Privacy Policy
Effective date: [YYYY-MM-DD — set this before publishing]
This policy covers the Pointer feedback widget (<pointer-feedback>), the
Pointer browser extension, and the Pointer dashboard. Pointer can be run as a hosted service
or self-hosted by an organization on its own server. When you use a self-hosted instance, that
organization — not the operator of the hosted service — controls your data; this policy
describes how the software handles data in either case.
What we collect
- Account information — email address, a hashed password, display name, and role, used to sign in and identify who left a comment.
- Feedback content — the comment text you write, the page route, the environment (local/staging/production), and metadata about the element you clicked: its selector, the CSS rules that apply to it, a text snapshot of nearby content, and (optionally) a screenshot.
- Diagnostic context (opt-in, per comment) — if a project enables it and you check "Report as a bug," recent console errors/warnings, failed or slow network requests (method, URL, status code, duration — never request/response headers or bodies), and your browser's user-agent string.
- Preferences — your interface language, theme, and (if set) a custom keyboard shortcut, stored against your account so they follow you across devices.
- Browser extension data — your session sign-in token, stored only in the extension's isolated session storage and never exposed to the pages you visit; and, per browser, which project/environment you last picked for each domain you activated the extension on.
How we use it
Collected data is used solely to operate the feedback/annotation workflow: authenticating you, displaying and organizing comments for your team, and giving an AI coding tool (which you choose and run yourself — Pointer does not include or operate one) enough context to apply the requested change to your real source code.
Where it's sent
All of the above is sent only to the Pointer server URL configured for your installation — either the hosted service, or a self-hosted server your organization runs and controls. Pointer does not sell your data, does not use it for advertising, and does not share it with third parties beyond what's needed to operate the server you've chosen to use.
Browser extension permissions
The Pointer browser extension requests the following, each solely to inject the feedback widget on a tab you explicitly activate:
- Host access (all sites) — to inject the widget into the page on tabs you activate. You choose which sites to activate on; the extension does not act on tabs you haven't activated.
- Content-Security-Policy adjustment — on an activated tab only, so the widget can load on sites with a strict CSP. Removed automatically when you deactivate or close the tab.
- Scripting — to inject the widget into the activated tab.
- Storage — to keep you signed in and remember your per-site project choice.
Data retention
Comments and account data are retained until deleted by you or an administrator of your workspace. Deleting a project removes its associated comments.
Security
Passwords are stored hashed, never in plain text. The browser extension keeps your sign-in token in isolated session storage — it is never written into any page you visit. Each workspace's data is isolated from other workspaces on the server side.
Children's privacy
Pointer is a developer tool and is not directed at children.
Changes to this policy
If this policy changes, the updated version will be published at this same URL with a new effective date.
Contact
Questions about this policy: [contact email — set this before publishing]