Privacy Policy.

Last updated October 11, 2026. POINT is operated by Aftershock Network, Inc., a Florida corporation (“POINT”, “we”, “us”). This explains what we collect, why, who sees it, and what you can do about it. Social media should be personal; that includes being straight about data.

The short version

1. What we collect

You give us: email, password (stored only as a one-way hash), display name, date of birth (to confirm you’re 13+; never shown), your Point, photo, cover, bio, location text, interests, links, posts, photos, video, comments, reactions, friend and follow relationships, Top Friends, feedback you send, and, if you add it, a phone number (confirmed by text; never shown; used only so friends who already have your number can find you, if you allow that). Business Spaces add business contact details that are meant to be public.

Collected automatically: IP address (stored salted and hashed in logs; the raw address is not kept beyond the request), browser and device type, pages and actions in the app, timestamps, and an audit trail of security-relevant events on your account (logins, password changes, privacy changes). We strip location metadata from photos you upload.

Payments: when you buy a membership, Stripe collects your card details on its own page. We receive a token, the card brand and last four digits, and charge results. We never see or store your full card number.

2. How we use it

3. Who sees what

Other members and the public: what you make public is public, including through link previews and search engines where you’ve allowed indexing. Friends-only content is visible to accepted friends. Your name and photo are visible to anyone who has your link even on a friends-only Space, so people can tell it’s you before they ask to connect. Your email, date of birth and phone number are never shown. Email and phone can be used to find you only if you turn that on, and the match is exact.

Service providers who process data for us under contract and only on our instructions: hosting (our own servers in the United States), Stripe (payments), Resend (email delivery), Telnyx (text messages), and Have I Been Pwned (we send a partial hash of a new password to check it against known breaches; the password itself never leaves our server).

Legal: we may disclose information to comply with law, a valid legal process, to protect the rights, safety and property of members, the public or POINT, or in connection with a merger or sale of Aftershock Network, Inc., in which case this policy continues to apply.

We do not sell personal information and have not in the preceding 12 months, and we do not share it for cross-context behavioral advertising.

4. Your choices and rights

5. Children

POINT is not for children under 13 and we don’t knowingly collect their information. If you believe a child under 13 has an account, email support@welcometopoint.com and we’ll remove it.

6. Retention

We keep your information while your account exists. After deletion it is removed from live systems immediately and from backups within 30 days. Logs with hashed IPs are kept for 90 days. Billing records are kept for 7 years as required for tax and accounting. Abuse-related records may be kept longer to prevent repeat abuse.

7. Security

Passwords are hashed with Argon2id. Sessions use short-lived tokens with rotation and reuse detection. All traffic is encrypted in transit. Uploads are re-encoded and stripped of metadata. Access to production systems is limited and logged, and we keep encrypted off-site backups. No system is perfect; if we learn of a breach affecting you we’ll tell you without undue delay.

8. Cookies

We use a small number of strictly necessary cookies for signing in and remembering your theme. There are no advertising or third-party tracking cookies. Details are in the Cookie Notice.

9. Changes

If we change this policy in a meaningful way we’ll tell you by email or in the app before it takes effect, and the date at the top will change.

10. Contact

Aftershock Network, Inc. · support@welcometopoint.com