Privacy
Cookies and measurement
Effective August 5, 2026
Punctilio uses a small amount of browser storage to provide the service. Optional analytics and advertising measurement stay off until you choose them.
Your choice
Public pages do not interrupt you with a first-visit prompt. You can make a choice from the public-site footer or when creating an account. You can allow optional measurement, use necessary storage only, or choose each category separately. During signup, allowing optional measurement and using necessary storage only receive equal weight. You can reopen Privacy choices from the public-site footer or your account settings.
Necessary storage is always active because it keeps the site secure and provides features you request. Analytics and advertising measurement are off by default. If your browser sends a Global Privacy Control signal, both optional categories stay off. They remain off after the signal is removed until you explicitly change your choices.
Before you choose, a sanitized landing record can remain in memory in the current tab so your choice can apply if you continue to account creation. It is not written to browser storage or sent as optional measurement before consent. Reloading or closing the tab clears it.
Necessary storage
punctilio_privacy. A first-party cookie that stores your analytics and advertising choices, the consent version, and the time of your decision. It lasts six months. It is host-only, uses SameSite=Lax, and is Secure on the live site.punctilio_privacy_deny_v1. A first-party local-storage safety copy used when either optional category is off. It prevents an older allow cookie from taking effect if a browser silently rejects a newer cookie write. It lasts no more than six months and is removed after a verified choice turns both optional categories on.sidebar:state. A first-party cookie that remembers whether the signed-in sidebar is open. It lasts seven days.- Authentication and security storage. Your login session, theme, security tokens, and interface preferences are stored locally when needed. Shared-room and signing sessions also use browser storage to keep access secure and complete the action you requested.
Analytics
If you allow Analytics, Vercel Analytics measures page views and selected interactions on public and sign-in pages. Vercel Analytics is cookieless and does not follow you across sites. It does not run in the signed-in product, shared rooms, recipient uploads, or signing pages.
Analytics datapoints can include the page path, referrer, country, region, city, device type, browser, operating system, and visitor and session identifiers. Vercel creates a hash from the incoming request to identify a visitor session. That visitor session has a 24-hour lifespan. The measured Punctilio page is sent without its query string or fragment. A referring site with a permissive policy may still cause the browser to supply that site's path or query in the referrer URL. Our current plan gives us a 12-month dashboard reporting window. Vercel may retain underlying analytics data longer under its own retention practices, and our dashboard window can change if our plan changes.
We also store a first-touch marketing record in your browser. It is treated as expired after 90 days and deleted on your next public or sign-in visit. It can contain campaign tags, the referring site without its query string, the landing path, and the time of the visit. It does not contain document activity or account content. Refusing or withdrawing Analytics removes this optional record.
If you create a new workspace, consented first-touch fields, your optional “How did you hear about us?” answer, and consent evidence can be copied to a service-only workspace record. Unless Analytics is withdrawn while signed in as the person who supplied that signup consent, those first-touch fields remain until the workspace is deleted. Withdrawal by that person removes the first-touch fields but preserves the explicit “How did you hear about us?” answer and the consent record. If that person withdraws while signed out, server cleanup runs the next time they sign in on the same browser with Analytics still off. Choices made by other workspace members affect their browser only.
Advertising measurement
If you allow Advertising measurement and arrive from a paid campaign, Punctilio stores a recent paid-touch record in your browser. It is treated as expired after 30 days and deleted on your next public or sign-in visit, or cleared at signup. It can contain campaign tags, the landing path, the time of the visit, and OpenAI's click reference called oppref.
At signup, the paid provider, campaign fields, landing path, touch time, and consent evidence can be copied to the same service-only workspace record. Unless you withdraw Advertising measurement while signed in as the person who supplied that signup consent, those cohort fields remain until the workspace is deleted. The click reference follows the shorter limits below.
If that visit leads to a confirmed Punctilio trial, our server can send OpenAI onetrial_started conversion event. The event contains the click reference, event time, a one-way event ID unique to the trial, the web action source, the Punctilio trial plan ID, and an opt-out flag that prevents future user-level personalization. It does not contain your email, hashed email, IP address, browser details, workspace name, or raw Punctilio or Stripe customer or subscription ID.
The server keeps the click reference only while it can support that one event. It is removed after confirmed delivery, when the seven-day delivery window expires, or when the paid touch becomes more than 30 days old. The one-way event ID and delivery metadata, such as the event name, fixed source URL, status, attempt count, errors, and timestamps, remain in our service-only records until the workspace is deleted. A delivered record no longer contains the click reference.
Punctilio does not install an OpenAI JavaScript pixel, use advanced matching, or allow advertising measurement inside the product, shared rooms, uploads, or signing. Refusing or withdrawing this category removes optional paid-touch browser storage. When you are signed in as the person who supplied the signup consent, it also clears the server-side paid-touch fields and click reference and cancels any not-yet-sent conversion tied to that consent. Choices made by other workspace members affect their browser only. A provider request already in flight when you withdraw may finish. If you are signed out, the server cleanup runs the next time you sign in on the same browser with Advertising measurement still off.
Changing your choice
Open Privacy choices from the public-site footer or account settings. A change takes effect immediately for optional browser collection. If the consent categories or vendor list materially change, Punctilio asks you again.
Questions about these choices can be sent to support@punctil.io.