Privacy Policy.
Last updated October 11, 2026. POINT is operated by Aftershock Network, Inc., a Florida corporation (“POINT”, “we”, “us”). This explains what we collect, why, who sees it, and what you can do about it. Social media should be personal; that includes being straight about data.
The short version
- We collect what you give us (account details, your Space, posts), what the service needs to run (device and log data), and what you choose to add (phone number for friend-finding).
- We use it to run POINT, keep it safe, bill memberships, and send you the emails and texts you’d expect. We don’t sell your data and we don’t run ads today.
- You control who sees your Space and posts. Friends-only means friends only.
- You can see, change, download a copy of, and delete your data from Settings.
1. What we collect
You give us: email, password (stored only as a one-way hash), display name, date of birth (to confirm you’re 13+; never shown), your Point, photo, cover, bio, location text, interests, links, posts, photos, video, comments, reactions, friend and follow relationships, Top Friends, feedback you send, and, if you add it, a phone number (confirmed by text; never shown; used only so friends who already have your number can find you, if you allow that). Business Spaces add business contact details that are meant to be public.
Collected automatically: IP address (stored salted and hashed in logs; the raw address is not kept beyond the request), browser and device type, pages and actions in the app, timestamps, and an audit trail of security-relevant events on your account (logins, password changes, privacy changes). We strip location metadata from photos you upload.
Payments: when you buy a membership, Stripe collects your card details on its own page. We receive a token, the card brand and last four digits, and charge results. We never see or store your full card number.
2. How we use it
- To provide POINT: show your Space and posts to the audience you chose, build your feed, deliver notifications.
- To keep it safe: detect abuse, spam, account takeover and fraud; enforce the Terms and Community Guidelines.
- To bill memberships and send receipts.
- To communicate: verification codes, password resets, security alerts, receipts, and the occasional product update you can opt out of. We don’t send marketing on behalf of anyone else.
- To improve POINT: aggregate, de-identified usage statistics. We don’t profile you for advertising.
3. Who sees what
Other members and the public: what you make public is public, including through link previews and search engines where you’ve allowed indexing. Friends-only content is visible to accepted friends. Your name and photo are visible to anyone who has your link even on a friends-only Space, so people can tell it’s you before they ask to connect. Your email, date of birth and phone number are never shown. Email and phone can be used to find you only if you turn that on, and the match is exact.
Service providers who process data for us under contract and only on our instructions: hosting (our own servers in the United States), Stripe (payments), Resend (email delivery), Telnyx (text messages), and Have I Been Pwned (we send a partial hash of a new password to check it against known breaches; the password itself never leaves our server).
Legal: we may disclose information to comply with law, a valid legal process, to protect the rights, safety and property of members, the public or POINT, or in connection with a merger or sale of Aftershock Network, Inc., in which case this policy continues to apply.
We do not sell personal information and have not in the preceding 12 months, and we do not share it for cross-context behavioral advertising.
4. Your choices and rights
- See and change: everything on your Space and in Settings.
- Privacy: switch between Public and Friends-only, control email and phone findability, block people, and choose post-by-post visibility.
- Delete: delete individual posts, photos and comments at any time, or delete your whole account from Settings. Deletion is immediate in POINT and complete within 30 days once backups cycle. Some records we must keep (for example, payment records for tax purposes, or audit records of abuse) are retained as required.
- Copy of your data: download a machine-readable export any time from Settings → Privacy, or email support@welcometopoint.com and we’ll send one within 30 days.
- Email and texts: security and billing messages are part of the service; product updates have an unsubscribe link; texts are only ever one-time codes you requested.
- Residents of California, Virginia, Colorado, Connecticut, Utah, Texas, Oregon and similar states: you have rights to access, correct, delete and port your data, to opt out of sale or targeted advertising (we do neither), and not to be discriminated against for exercising them. Use Settings or email support@welcometopoint.com; we’ll verify the request through your account. You may appeal a decision by replying to our response.
- EU/UK visitors: POINT is operated from and for the United States. If you use it from elsewhere, your data is processed in the United States. Where GDPR applies, our legal bases are performance of our contract with you, our legitimate interest in running a safe service, and your consent where we ask for it; you have the rights listed above plus the right to complain to your supervisory authority.
5. Children
POINT is not for children under 13 and we don’t knowingly collect their information. If you believe a child under 13 has an account, email support@welcometopoint.com and we’ll remove it.
6. Retention
We keep your information while your account exists. After deletion it is removed from live systems immediately and from backups within 30 days. Logs with hashed IPs are kept for 90 days. Billing records are kept for 7 years as required for tax and accounting. Abuse-related records may be kept longer to prevent repeat abuse.
7. Security
Passwords are hashed with Argon2id. Sessions use short-lived tokens with rotation and reuse detection. All traffic is encrypted in transit. Uploads are re-encoded and stripped of metadata. Access to production systems is limited and logged, and we keep encrypted off-site backups. No system is perfect; if we learn of a breach affecting you we’ll tell you without undue delay.
8. Cookies
We use a small number of strictly necessary cookies for signing in and remembering your theme. There are no advertising or third-party tracking cookies. Details are in the Cookie Notice.
9. Changes
If we change this policy in a meaningful way we’ll tell you by email or in the app before it takes effect, and the date at the top will change.
10. Contact
Aftershock Network, Inc. · support@welcometopoint.com