Skip to main content

Privacy Policy

Effective 30 September 2026

Poowha is a marketing platform for New Zealand agencies and businesses. It analyses a business’s digital presence, decides what to do next, produces the content to do it, and records the leads that result. This policy explains what it collects while doing that, where the data goes, and what you can ask us to do with it.

Who we are

Poowha is operated by Thith Digital, based in Auckland, New Zealand. For anything in this policy — access, correction, deletion, or a complaint — write to hello.poowha@gmail.com.

If you are a client of an agency that uses Poowha, that agency decides what is stored about you and why. We hold it on their behalf. Ask them first; we will help them answer.

What we collect

Your account: name, email address, and the version and timestamp of the terms you accepted.

Your organisation and the businesses it works with: names, websites, industry, region, timezone, and the notes and contact details you record against them.

Whatever the platforms you connect return. If you connect Google Search Console we read query, impression and click figures for the property you bind. If you connect Facebook or Instagram we read the Page and account you choose, its follower and reach figures, and the public comments and direct messages sent to it. We never read a personal profile, and we only ever reach a Page whose administrator has approved the connection.

Documents you upload to a client’s knowledge base, and the text extracted from them.

Leads and conversations: names, email addresses, phone numbers and the messages exchanged. Every lead carries a recorded lawful basis — how the contact details were obtained — because the Privacy Act 2020 requires collection by lawful and fair means and that question has to be answerable per record rather than remembered.

Where the voice agent is used, a compliance record per call: the consent basis, when the do-not-call list was checked, the local time at dial, whether the AI disclosure was given, and whether recording was announced or declined.

Where it is stored

In a Supabase Postgres database hosted in Sydney (ap-southeast-2), the closest region to New Zealand. Every table is protected by row-level security in the database itself, so one organisation cannot read another’s rows even if application code asks it to.

One exception, stated plainly because it is a real one: the endpoint that answers a live voice call runs in a United States region. It was measured — answering from Sydney adds roughly 150ms to every spoken turn, and the caller’s audio never travels there anyway. Call transcript text passes through that endpoint while a call is in progress. Everything it produces is stored in Sydney.

Who else processes it

Running the product means sending data to other companies. These receive it today: Supabase (the database, authentication and file storage, in Sydney); Vercel (hosting, which sees every request); Anthropic (the AI model that writes explanations, drafts and replies — it receives the business profile, page content, findings and message text relevant to the task); and Google (Search Console for the metrics you connect, PageSpeed Insights and Safe Browsing for the public URL of a website being audited).

These receive data only where an organisation configures them: Meta (Facebook and Instagram), DataForSEO (keyword and ranking research, which receives website URLs, keyword strings and competitor domains), OpenAI, Perplexity and Google Gemini (asked what they say about a business, for the AI-visibility check), Voyage AI (turns uploaded document text into embeddings so the agent can retrieve it), and Vapi (speech-to-text, text-to-speech and the phone number, where the voice agent is used — it holds the call audio).

We record every AI call: which model, how many tokens, what it cost, which tools it used and what it acted on. That is how spend is capped and how an answer can be traced back.

We do not sell data, and we do not share it with anyone not listed here.

AI, and what it is allowed to say

AI is never the sole source of a factual claim about your data. Deterministic checks produce the findings; the model explains and prioritises them, and every recommendation links back to the measurements behind it.

We do not have an agreement with any model vendor about training on what we send. Each vendor’s own terms govern that, and we will say so here rather than promise something we cannot enforce. If that matters to you, an organisation can supply its own Anthropic key so its calls bill and sit under its own account.

Cookies

Only the ones the product needs: a session cookie so you stay signed in, a short-lived cookie during a connection flow to stop a request being tampered with, and preferences such as whether the sidebar is collapsed and which client you were last looking at.

There is no analytics, no tag manager and no advertising cookie anywhere in the application.

How it is protected

Everything travels over TLS. Tenant isolation is enforced by row-level security in Postgres on every table rather than by application convention, and the test suite includes a cross-tenant leakage test per table.

Credentials you save — provider keys and OAuth tokens — are sealed with AES-256-GCM envelope encryption and can only be opened server-side. They are never returned to a screen after saving; you see the last four characters and a Replace button. No secret is written to a log or an error message.

Every change is recorded in an append-only event log that cannot be edited or deleted, so who did what to which record is answerable.

Your rights, and what deletion actually means

Under the Privacy Act 2020 you can ask what we hold about you and ask us to correct it. Write to hello.poowha@gmail.com and we will answer.

You can disconnect any platform at any time from the client’s Connections screen. That revokes our access token with the provider immediately, and we stop reading anything new.

Deleting a client or an organisation inside Poowha hides it from every screen and every query at once. Being honest about the rest: it does not yet erase the underlying rows. The event log is append-only by design — that is what makes it an audit trail — so removing personal data from it is a deliberate, audited operation rather than a delete. Until that is built, ask us at the address above and we will do it by hand and confirm when it is done.

We would rather say that than claim an automatic erasure that does not exist.

Changes

When this policy changes the effective date at the top changes with it, and the version you accepted is recorded against your account. Material changes will be notified in the product.

Poowha · Thith Digital · hello.poowha@gmail.com

Registered company name, NZBN and postal address are being added. Until then, every request reaches us at the address above.