Privacy Policy
Last updated 17 July 2026
Point is built local-first: the design goal is that nothing about your screen leaves your machine unless you choose it to. This policy explains what DesignCheck (“we”, the controller) collects when you use the Point website, account and app, and your rights under the GDPR.
Point can run entirely on-device using a local model (Ollama). In that mode, the content you point at is processed on your computer and is not sent to us or any third party.
1What we collect
| Data | Why |
|---|---|
| Account details (name, email, password hash) | To create and secure your account |
| Billing details (plan, transaction ID) | To take payment and manage your subscription — card data is handled by Mollie, not stored by us |
| Device & licence info | To activate the app and sync across your devices |
| Basic product & diagnostic events | To keep the app working and improve it (you can opt out) |
We do not collect the contents of your screen, your prompts, or your point-anchored memory on our servers by default.
2Your memory & the things you point at
Lists, notes and the “remember this” memory are stored on your device. If you enable cross-device sync (a Pro feature), that data is transmitted and stored encrypted so we can relay it between your devices — we don't mine it. You can turn sync off and delete synced data at any time.
3AI providers
When you run an action against a cloud provider you've connected (Anthropic, OpenAI, Google, Higgsfield), the specific content for that action is sent from your device to that provider under your account and their privacy policy. We are not in that path and do not receive that content. In local mode, nothing is sent.
4Cookies & analytics
Our website uses only essential cookies plus, with your consent, privacy-friendly analytics to understand traffic. We don't use advertising trackers.
5Legal bases (GDPR)
- Contract — to provide your account, licence and subscription.
- Legitimate interests — to secure and improve the Service (balanced against your rights).
- Consent — for optional analytics and marketing email; withdraw any time.
- Legal obligation — to keep invoices for tax purposes.
6Who we share with
Only the processors we need to run Point: our payment provider (Mollie), our hosting and database provider, and email delivery. They act on our instructions under data-processing agreements. We never sell your data.
7Retention
We keep account data while your account is active and delete it within a reasonable period after closure, except records we must keep by law (e.g. invoices). Diagnostic events are kept for a limited period.
8Your rights
You can access, correct, export, restrict or delete your data, object to processing, and withdraw consent. Email privacy@designcheck.nl. You also have the right to complain to the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).
9Security
We use encryption in transit and at rest, hashed passwords, and access controls. No system is perfectly secure, but local-first design keeps the most sensitive data off our servers entirely.
10Contact
DesignCheck, Netherlands — privacy@designcheck.nl. See also our Terms of Service.