AI Usage Policy
Last updated: 29 August 2026
1. Overview of AI Features
Pocket PMO incorporates AI-powered features to help you work more efficiently. These features include:
- AI Chat Assistant (opt-in): Optional conversational interface with four specialist contexts, Project Coordinator, Business Analyst, Programme Manager and PMO Analyst. Demoted to a secondary panel; never required to use the product
- Daily Brief & "Needs your attention" panel: Deterministic dashboard signals (overdue tasks, unowned items, unmitigated high risks, AI drafts awaiting approval). The optional Daily Brief workflow generates a concise summary on demand and may propose project updates marked [DRAFT] for your review
- AI Project Workflows (Autopilot): Automated background processing, task hygiene, requirements generation, governance audits, and cross-project risk monitoring. Every action is held as [DRAFT] for PM approval
- Proactive Delivery Watcher: A scheduled scan of your existing project data that raises findings for delivery drift, stale items, unowned work and overdue milestones, and may draft a suggested fix for each finding. Findings and drafted fixes are advisory only, nothing is changed, executed or sent until you explicitly approve it
- Portfolio AI (in the AI Hub): Portfolio-wide runners including Capacity Rebalance (proposes resource moves to relieve over-allocation) and Priority Scenario (ranks portfolio scenarios against a chosen constraint)
- Embedded Governance AI: Specialist AI inside parent features, variance narratives in Baselines, realization forecasts in the Benefits Register, draft 4-dimension Health Checks, communications suggestions, lesson matching and AI-generated test cases
- Document Generation & Editing: AI-generated and AI-edited project documents (PIDs, status reports, etc.). Edits to existing documents are versioned and require approval before becoming the live revision
- Meeting Scheduling: AI workflows can draft meetings and calendar invites (.ics) for you to send. Active platform users receive invites directly; for non-registered attendees, the PM is prompted to forward the invite, ensuring GDPR-compliant communication
- Smart Notifications: AI-drafted branded email notifications to active platform users regarding task assignments, RAID item updates, and other project events. Non-registered team members are flagged to the PM for manual follow-up
- Meeting Summarisation: Automatic extraction of actions, risks, and decisions from meeting notes
- Predictive Risk Analysis: AI-powered risk prediction and early warning detection
- Impact Simulation: Analysis of potential impacts from project changes
- Natural Language Queries: Ask questions about your project data in plain English
- Stakeholder Reports: AI-generated executive summaries and reports, including the dashboard status report and shareable snapshots. Summaries are drafted from your existing project data at the moment you generate them; when a snapshot is shared, the drafted summary is included in the read-only link you send
- Smart Scheduling & Replan: When a plan changes, AI can suggest tasks, detect likely dependencies and propose a ripple reschedule or recovery options for the rest of the plan. Proposals are shown as an explicit before/after choice and no dates move until you accept them
- Setup Coach: A guided getting-started assistant that suggests your next best step based on what you have already set up in your own workspace. It only reads your workspace state and never changes data
- Guided Project Coach: An in-project assistant that offers the next setup step (add a RAID item, set a budget, add scope) and can create the item for you from plain English. It always shows you what it will create and only writes on your confirmation
- Ask this report (snapshots): If you switch it on for a published snapshot, viewers can ask questions about that report. Answers are generated strictly from the frozen snapshot data — the assistant has no access to your live projects, other clients or anything outside that snapshot — and it cannot change or send anything. Questions are logged for you and the feature can be turned off at any time
- Free sandbox planner (no account): On our public site, AI can draft and reschedule a plan from a short description. It runs on the text you type in the sandbox only; the plan stays in your browser unless you choose to import it after signing up
- Instant Project Creation: AI-assisted project setup based on natural language descriptions
- 360° Lessons Loop: AI drafts candidate lessons from live delivery data (slipped milestones, closed high-impact RAID, decisions, standup blockers) each week and at project closure. All AI-drafted lessons are held with a "proposed" status and require explicit PM Approve / Edit / Dismiss — nothing writes to the Lessons Library, RAID or a new project's plan without a click. At new-project kickoff, matched prior lessons are surfaced as suggested actions (proposed RAID entries or plan tweaks) that only apply on approval. Every approved AI-authored write is recorded in the audit log against the approving user.
All AI features are clearly marked with the ✨ sparkles icon or "AI-powered" labels throughout the application.
2. How AI Processing Works
When you use AI features, your data is processed as follows:
- Data Transmission: Your project data is sent securely (via TLS 1.3 encryption) to our AI processing infrastructure
- External Processing: We use OpenAI GPT-5 family models (GPT-5, GPT-5-mini and GPT-5-nano) routed through a secure AI gateway. Selected non-reasoning workloads may also use Google Gemini Flash models (2.5 and 3.x) for cost optimisation
- Avatar Generation: If you create an avatar, the photo you upload is sent once to an image model (GPT-image) via the same gateway to produce a stylised portrait. The photo is not retained by the provider and is never used for training, facial recognition or identification
- Response Generation: The AI generates a response based on your input and project context
- No Retention: Your data is processed transiently and is NOT stored by the AI provider for training or any other purpose
3. Data Protection Measures
We implement the following safeguards to protect your data when using AI features:
- Encryption in Transit: All data is encrypted using TLS 1.3 during transmission
- Data Minimisation: We send only the data necessary for the specific AI feature being used
- Pseudonymisation: Where possible, personal identifiers are anonymised before AI processing
- No Model Training: Your data is never used to train AI models
- Transient Processing: Data is processed in memory and not persisted by AI providers
- Authentication Required: All AI endpoints require user authentication
- Rate Limiting: AI endpoints are protected against abuse with rate limiting
4. Third-Party AI Providers
We use the following AI service providers:
- OpenAI (GPT-5 family): Primary AI model provider for reasoning, text generation and analysis
- Google (Gemini Flash, 2.5 and 3.x): Secondary provider used for cost-efficient classification, summarisation and streaming chat tasks
- Resend: Transactional email delivery for AI-initiated notifications, meeting invites, and task assignments
- Sentry: Application error monitoring. Sentry receives stack traces, browser/device metadata and minimal user identifiers to help us detect and fix bugs. It does not receive project content sent to AI features
These providers operate under strict data processing agreements that prohibit:
- Using your data to train their AI models
- Storing your data beyond the processing request
- Sharing your data with third parties
- Using your data for any purpose other than fulfilling your request
5. What Data is Sent to AI
Depending on the AI feature used, the following data may be sent for processing:
- AI Chat: Your message and current project context (name, description, summary counts)
- Daily Brief / Workflow input: Any natural-language input you provide plus current project state (open tasks, risks, issues, actions, milestones, documents, team resources) so the workflow can propose appropriate updates, schedule meetings, edit documents or draft notifications
- AI Autopilot: Project data (tasks, risks, issues, milestones, budgets) for automated processing, all actions are marked [DRAFT] and require your approval
- Document Generation & Editing: Project details, RAID items, tasks, milestones, and existing document content when editing
- Meeting Scheduling: Meeting details (title, date, time, agenda) and team member names/emails from your project resources to generate calendar invites
- Email Notifications: Team member names and email addresses (for active platform users only) to deliver task assignments, RAID updates, and meeting invites
- Meeting Summarisation: The meeting transcript you provide
- Risk Analysis: Project tasks, existing risks, issues, actions, and milestones
- Natural Language Queries: Your question and relevant project data
Important: We recommend avoiding entering highly sensitive information (such as national security data, protected health information, or trade secrets) into AI features. While we implement strong safeguards, AI processing involves external transmission of your data.
6. Your Rights and Choices
You have the following rights regarding AI features:
- Opt-Out: You can use Pocket PMO without using AI features - all core functionality works without AI
- Informed Consent: AI features are clearly labeled so you know when AI is being used
- Data Control: You control what data you input into AI features
- Transparency: This policy explains exactly how your data is processed
- No Automated Decisions: AI provides suggestions and analysis, but you make all final decisions
- Draft Review: All items produced by AI workflows or Autopilot runs are marked [DRAFT], you must approve, edit, or dismiss them before they become official project records
- Meeting Control: Calendar invites are sent to the PM first as interactive invites (Accept/Decline). Only active platform users receive direct invites; non-registered attendees require PM forwarding
- Email Consent: Emails are only sent directly to users who have registered accounts (and therefore accepted the Terms of Service). Non-registered team members are never emailed directly by AI workflows
- Audit Log: Every AI workflow run creates an auditable entry recording the inputs, outputs and any actions proposed or taken, feeding into project reporting and compliance
7. AI Output Disclaimer
Please be aware of the following regarding AI-generated content:
- Not Professional Advice: AI outputs are for informational purposes and should not replace professional judgment
- Review Required: Always review AI-generated documents before sharing with stakeholders
- Potential Inaccuracies: AI may occasionally produce incorrect or incomplete information
- No Liability: You are responsible for verifying and validating AI outputs before use
- Human Oversight: AI is a tool to assist you, not replace your professional expertise
8. Industry-Specific Considerations
If you work in regulated industries, please consider the following:
- Healthcare/NHS: Avoid entering patient data or protected health information (PHI) into AI features
- Government/Defence: Do not use AI features for classified or sensitive government data
- Financial Services: Consider your regulatory obligations before using AI with customer financial data
- Legal: Privileged communications should not be processed through AI features
If you have specific compliance requirements, please contact us to discuss your needs.
9. Data Retention
AI processing and data retention:
- Transient Processing: Data sent to AI providers is processed in real-time and not stored
- Generated Content: Documents and outputs you choose to save are stored in your Pocket PMO account
- Conversation History: AI chat messages are stored in your account for continuity (deletable on request)
- Audit Logs: We log AI feature usage for security and debugging (no input/output content)
10. AI Credits & Fair Usage
To keep AI features fast, sustainable and affordable for all customers, every AI interaction consumes credits from your account. Each AI request equals 1 credit. Credits are allocated as follows:
- Free Trial: 25 credits granted on signup, valid for the duration of your 15-day trial
- Pro: 400 credits per month, reset on your billing anniversary
- PMO: 2,000 credits per month (shared across the team), reset on your billing anniversary
- Enterprise: Unlimited AI credits, subject to fair-use limits
- Top-up packs: Available at £5 / 250 credits, £15 / 1,000 credits, £40 / 3,000 credits, top-ups never expire
When you exhaust your monthly allowance, AI features will be paused until your next reset or until you purchase a top-up. Non-AI features always continue to work. Full transparency is provided via Settings → AI Credits, including a transaction log of every AI action. See our AI Credits help page for details.
11. Acceptable Use of AI Features
Our AI prompts, agent configurations, templates and generated report formats are our intellectual property. You may use AI outputs freely for your own project delivery, but you may not extract, copy or reverse engineer our prompts, models or templates, and you may not use the Service or its AI outputs to design, train, benchmark or improve a competing product or service. Scraping, bulk export and systematic recording of AI features is prohibited. See section 4 of our Terms of Service.
12. Updates to This Policy
We may update this AI Usage Policy as our AI features evolve. We will notify you of material changes via email or through the Service at least 30 days before they take effect. Your continued use of AI features after changes constitutes acceptance of the updated policy.
13. Contact Us
If you have questions about our AI usage or this policy:
- Visit our Support page
- Review our Privacy Policy for broader data protection information
- Review our Terms of Service for general service terms
This policy was last updated on 26 August 2026. See also our Terms of Service, Privacy Policy, and Cookie Policy.
