Privacy Policy
Last updated: September 4, 2026
1. Who We Are
Point Eight AI Pte. Ltd. ("Point Eight", "we", "us", or "our") is incorporated in Singapore and operates Point Eight Account.
Our registered address is 68 Circular Road, #02-01, Singapore 049422.
For privacy questions or requests, contact our Data Protection Officer at dpo@pointeight.ai.
2. Scope and Responsibilities
This policy applies to Point Eight Account and the account-related features used to sign in to supported Point Eight products.
Point Eight determines how and why global account data, authentication records, security records, and communications sent directly to us are processed. For those activities, Point Eight acts as the organization responsible for the processing, or as the controller where that term applies.
An organization may invite you to or manage your access to its Point Eight workspace. That organization controls its workspace content, membership decisions, and organization-specific attributes. Point Eight generally processes that information for the organization under its instructions and the applicable customer agreement. Requests about workspace content should normally be directed to the organization. You may still contact us if you are unsure, and we will help route the request.
Point Eight products may publish an additional privacy notice for product features and workspace content. That more specific notice applies to the product processing it describes.
3. Personal Data We Process
3.1 Account and Profile Data
Depending on the features you use, account and profile data may include:
- email address, username, display name, and full name;
- profile and background images, biography, birthday, and language preference;
- internal account identifier, account type, account status, and account-creation and update times;
- linked-account relationships and account-deletion status; and
- organization membership or organization-managed account attributes needed to provide workspace access.
Optional profile fields are not required to sign in unless the relevant Point Eight product explains otherwise.
3.2 Authentication Data
Authentication data may include:
- a salted, one-way password hash when password authentication is available;
- email verification challenge records, including a protected verification-code value, purpose, issue and expiry times, attempt count, and completion status;
- the sign-in method and provider-specific account identifiers; and
- session and token identifiers, issue and expiry times, rotation state, revocation state, channel, client, device, and app-version information.
We do not store readable passwords or readable email verification codes.
3.3 Data from Google Sign-In
If you choose Google Sign-In, Google may provide us with a Google account identifier, verified email address, name, and profile image. We request only the information needed to authenticate or link your Point Eight account. We do not receive your Google password.
3.4 Login, Device, and Security Data
When you access Point Eight Account, we may process:
- login time, IP address, authentication method, login result, and the requesting Point Eight product or channel;
- browser or device type, operating system, language, app version, client identifier, and request identifier; and
- errors, performance data, rate-limit events, and other security or diagnostic events.
3.5 Communications
We process the information you include when you contact us for account support, security matters, or privacy requests.
Please do not send sensitive personal data through profile fields or support messages unless it is necessary and we ask for it.
4. Where Data Comes From
We receive personal data directly from you, from an organization that provides or manages your workspace access, from Google when you choose Google Sign-In, from supported Point Eight products requesting authentication, and automatically from your browser, device, and use of the account service.
5. How and Why We Use Personal Data
| Purpose | Data Commonly Used | Basis Where Applicable |
|---|---|---|
| Create and manage an account | Account, profile, and authentication data | Provide the service you request and perform our agreement with you or the relevant organization |
| Authenticate users and maintain sessions | Authentication, login, device, and security data | Provide the requested sign-in service |
| Link supported sign-in methods | Account identifiers and verified provider or email identifiers | Provide the requested account feature and prevent duplicate or unauthorized account linking |
| Protect accounts and the service | Login, session, device, IP, rate-limit, and security data | Our legitimate interests in preventing unauthorized access, replay, fraud, and abuse, and protecting service availability |
| Operate and improve reliability | Diagnostic, error, compatibility, and performance data | Our legitimate interests in maintaining a reliable and secure account service |
| Provide support and handle privacy requests | Account data and communications | Respond to your request and comply with applicable obligations |
| Meet legal and dispute obligations | Relevant account, security, and communication records | Comply with law and establish, exercise, or defend legal claims |
Where consent is required for an optional processing activity, we will request it separately and explain how to withdraw it. Withdrawal does not affect processing already carried out lawfully.
An email address is required to use email sign-in. The Google account information described above is required to use Google Sign-In. You can choose another available sign-in method instead.
Point Eight Account does not make decisions based solely on automated processing that produce legal or similarly significant effects.
We do not sell personal data, use account-service data for targeted advertising, or use account, authentication, support, or workspace data to train general-purpose artificial intelligence models without a separate express agreement or consent where required.
6. How We Disclose Personal Data
6.1 Supported Point Eight Products
A supported Point Eight product may receive the minimum account and session information needed to recognize you and grant authorized access. Depending on the integration, this may include an account identifier, email address, display name, username, profile image, account status, and authentication method.
6.2 Organizations and Administrators
If an organization provides your workspace access, its authorized administrators may receive your organization membership, account status, and organization-related attributes. They do not receive your password, readable verification code, or authentication token.
6.3 Service Providers
Cloudflare provides the account service's edge network, security, Worker execution, database, email delivery, and operational logging infrastructure. Cloudflare processes relevant account and technical data to provide those services to us.
Google provides Google Sign-In when you select that method. Google also processes information independently under its own terms and privacy policy. Google is not our processor for all of its independent activities.
We require service providers acting on our instructions to protect personal data and use it only for the contracted services.
6.4 Legal, Safety, and Business Events
We may preserve or disclose information when reasonably necessary to comply with law or valid legal process, protect users or the public, investigate fraud or security incidents, enforce our agreements, or establish or defend legal claims. We limit a disclosure to what is reasonably necessary where permitted by law.
Personal data may also transfer as part of a merger, acquisition, financing, reorganization, insolvency, or sale of all or part of our business. The recipient must handle the data consistently with applicable law.
7. International Processing
Point Eight is established in Singapore. Cloudflare, Google, and other providers used for business communications may process personal data in Singapore, the United States, or other countries where they operate.
When applicable law requires safeguards for an international transfer, we use contractual or other recognized safeguards appropriate to the transfer. Contact dpo@pointeight.ai for information about safeguards relevant to your data.
8. Retention and Deletion
We keep personal data only while it is reasonably needed for the purposes in this policy. We consider the data type, account status, security risk, legal requirements, active disputes, and whether the data can be safely deleted or anonymized.
In particular:
- account and profile data is normally kept while the account is active;
- authentication tokens are currently configured to expire no later than 30 days after issue and may be revoked sooner;
- email verification codes expire 10 minutes after issue; related challenge records may remain for a limited period for attempt controls, abuse prevention, and operational cleanup;
- login, session, diagnostic, and security records may remain after a session ends when needed for replay detection, incident investigation, fraud prevention, or legal claims;
- support and privacy communications are kept while the request is handled and afterward when needed to document our response or meet legal obligations; and
- when an account or customer relationship ends, we delete or anonymize data that is no longer needed, subject to backup cycles and permitted legal, security, fraud-prevention, and dispute-related retention.
You may request account-data deletion as described below. A deletion request may not remove data that we or the relevant organization must retain or that is needed to protect accounts and the service.
9. Security
We use technical and organizational measures designed to protect personal data. These include TLS for data in transit, salted password hashing, protected verification-code values, signed and time-limited authentication tokens, Secure and HttpOnly session cookies, access controls, rate limiting, session rotation and revocation, and security monitoring.
No method of processing or storage is completely secure. If a personal data breach occurs, we will investigate, contain and mitigate it, and notify affected organizations, individuals, or authorities when required by applicable law or contract.
10. Your Privacy Rights
Depending on applicable law, you may have rights to ask how we process your personal data, access or obtain a copy, correct inaccurate data, request deletion or restriction, object to certain processing, receive certain data in a portable format, withdraw consent, appeal a refusal, and complain to a competent privacy authority.
Send requests concerning Point Eight-controlled account data to dpo@pointeight.ai. We will confirm receipt and may request information needed to verify your identity or authority. We will explain our response and any available appeal method. We will not discriminate against you for exercising an applicable privacy right.
If your request concerns organization-controlled workspace data, we may route it to the organization and tell you who is responsible for responding.
11. Cookies and Similar Technologies
Point Eight Account uses cookies that are necessary to authenticate users, maintain, refresh, rotate, and revoke sessions, and prevent abuse. These cookies use controls including Secure, HttpOnly, expiry, path, domain, and SameSite settings. Disabling them may prevent sign-in from working.
We do not use account-service cookies for third-party advertising or unrelated cross-site behavioral tracking. Google may use its own technologies when you choose Google Sign-In, subject to Google's privacy policy.
12. Children's Privacy
Point Eight Account is not directed to children. You must meet the minimum age required to use the relevant Point Eight product in your location, and an organization must not provide a child with access unless it has the authorization required by applicable law and its agreement with Point Eight.
If we learn that a child's personal data was processed without required authorization, we will investigate and take appropriate action, which may include disabling the account and deleting the data. Contact dpo@pointeight.ai with concerns.
13. Third-Party Privacy Information
14. Changes to This Policy
We may update this policy when our services, providers, practices, or legal obligations change. We will update the date at the top. When a change materially affects how we process personal data, we will provide additional notice before it takes effect when required, such as by registered email or an in-product notice. We will request new consent only when the changed processing requires it.
15. Contact Us
Point Eight AI Pte. Ltd.
68 Circular Road, #02-01
Singapore 049422
Data Protection Officer: dpo@pointeight.ai
General inquiries: contact@pointeight.ai
Legal: legal@pointeight.ai
Website: pointeight.ai