Privacy Policy
This Privacy Policy describes how Point11, Inc., a Delaware corporation (“Point11,” “we,” “us,” or “our”), collects, uses, discloses, and protects personal information when you visit our website (point11.ai), use our platform, or interact with our services.
1. Information We Collect
Information you provide: name, email address, company, and role when you create an account, fill out a form, or request a demo; billing details when you subscribe (payments are processed by Stripe; we never store full card numbers); and the content of your messages when you contact us.
Information collected automatically: device and usage data such as IP address, browser type, pages visited, and session duration, collected through cookies and similar technologies (see Section 5).
AI conversations: if you talk to the chat or voice assistant on our website, we collect the conversation content and session metadata. Voice calls are recorded and transcribed, and the voice assistant tells you so before a call starts. To make follow-up conversations useful, we also maintain a lightweight profile of your interactions (for example, topics you asked about). This applies to signed-in users and anonymous visitors alike, and the profile is shared between the chat and voice assistants. Anonymous chat conversations are deleted 31 days after they start and voice conversations 30 days after they end. Our voice provider, ElevenLabs, keeps each call's recording and transcript in its own systems for up to 30 days and then deletes them. Our chat assistant runs on Vercel, which keeps its own working copy of each chat session, including its messages, until the session closes (at most 30 days after that session starts) and for up to 7 days after that, and then deletes it. Deleting a conversation or closing your account does not shorten that period. The profile is kept until you ask us to delete it or, if you are signed in, until you close your account. To have it deleted, email legal@point11.ai.
Analytics product data: when customers run our analytics products, we collect publicly available web content about the requested websites and brands (including competitors' websites used for comparison), send AI-driven browser visits to those websites, hold conversations with AI models led by synthetic customers (AI-generated personas), and store the resulting reports as durable customer artifacts. We also produce aggregated, de-identified benchmarks across customers; these cannot reasonably be used to identify any person.
Customer uploads: customers may upload a CRM export to seed synthetic customer generation. The file is parsed in your browser. Columns that identify people (such as names, email addresses, phone numbers, street addresses, dates of birth, and account or device identifiers) or hold sensitive data (such as government identifiers, payment or health data, race, ethnicity, religion, sex, or gender) are rejected, and only the mapped rows you confirm are sent to us, with email addresses, links, and phone numbers removed from free-text fields. To confirm the mapping, the column headers and up to five sample values from each remaining column are sent to an AI model that proposes the mapping and to an AI model that checks the upload against our acceptable-use rules. The sample values are never stored in our AI model call records; the acceptable-use check keeps the headers and sample values as its record. The confirmed rows are processed by the AI model providers in Section 3 to build generalized customer profiles and are then deleted (rows of a failed upload within seven days).
Connected CRMs: a customer may instead connect HubSpot or Salesforce. To build generalized customer profiles, we read CRM records without names, email addresses, or other personal identifiers. If the customer also chooses connected contacts, we read those contacts' names, email addresses, job titles, and companies, and their call and meeting transcripts, and keep them up to date, to build a synthetic customer modeled on each contact; the AI model providers in Section 3 process these records.
Connected Google Ads: a customer may connect Google Ads by having one of its members sign in with Google. We read only the Google Ads accounts the customer chooses and, for each one, its keywords and Google's Quality Score history with impressions and cost, to show the customer how Google rates its ads. We change a Google Ads account only when the member whose sign-in connected it confirms a draft in Alpha: we then create paused ads from the customer's saved ad suite in the campaign or ad group that member picked, which can add a new paused ad group and upload the ads' images as image assets. We never enable ads, change budgets or bids, or pause or change anything already in the account. For the ads we created, we read their daily impressions, clicks, conversions, and cost. Vercel Connect holds the Google sign-in for us, and we never see the member's Google password. When the customer disconnects Google Ads, we revoke our access at once.
Connected Google Analytics: a customer may connect Google Analytics by having one of its members sign in with Google. We list the names of the properties that sign-in can reach, so the customer can choose which ones we read. From the ones it chooses, we read each property's time zone and currency and only daily totals: visits, key events, and purchase revenue, and the visits that arrived from AI assistants and the pages those visits landed on. We do not receive information about individual visitors, and we never change anything in Google Analytics. Vercel Connect holds the Google sign-in for us, and we never see the member's Google password. When the customer disconnects, we stop reading at once and revoke our access.
Connected Vercel Web Analytics: a customer may connect Vercel Web Analytics by having one of its members sign in with Vercel. We list the names of the Vercel projects that sign-in can reach with Web Analytics turned on, so the customer can choose which ones we read. From the ones it chooses, we read only daily totals: the visitors to the project's production website, the visitors that arrived from AI assistants, and the pages those visitors landed on. We do not receive information about individual visitors, and we never change anything in Vercel. Vercel Connect holds the Vercel sign-in for us, and we never see the member's Vercel password. When the customer disconnects, we stop reading at once and revoke our access.
2. How We Use Your Information
- Providing, operating, and improving the Point11 platform and services
- Processing transactions and sending related communications
- Responding to inquiries, support requests, and feedback
- Analyzing usage patterns to improve the product
- Detecting and preventing fraud, abuse, and security issues
- Complying with legal obligations and enforcing our terms
We do not sell personal information, and we do not use customer data to train our own AI models. Some AI model providers may use the data they process for us to improve their models; see Section 3.
Point11's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We use Google Ads data only to show the customer its own ads' quality and results and to create the paused ad drafts its member confirms, and Google Analytics data only to show the customer its own traffic and revenue totals and how they moved after changes to its website: we do not use this data for advertising, we do not sell it, we do not use it to train AI models, and our staff read it only with the customer's permission, to keep the service secure, or when the law requires.
3. Service Providers
We share information with service providers only as needed to operate the platform. Each may use it solely to provide services to us, except as described under AI model training below:
- Hosting and infrastructure: Vercel (application hosting, content delivery, file storage, background jobs, and isolated sandboxes that render websites and generated artifacts), Neon (database), Upstash (cache and rate limiting).
- Automated browsing: Browserbase (remote browsers that visit the websites a customer specifies, and competitors' public websites, for Experience runs) and BrowserStack (real mobile devices, when a customer tests a native mobile app).
- AI model providers: Anthropic, OpenAI, Google, xAI, and Meta (language, image, speech, and transcription models) and Perplexity (web search inside model tool loops), accessed via Vercel AI Gateway; ElevenLabs (the voice assistant, which runs an OpenAI language model within ElevenLabs' service); and, when a customer configures its own credentials, that customer's Amazon Bedrock, Microsoft Azure, or Google Vertex AI account.
- Business data and locations: Google (Places for business location lookup, PageSpeed Insights for site performance checks, and Web Risk for URL safety checks) and Mapbox (maps, and geocoding of business and customer location text).
- Tools a customer connects: HubSpot and Salesforce (CRM records the customer chooses to import), Google Ads (keywords and Quality Score from the Ads accounts the customer chooses, and paused ad drafts, with their results, only when a member confirms them), Google Analytics (daily traffic and revenue totals from the properties the customer chooses), Vercel Web Analytics (daily visitor totals from the projects the customer chooses), Slack (only when a customer installs the Slack agent into its own workspace), and Linear (only when a customer connects it to Alpha).
- Identity and payments: WorkOS (sign-in, single sign-on, and encrypted storage of the test-account credentials a customer provides for Experience runs), Stripe (payment processing).
- Communications: Resend (email delivery) and Google Workspace (our email and calendar, including demo bookings).
- Website analytics: Vercel Web Analytics and Speed Insights (anonymized page-view and performance telemetry).
- Product analytics: PostHog (US-hosted), within the signed-in application only. We send it your user ID, email address and name, the ID and slug of the organization you are working in, page views with query strings removed, and the type of any application error; our relay passes along your IP address. We do not record sessions, do not capture clicks or what you type, strip error messages and stack traces before they leave your browser, and create no PostHog profile for signed-out visitors.
AI model training: Meta may use the inputs and outputs of its Muse Spark models to improve its models under Meta's terms. Muse Spark currently runs many Point11 Analytics features, including business profile research and forecasts, synthetic customer generation, Discovery conversation analysis, customer research studies, CRM imports and connected CRM contacts, Alpha and Ask Data, Experience analysis, Inspector benchmarks, and First Month Free eligibility reviews, as well as the chat assistants on Point11's website and demos when you are not signed in. These calls can include public web content about the brands and websites analyzed, synthetic customer conversations, the CRM records and contact details described in Section 1, the questions and material customers enter, and the messages visitors who are not signed in send to our website chat assistant. For our other language and image model calls through Vercel AI Gateway, we ask the Gateway to use only providers that do not train on the data sent. Speech, transcription, and voice calls are handled under each provider's own terms.
We may also disclose information when required by law or valid legal process, or in connection with a merger, acquisition, or sale of assets (in which case we will notify you).
4. Data Retention
We retain personal information for as long as needed to provide our services, maintain our business relationship with you, comply with legal obligations, and resolve disputes. When it is no longer needed, we delete or anonymize it. Deleted data can remain in our encrypted database backup history for up to 30 days after it is deleted, and then it expires. You can request deletion of your data at any time by emailing legal@point11.ai.
When you close your user account, we delete your assistant profile, remove your name and email address from your user record, and delete the chat conversations and messages tied to your account within 30 days. Your sign-in record at our identity provider, WorkOS, is not deleted automatically; email legal@point11.ai to have it removed.
When an organization account is closed, whether by its owner in the product or by us at the owner's request, its API keys, invitations, and connected-tool grants are revoked at once. Thirty days after closure we begin permanently deleting, or irreversibly redacting, all of the organization's data, and we finish within 45 days of the closure. This covers everything the organization and its members provided and everything our services produced for it, including its campaigns and their Discovery, Research, Experience, and Inspector results; its customers, including synthetic customers and contacts synced from a connected CRM, and the business profiles and forecasts they were built from; records of calls and meetings; data read from Google Ads and our records of the paused ad drafts we created there; the daily totals read from Google Analytics and Vercel Web Analytics; uploaded CRM rows and stored files; conversations, voice sessions, and comments; Alpha and Ask Data content; saved locations, study drafts, and agent and site settings; and the inputs and outputs of its AI model calls. We keep only our security audit log, for at least one year; the billing and tax records the law requires us to keep; and records stripped of that data, which keep only identifiers, dates, and counts. To ask us to close an organization and delete its data, email legal@point11.ai.
Records of AI model calls, including their inputs and outputs, are kept for up to 365 days and then redacted; the fact of each call and its cost are kept with billing records. Retention periods for website conversations and customer uploads are described in Section 1.
Information you submit through our website forms and demo bookings (a booking also creates an event in our Google Workspace calendar), and the website visitor records linked to the __visitor_id cookie, have no fixed deletion date: we keep them until you ask us to delete them or we delete them.
6. Your Rights and Choices
You may request to:
- Access a copy of the personal information we hold about you
- Correct inaccurate personal information
- Delete your personal information
- Receive a copy of your data in a structured, machine-readable format, prepared by our support team
- Opt out of marketing emails (use the unsubscribe link or contact us)
If you are a California resident or a resident of another U.S. state with comprehensive privacy legislation, these rights, including the right to know, the right to opt out of the sale or sharing of personal information (we do not sell or share it), and the right to non-discrimination for exercising your rights, apply as provided by your state's law.
To exercise any of these rights, contact us at legal@point11.ai. We will verify your identity and respond within the time required by applicable law. We complete a request to delete an organization's data within 45 days, as described in Section 4.
7. Security
We implement commercially reasonable administrative, technical, and physical safeguards to protect personal information, including encryption in transit and at rest. For details on our security practices, see point11.ai/security. No method of transmission over the Internet is completely secure.
8. International Data Transfers
Point11 is based in the United States. If you access our services from outside the United States, your information will be transferred to and processed in the United States.
9. Children's Privacy
Our services are not directed to individuals under the age of 16. We do not knowingly collect personal information from children. If we become aware that we have collected personal information from a child, we will take steps to delete it.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page with a new “Last Updated” date and, where required, by providing additional notice (such as email).
11. Contact Us
Point11, Inc.
2301 Collins Avenue, Apt 334
Miami Beach, FL 33139
Email: legal@point11.ai