCCPA/CPRA · VCDPA · CPA · CTDPA
Limit use of sensitive dataRestrict use beyond what the service needsCPRA § 1798.121
Object or restrictObject to processing based on legitimate interestsGDPR Art. 18 and 21
Withdraw consentWithdraw consent at any time, without affecting past processingGDPR Art. 7(3) · LGPD · PIPL
No retaliationWe will never degrade your service because you exercised a rightCCPA § 1798.125

In the product you can already send us a privacy request through our request form without asking us. To exercise any of these, email support.polio.ai@gmail.com or use the request form in our Trust Center. We verify your identity through the email address on your account before we act. We answer within 30 days (GDPR) or 45 days (CCPA), and tell you if we need the extension the law allows. An authorised agent may submit a request with written proof of authority. You can also complain to your data protection authority — in the EU, the one where you live or work; in the UK, the ICO.

12. Children

The service is not directed to anyone under 18, and we do not knowingly collect their personal data. If you believe someone below that age has given us data, write to support.polio.ai@gmail.com and we will delete it. Where we know a user is under 16 we do not sell or share their data without opt-in consent, as California and EU member state law require.

13. Regional information

We have users in the EU, the UK and the United States. The sections below apply to you wherever you live.

California (CCPA/CPRA)

In the last 12 months we collected the categories in section 2 for the purposes in section 4, and disclosed them to the providers in section 7. We do not sell personal information for money. We do not share personal information for cross-context behavioural advertising. We do not use or disclose sensitive personal information beyond the purposes permitted by § 7027(m). California residents may also request the "Shine the Light" disclosure under Civ. Code § 1798.83.

EEA and United Kingdom

Our legal bases are in section 4 and our transfer safeguards in section 8. You may lodge a complaint with your national supervisory authority or, in the UK, the Information Commissioner's Office.

Brazil (LGPD)

You may confirm whether we process your data, request anonymisation of unnecessary data, ask who we shared it with, and revoke consent — write to support.polio.ai@gmail.com.

China (PIPL)

Where the PIPL applies we obtain separate consent before processing sensitive personal information, before sharing data with third parties and before transferring data outside mainland China.

Other regions

Residents of Virginia, Colorado, Connecticut, Utah, Texas and Florida have equivalent access, deletion, correction, portability and opt-out rights, plus a right to appeal a refused request by replying to our decision email.

14. Changes to this policy

We update this policy when what we do changes. The date at the top always reflects the current version, and previous versions are kept for audit. If a change is material we tell you by email or an in-app notice at least 30 days before it takes effect.

Generated by Poliogo from the services detected in this product. Poliogo is a compliance management platform, not a law firm, and this document is not legal advice.

Poliogo

Privacy documents that keep up with your code. We watch what your product uses, propose updates to your policies, and tell you in plain English when one needs your approval.

Product
  • Code Scanning
  • MCP Server
  • Automatic Pull Requests
  • Drift Monitoring
  • Cookie Banner
  • Accessibility Widget
  • Legal Documents
  • Pricing
Solutions
  • Indie Developers
  • Startups & Product Teams
  • Agencies & Freelancers
  • AI & No-Code Builders
Resources
  • Documentation
  • Setup Guides
  • Changelog
  • Connectors
Company
  • About
  • Security & Trust
  • Contact & Support
Legal
  • Legal Disclaimer
  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Data Processing Addendum
Alternatives & ComparisonsPoliogo vs TermlyPoliogo vs iubendaPoliogo vs OsanoPoliogo vs Ketch
Cookie Consent by FrameworkNext.jsReactWordPressShopifyVueNuxtSvelteKitAstroAngularRemixLaravelDjangoRuby on RailsWebflowFramerstatic HTML
Compliance by RegulationGDPRUK GDPRCCPA / CPRAEU AI ActCOPPAUS state privacy lawsAmendment 13ePrivacy DirectiveLGPDPIPEDA
Compliance by StackNext.jsSupabaseVercelLovableStripeOpenAIAnthropicClerkFirebasePostHogGoogle AnalyticsMeta PixelMixpanelSentryPineconeResendShopifyNetlifyCloudflareReplitWordPress.com
© 2026 Poliogo Inc. All rights reserved.

Poliogo is an automated code analysis and document display tool, not a law firm. Poliogo does not provide legal advice, representation, or guarantees of statutory compliance, ADA/WCAG certification, or legal immunity. Visual banners and generated documents are advisory tools and do not substitute for professional legal review.

Privacy PolicyTerms of ServiceLegal Disclaimer