Privacy Policy for TemplatePoint
Effective date: August 5, 2026 Last updated: August 9, 2026
TemplatePoint is an independent software project operated by Marius Solheim in Norway.
This Privacy Policy explains how TemplatePoint ("TemplatePoint," "we," "us," or "our") collects, uses, stores, and shares personal data when you:
- visit the TemplatePoint website;
- create or use a TemplatePoint account;
- use the TemplatePoint web application;
- join or administer an organization or workspace;
- use TemplatePoint's AI-assisted functionality;
- install or use the TemplatePoint browser extension; or
- contact TemplatePoint for support.
The website, web application, browser extension, and related functionality are collectively referred to as the "Service."
TemplatePoint is currently a pre-launch independent project and is not operated through a registered company. If the legal person or entity responsible for TemplatePoint changes, this Privacy Policy will be updated.
For privacy questions or requests, contact:
Operator: Marius Solheim Country: Norway Email: support@templatepoint.app
- Our role when processing personal data
TemplatePoint may process personal data in different roles depending on how the Service is used.
TemplatePoint as data controller
TemplatePoint acts as the data controller for personal data used to:
- create and administer user accounts;
- authenticate users;
- manage access to the Service;
- operate and secure the website, application, and browser extension;
- provide optional AI-assisted functionality;
- send verification, invitation, and other transactional emails;
- respond to support requests;
- prevent misuse and investigate security incidents;
- improve and maintain the Service; and
- comply with applicable legal obligations.
TemplatePoint as data processor
Organizations may use TemplatePoint to create or store templates and documents containing personal data about employees, applicants, customers, suppliers, or other individuals.
For personal data entered into TemplatePoint by or on behalf of an organization, the organization will ordinarily act as the data controller and TemplatePoint will act as its data processor.
The organization is responsible for:
- determining whether it has a lawful basis for processing the data;
- providing any required privacy notices;
- managing access to its content; and
- responding to requests from the individuals whose data it controls.
Where required, processing on behalf of an organization may be governed by a separate data processing agreement.
- Personal data we collect
The information we process depends on which parts of the Service you use.
2.1 Account and profile information
When you create an account, we may process:
- your name;
- your email address;
- your profile image;
- your authentication method;
- an identifier associated with your account;
- your organization and workspace memberships;
- your assigned roles and permissions; and
- account creation, verification, and login information.
Password-based authentication is handled through Supabase Authentication. TemplatePoint does not have access to your plaintext password.
2.2 Information received from identity providers
Where available, you may sign in using an external identity provider such as Google or Microsoft.
When you use an external sign-in provider, TemplatePoint may receive information authorized through that provider, such as:
- your name;
- your email address;
- your profile image; and
- a provider-specific account identifier.
TemplatePoint does not receive your Google or Microsoft password.
The identity provider may independently process information about your use of its authentication service under its own privacy policy and terms.
2.3 Organization, workspace, and membership information
When you create or join an organization or workspace, we may process:
- organization and workspace names;
- membership records;
- invitation email addresses;
- invitation status;
- roles and permissions;
- ownership and administrative information;
- records of content creation or modification; and
- information necessary to manage access to shared content.
2.4 Templates, documents, and other user content
We process information that you or your organization creates, uploads, imports, or stores through TemplatePoint, including:
- templates and documents;
- template titles and descriptions;
- categories and workspace structures;
- text and rich-text content;
- placeholders and field definitions;
- images and uploaded files;
- field values entered into templates;
- template versions and working-version history;
- content attribution;
- configuration and preference information; and
- other information you choose to submit.
You and your organization decide what information is entered into the Service.
You should not submit personal data, confidential information, special-category personal data, or other sensitive information unless it is necessary and you have an appropriate legal basis and authorization to process it.
2.5 AI feature data
TemplatePoint provides optional AI-assisted functionality.
When you intentionally use an AI feature, we may process and transmit information necessary to perform the requested operation, including:
- your instructions or prompt;
- the requested topic, format, tone, or language;
- selected template or document content;
- placeholder and field definitions;
- feedback provided when reviewing or regenerating content;
- relevant feature configuration; and
- the generated response.
Stored templates are not automatically sent to OpenAI merely because they exist in TemplatePoint.
Information is transmitted to OpenAI only when you actively invoke functionality that requires AI processing.
You should avoid submitting unnecessary:
- personal data;
- confidential business information;
- trade secrets;
- health information;
- authentication credentials;
- financial information; or
- other sensitive information
through AI prompts or AI-assisted content generation.
AI-generated results may be inaccurate, incomplete, or unsuitable for their intended purpose. You are responsible for reviewing generated content before using, publishing, sharing, or relying on it.
2.6 Transactional email information
We may process information needed to send:
- account-verification emails;
- authentication-related messages;
- password-reset messages;
- organization invitations;
- membership notifications;
- security notices; and
- other necessary Service communications.
This may include:
- your email address;
- sender and recipient information;
- the subject and contents of the message;
- verification, authentication, or invitation links;
- message delivery status;
- timestamps;
- bounce information; and
- technical delivery errors.
2.7 Support communications
When you contact us, we may process:
- your name;
- your email address;
- the contents of your message;
- screenshots or attachments you provide;
- relevant account or organization information; and
- our correspondence with you.
Do not include passwords, private authentication tokens, or unnecessary sensitive personal data in support requests.
2.8 Technical, security, and usage information
When you access the Service, we and our infrastructure providers may automatically process technical information such as:
- your IP address;
- browser type and version;
- device and operating-system information;
- requested URLs;
- request headers;
- timestamps;
- referring pages;
- authentication and session information;
- server and application logs;
- diagnostic and error information;
- security events; and
- approximate geographic information derived from an IP address.
We use this information to deliver the Service, maintain reliability, diagnose technical problems, protect accounts, and prevent unauthorized or abusive activity.
2.9 Optional analytics information (Microsoft Clarity)
On our public website pages (such as our marketing pages, and our Privacy Policy and Cookie Policy pages), we use Microsoft Clarity, an analytics tool provided by Microsoft, to understand how visitors interact with those pages.
Microsoft Clarity is never active by default. It only runs if you actively accept analytics cookies through the cookie banner presented on our public pages. If you decline or do not respond, Microsoft Clarity does not load and no analytics cookies are set.
Where you accept, Microsoft Clarity may collect:
- pages visited and navigation paths;
- clicks, scrolling, and other on-page interaction data;
- session recordings and heatmaps illustrating how visitors use a page;
- approximate device, browser, and screen information; and
- approximate geographic information derived from your IP address.
Microsoft Clarity operates only on our public pages. It is not active within the authenticated TemplatePoint application where you manage your account, organization, workspaces, or templates.
Your analytics choice is remembered in your browser (see our Cookie Policy for details) and you may change it at any time using the "Cookie settings" control available on our public pages.
- TemplatePoint browser extension
The TemplatePoint browser extension allows authenticated users to access and reuse templates from their TemplatePoint account while working in the browser.
Depending on the version and features used, the extension may:
- authenticate you through TemplatePoint;
- communicate with the TemplatePoint backend;
- retrieve templates, categories, fields, and related account information;
- display TemplatePoint content in an extension interface or webpage overlay;
- copy or insert user-selected template content into an active webpage;
- store limited authentication state, cached data, or preferences in browser storage; and
- access the current webpage only where necessary to provide a user-requested feature.
The extension does not use webpage content for advertising, profiling, creditworthiness assessment, or purposes unrelated to its disclosed functionality.
The extension does not sell user data.
The extension does not continuously monitor your browsing activity.
Where the extension needs to interact with webpage content, such access is limited to what is necessary to provide a feature initiated or enabled by the user, such as displaying the TemplatePoint interface or inserting selected content into an active field.
Information transmitted between the extension and TemplatePoint is sent over encrypted HTTPS connections.
Browser storage used by the extension may contain limited settings, cached template information, or authentication-related data. You can remove locally stored extension data by uninstalling the extension or clearing its storage through your browser.
- Chrome Web Store Limited Use disclosure
TemplatePoint's use of information received from Chrome APIs complies with the Chrome Web Store User Data Policy, including the Limited Use requirements.
Information obtained through Chrome extension permissions or Chrome APIs is:
- used only to provide or improve the extension's prominently disclosed user-facing functionality;
- not sold or transferred to third parties for advertising;
- not used for personalized advertising;
- not used to determine creditworthiness or for lending purposes; and
- not used for purposes unrelated to the extension's disclosed single purpose.
We may share such information with service providers only where necessary to provide, secure, or maintain the extension and only subject to appropriate data-protection obligations.
We may also disclose information where required by applicable law, regulation, legal process, or a valid governmental request.
- How we use personal data
We may use personal data to:
- provide and operate TemplatePoint;
- create, verify, and administer accounts;
- authenticate users and maintain sessions;
- create and administer organizations and workspaces;
- manage invitations, memberships, roles, and permissions;
- store, display, edit, version, and export user content;
- synchronize the browser extension with the TemplatePoint backend;
- provide optional AI-assisted functionality requested by the user;
- send transactional and security-related emails;
- respond to questions and support requests;
- investigate errors and improve reliability;
- understand and improve how visitors use our public pages, where you have given consent for optional analytics (Section 2.9);
- protect the Service against unauthorized access and misuse;
- maintain auditability and content attribution;
- enforce our terms and policies;
- establish, exercise, or defend legal claims; and
- comply with applicable legal obligations.
We do not sell personal data.
We do not use personal data submitted to TemplatePoint for third-party advertising.
- Legal bases for processing
Where the General Data Protection Regulation applies, we rely on one or more of the following legal bases.
Performance of a contract
We process personal data where necessary to provide the Service you request, including to:
- create and administer your account;
- authenticate you;
- provide access to organizations and workspaces;
- store and manage your templates and documents;
- operate the browser extension;
- provide an AI-assisted operation you intentionally request; and
- send necessary Service communications.
Legitimate interests
We may process personal data where necessary for our legitimate interests, provided those interests are not overridden by your rights and freedoms.
These interests include:
- operating and maintaining the Service;
- securing accounts and infrastructure;
- preventing misuse, fraud, and unauthorized access;
- diagnosing errors;
- improving functionality and usability;
- responding to support requests;
- maintaining appropriate audit and attribution records; and
- establishing or defending legal claims.
Legal obligations
We may process or retain personal data where necessary to comply with applicable laws, court orders, regulatory requirements, or valid requests from public authorities.
Consent
Where required by law, we may ask for your consent before carrying out a particular processing activity.
For example, our optional Microsoft Clarity analytics described in Section 2.9 operate only where you have accepted analytics cookies through our cookie banner.
You may withdraw your consent at any time. Withdrawal does not affect the lawfulness of processing performed before consent was withdrawn.
- AI-assisted processing and OpenAI
TemplatePoint uses the OpenAI API to provide optional AI-assisted functionality.
Information is sent to OpenAI only when you actively request an AI operation.
Depending on the feature, OpenAI may receive:
- your prompt or instructions;
- selected template content;
- field and placeholder definitions;
- language, tone, and format preferences;
- regeneration feedback; and
- other information necessary to produce the requested output.
OpenAI processes this information to provide the requested response.
Data submitted through the OpenAI API is not used to train OpenAI models by default unless the account holder explicitly opts into data sharing.
OpenAI may retain API inputs, outputs, and related metadata for a limited period for security and abuse-prevention purposes. Under standard API data controls, abuse-monitoring information may ordinarily be retained for up to 30 days unless longer retention is legally required or different data-retention controls apply.
Using TemplatePoint's AI functionality is optional. Users who do not invoke an AI feature will not have their stored template content sent to OpenAI for AI generation.
TemplatePoint does not use AI to make decisions that produce legal or similarly significant effects concerning users.
- Service providers
We use a limited number of service providers to operate TemplatePoint.
These providers receive only the information reasonably necessary to perform their respective services.
Supabase
Supabase provides TemplatePoint's database, authentication, storage, and related backend infrastructure.
Supabase may process:
- account and profile information;
- authentication information;
- organization and workspace memberships;
- roles and permissions;
- templates, documents, images, and other stored content;
- invitation information;
- version and attribution information; and
- application and security metadata.
Vercel
Vercel provides hosting, deployment, server-side application execution, and content-delivery infrastructure.
Vercel may process:
- IP addresses;
- request URLs and headers;
- browser and device information;
- server logs;
- application requests and responses;
- diagnostic and performance information; and
- data passing through server-side functions where technically necessary to provide the Service.
OpenAI
OpenAI provides the models used by TemplatePoint's optional AI-assisted functionality.
OpenAI receives information only when a user actively invokes a feature that requires AI processing, as described in Section 7.
Resend
Resend provides transactional email-delivery services.
Resend may process:
- recipient email addresses;
- sender information;
- email subjects and contents;
- verification and invitation links;
- delivery timestamps;
- delivery status;
- bounce information; and
- technical delivery metadata.
Microsoft Clarity (analytics)
Where you have given consent, Microsoft Clarity provides analytics for our public website pages, as described in Section 2.9.
Microsoft Clarity may process:
- page interaction data (clicks, scrolling, navigation);
- session recordings and heatmaps of public-page usage;
- device and browser information; and
- approximate location derived from IP address.
Microsoft Clarity only operates with your consent and only on our public pages. Microsoft acts as an independent controller for certain aspects of its processing under its own privacy statement.
Google and Microsoft (sign-in)
Where enabled, Google or Microsoft may provide authentication services. This is separate from Microsoft's role in providing optional Clarity analytics, described above.
When you sign in through one of these providers, TemplatePoint may receive your name, email address, profile image, and provider-specific account identifier.
These providers may act as independent data controllers for information they process in connection with their authentication services.
Professional advisers and public authorities
We may disclose relevant personal data to professional advisers, courts, regulatory bodies, law-enforcement authorities, or other public authorities where disclosure is required or permitted by law.
We may also disclose information where reasonably necessary to protect the security, rights, property, or safety of TemplatePoint, its users, or others.
- International data transfers
Some of our service providers or their subprocessors may process personal data outside Norway or the European Economic Area.
Where personal data is transferred to a country that has not been recognized as providing an adequate level of data protection, the transfer may be protected through mechanisms such as:
- the European Commission's Standard Contractual Clauses;
- an applicable adequacy decision;
- the EU–US Data Privacy Framework, where applicable; or
- another lawful transfer mechanism.
Where appropriate, additional contractual, organizational, and technical safeguards may also be used.
- Data retention
We retain personal data only for as long as reasonably necessary for the purposes described in this Privacy Policy.
Retention periods depend on the type of information and why it is processed.
Account information
Account information is generally retained while your account remains active.
When an account is deleted, personal data associated solely with that account will generally be deleted or anonymized, subject to limited exceptions for:
- organization-owned content;
- backups;
- security and audit records;
- legal obligations;
- dispute resolution; and
- establishing or defending legal claims.
Organization-owned content
Templates, documents, version history, attribution records, and other content created within an organization may belong to or remain necessary for that organization.
Deleting an individual user account does not necessarily delete content that:
- belongs to an organization;
- is shared with other users;
- was created as part of the user's work for an organization;
- must remain to preserve version history or attribution; or
- is required for security or audit purposes.
Transactional email records
Transactional email records may be retained for as long as reasonably necessary to:
- verify successful delivery;
- troubleshoot authentication or invitation issues;
- investigate abuse;
- maintain security; and
- comply with applicable legal obligations.
Support communications
Support correspondence may be retained for as long as necessary to resolve the request, document the response, handle related disputes, and maintain appropriate business records.
Technical and security logs
Technical, diagnostic, and security records may be retained for a limited period necessary to operate and secure the Service, investigate incidents, and defend legal claims.
Backups
Deleted information may remain in encrypted or access-restricted backups for a limited period until those backups are overwritten or expire under the applicable backup schedule.
- Account and organization deletion
You may delete your account using the available Service interface or by contacting us.
Before deleting your account, you should transfer ownership or administrative responsibility for any organization that must remain active.
Account deletion may not delete content that:
- belongs to an organization;
- is shared with other authorized users;
- must remain for version history or attribution;
- is retained in security or audit records;
- remains temporarily in backups; or
- must be retained for legal reasons.
Authorized organization administrators may be able to delete an organization and its associated content.
Following organization deletion, associated data will generally be scheduled for deletion, subject to applicable backup periods, security records, and legal-retention requirements.
- Data security
We use reasonable technical and organizational measures intended to protect personal data against unauthorized access, alteration, disclosure, loss, or destruction.
These measures may include:
- managed authentication;
- encrypted HTTPS communication;
- organization and role-based access controls;
- database access policies;
- restricted administrative access;
- application and security logging;
- environment separation;
- backups;
- security testing; and
- dependency and vulnerability management.
No online service, database, browser extension, or transmission method can be guaranteed to be completely secure.
You are responsible for protecting your login credentials and for using a strong, unique password where password-based authentication is used.
Please contact us promptly if you believe your account has been accessed without authorization.
- Your responsibilities
You and your organization are responsible for the information submitted to TemplatePoint.
This includes responsibility for:
- having a lawful basis for processing personal data entered into templates or documents;
- providing required information to employees, applicants, customers, or other individuals;
- configuring memberships and permissions appropriately;
- removing access when it is no longer required;
- responding to data-subject requests concerning organization-controlled data;
- reviewing AI-generated content before use;
- avoiding unnecessary submission of sensitive data to AI features; and
- complying with applicable privacy, confidentiality, employment, records-management, and sector-specific requirements.
- Your data-protection rights
Where applicable, you may have the right to:
- request access to personal data we hold about you;
- request correction of inaccurate or incomplete information;
- request deletion of your personal data;
- request restriction of processing;
- object to processing based on legitimate interests;
- receive eligible personal data in a structured, commonly used, machine-readable format;
- request transmission of eligible data to another controller;
- withdraw consent where processing is based on consent; and
- lodge a complaint with a competent data-protection authority.
These rights are subject to applicable legal conditions and exceptions.
Where TemplatePoint processes personal data solely on behalf of an organization, you should ordinarily direct your request to that organization. We will provide reasonable assistance where required by law and our agreement with the organization.
We may need to verify your identity before responding to a request.
- Complaints
You may contact us at support@templatepoint.app if you have concerns about how personal data is processed.
You may also lodge a complaint with the Norwegian Data Protection Authority:
Datatilsynet
You may alternatively contact the competent data-protection authority in the country where you live, work, or believe an infringement occurred.
- Cookies and browser storage
TemplatePoint may use cookies, browser storage, and similar technologies necessary to:
- authenticate users;
- maintain active sessions;
- protect the Service against misuse;
- store preferences;
- support application functionality;
- cache information; and
- maintain security.
The browser extension may use Chrome extension storage or similar browser storage to save limited preferences, authentication-related information, or cached content required for its functionality.
Strictly necessary technologies, such as our authentication and language-preference cookies, may be used without consent where permitted by law.
With your consent, we use Microsoft Clarity analytics cookies on our public pages, as described in Section 2.9 and in our Cookie Policy. These analytics cookies are never set unless you actively accept them through our cookie banner, and you may withdraw your consent at any time using the "Cookie settings" control on our public pages.
Any future non-essential advertising or personalization technologies will be disclosed and, where required, will not be enabled until valid consent has been obtained.
- Children's privacy
TemplatePoint is intended for professional and general productivity use and is not directed toward children.
You must not create an account or use the Service if you are below the age at which you can lawfully consent to personal-data processing in your jurisdiction, unless your use is authorized by a parent, guardian, employer, educational institution, or another legally authorized party.
If we become aware that personal data has been collected from a child without an appropriate lawful basis, we may delete the information and close the associated account.
- Payment processing
TemplatePoint does not currently process paid subscriptions through Stripe or another external payment processor.
TemplatePoint does not currently request or store payment-card details through the Service.
If paid subscriptions or external payment processing are introduced, this Privacy Policy will be updated before the payment functionality begins processing customer payment data.
- Business or ownership changes
If TemplatePoint is transferred to a registered company or becomes involved in a merger, acquisition, financing, restructuring, sale of assets, or similar transaction, personal data may be transferred as part of that change.
Where required, users will be notified of a material change in the person or entity responsible for their personal data.
- Changes to this Privacy Policy
We may update this Privacy Policy when:
- the Service changes;
- new functionality is introduced;
- the browser extension's permissions or data practices change;
- service providers change;
- a registered company assumes responsibility for TemplatePoint;
- legal or regulatory requirements change; or
- our processing practices change.
The updated policy will be published on this page with a revised "Last updated" date.
Where a change materially affects how personal data is processed, we may provide additional notice through the Service or by email where appropriate.
- Contact
For questions, privacy requests, or concerns relating to this Privacy Policy or your personal data, contact:
Marius Solheim Operator of TemplatePoint Country: Norway Email: support@templatepoint.app