Privacy & Gmail data
What Pointum accesses, why it is used, what is retained, and how you stay in control.
Effective August 22, 2026
Gmail access
Pointum requests Google's gmail.readonly permission. It allows read-only mailbox access; Pointum cannot send, edit, or delete your email.
Pointum searches only messages that match its filters for supported airline and bank loyalty-statement senders and a bounded date range. Unrelated messages are not used for any other purpose.
Processing and storage
By default, statements retrieved through the Gmail API connection are processed in memory with deterministic parsers solely to update balances in Wallet. If you separately enable AI statement fallback, only text from a likely statement that those parsers could not recognize is sent to a contracted AI service solely to extract a Wallet balance. Pointum discards message bodies, subjects, snippets, and attachments after processing and does not persist or log them.
From Gmail data, Pointum retains only the derived loyalty balance and program/sender metadata. To operate the connection, it also retains your connected Gmail address, encrypted OAuth credential, and sync status until you disconnect.
Your derived Wallet balance may be shared with contracted service processors only when needed to fulfill a feature you initiate or configure, such as Chat, transfer planning, or watch alerts. Gmail message text is included only when you explicitly enable AI statement fallback, solely for that visible Wallet extraction feature.
Google API Limited Use
Pointum's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Read Google's policy.
- Google-derived data is used only for visible features you initiate or configure, including Wallet balances, points and transfer planning, and watch alerts.
- It is not used for advertising or ad personalization.
- It is not used to determine creditworthiness or for lending decisions.
- It is not used to train general-purpose AI or machine-learning models.
- Content retrieved through the Gmail API connection is not read by people. Only after you enable AI statement fallback may likely statement text be sent to a contracted AI service for the extraction you requested; it is not used to train or improve general-purpose models.
- Google user data is not sold or transferred except as needed to operate the user-facing feature, protect security, meet legal requirements, or with your explicit consent.
Your control and retention
Disconnect the Gmail API connection in Wallet at any time. Pointum then deletes the encrypted OAuth credential and all derived balances and source metadata associated with that connection.
Disconnecting Pointum does not change or delete messages in Gmail. You can also revoke Pointum from your Google Account, but use Disconnect Gmail in Wallet to delete data already derived through the Gmail API connection. The optional email-forwarding importer is a separate feature and is not controlled by this OAuth disconnect.