Skip to content
Legal

Privacy policy

This explains what PinSked stores, what it deliberately does not store, and what you can ask us to do with any of it. It is written to be read, not to be survived.

Last updated 7 August 2026

Who we are

PinSked operates the PinSked application and this website. For data protection purposes we are the controller of the personal data described below. Registered address available on request — contact [email protected].

Where you use PinSked to publish on behalf of your own clients, you are the controller of your clients' data and we act as your processor for it.

What we collect

Account data

  • Your name and email address.
  • A hashed password, and — if you enable them — two-factor secrets or passkey credentials.
  • The team you belong to and your role in it.

Content you create

  • Pin drafts: titles, descriptions, alt text, destination links and target boards.
  • Images you upload and images we render from templates.
  • Brand kits, presets, schedules and approval decisions.

Connection data

  • Your Pinterest account ID, username, account type and the scopes you granted.
  • Encrypted OAuth access and refresh tokens, plus their expiry times.
  • The timezone you set for each connected account.

Billing data

  • Your credit balance and a ledger of purchases and deductions.
  • Billing name, country and any tax identifier you supply.
  • We never see or store your card details. Payments are handled by our payment provider, who is the merchant of record.

Technical data

  • Server logs containing IP address, browser user agent, timestamps and the pages requested.
  • Audit log entries for security-relevant actions: approvals, schedule changes, account connections and disconnections, and logins.
  • Error reports when something in the application breaks.

Pinterest data

PinSked talks only to Pinterest's official API. We do not scrape pinterest.com and we do not use unofficial endpoints.

Data we read from Pinterest on your behalf — your board list, pin performance and account statistics — is fetched live and cached for minutes, not stored. Board lists are cached for up to fifteen minutes and analytics for up to ten minutes so that a page load does not hammer the API. After that the cache expires and the data is gone from our systems.

The exceptions are the small identifiers we need to keep working: your Pinterest account ID, your username for display, the board ID a scheduled pin is aimed at, and the pin ID Pinterest returns after a successful publish.

Disconnecting an account deletes the stored tokens for it. You can also revoke PinSked's access from Pinterest's own settings at any time, which stops us being able to read or publish anything.

AI processing

When you ask PinSked to draft copy, the text or image you provide is sent to a third-party model provider to generate a suggestion. What we send is limited to what the generation needs: your prompt or keyword, the source text or image, and your board names when you have asked for a board suggestion.

If you connect your own provider key, requests go to that provider under your own account and are governed by their terms. If you use the built-in provider, we send the request under ours. In both cases we record the generation's metadata — model, token counts, cost and the resulting draft — so you can see what a credit was spent on. We do not use your content to train models, and we select providers that contractually do not train on API inputs.

How we use it

  • To run the product: render pins, draft copy, hold the approval queue and publish on schedule.
  • To keep your account secure and to investigate abuse.
  • To charge credits correctly and show you what they were spent on.
  • To send service email: publishing failures, low balance warnings, re-authorisation notices, and receipts.
  • To fix bugs and understand which parts of the product are actually used.

We do not sell personal data, and we do not share it with advertisers.

Legal bases

Where the UK/EU GDPR applies, we rely on:

  • Contract — to give you the service you signed up for.
  • Legitimate interests — security, abuse prevention, and improving the product, balanced against your rights.
  • Legal obligation — tax and accounting records.
  • Consent — for any non-essential cookies and for marketing email, which you can withdraw at any time.

Who we share with

We use a small number of processors, each for a specific job:

ProcessorPurposeData
Hosting providerApplication servers and databaseAll application data
Cloudflare R2Image storage and deliveryUploaded and rendered images
Payment providerCheckout, invoicing and taxBilling details, card data (never seen by us)
Email providerTransactional emailName, email address, message content
AI model providersCopy and image generationPrompts and source content you submit
PinterestPublishing and analyticsPin content you approved for publishing

We will also disclose data where the law requires it, or to establish or defend legal claims. If the business is ever sold, your data would transfer with it and you would be told before that happened.

How long we keep it

  • Account and content — while your account is open, then deleted within 30 days of closure.
  • Pinterest tokens — until you disconnect the account, then deleted immediately.
  • Cached Pinterest data — 10 to 15 minutes.
  • Audit logs — 24 months, because they are the record of who approved what.
  • Server logs — 30 days.
  • Billing records — as long as tax law requires, typically 6 to 7 years.

Security

  • All traffic runs over TLS.
  • OAuth tokens and provider API keys are encrypted at rest and never displayed after they are saved.
  • Passwords are hashed; two-factor authentication and passkeys are available and recommended.
  • Access to production systems is limited to the people who need it and is logged.

No service can promise perfect security. If a breach affects your personal data we will notify you and the relevant supervisory authority within the timeframes the law sets.

Your rights

Depending on where you live, you can ask us to:

  • Give you a copy of the personal data we hold about you.
  • Correct anything that is wrong.
  • Delete your data, subject to records we are legally required to keep.
  • Restrict or object to certain processing.
  • Export your data in a portable format.
  • Withdraw consent where consent is what we relied on.

Email [email protected] and we will respond within 30 days. If you are in the UK or EU and you are not satisfied, you can complain to your local data protection authority.

International transfers

Our servers are in the EU. Some processors — payment, email and AI providers — operate in the United States. Those transfers are covered by Standard Contractual Clauses or an equivalent approved mechanism.

Children

PinSked is a business tool and is not directed at anyone under 16. We do not knowingly collect data from children. If you believe a child has created an account, tell us and we will remove it.

Changes to this policy

When this policy changes we update the date at the top. For changes that materially affect how we handle your data, we will email account owners at least 14 days before the change takes effect.

Contact

Privacy questions and data requests: [email protected]. Everything else: [email protected].