← ONPOINT BILLING

Privacy Policy

Effective date: September 1, 2026 · Updated October 3, 2026 (the new name, analytics in the app, the iPhone and Android apps, and the import screen’s column-heading match)

The short version: OnPoint Billing uses an account to securely sync your time entries across your devices and back them up in the cloud, so your work is available wherever you sign in and isn't lost if a device is. This policy explains what we store, who helps us process it, and the controls you have. We don't sell your data, the app shows no ads, and nothing you type into OnPoint is ever sent to an advertising or analytics service.

Who we are

OnPoint Billing is made by Tycho Works LLC, a Colorado limited liability company ("we," "us," "OnPoint"). You can reach us at support@onpointtimeentry.com.

Accounts and cloud sync

OnPoint is built around an account that keeps your work synced and backed up. When you create an account and sign in, the information you enter in the app is stored in our cloud database so that it is backed up and available on every device where you sign in. The data that syncs to your account includes:

You can keep working when you are offline. Entries are held on your device and sync to your account the next time you connect. An account is required to sync across devices. If you use the app without signing in, your entries remain only on that device until you sign in, at which point they sync to your account.

Account information we collect

To create and protect your account, we collect your email address and the authentication information needed to sign you in and keep the account secure. We use your email to operate your account and to contact you about your subscription, security, or important changes to the service. We do not use it for advertising.

How your data is stored and protected

Our cloud database, authentication, and storage are provided by Supabase, which runs on managed cloud infrastructure. Your data travels over encrypted connections (TLS) and is stored on that infrastructure, which encrypts data at rest. Access is restricted to your own account through per-row access controls, so other users of the app cannot read your data. The one deliberate exception is team mode, described next.

If you join a team

Team mode is a shared workspace, and joining one is a choice you make by accepting an invitation. While you are a member, time you capture in that team's workspace, meaning its date, hours, client, project, description, and the rate the team has set for you, is visible to that team's administrators and reviewers. They can edit it, approve it, move it to another team member, and put it on the team's bill to the client. Every one of those actions is recorded against the name of the person who took it, and you can see that history on the entry.

Your personal workspace stays private to you: time you capture outside the team is never visible to the team, and the team cannot bill it. You can switch between workspaces at any time, and the app shows which one you are in.

Time you captured for a team belongs to that team's billing records. If you leave the team, or are removed, that time stays with them, because it is what their invoices to their clients are made of, and for the same reason an account holding team time cannot be deleted until the team has released it. Your personal entries are unaffected and remain yours.

We use reasonable administrative and technical safeguards to protect your information. No method of transmission over the internet or method of electronic storage is completely secure, however, so we cannot guarantee absolute security. You are responsible for keeping your account credentials confidential.

Service providers we share data with

We share information only with the providers that make the service work, and only as needed for them to perform their function:

Each provider processes data under its own terms solely to provide its part of the service. We do not sell or rent your data to anyone.

Subscription validation

Because OnPoint is a paid subscription, the app periodically confirms your subscription is active. This check does not involve your time entries, client names, descriptions, rates, or bills. For subscriptions bought on our website, Stripe tells our server when a subscription starts, changes, or ends, and the app reads that status from your own account in our cloud database. Subscriptions purchased inside the iPhone or Android app are billed by Apple or Google, and the app confirms them through RevenueCat, which receives your account identifier and returns your purchase state. If you are offline, the app keeps working and re-checks the next time you connect.

Voice dictation and AI

If you use the in-app microphone, speech-to-text is performed by your device's own built-in speech recognition. OnPoint receives only the resulting text and never records, stores, or transmits audio. Where that speech recognition runs is governed by your device and its settings.

OnPoint uses AI in three places, all over the same encrypted path: Dictation (the mic on the Time tab and Chain Dictation) turns your dictated text into structured entries; Polish rewrites a rough description into invoice-ready wording; and the Assistant answers questions about your logged time and performs actions you request. When you use these while signed in, the text you dictated or typed, along with your client codes or names and project names so the AI can match them, and never audio, is sent over an encrypted connection through our server to our AI provider, Anthropic, which returns the result. Anthropic does not use data submitted through its API to train its models, and retains it only briefly for abuse monitoring before deletion. Voice commands (such as "hold this" or "next entry") are handled entirely on your device. If you are not signed in, are offline, or the AI service is unavailable, dictation falls back to on-device processing. When you import clients and projects from a spreadsheet and OnPoint can't match its column headings on its own, it sends the heading row to our AI provider to suggest the match, never a row of your data.

Email features

When you use the app's email options, the app opens your mail service with a draft prefilled. Your messages travel through your email provider, not through us, and we never see them. Team mode can also email a team's invoices directly from the app to the client addresses the team has entered; those messages are sent through our email delivery provider, Resend, which receives the recipient address and the invoice being sent, under its own privacy policy.

Analytics

What changed on October 3, 2026. Until that date the app carried no analytics code, and this policy said so. It no longer says so. We measure what happens in the app so we can see where people get stuck and whether our marketing brings anyone here. What has not changed is the boundary that matters: nothing you type into OnPoint (no time entry, client name, project, description, bill, or spoken word) is ever sent to an analytics or advertising service. The measurement is of what happened (an account was created, an entry was saved, a bill was exported, a subscription started), never of what it said.

When you arrive at this website from a link that carries campaign labels or an advertising click identifier, your browser keeps the first one it sees and, if you go on to create an account, it is stored against the account so that we can tell which campaign led to the signup. That is the whole of what it is used for.

These services receive the technical data that accompanies any web request, such as IP address and browser type, and process what they collect under their own privacy terms. None of them can see your time entries, clients, projects, descriptions, bills, or dictated audio, because the app never sends any of that to them, and the list of what an event may carry is fixed in the app's code and tested on every release. A content blocker or a private window stops Google Analytics; the app works the same without it.

What we do not do

We do not sell, rent, or trade your personal information. We have never used your time entries, clients, descriptions, bills, or dictated audio for advertising or analytics, and no analytics or advertising service receives them. We do not target ads to you based on anything you enter in OnPoint. The services described under Analytics are the whole of our measurement. Our service providers keep limited operational logs as described above to run and secure the service.

How long we keep your data, and how to delete it

We keep your synced data for as long as your account is active so the app can do its job. You stay in control of it:

Data held on your device is removed when you delete entries, clear this site's browsing data, or remove the app from the device. Backup files you download remain wherever you saved them until you delete them.

Your privacy rights

Depending on where you live, including under the Colorado Privacy Act, you may have the right to access the personal data we hold about you, correct it, delete it, obtain a portable copy, and appeal our decision on a request. The app's export and backup feature gives you a portable copy of your data directly; for access, correction, deletion, or appeal, email support@onpointtimeentry.com and we will respond as required by applicable law. We will not discriminate against you for exercising these rights.

Where your data is processed

Your account data is stored and processed on cloud infrastructure located in the United States. By using the app, you understand that your information will be processed there.

Children

OnPoint is a professional tool and is not directed to children under 16. We do not knowingly collect personal information from children. If you believe a child has provided us information, contact us and we will delete it.

Changes to this policy

If we change this policy, we will post the updated version here with a new effective date and, where appropriate, notify you in the app or by email.

Contact

Questions about this policy: support@onpointtimeentry.com.