Legal

Privacy Policy

Version 2026-10-02 · Last updated: October 2, 2026

Who we are

Pointerly is operated by SEAN LUIS GUADA RODRIGUEZ CONSULTORIA EM TECNOLOGIA DA INFORMACAO LTDA, CNPJ 47.348.090/0001-70, a company incorporated in Brazil with its registered office at Avenida Prefeito Osmar Cunha, 416, Centro, Florianópolis – SC, CEP 88015-100, Brazil ("Pointerly", "we", "us"). This policy explains how we handle personal data when you use our websites, web app, iOS app, browser extension, API, and related services, and when you interact with links, pages, or messages that our customers create with Pointerly.

We are the controller for the processing described as ours below. Our data protection officer (encarregado under Brazil's LGPD) is Sean Luis Guada Rodriguez, who can be reached at privacy@pointerly.io. Use this address for any privacy question or request, including from outside Brazil.

Controller and processor roles

Pointerly as controller. We decide how and why personal data is used for our own purposes: running accounts and billing, our website and marketing, security and abuse prevention, usage metering, support, and legal compliance.

Pointerly as processor. Our customers (creators, brands, and businesses with a Pointerly workspace) decide what Pointerly does with their Customer Content. That includes data about their own audience: people who click their links or visit their pages, people who comment on their posts or message their Instagram, Facebook, WhatsApp, or Telegram accounts, broadcast subscribers, and contacts they import. For that data the customer is the controller (under LGPD, the "controlador") and Pointerly is its processor ("operador"), acting on the customer's instructions under our Terms and any data processing agreement.

If you are a visitor, subscriber, or other end user of a Pointerly customer and want to exercise your rights over that data, contact the customer directly. If you contact us, we will pass your request to the customer where we can identify them, and we will help them respond. We may still act as a controller for limited purposes on end-user data, such as security, abuse prevention, and metering, as described below.

Data we collect

Account data

Name, email address, password (stored hashed by our authentication provider) or sign-in provider (Google, Apple, Facebook, and others), phone number where you give it, profile photo, language and time zone, multi-factor authentication status, and workspace memberships and roles.

Workspace content

Links and their destinations, bio pages, storefronts, products, collections, automations, message templates, posts and scheduled posts, scripts, campaigns, creator and brand profiles, contracts, files and attachments you upload, notes, support tickets, and Delegated Workspace requests.

Connected account data

When you connect a platform, we receive what that platform shares under the permissions you grant, such as account and page identifiers, profile details, posts and media, comments, direct messages, insights and metrics, WhatsApp Business Account and phone number details and message templates, Telegram bot tokens and chat identifiers, YouTube channel data, files and records from tools such as Google Drive, Sheets, Calendar, Gmail, and Notion where you connect them, and the access tokens needed to keep the connection working.

Affiliate and commerce data

Affiliate tags and programs, retailer product data, storefront imports from the browser extension, sub-IDs, earnings and order reports you import or sync, and attribution settings.

AI inputs and outputs

Prompts, chat messages with Poppy, instructions, attachments you give to AI features (and text extracted from them), and the content the AI produces.

Billing data

Plan, invoices, usage records, credit balances, tax details, billing contact, and payment status. Card details are collected and stored by Stripe, not by Pointerly. For brand payments, Stripe collects identity and payout details from creators.

Device and technical data

IP address, browser and device type, operating system, app version, push notification token for the iOS app, session and sign-in events, request logs, error logs, and API usage.

Communications

Emails and messages you send us, support conversations, survey answers, and waitlist or contact form submissions.

Referral data

Referral codes, who referred whom, rewards, and salted one-way hashes of sign-in IP addresses used to detect self-referrals.

Voice dictation in the web app uses your browser's built-in speech recognition. Pointerly receives only the resulting text. Your browser vendor (for example Google for Chrome or Apple for Safari) may process the audio under its own terms.

Visitors, subscribers, and other end users

When someone interacts with a Pointerly customer's link, page, or messaging account, we process the following on the customer's behalf:

  • Link clicks and page views: IP address, user agent, device type, browser, operating system and its major version, approximate location (country, region, city) that our hosting provider derives from the IP address, referring page, campaign (UTM) parameters, the link and variant served, a visitor identifier, and whether the visit looks automated. We use this to route the visitor, report analytics to the customer, count usage, and detect abuse. The full IP address is used only while the request is handled: we store it shortened (IPv4 to its first three parts, IPv6 to its first 48 bits). The visitor identifier is a one-way hash of the IP address and user agent combined with a secret that changes every calendar month and is then destroyed, so it lets us count unique visitors within a month but cannot be linked back to an IP address afterwards. Visits flagged as automated are kept in analytics but are not billed as usage. Raw request details are deleted after 90 days, as described under "Retention".
  • Comments and direct messages: the sender's platform user ID, username or name, profile photo where provided, message or comment text, and timestamps, so the customer's automations can reply.
  • WhatsApp and Telegram subscribers: phone number or chat ID, name, messages exchanged, opt-in and opt-out status, delivery and read status, and which broadcast links they clicked.
  • Abuse reports: the reported address, category, details, an optional email address, and a salted hash of the reporter's IP address and browser that changes daily, used only to limit repeat reports.
  • Shop assistants: the shopper's messages and the products suggested. Shopper messages may be processed by OpenAI to understand the request, under the sensitive-data handling described in "AI processing": never by DeepSeek and never under a data-sharing program.

Public bio pages and links do not show a cookie banner and do not load our website analytics tools. The routing data above is processed server-side when the link is used.

Sources of data

We collect data from you; from members of your workspace; from platforms and tools you connect; from imports you run; from your use of the service; from end users who interact with our customers' links, pages, and messaging accounts; from payment, authentication, and infrastructure providers; and from public pages, such as retailer product pages, where relevant to a feature you use.

AI processing

Pointerly's AI features run on third-party large language models. When you use Poppy, generate posts, captions, or scripts, receive message or keyword suggestions, run a shop assistant, when we classify a link destination for safety, or when a Delegated Workspace operator uses AI on your request, we send the relevant inputs to an AI provider. Inputs can include your prompt, the conversation so far, relevant workspace data (for example link, product, post, or analytics details), text from attachments, data from tools you connected when you ask Poppy to use them, and, for shop assistants, shopper messages.

We handle two kinds of AI requests differently. Sensitive data is Google user data (Gmail, Calendar, Drive, Sheets, Meet, and Analytics), YouTube data, content from other workspaces and mailboxes you connect (such as Notion, Outlook, and IMAP mail), files attached to Delegated Workspace requests, and messages from your audience (shop assistant chats and other end-user messages). Everything else, such as your prompts and your links, products, posts, and bio pages, is standard.

Sensitive data

Sent only to OpenAI, under your workspace's own OpenAI key if you added one, otherwise under our OpenAI account. It is never sent to DeepSeek and never retried on another provider. If OpenAI is not available, the feature that needs it tells you so; it does not fall back. Once a Poppy conversation, Delegated Workspace request, or automation step includes sensitive data, the rest of that work, including follow-up questions and file search, is handled the same way.

OpenAI (United States)

Our primary AI provider, and the only one that receives sensitive data, as described above. Our OpenAI account takes part in an OpenAI program under which OpenAI may use inputs and outputs sent through that account to develop and improve its models. If you prefer that your content is not sent through our account, add your workspace's own OpenAI key in Settings → AI. Text embeddings used to search files you attach are also created with OpenAI.

DeepSeek (People's Republic of China)

Our fallback provider for standard requests only. When OpenAI is unavailable, rate-limited, or returns an error, a standard request may be sent to DeepSeek instead. DeepSeek never receives sensitive data: no Google user data, no mailbox or connected-workspace content, no attached files, and no messages from your audience. DeepSeek processes and stores data in the People's Republic of China, whose laws may allow public authorities to access data without the safeguards available in the EU, UK, or Brazil. DeepSeek's own terms govern its use of the data.

Your own provider key

If your workspace adds its own OpenAI or DeepSeek key in settings, standard requests use that key, and your agreement with that provider governs how it handles the data. Sensitive data uses only an OpenAI key you add; a DeepSeek or other OpenAI-compatible key is never used for it. Settings → AI shows which provider and model your workspace runs on, including for sensitive data.

  • We choose providers and fallback order based on cost and reliability, and we may change them. We will update this policy and our subprocessor list when we do.
  • Pointerly does not train its own AI models on your content. AI output is stored in your workspace like other content.
  • Do not submit sensitive personal data (such as health, financial account, or identity document data) to AI features unless it is necessary.
  • The iOS app does not call AI providers directly. AI features in the app run on our servers in the same way as on the web.

Meta platform data

When you connect Instagram, Facebook, or WhatsApp, we access Meta platform data only through the permissions you approve and only to provide the features you use, such as replying to comments and messages, sending WhatsApp messages and broadcasts, publishing posts, and showing insights. We comply with the Meta Platform Terms and Developer Policies.

  • We do not sell Meta platform data or use it for advertising profiles.
  • We do not share it with third parties except our subprocessors, as needed to provide the features you use, or as the law requires.
  • Disconnecting an account in Pointerly stops further access. You can also remove Pointerly from your Meta account settings.
  • Meta sends us data deletion requests when a user removes our app. We process them and provide a confirmation code with a status page at /data-deletion-status. For how to request deletion yourself, see our data deletion instructions.

Google user data and YouTube

Connecting a Google or YouTube account to Pointerly is optional and always started by you. When you connect YouTube, Pointerly uses the YouTube API Services and Google OAuth. By connecting, you agree to the YouTube Terms of Service, and the Google Privacy Policy describes how Google handles your data.

We request the narrowest scopes that make the features work:

  • Sign-in (openid, userinfo.email, userinfo.profile): your email, name, and profile picture, to create and identify your Pointerly account.
  • Uploading (youtube.upload): uploads the video and thumbnail you composed in Pointerly to your own channel, only when you press publish.
  • Reading your channel (youtube.readonly): confirms which channel is connected, tracks when YouTube finishes processing your upload, and shows view counts of your own videos.
  • Channel metrics (yt-analytics.readonly): views, watch time, and subscriber counts, shown only to the workspace that owns the connection.
  • Google Workspace tools (Drive, Sheets, Calendar, Gmail, Meet), where you connect them: the files, events, or messages a feature needs at your request. Some of these connections are brokered by our integration provider Composio.

Google user data. We handle information received from Google APIs in line with the Google API Services User Data Policy, as follows:

  • We do not sell Google user data.
  • We do not transfer Google user data to third parties except as necessary to provide or improve the features you requested, to comply with law, or as part of a merger or acquisition with notice to you.
  • We do not use Google user data for advertising, ad targeting, or credit scoring.
  • We do not allow humans to read Google user data unless you give explicit consent for specific data, it is necessary for security or to comply with law, or the data has been aggregated and anonymized.

When an AI feature needs Google user data, it is sent only to OpenAI, under your workspace's own OpenAI key if you added one or otherwise under our OpenAI account, and never to DeepSeek (see AI processing).

Storage and deletion. We store the OAuth tokens for the connection, encrypted, together with your channel identifier, public channel details, and the identifiers and metrics of videos published through Pointerly. You can disconnect at any time in Integrations, which deletes the stored tokens, and you can revoke access at myaccount.google.com/permissions. Deleting your workspace deletes the associated connection data.

Amazon and restricted partner data

Pointerly classifies Amazon Ads API and Creator Connections-derived data, such as campaign identifiers, advertising or affiliate metrics, eligibility and enrollment data, raw partner payloads, and credential references, as restricted partner data.

  • We do not sell Amazon Ads, Amazon affiliate, or Creator Connections data.
  • Automated third-party exports of restricted partner data are blocked by default.
  • Exports that contain it must be started by the customer and sent only to the customer's own connected destination, and we keep audit records of them.
  • Official Amazon Creator Connections API sync stays disabled unless Amazon approves the required app, scopes, and endpoints.

Delegated Workspace and staff access

If your workspace enables the Delegated Workspace add-on, Pointerly operators assigned to it can see and work with the workspace's data within the operator role to carry out your requests. Operators are Pointerly staff with an approved company email address, must use multi-factor authentication, cannot access billing, members, API keys, or the browser extension, and their access is logged. Access ends when the add-on ends.

Outside Delegated Workspace, a small number of authorized staff may access account data when needed to provide support you ask for, keep the service secure, investigate abuse or reports, or comply with law. Administrative access requires multi-factor authentication and is logged.

How we share data

  • Subprocessors and service providers who host, store, process, or deliver data for us, listed on our Subprocessors page.
  • Link safety services: destination addresses of links are checked against Google Web Risk and Cloudflare's DNS filtering resolvers (and abuse.ch URLhaus when enabled). The destination host and address and the page's public title, description, and site name may be classified by our AI providers (OpenAI, with DeepSeek as fallback). This is standard data: no visitor or account data is sent.
  • Platforms and tools you connect, when you publish, send, export, or sync through them. They handle the data under their own terms.
  • Members of your workspace, according to their roles, and Delegated Workspace operators where you enable it.
  • The public, for content you choose to publish, such as bio pages, storefronts, creator and brand profiles, and posts.
  • Authorities and others where the law requires it, to respond to valid legal process, to protect people from harm, to enforce our terms, or to report illegal content such as child sexual abuse material.
  • A buyer or successor in a merger, acquisition, financing, or sale of assets, subject to this policy.

We do not sell personal data and do not share it for cross-context behavioural advertising.

International transfers

Pointerly is based in Brazil, and most of our providers process data in the United States. Some providers process data in other countries, including the People's Republic of China for our fallback AI provider (DeepSeek), which only receives standard AI requests and never the sensitive data described under "AI processing", and global edge locations for content delivery. These countries may not offer the same level of protection as your own.

Where GDPR, UK GDPR, or LGPD require a safeguard for these transfers, we rely on the contractual safeguards our providers offer, such as data processing agreements and standard contractual clauses, where they offer them, and on the other grounds the law allows, such as transfers necessary to perform our contract with you. You can ask us which safeguard applies to a given provider.

Retention

We keep personal data only as long as we need it for the purposes above. Typical periods:

Account and workspace data

While the account or workspace is active. When you delete your account, access is revoked immediately and your personal account data is deleted from active systems after a 30-day grace period. Workspaces you own are transferred to another member you choose or, if there is none, archived: their links are paused, pages unpublished, and members removed. An archived workspace is permanently deleted, with its links, pages, analytics, and files, 12 months after it was archived; the former members we have on record are emailed 30 days before. Payment records shared with a brand and security logs are kept as described below. You can ask us to delete an archived workspace sooner at privacy@pointerly.io.

Link click and page-view records

Kept for as long as the workspace exists, unless the customer deletes the link or the workspace, so reports keep working. Only a shortened IP address is ever stored. After 90 days we delete the shortened IP address, the full user agent, the full referring address, and the city from each record; country, region, device, browser, operating system, referring domain, and campaign parameters remain. Your plan’s analytics window limits how far back reports show data; it does not shorten storage.

Messages, subscribers, and automation history

For as long as the customer keeps them in the workspace, or until the connected account is disconnected and the related data is deleted, or a platform deletion request is processed.

Connected account tokens

Until you disconnect the account, the token is revoked, or the workspace is deleted.

AI conversations and generated content

In the workspace until the customer deletes them or the workspace is deleted. Retention by AI providers is described under "AI processing".

Billing and tax records

For the period required by tax and accounting law, which may be several years after the account closes.

Security, audit, and operational logs

For as long as needed for security, investigations, and compliance. Some operational logs, such as scheduled job history, are pruned after 7 days.

Backups

Our database provider keeps encrypted daily backups for 7 days, so deleted data leaves our backups within 8 days.

Enforcement and legal records

Data about policy breaches, abuse reports, and legal requests may be kept for as long as needed to prevent repeat abuse, comply with law, or defend legal claims.

Security

We protect data with encryption in transit, provider-managed encryption at rest, encrypted storage of connection tokens and AI provider keys, database-level workspace isolation, role-based permissions, multi-factor authentication for staff, and audit logs. No system is perfectly secure. See our Security page for details. If a personal data breach affects you, we will notify you and the authorities where the law requires.

Your rights

Depending on where you live, you may have the right to:

  • confirm whether we process your data and get access to a copy of it;
  • correct inaccurate or incomplete data;
  • delete data, or have it anonymized or blocked where it is unnecessary or unlawful;
  • receive your data in a portable format, or have it sent to another provider;
  • restrict or object to processing, including processing based on legitimate interests and direct marketing;
  • withdraw consent at any time, without affecting earlier processing;
  • know which third parties we share data with, and the consequences of refusing consent;
  • ask for review of decisions made solely by automated processing;
  • complain to a data protection authority, such as your local EU supervisory authority, the UK Information Commissioner's Office, or Brazil's Autoridade Nacional de Proteção de Dados (ANPD).

You can access, export, and delete much of your data in the product, and delete your account in account settings. Otherwise, email privacy@pointerly.io. We will verify your identity and, for requests made on someone else's behalf, your authority. We respond within the time the law requires, for example one month under GDPR (extendable in some cases) and 15 days for a full response under LGPD. If we turn down a request, we will explain why and how to appeal.

If your data reached us through a Pointerly customer, such as a creator whose link you clicked or a business you messaged, see "Controller and processor roles" above.

California and other US states

This section applies to residents of California and other US states with comprehensive privacy laws. In the past 12 months we collected these categories of personal information: identifiers (name, email, IP address, account IDs); customer records and commercial information (billing and purchase history); internet and network activity (usage, clicks, logs); approximate geolocation; the content of communications you send us or through the service; and account login credentials, which are sensitive personal information. Sources, purposes, recipients, and retention are described above.

  • We do not sell personal information or share it for cross-context behavioural advertising.
  • We do not use sensitive personal information to infer characteristics about you.
  • We do not knowingly sell or share the personal information of consumers under 16.

You may request to know, access, correct, or delete your personal information, and to appeal our decision, by emailing privacy@pointerly.io. You may use an authorized agent. We will not discriminate against you for exercising your rights. We do not sell or share personal information. We also honour a Global Privacy Control signal on our website as a refusal of analytics cookies, which otherwise stay off unless you accept them.

Children

Pointerly accounts are for adults aged 18 or older. Our services are not directed to children, and we do not knowingly collect personal data from children under 13 (or under 16 in the EU and UK, or the age set by local law). Our customers must not use Pointerly to target children with messages or restricted products. If you believe a child has given us personal data, contact privacy@pointerly.io and we will delete it.

Automated decisions

We use automated processing to route links, flag likely bot traffic, enforce usage limits, detect abuse, and power AI features. We do not make decisions based solely on automated processing that produce legal or similarly significant effects on you. Where an automated signal leads to an enforcement action on your account, you can ask for human review, as described in our Acceptable Use Policy.

Marketing communications

We send service messages, such as security, billing, and product notices, as part of providing the service. We send marketing email only where the law allows, and every marketing email has an unsubscribe link. Push notifications in the iOS app can be turned off in your device settings.

Changes to this policy

We may update this policy when our services, providers, or the law change. We will update the date above and, for material changes, notify you by email or in the product before they take effect.

Contact

Questions about this policy or our data practices: email privacy@pointerly.io or write to SEAN LUIS GUADA RODRIGUEZ CONSULTORIA EM TECNOLOGIA DA INFORMACAO LTDA, Avenida Prefeito Osmar Cunha, 416, Centro, Florianópolis – SC, CEP 88015-100, Brazil.

Version history

  • October 2, 2026: Added abuse reports and link safety checks. Filled in company details and data protection officer. AI: sensitive data (Google user data, mailboxes, attached files, audience messages) is processed only by OpenAI, never by DeepSeek or another fallback provider. Visitor data: IP addresses are stored shortened, raw request details are deleted after 90 days, the visitor identifier uses a monthly secret that is then destroyed, and bot clicks are not billed. Archived workspaces are deleted 12 months after archiving, with notice to former members. Backups: stated the actual 7-day backup retention. Global Privacy Control is honoured as a refusal of analytics cookies.
  • October 1, 2026: Rewritten. Named our AI providers (OpenAI and DeepSeek) and the data each receives, added controller/processor roles, end-user data, Meta platform data, Delegated Workspace access, international transfers including China, a retention table, and rights under GDPR, UK GDPR, LGPD, and US state laws.
  • September 4, 2026: Previous version.