Pointy — Privacy Policy
Effective date: June 7, 2026 Last updated: October 4, 2026
Pointy is a Chrome extension that displays cents-per-point (CPP) value ratings on hotel and airline award-search pages. This policy explains exactly what data Pointy handles, where it goes, and the choices you have.
Pointy is built local-first: the information needed to calculate and rate your points is processed and stored on your own device. Pointy does not sell your data, does not show ads, and does not build advertising or cross-site tracking profiles.
1. Summary
| What | Where it goes | Default | Your control |
|---|---|---|---|
| Award-search prices & points costs (read from the page) | Stays on your device | On (core feature) | Uninstall to stop |
| Your search history & computed value thresholds | Stored on your device only | On (core feature) | Clear via browser/extension |
| Currency exchange rates | Fetched from a third-party rates API | On | — (no personal data sent) |
| Error/diagnostic reports | Pointy's error-logging backend | On (opt-out) | Toggle off in the popup |
| Anonymous usage statistics (DAU/MAU, which chains are used) | Google Analytics 4 | Off (opt-in) | Toggle on in the popup |
2. Data Pointy reads on supported sites
Pointy runs only on the booking/award-search pages of the travel brands it supports (the full list is in the extension's permissions and the Chrome Web Store listing). On those pages, Pointy reads content already displayed to you — room/fare prices, points or miles costs, dates, and route or property identifiers — in order to calculate the cents-per-point value and draw the on-page rating badges.
- This reading happens on your device, in your browser.
- Pointy does not read pages on any other website.
- Pointy does not access your account, log-in credentials, payment details, or booking history.
3. Data stored on your device
To rate your redemptions, Pointy keeps a local history of the CPP values it has calculated, and derives per-chain value thresholds from that history. This data:
- is stored using Chrome's local extension storage (
chrome.storage.local), - remains on your device and is not transmitted to Pointy or any third party,
- is used only to personalize your "good / average / poor value" ratings, which improve as you run more searches.
You can delete this data at any time with Delete history in the Pointy popup's Settings, by removing the extension, or via your browser's extension storage controls.
4. Currency exchange rates
To express values in your currency, Pointy fetches up-to-date exchange rates
from a third-party rates provider (open.er-api.com). These requests retrieve
public rate tables only; they contain no personal data, no search terms, and
no identifiers.
5. Error and diagnostic reports (default ON — you can opt out)
To detect when a supported site changes and breaks Pointy, the extension can
send structured, minimized error reports to Pointy's own logging backend
(a rate-limited Google Cloud Function on the point-optimizer Firebase
project).
These reports are strictly allowlisted and contain only:
- the error type/name,
- a code location in the form
file:line, - the origin only of the supported site where the error occurred (e.g.
https://www.example.com— no path, no query string, so no search terms, dates, destinations, or prices), - which supported chain and which part of the extension was involved,
- a small set of primitive technical fields (e.g., extension version, counts, true/false flags),
- a random installation ID and a random session ID. Pointy generates these itself; they are not linked to your name, email, Google account, or any travel-brand account, and are used only to group reports and enforce rate limits. Turning error reports off stops them from being sent.
Error reports never include URL paths or query parameters, raw error messages, stack traces, page content, your searches, or any personal information.
To prevent abuse, the logging backend also uses a one-way hash of your IP address to rate-limit reports. The IP address itself is not stored, and these rate-limit records are deleted automatically after 2 days.
This channel is on by default but fully optional. You can turn it off at any time using the "Send anonymous error reports" toggle in the Pointy popup's Settings section. When off, no error reports are sent.
6. Usage analytics (default OFF — opt-in)
Pointy can optionally send anonymous, aggregate usage statistics to Google Analytics 4 to help understand how many people use Pointy and which chains are most used. This is disabled by default and only runs if you explicitly turn on the "Share anonymous usage data" toggle in the popup's Settings section.
When enabled, the only data sent is a small set of allowlisted, non-identifying fields, such as:
- which chain was used and whether it is a hotel or airline,
- a coarse result bucket (e.g., how many results were rated),
- the extension version,
- daily/monthly active-use signals (DAU/MAU).
Usage analytics never include URLs, search terms, destinations, dates, prices, names, or any other personal information. Pointy uses a dedicated analytics identifier for this channel that is created only when you opt in and is deleted when you opt out. This identifier is separate from the error-reporting channel.
7. What Pointy never does
- No selling or sharing of personal data.
- No advertising, ad networks, or ad targeting.
- No cross-site browsing profiles or behavioral tracking.
- No collection of credentials, payment information, or booking/account data.
- No transmission of your search history, destinations, dates, or prices to Pointy's servers or any third party.
8. Data retention
- On-device data (search history, thresholds) persists until you clear it or uninstall Pointy.
- Error reports are retained only as long as needed to diagnose and fix issues, and are then deleted.
- Rate-limit records (hashed IP address) are deleted automatically after 2 days.
- Usage analytics are retained according to Google Analytics' standard retention settings.
9. Third-party services
- Google Firebase / Cloud Functions — receives optional error reports (Section 5). See Google's privacy terms: https://firebase.google.com/support/privacy
- Google Analytics 4 — receives optional, opt-in usage statistics (Section 6). See: https://policies.google.com/privacy
- open.er-api.com — provides currency exchange rates (Section 4). No personal data is sent.
10. Children's privacy
Pointy is not directed to children under 13 and does not knowingly collect personal information from children.
11. Your choices
- Error reports: turn off "Send anonymous error reports" in the popup.
- Usage statistics: leave "Share anonymous usage data" off (the default), or turn it off if you previously enabled it.
- Saved history: use Delete history in the popup's Settings to remove your saved values and ratings for every program.
- All data: uninstall the extension to stop all processing and remove on-device data.
12. Changes to this policy
If this policy changes materially, we will update the "Last updated" date above and, where appropriate, note the change in the extension's release notes.
13. Contact
Questions about this policy or your data can be sent to: sunnierseattle@gmail.com