Pointy — Privacy Policy

Effective date: June 7, 2026 Last updated: October 4, 2026

Pointy is a Chrome extension that displays cents-per-point (CPP) value ratings on hotel and airline award-search pages. This policy explains exactly what data Pointy handles, where it goes, and the choices you have.

Pointy is built local-first: the information needed to calculate and rate your points is processed and stored on your own device. Pointy does not sell your data, does not show ads, and does not build advertising or cross-site tracking profiles.


1. Summary

What Where it goes Default Your control
Award-search prices & points costs (read from the page) Stays on your device On (core feature) Uninstall to stop
Your search history & computed value thresholds Stored on your device only On (core feature) Clear via browser/extension
Currency exchange rates Fetched from a third-party rates API On — (no personal data sent)
Error/diagnostic reports Pointy's error-logging backend On (opt-out) Toggle off in the popup
Anonymous usage statistics (DAU/MAU, which chains are used) Google Analytics 4 Off (opt-in) Toggle on in the popup

2. Data Pointy reads on supported sites

Pointy runs only on the booking/award-search pages of the travel brands it supports (the full list is in the extension's permissions and the Chrome Web Store listing). On those pages, Pointy reads content already displayed to you — room/fare prices, points or miles costs, dates, and route or property identifiers — in order to calculate the cents-per-point value and draw the on-page rating badges.

3. Data stored on your device

To rate your redemptions, Pointy keeps a local history of the CPP values it has calculated, and derives per-chain value thresholds from that history. This data:

You can delete this data at any time with Delete history in the Pointy popup's Settings, by removing the extension, or via your browser's extension storage controls.

4. Currency exchange rates

To express values in your currency, Pointy fetches up-to-date exchange rates from a third-party rates provider (open.er-api.com). These requests retrieve public rate tables only; they contain no personal data, no search terms, and no identifiers.

5. Error and diagnostic reports (default ON — you can opt out)

To detect when a supported site changes and breaks Pointy, the extension can send structured, minimized error reports to Pointy's own logging backend (a rate-limited Google Cloud Function on the point-optimizer Firebase project).

These reports are strictly allowlisted and contain only:

Error reports never include URL paths or query parameters, raw error messages, stack traces, page content, your searches, or any personal information.

To prevent abuse, the logging backend also uses a one-way hash of your IP address to rate-limit reports. The IP address itself is not stored, and these rate-limit records are deleted automatically after 2 days.

This channel is on by default but fully optional. You can turn it off at any time using the "Send anonymous error reports" toggle in the Pointy popup's Settings section. When off, no error reports are sent.

6. Usage analytics (default OFF — opt-in)

Pointy can optionally send anonymous, aggregate usage statistics to Google Analytics 4 to help understand how many people use Pointy and which chains are most used. This is disabled by default and only runs if you explicitly turn on the "Share anonymous usage data" toggle in the popup's Settings section.

When enabled, the only data sent is a small set of allowlisted, non-identifying fields, such as:

Usage analytics never include URLs, search terms, destinations, dates, prices, names, or any other personal information. Pointy uses a dedicated analytics identifier for this channel that is created only when you opt in and is deleted when you opt out. This identifier is separate from the error-reporting channel.

7. What Pointy never does

8. Data retention

9. Third-party services

10. Children's privacy

Pointy is not directed to children under 13 and does not knowingly collect personal information from children.

11. Your choices

12. Changes to this policy

If this policy changes materially, we will update the "Last updated" date above and, where appropriate, note the change in the extension's release notes.

13. Contact

Questions about this policy or your data can be sent to: sunnierseattle@gmail.com