Privacy Policy
Last updated 20 Aug 2026
At Pointing Space, we prioritize your privacy and are committed to maintaining it. This Privacy Policy explains the limited types of information we collect, how we use it, and your rights regarding any data associated with our web application (the “Service”).
The Service is designed to be anonymous. We do not ask for an email address, password, phone number, or other account details. You are not required to create a named account to use Pointing Space.
1. Information We Collect
Pointing Space collects and stores only anonymous data needed to run a planning-poker session. This data does not contain personally identifiable information (PII) such as your real name, email, or payment details, and we do not use it to identify you as an individual.
Depending on how you use the Service, this may include:
- A display name and avatar you choose for a table (these are visible to others in the same room and are not verified as your real identity)
- Votes, room state, and presence information for the table you join
- An anonymous Firebase Authentication user ID (a random identifier, not linked to a name, email, or password)
- A local player identifier stored in your browser so you can rejoin with the same seat
Pointing Space does not use analytics tools (such as Google Analytics) to monitor, track, or analyze your interactions with the Service.
2. Firebase and Third-Party Infrastructure
The Service is hosted and operated using Google Firebase. We use the following Firebase products:
- Firebase Authentication (anonymous sign-in). When you use the Service, Firebase signs you in anonymously. This creates a random user ID so the app can authorize access to rooms. No email, password, or social login is used. The session is anonymous and is not tied to your real-world identity.
- Firebase App Check. App Check helps protect our backend from abuse. On the web it uses Google reCAPTCHA v3 to attest that traffic comes from our app rather than automated abuse. reCAPTCHA may collect device and usage signals as described in Google’s policies. We do not use App Check to identify you personally.
- Firebase Realtime Database. Anonymous room data (display names, votes, and table state) is stored so your team can estimate together in real time.
- Firebase Hosting. Delivers the website itself.
Google processes this data as our infrastructure provider. See Google’s Firebase Privacy and Security documentation and the Google Privacy Policy.
3. Cookies, Local Storage, and Similar Technologies
We do not set advertising or analytics cookies. The Service and Firebase do use cookies, local storage, and similar browser storage that are necessary for authentication, security, and keeping you seated at a table.
Firebase Authentication (anonymous) typically persists your anonymous session
in browser storage (commonly IndexedDB, for example firebaseLocalStorageDb),
including an anonymous user ID and tokens needed to stay signed in. The Firebase Auth web SDK
does not rely on advertising cookies. Clearing site data will sign you out of that anonymous
session.
Firebase App Check stores an App Check token in browser storage (commonly IndexedDB) so subsequent requests can be attested. Because App Check on this site uses reCAPTCHA v3, Google may set cookies and similar storage on Google / reCAPTCHA domains, including:
-
_GRECAPTCHA(and related reCAPTCHA cookies) used by Google to provide risk analysis and distinguish humans from bots -
reCAPTCHA-related entries in local storage (for example keys such as
rc::a,rc::b,rc::c, orrc::f)
Those reCAPTCHA cookies are set by Google, not by Pointing Space, and are used for abuse protection rather than to create a Pointing Space account or profile.
Firebase may also use IndexedDB for operational data such as a heartbeat store
(for example firebase-heartbeat-database).
Our app stores your chosen display name, avatar, and a local player id in the browser (via local storage / similar storage used by the app) so you do not have to re-enter them every visit. This is anonymous session data, not an identified user profile.
You can delete these cookies and storage items through your browser settings. Doing so may sign you out, require a new anonymous Firebase session, and/or reset your local display name.
4. How We Use Collected Data
Anonymous data is used solely to operate the Service: seating you at a table, showing votes, protecting the backend with App Check, and keeping an anonymous auth session. We do not use this data for marketing and do not share it with third parties for marketing, advertising, or tracking purposes.
5. Data Security
We take data security seriously and implement industry-standard measures, including Firebase Authentication and App Check, to protect information stored in our database. While we work hard to protect your data, please understand that no system is entirely foolproof, and we cannot guarantee complete security.
6. Data Retention
Anonymous data is retained as long as necessary to fulfill the purposes outlined in this Privacy Policy. Room data may be removed when it is no longer needed for the operation of the Service. Because we store only anonymous, non-personally identifiable data, this information is not treated as a personal account that can be recovered by name or email.
You can remove local browser data yourself at any time. An anonymous Firebase Auth session can be cleared by deleting site data in your browser.
7. Changes to This Privacy Policy
We may update this Privacy Policy occasionally to reflect changes in our practices or for other operational, legal, or regulatory reasons. If we make significant updates, we will update the “Last Updated” date at the top of this Policy. We encourage you to review this Policy periodically.