Who I am
I'm Ellis, and I built NullPoint to help people catch scam emails, texts, and phone calls before they do damage. NullPoint is not a phone carrier, email provider, or bank. I do not place calls, read your mail without permission, or share your data with advertisers.
What I collect and why
Your account: email address and password (hashed — I can never see your actual password) so you can log in.
Mailbox credentials: if you connect Gmail, Yahoo, or Outlook, I store your app password or OAuth token, encrypted. I need it to read your incoming mail and check it for threats. I never read mail unless you've connected a mailbox.
Message content: subject lines, sender addresses, and body text from mail you've connected. I use this to score threats. Automated 90-day deletion is not implemented in this pilot, so connected content remains until the retention job or account deletion workflow is completed.
Your grades and reports: when you mark something safe or report it, the decision is stored in your account namespace. Automatic fleet-wide promotion is disabled in production.
Phone intelligence: the current iOS directory synchronizes service and vendor number intelligence. Personal phone-number enrollment is not implemented, and NullPoint does not receive carrier-call audio or your native call history.
Billing: production billing is disabled. If enabled after its release gate, Stripe will handle card data; NullPoint will not store card numbers.
What I don't do
I don't sell your data. Ever.
I don't share your inbox with other users. Cross-account model training and automatic fleet promotion are disabled for this pilot.
I don't use your data to train models for other companies.
I don't track you across other websites.
Third-party lookups
When you run a phone or email lookup in the Identity tab, I send that identifier to a vendor (like IPQS or Have I Been Pwned) to check for known scams or data breaches. I only do this when you ask. Those vendors have their own privacy policies.
How long I keep your data
Raw email content: retained during the pilot until an automated retention job is deployed; this is an App Store/public-pilot blocker.
Your grades and block decisions: retained in your account namespace.
Your account info: until you delete your account.
Billing records: as long as legally required.
Your rights
Self-service deletion is disabled on production until deletion, token revocation, and cross-store cleanup run as one retryable workflow. This pilot must not be opened publicly before that gate is complete. Access, correction, and export are also manual pilot processes rather than finished self-service features.
Kids
NullPoint is not for children under 13. If you believe a child has signed up, contact me and I'll remove the account.
Changes
I'll update this page as the product grows. The date at the top shows when it last changed.