Privacy Policy
Effective: August 5, 2026 · Last updated: August 5, 2026
Anchor Point Consultancy LLC (“Point Forward,” “we,” “us”) operates the Point Forward SaaS platform at pointforward.net (the “Service”). This Privacy Policy explains what personal information we collect, how we use it, who we share it with, how long we keep it, and the rights you have over it. We wrote it in plain language on purpose.
1. What we collect
Account information you provide directly: name, work email address, organization name, role, password (hashed with bcrypt — we never see the plaintext).
Content you create in the Service: commitments, tasks, comments, contributions, project notes, and the metadata around them (created-at timestamps, assignees, dependencies).
Operational metadata we generate about your use of the Service: login events, IP address at login, browser user-agent, feature-usage events (page views, button clicks), and immutable audit trail entries capturing who did what and when.
Payment information if you subscribe: handled by Stripe. We store only the Stripe subscription ID and plan tier; we never receive or store your card number or CVC.
Communications you send us via support, contact forms, or invitation flows: your message, your email, timestamp.
2. How we use it
- To provide the Service — authenticate you, render your dashboard, deliver notifications you subscribed to.
- To operate the accountability record — the immutable audit log is the core product, and preserving it is why customers pay us.
- To keep the Service secure — rate-limit brute-force login attempts, detect unusual account activity, respond to security incidents.
- To improve the Service — anonymized aggregate usage patterns inform product decisions.
- To communicate with you — transactional emails (activations, password resets, commitment reminders you opted into) and, if you consent separately, product update emails.
- To comply with legal obligations — respond to lawful legal process, enforce our Terms of Service.
We do not sell your personal information to anyone, ever. We do not use your content to train third-party AI models.
3. Who we share it with — sub-processors
We use a small number of trusted third-party sub-processors to run the Service. Each is contractually required to protect your data and use it only for the purpose we retain them for.
- MongoDB Atlas — encrypted-at-rest database hosting (US region).
- Emergent Labs — application hosting and Kubernetes infrastructure.
- Stripe, Inc. — payment processing. Stripe's privacy policy: stripe.com/privacy.
- Resend, Inc. — transactional email delivery.
- PostHog, Inc. — product analytics (self-hostable, opt-out available in-product).
- OpenAI / Anthropic / Google (LLM providers) — used strictly for AI-assisted insights inside the Service, gated by user action. Content submitted is not used for training under our contracts.
We publish sub-processor changes at least 30 days before they take effect for enterprise customers on request.
4. How long we keep it
Active accounts: we keep your data for as long as your account is active plus 90 days after cancellation to allow reactivation.
Audit-log entries: immutable and retained for the full life of the organization's account plus 7 years thereafter, in line with common regulatory retention expectations (SOX, HIPAA financial records, federal-grant audit windows). This is a product feature, not a bug — the accountability record is what customers pay us for.
Deleted data: soft-deleted for 30 days (recoverable via support), then hard-deleted, except audit-log entries as above.
Backup retention: encrypted daily backups retained 30 days, then destroyed.
5. Your rights
Regardless of where you live, you have the right to:
- Access — request a copy of the personal information we hold about you.
- Correction — ask us to fix inaccurate data.
- Deletion — ask us to delete your data, subject to audit-log retention (item 4).
- Portability — export your commitments and audit trail in JSON or CSV.
- Object / restrict — ask us to stop specific uses of your data.
- Withdraw consent — for analytics cookies (via in-product Cookie Preferences) or marketing emails at any time.
To exercise any right, email dynesdalila@proton.me. We respond within 30 days.
GDPR (EU/EEA/UK residents): our legal bases for processing are (a) contract performance when you use the Service, (b) legitimate interest for security and product improvement, and (c) consent for optional analytics and marketing. You may lodge a complaint with your local supervisory authority.
CCPA/CPRA (California residents): we do not sell or share personal information for cross-context behavioral advertising. You may request the categories of information collected and disclosed, and exercise the rights above without discrimination.
6. How we protect it
- Encryption in transit (TLS 1.2+) and at rest (AES-256 on MongoDB Atlas).
- Passwords stored as bcrypt hashes (cost factor 12+); never in plaintext, never in logs.
- JWT-based session tokens with configurable expiry.
- Optional TOTP two-factor authentication for admin accounts.
- Role-based access control enforced at the API layer with tenant isolation verified by automated regression tests.
- Immutable audit logs of every state-changing action, kept in a separate collection with no delete/update path.
- Brute-force rate-limiting on authentication endpoints.
- Security incident response process — customers notified within 72 hours of confirmed breach.
7. Cookies and analytics
We use two categories of cookies. Essential cookies are required to keep you signed in and to remember your preferences; you cannot disable them and still use the Service. Analytics cookies (via PostHog) help us understand feature usage in aggregate. You can accept or reject analytics cookies via the Cookie Preferences panel at any time.
8. International transfers
Our infrastructure is hosted in the United States. If you access the Service from outside the US, your information will be transferred to and processed in the US. For EU/EEA/UK data subjects, we rely on Standard Contractual Clauses with our sub-processors where applicable.
9. Children
Point Forward is not intended for anyone under 16, and we do not knowingly collect data from minors. If we learn we have collected such data, we will delete it.
10. Changes to this policy
We may update this policy from time to time. If we make material changes, we will notify active account holders by email at least 30 days before the change takes effect. The “Last updated” date at the top always reflects the current version.
11. Contact us
Data controller: Anchor Point Consultancy LLC
Email: dynesdalila@proton.me
Security disclosures: see /.well-known/security.txt
