Privacy Policy
Last updated: 24 August 2026
The short version
PontX is a local-first application. Your documents, your search index, and your chat history live on your computer. They are never uploaded to us — we operate no cloud that could read them. What little we do process is described below, split by how you interact with us.
1. The PontX application
All indexing, search, and preview happen locally on your device. We do not collect your documents, file names, search queries, chat messages, or telemetry from the application.
The application talks to the internet only for connections you enable:
- AI connections (MCP or your own API key). If you connect an AI assistant such as Claude, Gemini, or ChatGPT, the content you ask it to read is sent to that provider under their privacy terms. If you use a local AI (e.g. Ollama or LM Studio), nothing leaves your machine at all.
- Model downloads. Optional search-quality models are downloaded from their public repositories on first use.
- License checks (when subscriptions launch). The application periodically confirms your subscription status with our license server. This exchange contains license identifiers — never your documents.
2. The pontx.ai website
- Server logs. Our hosting provider (located in the EU) keeps standard web-server logs (IP address, browser type, pages requested) for security and troubleshooting, retained for a short period.
- Content delivery. The site is served through Cloudflare, which processes connection data as a network service provider.
- Cookies. The site currently uses only cookies that are strictly necessary for it to function. We run no analytics and no advertising trackers. If this ever changes, this policy will be updated and your consent requested where required.
3. Accounts and purchases (when available)
When the PontX account portal opens, creating an account and purchasing a subscription will involve:
- What we will process: your email address, account password (stored hashed), subscription and payment status, billing details required for invoicing (e.g. name, country, VAT number for businesses), and device activation identifiers (a hashed device fingerprint used to enforce the activation limit).
- What we will not process: your card details — payments are handled by a licensed payment provider; card data never touches our servers.
- Why (legal bases under the GDPR): performing our contract with you (account, license, support); complying with legal obligations (invoicing, accounting, tax); our legitimate interest in securing the service and preventing fraud; and your consent for anything optional (such as product news — never on by default).
- How long: account data for as long as your account exists; invoicing records for the periods required by Bulgarian accounting and tax law; everything else no longer than needed for its purpose.
4. PontX Anywhere (remote access)
The Anywhere relay passes end-to-end encrypted traffic between your devices and your own computer. The relay cannot read the content that passes through it. We process only minimal connection metadata (such as timestamps and traffic volume) needed to operate the relay and prevent abuse.
Your rights
Under the GDPR you have the right of access, rectification, and erasure of your personal data; the right to restrict or object to its processing; the right to data portability; and the right to withdraw any consent at any time. You also have the right to lodge a complaint with a supervisory authority — in Bulgaria, the Commission for Personal Data Protection (CPDP), or the authority of your own EU country.
Transfers outside the EU
Our servers are located in the EU. We do not transfer the account data we control outside the EU. Note that if you choose to connect a non-EU AI provider from the application, that connection is between you and the provider.
Children
PontX is not directed at children and we do not knowingly process children’s data.
Changes and contact
We will post any changes to this policy on this page with an updated date. Questions and requests: [email protected].