Legal

Cookie Policy

Last updated: October 2, 2026

What this policy covers

This policy explains the cookies and similar technologies, such as local storage, that Pointerly uses on pointerly.io, in the web app, and on related domains. Cookies are small files a website stores in your browser. Local storage works in a similar way but is never sent to our servers automatically. All cookies listed here are set by Pointerly on our own domains unless we say otherwise.

Where we ask for consent

On our website, sign-in pages, and dashboard, a banner asks for your choice the first time you visit and again when this policy changes in a way that affects your choice. You can accept all cookies, reject optional cookies, or choose by category. Analytics tools do not load until you accept analytics cookies.

If your browser sends a Global Privacy Control signal, we treat it as a refusal of analytics cookies: analytics tools do not load and the analytics switch stays off, even if you chose "Accept all" before turning the signal on.

The banner is not shown on our customers' bio pages, short links, and public profiles, because no optional cookies are used there. See "Short links and public pages" below.

Strictly necessary cookies

These cookies are needed for sign-in, security, to route your requests to the right workspace, and to complete a referral sign-up you asked for. The service cannot work without them, so they do not need consent and cannot be switched off in the banner.

NamePurposeDuration
sb-<project>-auth-token (may be split into .0, .1, …)Keeps you signed in. Set by our authentication provider, Supabase.Up to 400 days, renewed while you use the app; removed when you sign out
sb-<project>-auth-token-code-verifierSecures the sign-in handshake with Google, Apple, Facebook, and other providers.Until sign-in completes
pointerly-active-team-idRemembers which workspace you are working in, so requests reach the right one.Browser session
pointerly-mfa-okShort-lived cache of your multi-factor authentication check.5 minutes
pointerly-account-activeShort-lived cache confirming that your account is active.5 minutes
pointerly-client-realmShort-lived cache of whether you are a customer or staff account, to route you correctly.5 minutes
airtable_pkce_verifierSecures the connection handshake when you connect Airtable.Until the connection completes
ptr_refSet only when you click "Accept invite" on a referral invite (or open an invited sign-up link). It carries the invite you chose through sign-up and account approval, so you receive the welcome gift and the person who invited you gets credit. Viewing an invite page does not set it.60 days, or until your new workspace claims the invite

Preference cookies

These cookies remember choices you make. They are set only when you change the setting, and they are not used to track you across other sites.

NamePurposeDuration
pointerly.marketing-style.v1Remembers the website colour style you picked, so pages load in it.1 year
pointerly-workspace-viewRemembers whether each workspace opens in the Workspace or Delegated view.1 year
sidebar_stateRemembers whether the dashboard sidebar is expanded or collapsed.7 days

Analytics cookies

We use these only if you accept analytics cookies. They help us understand how people use our website so we can improve it. If you later reject analytics cookies, we stop loading these tools and delete their cookies from our domains.

NamePurposeDuration
_ga, _ga_<id>Google Analytics: distinguishes visitors and sessions to measure website use.Up to 2 years
_clck, _clsk, CLID, ANONCHK, MR, MUID, SMMicrosoft Clarity: records how visitors use our marketing pages (clicks, scrolling, page views) to improve them. Clarity runs only on marketing pages, never in the dashboard.From the session up to 1 year, depending on the cookie

Google and Microsoft process this data under their own privacy policies. We do not use advertising cookies, and we do not use these tools to build advertising profiles.

Browser storage

We also use local storage in your browser for the following. This data stays on your device unless a feature sends it to us, for example when you save a draft.

Consent record

cookie-consent stores your cookie choices and the version of this policy you answered, so we do not ask again.

Sign-in and workspace

pointerly-active-team-id, pointerly_last_auth_provider (the sign-in method you used last), pointerly-pending-invite-token (a team invite you are accepting), and enterprise_proposal_token (an enterprise proposal you opened).

Drafts

Unsaved work kept on your device so it is not lost, such as pointerly-bio-editor-autosave-v2, pointerly.teleprompter.v1, and waitlist form progress (pointerly.waitlist.lead).

Interface state

Sort orders, open panels, the last page you visited, dictation language, and similar settings, for example links-sort-preference, pointerly:last-workspace-path, pointerly:dictation-lang, pointerly:operator-panel, and support:seen:<id>.

Dismissed notices

Records that you have seen or closed onboarding, tips, install prompts, and banners, for example pointerly_dashboard_onboarding_seen, pointerly-pwa-install-dismissed, pointerly_join_dismissed, and pointerly_tiktok_escape_dismissed.

When you reject optional cookies, we also clear stored preferences such as the theme, sidebar state, and last sign-in method from local storage.

Third-party services

Some services we use can set cookies or read device information on their own domains when you interact with them:

  • Sign-in providers (Google, Apple, Facebook, and others) when you sign in or connect an account with them.
  • Stripe on its checkout and billing portal pages, for payments and fraud prevention.
  • Cloudflare Turnstile on sign-up, waitlist, and contact forms, which checks browser signals to tell people from bots.
  • Mapbox, which serves the map tiles in analytics dashboards and receives your IP address when your browser loads them.
  • Platforms you connect, such as Meta, TikTok, Google, and Amazon, during their authorization screens.

Those providers' own policies apply, for example the Google Privacy Policy, the Microsoft Privacy Statement, the Stripe Privacy Policy, and the Meta Privacy Policy.

Managing your choices

Cookie preferences

Reopen the banner to change your choices at any time.

Browser settings

Most browsers let you block or delete cookies and site data. Blocking strictly necessary cookies will stop sign-in and the dashboard from working.

Provider tools

Changes to this policy

We update this policy when we add, remove, or change cookies. When a change affects optional cookies, we ask for your choice again.

Contact

Questions about cookies: email privacy@pointerly.io.

Version history

  • October 2, 2026: The referral cookie is now set only when you accept an invite, and is listed as strictly necessary. Global Privacy Control is honoured as a refusal of analytics cookies. Short links and public pages store a shortened IP address, delete raw request details after a set period, and count unique visitors with a monthly-rotating identifier.
  • October 1, 2026: Rewritten with a full list of the cookies and browser storage we use, where the consent banner appears, and how short links and public pages behave.
  • April 30, 2026: Previous version.