Skip to content

A note on how we think about your clients' data

On this page

This is our own answer rather than advice about how to ask for one, and it is being written in September because engagement letters go out in December and what they say is fixed for the season. Everything below points at a document you can read. Where our plain-language version and the document differ, the document is the one that binds.

  • Point reads client mail. That is what it is for, and no sentence on this page takes it back. What the page is about is what happens to that mail afterwards.
  • The two documents underneath all of it are public, versioned and dated: privacy and subprocessors, both version 1.0, both effective July 7, 2026. The binding version of most of it is in the terms.
  • Your mail is not sold, is not used to train generalized AI models unless you authorize that, and is not in the advertising pipeline. We do run advertising technology on our public marketing pages, and those two things are kept apart by name rather than by assurance.
  • Tax-return information sits outside what our standard service covers. That is a named exclusion in our own terms, and for a tax practice it is worth raising before you connect a mailbox rather than after a season has run through it.
  • We hold no security certification and there is no badge on this site. What exists instead is two dated documents, a log of what the software did, and four things you can test yourself in a first week.

What we hold, and what we made from it

Point runs on top of the mailbox your firm already keeps, on Google or on Microsoft. Nothing migrates, so the archive stays where it is and the copies described here are additions to it rather than a move.

There are three kinds of thing on our side, and firms usually think of the first one only.

The correspondence itself. Messages, threads, senders and recipients, headers, attachments, folders and labels, calendar events and availability, and the contacts around them. This is what the grant you made at your provider covers, and the grant is the reason there is no password of yours anywhere in our systems. Where that key is held, and where the off switch actually sits, is where your email credentials are kept.

What the software made from it. Summaries, the tasks lifted out of a thread with the date the client named, ranking signals, generated titles, and a search index built from numeric representations of your text so that search can work by meaning rather than by spelling. This is the part that decides most of the answers below, because it is what the product actually runs on. Our subprocessor list itemizes indexes, embeddings, summaries and outputs beside the content they came from, which is what makes it possible to ask a deletion question about them rather than infer one.

Excerpts on somebody else’s infrastructure. Producing any of the above means sending pieces of your mail to a model provider. Amazon Web Services hosts the service. Anthropic and OpenAI do the language-model processing, and OpenAI also handles voice when voice mode is used. Google’s Generative AI API produces the embeddings behind semantic search. Firebase Cloud Messaging delivers push notifications, which can carry a snippet of a message in the payload. Resend sends transactional mail, Stripe handles billing, and Cloudflare serves the marketing site you are reading. All of them are named with their roles and the data each one touches on the list, which carries a version and an effective date so you can compare it against the copy you kept.

Google and Microsoft appear on that list in a different column. For Gmail, Outlook, Calendar and sign-in they are not our subprocessors at all. They are your providers, acting on the authorization you gave, under the terms you already have with them.

One case has none of this in it. Lock a message end to end and it can be opened by its recipient and by nobody else, us included, so there is no excerpt sent anywhere, nothing derived from it, and no third-party copy for this note to describe. The cost is the obvious one: a message we cannot read is not ranked, summarized or turned into a task. It suits the handful of messages a year that warrant it rather than the way a practice runs its mail. What actually needs sealing is worked through in using an AI inbox without breaking confidentiality.

Who can read it

Four different sets of people, and the question is usually asked about the wrong one first.

People here. Not nobody. Our privacy policy at section 6.8 limits human access to support at your request, security and abuse investigation, legal compliance, troubleshooting, service operation, and cases where you have consented. A supplier who tells you no employee can ever see anything has either not thought about how support works or has described a product that cannot be fixed when it breaks. This one is testable, which is worth more than the sentence: raise a ticket about a real thread in your first week and watch what the reply turns out to know.

The model providers. They receive excerpts, under business terms with no-training controls where those controls exist. They may also process prompts, outputs, logs and telemetry for safety, abuse prevention and reliability under their own terms rather than ours, which our data processing addendum says in as many words at section 7.2. That is the copy furthest from anything your firm controls, and it is the one a no-training answer tends to hide rather than address.

Your own people. A team joins with a seat each, and a seat sees the mailbox it is connected to. What Point does not do is draw a wall between one of your clients and another inside a single mailbox. The isolation it holds is between separate businesses you operate, which is a real line and not the line most firms picture when they hear the word. Keeping one business isolated from another sets out exactly what it holds and the four places it stops.

Whoever administers your workspace. If Point is used through an organization, admins can access, manage, export, delete and restrict what is in it, and your organization’s own policies apply on top of ours. Section 16 of the policy says so. In a five-person firm that is usually the owner, which makes it uninteresting until the day somebody leaves.

There is a fifth party worth naming because the answer is deliberately none. A message from a sender Point has never seen is set aside before anything reads it for meaning, which is what stops an unknown correspondent from issuing instructions to your inbox simply by writing to you. Prompt-injection defenses and quarantine workflows are named in the security section of the policy rather than left as a feature claim, and what Point actually did with a held message is a line in the activity log.

How long any of it stays

Retention decides more than any other clause on this page, because nothing can be misused, trained on or handed over later if no copy was kept. The full table is section 10 of the policy. The rows a practice cares about are these.

Correspondence in an active account is kept while the account is active, unless it is deleted earlier by you or by your settings. Deleted content comes out of active systems within a reasonable period, and backups may hold it until they are overwritten on their normal cycle.

Derived material generally lives as long as the content it came from. That is the row firms do not ask about, and it is the one that decides whether a deletion reaches the summary and the index entry or only the message. Ours is written down rather than left to be discovered.

The connection to your mailbox lasts until the account is disconnected or the authorization expires. That switch is at Google or Microsoft as well as here, which means you can end our access without asking us to do anything.

On termination, our addendum commits to deleting or returning your data within 60 days, at your choice, if that is supported by the service and specified in your agreement. Read the condition rather than the number. Backups may be retained until overwritten. Billing and tax records are kept as long as tax and accounting law requires, which is often seven years, and that is invoices rather than correspondence.

Security, fraud and system logs are kept as long as they are needed to protect the service. That is the ordinary answer in this category and it is genuinely open-ended, which is worth knowing rather than glossing.

What we do not do with it

Three commitments, each narrower than the slogan version and each pointing at a paragraph.

It is not sold. Section 6.2 of the policy says so, and the state-privacy terms in the addendum repeat it as an obligation we carry as your processor, which is the version that binds.

It is not used to train generalized models unless you authorize it. The exact wording is section 6.5 of the policy and section 6.8 of the terms, and the contractual one is the terms. The word carrying the load is generalized. What sits outside it is us making this product better for your firm, which is where nearly all of your mail actually goes: ranking that learns which senders you open, an index that fills with your own correspondence, prompts rewritten after somebody watched a thread go wrong. Every commitment in this category has that shape, and how to read one, including ours, is keeping client data out of AI model training, which quotes the sentence and takes it apart properly.

It is not in the advertising pipeline, and we run advertising. Both halves are true and the combination is the part worth stating. Our public marketing pages use Google advertising and measurement technology, so a visit to this page is measurable. Customer content, connected email and calendar content, attachments, prompts, outputs, search indexes, embeddings, summaries and access tokens are excluded from all of that by name, in sections 6.3, 6.4 and 6.6 of the policy, and the Google API data specifically is held to Google’s own Limited Use rules. A firm that found the analytics script on this site and wondered has asked a reasonable question, and the answer is a paragraph in a document rather than a reassurance from us.

One more that is not a commitment but a fact about how this is built. Our terms at section 6.7 reserve the ability to change models, embedding models, model providers and infrastructure providers. Every product in this category holds that right and has to, because a service frozen to one provider would be a worse service inside a year. It is also why the subprocessor list carries a version and a date: the durable half of the answer is the conduct commitment, and the half naming a company is a fact you should be able to notice changing.

The mail our standard service does not cover

This is the section a tax practice should read before any of the others.

Section 5.1 of the terms says our standard service is not designed, priced or offered as a regulated-data service, and then names what must not be put through it without a separate written supplement we have accepted. Tax-return information is on that list, along with protected health information under HIPAA, payment-card data, biometric data, children’s data, and other categories under specialized statutory or professional-secrecy rules.

For most professional-services firms that exclusion never comes up. For a tax practice it is the whole question, because a firm mailbox in February carries return information by definition. The relevant document is an IRC 7216 addendum, and our terms list it among the supplements that may be offered where we support the use case. Whether it is available for your firm and your season is a question to put to us before you connect a mailbox. If the answer is not yet, then the standard service is not the right home for that mailbox this year, and October is a better month to establish that than April.

Nothing in this section changes what section 7216 asks of you as a preparer, which is your obligation rather than ours and does not transfer to a supplier. Where the profession’s existing rules already speak to handing work to an outside party is AI and the CPA Code of Professional Conduct.

What we have not earned yet

There is no SOC 2 report, no ISO certificate and no trust badge on this site, and there will not be one until there is a held certification with a dated report behind it. An unearned badge is a false claim rather than a design choice, and a firm that accepted one would be relying on something that does not exist.

That leaves you with less than a mature vendor would offer, so it is worth being exact about what does exist. Two public documents carrying versions and effective dates. A terms document with the data processing addendum inside it, including the deletion window, the subprocessor-change clause and the training position in its contractual form. A list of the companies that touch your mail, dated so you can diff it. And a log of what the software did on your behalf, which is the one answer here you can check every working day.

Four things you can test rather than take on trust, and all four fit inside a first week. Ask for your data back and open what arrives. Remove a seat and confirm what that person can still reach. Raise a support ticket about a real thread and watch what the reply knows. Keep a copy of the subprocessor list and compare it in six months. The discipline of grading any vendor’s answers, including ours, is questions to ask any AI tool about your data, and it applies to this page as much as to anybody else’s.

Two limits we are not going to write around. Our own security section says no method of transmission, storage or processing is completely secure, which is true of us and of everyone else in this category. And Point is in private beta and priced per seat, so there is no published price, tier or trial length to put in a procurement file. If your process needs a certificate and a number today, we do not have either, and that is a legitimate reason to wait.

What a December letter can carry

Engagement letters are the reason this note has a date on it. A letter is a contract for services, which makes it a sound place to record how the practice operates and where responsibility sits, and a weak place to seek anybody’s permission. For a 1040 client, a permission written into the letter is empty as consent, and the reasons are set out in what to put in your engagement letter about AI, which is a November decision rather than a December one.

What we can hand whoever drafts it is three sentences you can check against the documents above. A model reads the correspondence, because that is how the software works. Under the agreement it is not used to build the generalized models other people query, and the AI providers are used with training turned off wherever that control exists. It is used to run and improve the service for your firm, it is kept for the periods in section 10, and here is the dated list of companies that touch it.

The sentence not to write anywhere near a client is that their information is never seen by AI. It is untrue of any product in this category, including ours, and it fails in the worst way available, because the client finds out rather than being told.

The parts that stay with you

Four decisions we cannot make from here, and together they set more of your exposure than anything in our terms does.

Who connects a mailbox. Usually fewer people than the first answer, and it is worth deciding rather than discovering.

How far Point goes. Each kind of work carries its own setting, from suggest-only through preparing something and waiting on you, to handling it. Every kind starts on review. At the top of a setting, Point stops pausing for you before it acts, and that is the whole reason to move one up there. Where you leave those settings decides which of our answers still cover you, and that decision is worked through in setting how much your inbox does on its own. Everything Point did is timestamped in the log and most of it can be put back; the exception is a message already delivered, which is on somebody else’s server and out of reach of any product’s undo.

Who may accept terms for the practice. Our training commitment has your own authorization written into it as the exception, and the realistic route from a small firm into a training corpus is a person agreeing to something on a Tuesday. A consent screen in a research program, a helpful toggle in an unrelated tool, or a K-1 pasted into a free summarizer at eleven at night in March. All of those sit outside every document on this page. The version of a policy a four-person firm will actually follow is a simple AI policy.

Whether to do any of this now. The conversation about software reading client mail does not compress and does not go well in February, which is the seasonal case made in getting ready for the 2027 tax season. If your firm has not had it, that is the work, and it is not this page.

Everything Point does, written out rather than summarized, is on the benefits page. The same ground in a practice’s language is Point for accountants, what is changing here between now and the end of the year is what we’re building this quarter, and Point is the shortest version there is.

Common questions

Does Point read our clients’ email?

Yes. Ranking a pile, summarizing a thread, pulling an ask out of the fourth paragraph and finding something by what you remember about it all require reading the mail, and there is no version of this product that does those things without it. The question worth asking next is not whether a model sees the correspondence but what persists afterwards, which is the retention section above rather than the training one.

Is our mail used to train AI?

Not to train generalized third-party or foundation models, unless you expressly authorize it, and the AI providers are used with no-training controls where those controls exist. Your content is used to run and improve the service for your firm, which covers ranking that learns your senders, an index that fills with your own correspondence, and prompts rewritten after a failure. Those are two different sentences because they are two different things, and the full anatomy of that distinction is in keeping client data out of AI model training.

Can somebody at Point read one of our threads?

In defined circumstances, yes: support you asked for, a security or abuse investigation, legal compliance, troubleshooting and service operation, or with your consent. That is section 6.8 of the privacy policy. Any supplier claiming no human can ever reach customer content is describing either a product without support or a sentence nobody checked. You can test ours cheaply by raising a ticket about a real thread and reading what comes back.

What happens to everything if we stop using Point?

Disconnecting ends our access, and the switch exists at Google or Microsoft as well as here. Your address, archive and contacts were never moved, so there is nothing to migrate back. On termination our addendum commits to deleting or returning your data within 60 days at your choice, where that is supported and specified in your agreement, and backups may hold copies until they are overwritten on their normal cycle. Derived material such as summaries and index entries is retained while the content it came from is retained.

We prepare returns. Can we connect the firm mailbox?

Ask us before you do. Tax-return information is a named exclusion from our standard service in section 5.1 of the terms, and bringing it inside takes a separate written supplement rather than a setting or an assurance. That is a real constraint for a tax practice rather than boilerplate, since a firm mailbox in season carries return information as a matter of course. It is a better question for October than for the first week of April.

Do you have SOC 2?

No, and there is no badge on this site claiming otherwise. A badge goes up when the certification is held and there is a dated report to hand over. What we can give you instead is the documents, dated and versioned, and a short list of things you can verify yourself inside a trial. If your process requires a certification report before anything can be connected, then waiting is the correct answer.

Does Point keep one client’s mail separate from another’s?

Not in that shape. The isolation Point holds is between separate businesses you operate, so what sits inside one is not visible from the other. Inside a single practice mailbox, a seat sees the mailbox. What that changes about confidentiality inside a firm, where reading used to be limited by how long a thread was, is using an AI inbox without breaking confidentiality.

The short version

Point reads client mail, because that is the product, and this note is about what happens next. We hold the correspondence, the things the software makes from it, and excerpts sitting with the model providers named on a dated subprocessor list. People here can reach content in defined support, security and operational circumstances rather than never. Retention is written down per category, deletion reaches derived material as well as messages, and backups turn over on their own cycle. Your mail is not sold, not used to train generalized models unless you authorize it, and excluded by name from the advertising technology running on our public pages. Tax-return information sits outside the standard service and takes a separate supplement, which is the sentence a tax practice should act on before connecting anything. We hold no certification and publish no price, so a firm that needs either today should wait. What we have instead is two dated documents, a contract that carries the commitments, a log you can read daily, and four answers you can test yourself in a first week. If the partner conversation behind all of this has not happened, that is the piece of work, and the fall is when it costs the least.

Ready for a calmer inbox?

Join the private beta

We're onboarding a few teams at a time. Leave your email, confirm it once, and we'll send an invitation the moment a place opens.

By joining you agree to our privacy policy.

Private beta

What you're joining

It runs on the mail you have

Point sits on top of Gmail or Outlook. Your address, your history and your contacts stay exactly as they are, so there is nothing to migrate.

You set how much Point does

Out of the box everything waits for your review, replies included. You hand over only what you trust, one kind of work at a time.

Join the private beta

We're onboarding a few teams at a time. Leave your email, confirm it once, and we'll send an invitation the moment a place opens.

By joining you agree to our privacy policy.