🐕 Pointer

Privacy Policy

Effective date: 2026-09-23

This policy covers the Pointer feedback widget (<pointer-feedback>), the Pointer dashboard, the Pointer browser extension, and the Pointer CLI (pointer-feedback, used to install the widget and apply comments). Pointer can be run as a hosted service or self-hosted by an organization on its own server. When you use a self-hosted instance, that organization — not the operator of the hosted service — controls your data; this policy describes how the software handles data in either case. For the engineering-level view of what is captured, see Data & self-hosting.

1.Data controller

The hosted service at pointer.moamen.work is operated by Moamen UI (operating as "Pointer"), based in Riyadh, Kingdom of Saudi Arabia, which acts as the data controller for hosted-service accounts under the Saudi Personal Data Protection Law (PDPL). [LEGAL-REVIEW: confirm the controller's registered legal name, commercial registration (CR) number, and registered address before this page is relied on by a paying customer.] If your organization self-hosts Pointer, your organization is the data controller for your installation, not Moamen UI.

2.Legal basis (PDPL)

Under the Saudi Personal Data Protection Law, we process account information and feedback content on the basis of legitimate interest — operating the feedback and annotation service you or your organization signed up for. Where a project enables the optional "Report as a bug" diagnostic context, we rely on your consent, given per comment, to collect that additional data. [LEGAL-REVIEW: confirm this maps to the correct PDPL Article references for legitimate-interest and consent processing once counsel reviews.]

3.Legal basis (GDPR section)

For users located in the European Economic Area, we additionally note the equivalent GDPR basis: legitimate interest (Art. 6(1)(f)) for operating the service, and consent (Art. 6(1)(a)) for optional diagnostic context. Pointer does not make an EU-residency promise — all data is stored in the Oracle Cloud Riyadh region regardless of where you are located (see Data residency below); this section exists so EEA-based users know which rights apply to them, not to promise EU storage.

4.What we collect

5.Browser storage — what the widget stores on your device

The <pointer-feedback> widget stores the following in your browser. No cookie is set — the widget uses only localStorage and sessionStorage, scoped to the site that embeds it.

6.Screenshots

A screenshot may be captured alongside a comment when the screenshot option is enabled for the project. It is stored server-side in the same region as the database, attached to that comment, and is deleted when the workspace it belongs to is deleted. Deleting a single comment hides it and its screenshot from every screen; the file itself is removed by a scheduled clean-up of deleted comments (see the retention table) rather than immediately. A screenshot depicts the customer's application UI at the moment of the comment, not the commenter's personal data. On a data-subject access/erasure request, the operator can delete individual screenshots on a targeted basis.

7.Data retention

Comments and user accounts are retained until deleted by you or an administrator of your workspace; deleting a comment or project hides it everywhere immediately. Separately, the following operational data classes are retained on a fixed schedule and then purged automatically:

A full account deletion tombstones your account: your comments and replies are kept but re-attributed to the tombstone rather than your name. A full, unrecoverable hard-delete of a workspace's comment rows happens only when the whole workspace is deleted — including when a workspace admin requests it themselves (Settings → Danger zone), after the cancellable grace period above.

8.Data residency

All Pointer data — accounts, comments, screenshots, and diagnostic context — is stored in the Oracle Cloud Riyadh region (Middle East). No data is transferred to the EU or US except for transactional email delivery via Brevo (see Subprocessors below).

9.Subprocessors

10.Widget consent posture — for your own privacy policy

If you embed the Pointer widget in your own product, you are the data controller for the people who use it. The paragraph below is written so you can paste it into your own privacy policy as a starting point:

Paste into your privacy policy

"We use Pointer (a third-party feedback tool) to collect feedback from our team and users. The Pointer widget stores a session token and display preferences in your browser's localStorage (no cookies are set). Data is processed in Saudi Arabia. See Pointer's privacy policy for details."

11.Internal access & operator visibility

By default, Pointer staff access to the hosted service is metadata only — counts, statuses, tenants, billing, and health — not the content of your comments or replies. Current status (as of this policy's effective date): the underlying database access used by operator/support tooling can, today, read any workspace's comment content when an operator uses it, and that access is not yet logged to a customer-visible security log. An audited, time-boxed impersonation flow — visible to your workspace admin through an in-product audit log — is designed and is being built, but has not shipped yet. Until it ships, treat operator access to comment content as "staff access on an as-needed basis," not as "audited and time-boxed." This section will be updated, with a changed effective date, once that audited access log ships.

12.Your rights (PDPL)

Under the PDPL, you may request: access to your personal data, correction of inaccurate data, deletion of your data, portability of your data to another provider, and to object to certain processing. Contact us using the details below to exercise any of these.

13.Your rights (GDPR)

If you are located in the EEA, you additionally have the standard GDPR rights: access, rectification, erasure, restriction of processing, data portability, and objection, plus the right to lodge a complaint with your local supervisory authority. These rights apply only to the extent GDPR applies to you as an EEA-based data subject; Pointer does not claim EU establishment.

14.Children's privacy

Pointer is a developer tool and is not directed at children. We do not knowingly collect data from children. [LEGAL-REVIEW: confirm the applicable minimum age threshold for account holders (e.g. 16, per GDPR Art. 8, vs. a locally applicable PDPL threshold) before this page is relied on for a paying customer.]

15.Changes to this policy

If this policy changes, the updated version will be published at this same URL with a new effective date.

16.Contact

Questions about this policy, or to exercise your rights above: moamen.ui@gmail.com

This is not legal advice. A Data Processing Agreement (DPA) is not yet offered — it is deferred to the first paying customer (founder decision F6). [LEGAL-REVIEW: schedule a full legal review of this policy, and confirm DPA availability/timeline, before it is the sole basis for a paying customer's compliance obligations.]