Legal

Privacy Policy

Effective date: May 19, 2026

1. Overview

OnPoint ("we," "us," or "our") is committed to protecting your personal information. This Privacy Policy describes how we collect, use, and share information when you use our knowledge management platform (the "Service"). By using the Service, you agree to the collection and use of information as described here.

2. Information We Collect

Account information: When you create an account or are invited to the Service, we collect your name and email address. Usage data: We log your activity within the Service, including sign-in events (with IP address), content you access or modify, searches performed, and administrative actions. This data is used for security, audit, and operational purposes. Communications: If you contact us for support, we retain records of that correspondence. We do not collect payment card information directly. If the Service incorporates billing, payment processing is handled by a third-party provider.

3. Mobile Phone Numbers and SMS

When you enable text-message multi-factor authentication, we collect the mobile phone number you provide and use it solely to send one-time verification codes (OTPs) at sign-in or during MFA enrollment. Phone numbers are stored alongside your account record and transmitted to our SMS provider (Twilio) for the sole purpose of OTP delivery. We do not use mobile phone numbers for marketing or promotional messages. Mobile information, including phone numbers and consent records, is not shared with third parties or affiliates for marketing or promotional purposes. Phone numbers may be shared with sub-processors only to the extent necessary to deliver authentication messages (see the sub-processors section below). You may remove your phone number at any time from Settings > Security, which immediately revokes the MFA factor and stops all messages to that number. You can also reply STOP to any verification message to opt out; replying HELP returns support contact information. Standard message and data rates from your carrier may apply.

4. How We Use Information

We use the information we collect to: (a) provide, operate, and improve the Service; (b) authenticate users and enforce access controls; (c) send transactional communications such as sign-in links and account notifications; (d) detect and investigate security incidents; (e) comply with legal obligations; and (f) generate anonymized, aggregated analytics about Service usage. Derived insights and product features: We process the content and contact data you store in the Service to provide product features that surface insights, relationships, and recommendations. These features may identify connections between your contacts, suggest next steps, map your professional network, and assist with outreach. Insights are generated for your benefit and are visible only to you and authorized members of your organization.

5. How We Share Information

We do not sell your personal information. We do not share contact or communications data with third parties for their own marketing, advertising, or sales purposes. We share information only in these circumstances: Service providers: We share data with sub-processors that help us operate the Service (see Section 7). Legal requirements: We may disclose information if required by law, regulation, legal process, or governmental request. Business transfers: In the event of a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. With your consent: We may share information for any other purpose with your explicit consent.

6. Data Retention

We retain your personal data for as long as your account is active or as needed to provide the Service. Activity logs are retained for a configurable period (default 90 days) and then purged automatically. You may request deletion of your account and associated data at any time (see Section 9).

7. Sub-Processors

We use the following sub-processors to operate the Service: Supabase, Inc. — database, authentication, and file storage (United States) Vercel, Inc. — application hosting and edge infrastructure (United States) Resend, Inc. — transactional email delivery (United States) Twilio, Inc. — SMS one-time-password delivery (United States) Anthropic PBC — AI-assisted content features (United States) Each sub-processor is bound by contractual obligations to protect your data consistent with this Policy.

8. Data Security

We implement technical and organizational measures to protect your information against unauthorized access, alteration, disclosure, or destruction. These include encryption in transit (TLS), row-level security on all database tables, access controls, and audit logging of sensitive operations. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

9. Your Rights

Depending on your location, you may have the following rights with respect to your personal data: Access: Request a copy of the personal data we hold about you. Portability: Receive your data in a structured, machine-readable format. Correction: Request correction of inaccurate or incomplete data. Deletion: Request deletion of your account and associated personal data. Objection: Object to certain processing activities. To exercise any of these rights, contact us at privacy@ontel.co. We will respond within 30 days. For users in the European Economic Area or United Kingdom, you also have the right to lodge a complaint with your local supervisory authority.

10. International Transfers

The Service is operated from the United States. If you are accessing the Service from outside the United States, your information may be transferred to, stored, and processed in the United States. By using the Service, you consent to this transfer. Where required, we rely on appropriate transfer mechanisms such as Standard Contractual Clauses.

11. Cookies and Tracking

We use session cookies and similar technologies solely to maintain your authenticated session and preserve user preferences. We do not use third-party advertising or behavioral tracking cookies. You may disable cookies in your browser settings, but doing so will prevent you from using the Service.

12. Children

The Service is not directed to individuals under 18. We do not knowingly collect personal information from children. If you believe a child has provided personal information to us, please contact us and we will delete it.

13. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated Policy with a new effective date. We encourage you to review this Policy periodically.

14. Contact

For privacy-related questions or to exercise your rights, contact us at privacy@ontel.co.