PointOne Connected Applications Privacy Notice

Last Updated September 30, 2026

1. Scope of this Notice

This Connected Applications Privacy Notice ("Notice") explains how PointOne Technologies, Inc. ("PointOne," "we," "us," or "our") collects, uses, discloses, and protects information when you connect PointOne to a third-party platform or use PointOne through an integration, plug-in, or AI assistant that we make available (each, a "Connected Application"). Connected Applications currently include the PointOne app for ChatGPT and may include other assistants, productivity tools, and practice-management or billing integrations that PointOne offers from time to time.

This Notice supplements the PointOne Privacy Policy. Where this Notice is silent, the PointOne Privacy Policy applies. Where this Notice and the PointOne Privacy Policy conflict with respect to a Connected Application, this Notice controls.

This Notice does not govern the third-party platform through which you access a Connected Application (for example, OpenAI and ChatGPT). Those platforms collect and process information under their own terms and privacy policies, which you should review separately.

2. Our role and the role of your organization

PointOne is a business-to-business service. You use a Connected Application through an account that a law firm or other organization (your "Organization") has established with PointOne.

  • Customer Data. Information that PointOne processes on behalf of your Organization under a written agreement — including time entries, client and matter information, timekeeper directories, billing rules, and related records — is "Customer Data." With respect to Customer Data, PointOne acts as a service provider or data processor and your Organization is the business or data controller.PointOne's processing of Customer Data is governed by our agreement with your Organization, and that agreement controls over this Notice to the extent of any conflict.

  • Account and usage information. Information about your account, your device, and your use of a Connected Application that PointOne collects for its own purposes (such as securing, operating, and improving the service) is processed by PointOne as a controller, as described in this Notice.

If you have questions about how your Organization uses Customer Data, or wish to exercise rights concerning Customer Data, please contact your Organization first. PointOne will assist your Organization as required by our agreement and applicable law.

3. Information we collect

We collect the following categories of information in connection with Connected Applications.

3.1 Information you or your Organization provide

  • Account and profile information: your name, work email address, professional title, Organization name, role or administrator status, time zone, and account settings.

  • Authorization tokens: OAuth access issued by PropelAuth for the PointOne app for ChatGPT when you authorize the connection. In connection with the PointOne app for ChatGPT, the Connected Application and ChatGPT never request or accept passwords, API keys, or one-time codes. You sign in on the hosted login page operated by PropelAuth, PointOne's authentication provider; the Connected Application and ChatGPT receive only OAuth access and refresh tokens.

  • Requests and instructions: the content of requests that a Connected Application sends to PointOne on your behalf — for example, a search you run, a time entry you ask PointOne to create or update, a timer you start, or a report you request. Depending on the Connected Application, this may include narratives, dates, durations, client and matter references, and similar details you include in your request.

3.2 Customer Data accessed or returned through a Connected Application

When you use a Connected Application, PointOne reads Customer Data from your Organization's PointOne workspace and returns results to the third-party platform so that it can respond to you. Subject to your permissions, your Organization's configuration, and any ethical walls, this may include user and firm information, directory information, client and matter information, time-entry and timer information, billing guidelines and classification codes, compliance findings, and reports and summaries. Some of this information may be confidential, privileged, or personal.

A Connected Application only returns information you are already authorized to access in PointOne. Connected Applications do not expand your permissions. Access through the PointOne app for ChatGPT is also limited by the scopes authorized for the connection. Time-entry reads and writes are limited to your own time, except that firm-wide time reads require both the applicable firm-read scope and the firm-admin role in PointOne. The connection does not provide firm-wide time-entry write access or permit acting as another timekeeper.

PointOne does not solicit, and Connected Applications are not designed to collect, special-category or otherwise restricted data — including health information, government identifiers, financial account numbers, or biometric data. Time-entry narratives and matter records supplied by your Organization may incidentally contain such information. Where they do, PointOne handles it as Customer Data under our agreement with your Organization, and does not use it for profiling or to train, fine-tune, or evaluate artificial-intelligence models.

3.3 Information collected automatically

When you use a Connected Application, PointOne automatically collects technical and usage information, such as IP address, request timestamps, device and browser information, the Connected Application and feature used, request status and duration, error and diagnostic information, and security-related events. We also maintain audit records that attribute each action taken through a Connected Application to the user and Organization that initiated it. For the PointOne app for ChatGPT, audit records contain argument field names and types rather than argument values, and application logs do not contain request or response bodies.

We use this technical information only to secure, operate, and improve the service, prevent abuse, and troubleshoot errors. We do not use it for behavioral profiling, advertising, or analysis of your query patterns. It is retained under the audit, security, and diagnostic records bucket described in Section 9.

3.4 Information from third-party platforms

The third-party platform you use to access a Connected Application (such as OpenAI) may provide PointOne with information needed to establish and maintain the connection, such as a platform identifier for your account or session. PointOne receives only the specific requests a Connected Application sends to perform the action you asked for. We do not request, receive, reconstruct, or infer your conversation history with a third-party AI assistant. No PointOne tool accepts a location input; where a Connected Application needs to interpret dates or times, PointOne uses the time zone stored in your account settings.

4. How we use information

We use information collected through Connected Applications to:

  • Provide the Connected Application — retrieving, creating, updating, and reporting on Customer Data at your direction, subject to your Organization's permissions, configuration, and ethical walls. Time entries created through the PointOne app for ChatGPT become part of your work history in PointOne. PointOne uses that history within your Organization's tenant to personalize matter suggestions for you; it does not use that history to train AI models or share it across Organizations.

  • Authenticate you and your Organization and maintain the connection between PointOne and the third-party platform.

  • Secure, audit, troubleshoot, improve, and maintain the reliability of the service, including detecting and investigating fraud, abuse, and security incidents.

  1. Artificial intelligence and model training

Connected Applications are designed to let you use a third-party AI assistant to interact with PointOne. The AI assistant is operated by the third-party platform, not by PointOne, and its outputs are generated by that platform.

PointOne does not sell Customer Data, use Customer Data for targeted advertising, or use requests, responses, or Customer Data processed through Connected Applications to train, fine-tune, or evaluate artificial-intelligence models. Where PointOne uses AI features within its own service , that processing is governed by our agreement with your Organization. For the PointOne app for ChatGPT, where AI features are enabled for your Organization, PointOne sends your inputs to OpenAI to process through its normal compliance process. Both model calls are disabled when your Organization turns off AI features. PointOne's AI vendors perform inference under terms prohibiting training on PointOne's data.

The third-party platform's own use of your prompts, conversations, and the responses it receives from PointOne is governed by that platform's terms and your or your Organization's settings with that platform. Please review those terms to understand whether the platform retains your data or uses it to improve its models.

6. How we disclose information

We may disclose information collected through Connected Applications as follows:

  • Third-party platforms, at your direction. When you use a Connected Application, PointOne returns results to the third-party platform you are using so that it can respond to you. Once information is returned to that platform, it is subject to the platform's privacy practices.

  • Your Organization. Your Organization's administrators and other authorized users may access information about your use of Connected Applications, and the Customer Data you access through them, in accordance with your Organization's permissions and instructions.

  • Practice-management, billing, and other integrations. When you release time or otherwise direct PointOne to send information to a system your Organization has configured, PointOne transmits that information to that system.

  • Service providers. Vendors that provide hosting, infrastructure, authentication, security, monitoring, AI processing, and customer-support services to PointOne, under contractual obligations to protect the information and use it only to provide services to PointOne.

  • Legal, safety, and protective purposes. Where we believe disclosure is required by law, subpoena, or legal process; to enforce our agreements; or to protect the rights, property, or safety of PointOne, our customers, our users, or the public.

  • Business transactions. In connection with a merger, acquisition, financing, reorganization, or sale of all or part of our business, subject to confidentiality obligations and to our agreement with your Organization.

  • With your consent or at your direction.

PointOne does not make Customer Data publicly available through Connected Applications.

7. Third-party platforms and integrations

Connected Applications depend on third-party platforms that PointOne does not control. Each platform has its own terms of service and privacy policy, and PointOne is not responsible for a third party's collection, use, retention, or disclosure of information, or for the accuracy or availability of its services. In particular:

  • Disconnecting a Connected Application stops future access by that platform to PointOne, but does not delete information the platform has already stored, and does not reverse actions already completed in PointOne or in a downstream billing system.

  • Managing or deleting conversations within a third-party AI assistant does not delete the underlying Customer Data in PointOne.

  • Your Organization may prohibit or restrict use of particular platforms or of Connected Applications for particular matters, clients, or categories of information. You are responsible for complying with those restrictions and with your professional, ethical, and contractual obligations.

8. Security

PointOne maintains administrative, technical, and physical safeguards designed to protect information processed through Connected Applications, including authenticated and scoped access, isolation between Organizations and users, enforcement of your Organization's permission and ethical-wall settings, encryption in transit and at rest, audit logging, and controls designed to prevent sensitive system details from being disclosed in error messages. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. You should not send information through a Connected Application that your Organization's policies do not permit.

9. Data retention

We retain information collected through Connected Applications for as long as necessary for the purposes described in this Notice. We retain and delete Customer Data in accordance with our agreement with your Organization.

How long we retain information depends on a number of factors, including whether we need to retain it:

  • to comply with the terms of your Organization's agreement with us, including any retention period your Organization has configured;

  • to secure and operate the service, investigate security incidents, and maintain audit trails;

  • to comply with or demonstrate compliance with our legal obligations, to resolve disputes, or to enforce our agreements; and

  • in relation to account information, for our tax, accounting, and audit requirements.

Information held by third-party platforms, including conversations, prompts, and responses, is retained under that platform's policies and your or your Organization's settings, not by PointOne.

When we have no ongoing legitimate business need or legal reason to process information, we will delete or de-identify it or, if that is not possible (for example, because it is held in backup archives or append-only audit logs), we will securely store it and isolate it from any further processing until deletion is possible.

10. International Data Transfers

PointOne is headquartered in the United States, and information may be processed and stored in the United States and in other countries where PointOne, the third-party platform, or our service providers operate. Those countries may have data-protection laws that differ from those of your jurisdiction. Where required, transfers of Customer Data are governed by our agreement with your Organization, including any data-processing addendum and approved transfer mechanism such as Standard Contractual Clauses. For the PointOne app for ChatGPT, where your Organization enables AI features, client-or-matter search phrases are processed through OpenAI's US-hosted embeddings API.

11. Your choices and rights

11.1 Controls available to you

  • Disconnect. You may disconnect a Connected Application at any time through the third-party platform's settings or by revoking PointOne's authorization.

  • Permissions. Your access through a Connected Application is subject to your access permissions in PointOne and the connection limits described in Section 3.2. Ask your Organization's administrator to adjust your PointOne permissions if needed.

  • Third-party platform settings. Use the platform's own controls to manage its retention and use of your conversations.

11.2 Rights concerning customer data

Because your Organization controls Customer Data, requests to access, correct, delete, restrict, or export Customer Data — including time entries and other records you have accessed or created through a Connected Application — should be directed to your Organization. PointOne will support your Organization in responding as required by our agreement and applicable law.

11.3 Rights concerning information PointOne controls

Depending on where you live, you may have the right to request access to, correction of, deletion of, or a copy of personal information that PointOne holds about you as a controller; to object to or restrict certain processing; to withdraw consent where processing is based on consent; and to lodge a complaint with a supervisory authority. You may exercise these rights by contacting us at the address in Section 14. We may need to verify your identity before responding, and we will respond in accordance with applicable law. We will not discriminate against you for exercising your rights. If we decline your request, you may appeal that decision by contacting us at the address in Section 14.

11.4 Jurisdiction-specific disclosures

  • European Economic Area, United Kingdom, and Switzerland. Where PointOne acts as a controller, we process personal data on the basis of performance of a contract, compliance with legal obligations, our legitimate interests (including securing, operating, and improving the service), and, where required, your consent.

  • California and other U.S. states. With respect to personal information collected through Connected Applications, PointOne does not sell personal information and does not share personal information for cross-context behavioral advertising. The categories of personal information we collect, the purposes for which we use them, and the categories of recipients are described in Sections 3, 4, and 6. Connected Applications are offered to employees and contractors of our business customers; rights under state privacy laws may be limited accordingly and may need to be exercised through your Organization.

  • Canada. We handle personal information in accordance with applicable Canadian privacy laws, including PIPEDA and, where applicable, Quebec's Law 25. Where we rely on your consent, you may withdraw it at any time, and you may request access to or correction of your personal information. Residents of Quebec may also have the right to data portability and to request that we cease disseminating their personal information.

  • Other jurisdictions. Additional rights may apply under local law. Contact us to learn more.

12. Children

Connected Applications are business tools intended for authorized users of PointOne and are not directed to, and may not be used by, anyone under the age of 18. We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us at the address below.

13. Changes to this Notice

We may update this Notice from time to time to reflect changes to Connected Applications, our practices, our service providers, or applicable law. We will post the updated Notice and revise the "Last updated" date above, and we will provide any additional notice required by law or by our agreement with your Organization. Your continued use of a Connected Application after an update means you have read the revised Notice.

14. Contact us

If you have questions about this Notice or PointOne's privacy practices, please contact us: PointOne Technologies, Inc., 33 East 33rd street, 10016, New York City, New York, team@pointone.com.

For requests concerning Customer Data, please contact the law firm or organization that provides your PointOne account.