What we hold,
and what we do with it.
Last updated 15 September 2026
The short version
We hold your email, the writing you give us, what we read from your public website, and what you make in Pointed. We use it to draft for you and for nothing else.
We never train models on your content. Your writing goes to a model provider to produce your drafts, and that is the end of it.
You can export everything or delete everything from inside the product, without emailing anyone. Deleting means deleting.
Analytics only runs if you said yes. If you declined, the script was never loaded.
- Who we are
- What we collect
- Why, and on what basis
- AI processing
- Who else sees it
- How long we keep it
- Your rights
- Cookies
- Security
- Changes
Who we are
Pointed is a growth system for founder-led brands, at trypointed.com. We are the data controller for the information described here.
For anything in this policy, including a request to see, correct, export or delete your data, email [email protected]. We answer within 30 days and usually much faster.
What we collect
What you give us
- Your email address. This is the whole of your account. There is no password, so there is nothing else to store.
- Your website address, and whatever is publicly readable at it.
- Writing you paste or upload as a voice sample.
- Your answers to the tone of voice questions, and which proposed voice rules you kept or rejected.
- Everything you make in Pointed: briefs, articles, edits, reply drafts, listening lanes, topic clusters.
What we read from your public site
When you give us your URL, we fetch pages that are publicly available: your homepage, a handful of common pages such as about and pricing, and up to ten recent blog posts found through your sitemap, your feed or ordinary paths. We respect robots.txt. We do not attempt to reach anything behind a login, and we do not submit forms.
What you connect
Connections work in one of two ways. For Slack and Reddit you sign in and we store an access token, encrypted. For Google Search Console you do not sign in at all: you add a Pointed address as a restricted user on your own property, so the access is listed in your Search Console settings under our name and you can remove it there without telling us. What each connection can do is limited to the permission you granted:
| Connection | What we can do with it |
|---|---|
| Google Search Console | Read the search queries and page performance for the property you shared, and only that property. Restricted permission is read only: we cannot change your site, your settings or who else has access. |
| Slack | List public channels and post messages to the channel you chose. |
| Post a comment you have written and approved, as you, when you click send. We never vote, never post on a schedule and never post in bulk. |
You can disconnect any of these at any time, from inside Pointed, and we delete our copy of the token when you do. For Slack and Reddit, deleting the token is the end of our access. For Search Console the grant lives on your property rather than in a token here, so to revoke the access itself, remove the Pointed address in Search Console under Settings, then Users and permissions. We say this in the product too, at the point you disconnect, because a grant you believe you removed and did not is worse than one you know about.
What we record automatically
- An audit trail. Every approval, edit, rejection, publish and connection, with a timestamp. This is a product feature as much as a log: it is what lets you see why a draft exists and roll a change back.
- Usage. Which jobs ran, which model was used, how many tokens, so we can meter your credits honestly and show you where your month went.
- Technical logs. Request paths, timings and errors, kept briefly so we can fix what breaks.
We do not build a behavioural profile of you and we do not track you across other websites.
Why, and on what basis
| What | Why | Lawful basis |
|---|---|---|
| Email, sign-in links, sessions | So you can get into your account | Performance of a contract |
| Your writing, site content, connections | To produce the drafts you are paying us for | Performance of a contract |
| Audit trail and usage | To show you what happened and to bill you accurately | Performance of a contract, and our legitimate interest in accurate billing |
| Service emails: a draft is ready, a payment failed | So the product is useful | Performance of a contract |
| Analytics | To know whether anyone visits | Consent, which you can withdraw below |
| Billing records | Tax and accounting | Legal obligation |
AI processing
This matters more than the rest of this page, so it gets said plainly.
To write a draft, we send a model provider the material it needs: your voice document, the relevant parts of your writing and your website, the brief, and for a reply the thread being replied to. We send the least that will produce a good draft.
We do not train models on your content, and we do not permit our providers to. We use commercial API endpoints, under terms where inputs and outputs are not used for model training.
Our models are reached through OpenRouter, which routes to the underlying provider. Today that is Anthropic for drafting and extraction, and for AI visibility checks we deliberately ask ChatGPT, Perplexity and Gemini the questions your buyers would ask, so the answers we show you are the real ones.
Every draft records which model wrote it. You will see that on the draft itself.
What a model writes is not automatically true. Pointed is built so a person reads and approves everything before it goes anywhere, and there is no setting that changes that.
Who else sees it
We do not sell your data, and we do not share it for advertising. These are the companies that process it on our behalf, all under contract:
| Who | What for | Where |
|---|---|---|
| Cloudflare | Hosting, the database, content delivery | Global edge, data at rest in the EU and US |
| OpenRouter, and through it Anthropic, OpenAI, Google and Perplexity | Drafting, extraction and AI visibility checks | US |
| Apify | Collecting public community discussions for your listening lanes | EU |
| Stripe | Payments. We never see or store your card details. | US and EU |
| Brevo | Sign-in links and service emails | EU |
| Ahrefs Analytics | Counting visits, only with your consent | EU |
Transfers outside the UK and EEA rely on the International Data Transfer Addendum or Standard Contractual Clauses, as applicable.
If we add a processor that handles your content, we will say so here before it starts, and email you if the change is material.
How long we keep it
- Your account and your work: for as long as you have an account, and 30 days after you delete it, after which backups have rotated out.
- Dismissed listening items: 90 days. They are kept that long only because they improve what we show you next.
- Listening items you never acted on: 30 days.
- Sign-in links: 15 minutes, then they are dead and deleted.
- Technical logs: a few days.
- Billing records: six years, because tax law requires it. This is invoices, not your content.
Your rights
Under UK and EU data protection law you can ask us to give you a copy of your data, correct it, delete it, restrict what we do with it, or object to it. You can also complain to a regulator: in the UK that is the Information Commissioner's Office.
Two of these you do not have to ask us for, because they are buttons in the product:
- Export. Everything we hold for you, as one file, including your articles as markdown so they are useful somewhere else. From your billing page, or by API.
- Delete. Your brand or your whole account. It cascades every table, revokes every connected account, and cancels any subscription. It cannot be undone, which is why we ask you to type your email to confirm.
Cookies and analytics
We use no advertising cookies and no cross-site tracking.
Signing in stores a session token in your browser so you stay signed in. That is necessary for the product to work and does not require consent.
Analytics only loads if you agreed. If you declined, the script is never fetched, so there is nothing to opt out of afterwards.
Security
- Everything is served over HTTPS.
- There are no passwords to steal: sign-in is a one-use link that expires in 15 minutes.
- Connected account tokens are encrypted at rest with AES-GCM.
- Your data is scoped to your brand in the query layer, not just in the interface, and that separation is covered by automated tests that run on every change.
- We never put a secret in a log line or a URL.
If you find a security problem, email [email protected]. We will not take legal action against anyone reporting a genuine issue in good faith.
Changes
If we change this policy we will update the date at the top. If a change materially affects what we do with your content, we will email you before it takes effect rather than relying on you to re-read this page.