Pointmoon

Privacy

Pointmoon is built to ground software in places without turning those places into a user profile. The public API and MCP service collect limited operational and adoption telemetry.

Last updated September 23, 2026.

API and MCP calls

What the adoption log keeps.

For served calls to the public API or MCP endpoint, Pointmoon may keep an anonymous caller identifier derived from a salted one-way HMAC of the network origin and coarse client family, the transport and endpoint/tool used, a timestamp, whether a valid internal service token was presented, a coarse caller classification, and a normalized self-declared client label when one is supplied.

The adoption record does not store raw IP addresses, latitude/longitude, place names, query strings, MCP tool arguments, request payloads, or response payloads. The raw network address is used only as an input to the HMAC that produces the anonymous caller id.

Website analytics

Optional, sanitized analytics.

The Pointmoon website can use PostHog when analytics is configured. Before analytics events leave the browser, URL-like fields are reduced to origin and pathname: query parameters and fragments are removed. Session replay masks all inputs, does not record console logs, and removes captured network request/response headers and bodies. Web-vital performance data, page views, page leaves, autocapture and heatmaps may be collected.

Analytics providers may process normal connection/device metadata needed to deliver their service. Pointmoon does not intentionally send location query values, place names or form input contents to website analytics.

Upstream providers

Field-truth requests contact data sources.

To answer a live request, Pointmoon may query environmental, geospatial or observation providers for the requested place or coordinate. Those providers have their own privacy and usage terms. Pointmoon returns source and attribution information with data where the contract requires it.

Control

Self-hosting and telemetry controls.

The open-source server can disable adoption telemetry entirely through configuration. Website analytics is off when the public PostHog configuration is absent.

For a privacy question or request, use the public support page.