Point Eight Account · Legal

Privacy Policy

Last updated: September 4, 2026

Summary: Point Eight Account is the shared sign-in service for supported Point Eight products and workspaces. This policy explains how Point Eight AI Pte. Ltd. handles personal data needed to create accounts, authenticate users, maintain sessions, protect the service, and respond to support and privacy requests. This policy is a privacy notice. It is not a request for blanket consent. Where a particular optional use requires consent, we will ask for that consent separately.

1. Who We Are

Point Eight AI Pte. Ltd. ("Point Eight", "we", "us", or "our") is incorporated in Singapore and operates Point Eight Account.

Our registered address is 68 Circular Road, #02-01, Singapore 049422.

For privacy questions or requests, contact our Data Protection Officer at dpo@pointeight.ai.

2. Scope and Responsibilities

This policy applies to Point Eight Account and the account-related features used to sign in to supported Point Eight products.

Point Eight determines how and why global account data, authentication records, security records, and communications sent directly to us are processed. For those activities, Point Eight acts as the organization responsible for the processing, or as the controller where that term applies.

An organization may invite you to or manage your access to its Point Eight workspace. That organization controls its workspace content, membership decisions, and organization-specific attributes. Point Eight generally processes that information for the organization under its instructions and the applicable customer agreement. Requests about workspace content should normally be directed to the organization. You may still contact us if you are unsure, and we will help route the request.

Point Eight products may publish an additional privacy notice for product features and workspace content. That more specific notice applies to the product processing it describes.

3. Personal Data We Process

3.1 Account and Profile Data

Depending on the features you use, account and profile data may include:

Optional profile fields are not required to sign in unless the relevant Point Eight product explains otherwise.

3.2 Authentication Data

Authentication data may include:

We do not store readable passwords or readable email verification codes.

3.3 Data from Google Sign-In

If you choose Google Sign-In, Google may provide us with a Google account identifier, verified email address, name, and profile image. We request only the information needed to authenticate or link your Point Eight account. We do not receive your Google password.

3.4 Login, Device, and Security Data

When you access Point Eight Account, we may process:

3.5 Communications

We process the information you include when you contact us for account support, security matters, or privacy requests.

Please do not send sensitive personal data through profile fields or support messages unless it is necessary and we ask for it.

4. Where Data Comes From

We receive personal data directly from you, from an organization that provides or manages your workspace access, from Google when you choose Google Sign-In, from supported Point Eight products requesting authentication, and automatically from your browser, device, and use of the account service.

5. How and Why We Use Personal Data

Purpose Data Commonly Used Basis Where Applicable
Create and manage an account Account, profile, and authentication data Provide the service you request and perform our agreement with you or the relevant organization
Authenticate users and maintain sessions Authentication, login, device, and security data Provide the requested sign-in service
Link supported sign-in methods Account identifiers and verified provider or email identifiers Provide the requested account feature and prevent duplicate or unauthorized account linking
Protect accounts and the service Login, session, device, IP, rate-limit, and security data Our legitimate interests in preventing unauthorized access, replay, fraud, and abuse, and protecting service availability
Operate and improve reliability Diagnostic, error, compatibility, and performance data Our legitimate interests in maintaining a reliable and secure account service
Provide support and handle privacy requests Account data and communications Respond to your request and comply with applicable obligations
Meet legal and dispute obligations Relevant account, security, and communication records Comply with law and establish, exercise, or defend legal claims

Where consent is required for an optional processing activity, we will request it separately and explain how to withdraw it. Withdrawal does not affect processing already carried out lawfully.

An email address is required to use email sign-in. The Google account information described above is required to use Google Sign-In. You can choose another available sign-in method instead.

Point Eight Account does not make decisions based solely on automated processing that produce legal or similarly significant effects.

We do not sell personal data, use account-service data for targeted advertising, or use account, authentication, support, or workspace data to train general-purpose artificial intelligence models without a separate express agreement or consent where required.

6. How We Disclose Personal Data

6.1 Supported Point Eight Products

A supported Point Eight product may receive the minimum account and session information needed to recognize you and grant authorized access. Depending on the integration, this may include an account identifier, email address, display name, username, profile image, account status, and authentication method.

6.2 Organizations and Administrators

If an organization provides your workspace access, its authorized administrators may receive your organization membership, account status, and organization-related attributes. They do not receive your password, readable verification code, or authentication token.

6.3 Service Providers

Cloudflare provides the account service's edge network, security, Worker execution, database, email delivery, and operational logging infrastructure. Cloudflare processes relevant account and technical data to provide those services to us.

Google provides Google Sign-In when you select that method. Google also processes information independently under its own terms and privacy policy. Google is not our processor for all of its independent activities.

We require service providers acting on our instructions to protect personal data and use it only for the contracted services.

6.4 Legal, Safety, and Business Events

We may preserve or disclose information when reasonably necessary to comply with law or valid legal process, protect users or the public, investigate fraud or security incidents, enforce our agreements, or establish or defend legal claims. We limit a disclosure to what is reasonably necessary where permitted by law.

Personal data may also transfer as part of a merger, acquisition, financing, reorganization, insolvency, or sale of all or part of our business. The recipient must handle the data consistently with applicable law.

7. International Processing

Point Eight is established in Singapore. Cloudflare, Google, and other providers used for business communications may process personal data in Singapore, the United States, or other countries where they operate.

When applicable law requires safeguards for an international transfer, we use contractual or other recognized safeguards appropriate to the transfer. Contact dpo@pointeight.ai for information about safeguards relevant to your data.

8. Retention and Deletion

We keep personal data only while it is reasonably needed for the purposes in this policy. We consider the data type, account status, security risk, legal requirements, active disputes, and whether the data can be safely deleted or anonymized.

In particular:

You may request account-data deletion as described below. A deletion request may not remove data that we or the relevant organization must retain or that is needed to protect accounts and the service.

9. Security

We use technical and organizational measures designed to protect personal data. These include TLS for data in transit, salted password hashing, protected verification-code values, signed and time-limited authentication tokens, Secure and HttpOnly session cookies, access controls, rate limiting, session rotation and revocation, and security monitoring.

No method of processing or storage is completely secure. If a personal data breach occurs, we will investigate, contain and mitigate it, and notify affected organizations, individuals, or authorities when required by applicable law or contract.

10. Your Privacy Rights

Depending on applicable law, you may have rights to ask how we process your personal data, access or obtain a copy, correct inaccurate data, request deletion or restriction, object to certain processing, receive certain data in a portable format, withdraw consent, appeal a refusal, and complain to a competent privacy authority.

Send requests concerning Point Eight-controlled account data to dpo@pointeight.ai. We will confirm receipt and may request information needed to verify your identity or authority. We will explain our response and any available appeal method. We will not discriminate against you for exercising an applicable privacy right.

If your request concerns organization-controlled workspace data, we may route it to the organization and tell you who is responsible for responding.

11. Cookies and Similar Technologies

Point Eight Account uses cookies that are necessary to authenticate users, maintain, refresh, rotate, and revoke sessions, and prevent abuse. These cookies use controls including Secure, HttpOnly, expiry, path, domain, and SameSite settings. Disabling them may prevent sign-in from working.

We do not use account-service cookies for third-party advertising or unrelated cross-site behavioral tracking. Google may use its own technologies when you choose Google Sign-In, subject to Google's privacy policy.

12. Children's Privacy

Point Eight Account is not directed to children. You must meet the minimum age required to use the relevant Point Eight product in your location, and an organization must not provide a child with access unless it has the authorization required by applicable law and its agreement with Point Eight.

If we learn that a child's personal data was processed without required authorization, we will investigate and take appropriate action, which may include disabling the account and deleting the data. Contact dpo@pointeight.ai with concerns.

13. Third-Party Privacy Information

14. Changes to This Policy

We may update this policy when our services, providers, practices, or legal obligations change. We will update the date at the top. When a change materially affects how we process personal data, we will provide additional notice before it takes effect when required, such as by registered email or an in-product notice. We will request new consent only when the changed processing requires it.

15. Contact Us

Point Eight AI Pte. Ltd.

68 Circular Road, #02-01
Singapore 049422

Data Protection Officer: dpo@pointeight.ai
General inquiries: contact@pointeight.ai
Legal: legal@pointeight.ai
Website: pointeight.ai