Privacy

Pointr has no accounts, no sign-in, and no database of your data. This page says exactly what stays on your computer, what leaves it and where it goes, and what little our server holds while it works.

Pointr does not save your screenshots, questions, clipboard text, or answers on any server of ours.
Your API keys and tokens stay on your computer, encrypted with your Windows account.
Anonymous usage data is off unless you turn it on, and even then it never includes what you asked or what was on your screen.
Your requests do pass through to Google (and Tavily or GitHub if you connect them), so their terms apply too. Details below.
Last updated 2026-09-29

What stays on your computer

Pointr keeps a small folder of its own on your machine, and nothing in it is sent anywhere.

Settings
Your voice choice and on/off switches, plus the random ID used only if you opt in to usage data.
API keys and tokens
Gemini, OpenAI, Tavily and GitHub credentials, encrypted with Windows (DPAPI) so they only unlock under your Windows account. Copying the file to another machine or user gives you unreadable text.
Agent history
Your last 50 multi-step runs: what you asked, the steps taken, any text it typed, and the final answer. No screenshots. Wipe it with "Clear history" in the History window.
Browser component
The browser Pointr downloads the first time you run a browser task.
Your voice
When you hold Ctrl + Win, speech is turned into text on your own computer by a speech model Pointr downloads once. The audio is never uploaded and never saved: it's discarded as soon as the text is ready. The microphone is only on while you hold the keys. Only the resulting text leaves your computer, exactly like a typed question. The exception is if you choose "My OpenAI key" under Settings → Voice: then your speech is sent straight from your computer to OpenAI, under your own key, to be turned into text. It does not pass through Pointr's server.
Voice shortcut
To notice when you hold Ctrl + Win, Pointr uses a Windows keyboard hook that watches those two keys. It looks at nothing else you type and never records, stores or sends your keystrokes.
Speech model
NVIDIA's Parakeet model (about 670 MB, licensed CC-BY-4.0), downloaded from Hugging Face the first time you set up voice. Downloading it tells Hugging Face your IP address, like any download.

To remove everything Pointr keeps locally, delete the folders %APPDATA%\dev.pointr.app and %LOCALAPPDATA%\dev.pointr.app (where the speech model lives).

What leaves your computer, and where it goes

Pointr works by sending what it needs to answer you to a backend, which passes it to an AI model. The backend is hosted by the project, or you can run your own since the code is open source.

Screenshot & question
Sent with every question. On a multi-step task a fresh screenshot is sent before each step. They go to Pointr's backend, which forwards them to the AI provider you picked in Settings (Google Gemini or OpenAI) using your own API key. Your OpenAI key is only sent when OpenAI is the chosen provider.
Clipboard text
Only for agent: tasks, sent along with the task so the agent can use it. Same path as above.
Browser page details
During a browser task, the names of the buttons, links and fields on the page, and its address, are sent with each step so the model can pick what to click.
Web search terms
Only if you connect Tavily and a task needs live information. Sent to Tavily through the backend using your key.
GitHub requests
Only if you connect GitHub. Read-only requests using your token. Nothing is ever written back to GitHub.
Update check
Pointr asks GitHub for the latest release number on start. It sends no personal information.
Your API keys & tokens
Sent to the backend with each request only so it can call Google, Tavily or GitHub for you. They are used for that request and not stored.

What Pointr's server holds

Nothing is written to a database, and the server's queue keeps no data on disk. What it does hold, and for how long:

Screenshots & questions
In memory only, for as long as the request takes. Not saved.
Task results
The answer and plan for an agent task wait in memory for 5 minutes so your app can pick them up, then expire.
Short conversation memory
The last few questions and answers of a session, so follow-ups make sense. Kept in the server's memory only, never on disk, and cleared whenever the server restarts.
Your IP address
Held in memory for about a minute to limit abuse (rate limiting), then dropped.
Logs
Timings and error messages, such as how long a request took and whether it succeeded. Logs do not include your questions, screenshots, clipboard text, or answers, and are size-limited and rotated.

Like any web service, the infrastructure it runs on (hosting, DNS, certificates) necessarily sees standard connection details such as IP addresses. Pointr does not use them for anything.

Third parties

Google (Gemini). Your screenshots and questions reach Google's Gemini API under your own API key. How Google handles that content depends on your key's plan, and its terms differ between free and paid use. Read Google's Gemini API terms for your tier before using Pointr with anything sensitive.

OpenAI (if you choose it). If you switch the provider to OpenAI in Settings, your screenshots and questions go to OpenAI's API under your own key instead of Google's. Pointr asks OpenAI not to store its responses (the API's store option is turned off). See OpenAI's privacy policy and its API data controls for how it treats API traffic.

Tavily and GitHub. Only used if you connect them, and only for the requests described above. Their own policies apply to what they receive.

PostHog. Receives anonymous usage data from the app, and only if you opt in (see below), and anonymous page views from this website (see "This website").

Anonymous usage data (optional)

Pointr asks once, the first time you use it, and the default is off. You can change your answer any time in Settings under "Share anonymous usage data".

If you turn it on, sent
Which features get used, how many steps a task took, how it ended (finished, stopped, or errored), the Pointr version, your Windows build number, and a random ID made on your computer that isn't linked to you. Pointr also tells the analytics service not to record your IP address or location.
Never sent, on or off
Screenshots, your questions or task text, clipboard contents, file names or contents, Pointr's answers, and API keys or tokens.
Where it goes
PostHog, a product analytics service. See PostHog's privacy policy.

The random ID resets if you delete the settings file, and turning the option off stops anything further from being sent.

This website

To see how many people visit and which posts or links they came from, this site counts page views with PostHog. It is deliberately light.

Counted
Which page was opened, the site you came from and any utm_ tags on the link, your browser and device type, screen size, how far down the page you scrolled, and clicks on the download button and on links that leave the site.
Not used
No cookies, no ads, no session recordings, and no IP address or location. The visit ID is random, stays in your browser only until you close the tab, and is not linked to you.
Opting out
Turn on Do Not Track or Global Privacy Control in your browser and nothing is sent. You can also add ?notrack=1 to any address on this site to stop it in that browser.

You're in control

Turn usage data off in Settings, clear your history in the History window, disconnect any key from Settings, or delete the local folder to remove everything Pointr keeps. Pointr is open source under the AGPL-3.0, so you can read exactly what it does, or run your own backend instead of the hosted one.

Questions or concerns? Open an issue at github.com/satvikydv/pointr.