Skip to content
PinForge AI
FeaturesPricingAboutFAQContact
Log in Get started
FeaturesPricingAboutFAQContact

Privacy Policy

Last updated: December 1, 2024 · Effective: December 1, 2024

Plain English summary: We collect only what we need to run PinForge AI. We never sell your data. We never store your Pinterest password — only the OAuth token Pinterest issues. You can delete your data anytime by emailing privacy@pinforgeai.com.

Contents

  1. Who we are
  2. Data we collect
  3. How we use your data
  4. Pinterest OAuth & API
  5. AI providers (Gemini, OpenAI, DeepSeek)
  6. Third-party services
  7. Data storage & security
  8. Cookies & local storage
  9. Your rights
  10. GDPR (EU users)
  11. Children's privacy
  12. Changes to this policy
  13. Contact us

1. Who we are

PinForge AI ("we", "us", "our") is a Software-as-a-Service platform that provides Pinterest scheduling and AI content generation services. We operate at pinforgeai.site.

For privacy inquiries, contact us at: privacy@pinforgeai.com

2. Data we collect

2.1 Account data

When you create a PinForge AI account, we collect:

  • Email address (used for login and communications)
  • Full name (optional, for personalization)
  • Password (stored as a bcrypt hash — we never store plain-text passwords)
  • Account creation timestamp

2.2 Pinterest connection data

When you connect a Pinterest account via OAuth2, we store:

  • Pinterest username and display name (from Pinterest's API)
  • Pinterest profile image URL (from Pinterest's API)
  • OAuth access token (encrypted at rest)
  • OAuth refresh token (encrypted at rest)
  • Token expiry timestamp

We never store your Pinterest password. The OAuth2 flow means you log in through Pinterest's own consent screen — we only receive the token Pinterest issues after you approve.

2.3 Content you create

When you create pins, we store:

  • Uploaded images (stored on our servers temporarily; moved to Supabase Storage in future updates)
  • Pin titles, descriptions, hashtags, alt text
  • Destination links (affiliate URLs, product URLs)
  • Target board ID and name
  • Scheduled post times
  • Content hash (SHA-256 of title + description, used for duplicate prevention)

2.4 Activity logs

We maintain an audit log of every posting action, which includes:

  • Timestamp of each attempt
  • Status (posted, failed, skipped, duplicate, rate_limit)
  • Pinterest pin ID (if successfully posted)
  • Error messages (if failed)
  • Board name and title

2.5 Usage data

We may collect basic usage analytics such as pages visited and features used. We do not use third-party tracking pixels or ad network tracking.

2.6 AI API keys

If you provide your own Gemini, OpenAI, or DeepSeek API keys in Settings, we store them encrypted in our database. These keys are used only to make AI content generation requests on your behalf — never for any other purpose.

3. How we use your data

We use your data exclusively to:

  • Provide the PinForge AI service (authentication, pin scheduling, AI content generation)
  • Send transactional emails (account confirmation, support responses, billing notifications)
  • Maintain the security and integrity of your account
  • Enforce our safety limits (daily cap, duplicate prevention)
  • Improve our service (aggregate, anonymized usage patterns only)
  • Comply with legal obligations

We never sell your data. We never use your data for advertising. We never share your content with other users.

4. Pinterest OAuth & API compliance

PinForge AI is built exclusively on the official Pinterest API v5. Our use of Pinterest's API complies with:

  • Pinterest API Terms of Service
  • Pinterest Developer Guidelines
  • Pinterest's OAuth2 authorization flow

We request only the minimum OAuth scopes required: boards:read, boards:write, pins:read, pins:write, user_accounts:read.

Users can revoke PinForge AI's access to their Pinterest account at any time by visiting Pinterest's security settings at pinterest.com/settings/security.

5. AI providers

PinForge AI uses third-party AI providers to generate pin content. Depending on your selected provider:

5.1 Google Gemini (default)

Your product description, keywords, and optionally your image are sent to Google's Gemini API to generate pin content. Google's handling of this data is governed by the Gemini API Terms of Service and Google's Privacy Policy. If you use your own Gemini API key, you are subject to Google AI Studio's terms directly.

5.2 OpenAI (optional)

If you choose OpenAI as your AI provider, your content is sent to OpenAI's API. OpenAI's handling is governed by the OpenAI API Data Usage Policies.

5.3 DeepSeek (optional)

If you choose DeepSeek, your content is sent to DeepSeek's API. Please review DeepSeek's Privacy Policy before using this provider.

Important: We recommend not including sensitive personal information in your product descriptions sent to AI providers, as these are processed by third-party servers.

6. Third-party services

We use the following third-party services to operate PinForge AI:

  • Supabase — Authentication, database (PostgreSQL), and file storage. Data is hosted on AWS infrastructure. Supabase Privacy Policy
  • Railway — Backend hosting (FastAPI server). Railway Privacy Policy
  • Vercel — Frontend hosting (Next.js). Vercel Privacy Policy
  • Stripe (coming with paid plans) — Payment processing. We never store full payment card details. Stripe Privacy Policy
  • Pinterest API — Pin and board management via official API. Pinterest Privacy Policy

7. Data storage & security

Your data is stored in a Supabase PostgreSQL database with the following protections:

  • All data is encrypted at rest (AES-256)
  • All data in transit is encrypted via TLS 1.2+
  • Passwords are hashed using bcrypt (never stored in plain text)
  • OAuth tokens are stored with database-level encryption
  • API keys you provide are stored encrypted
  • EXIF metadata is stripped from images before storage
  • Access to the database is restricted to PinForge AI's backend service only

We retain your data for as long as your account is active. If you delete your account, we delete all associated data within 30 days, except where legally required to retain it (e.g., billing records for 7 years in some jurisdictions).

8. Cookies & local storage

PinForge AI uses minimal cookies and browser storage:

  • Supabase Auth session cookie — Required for keeping you logged in. This is an essential cookie; the service cannot function without it.
  • Theme preference — Stored in localStorage to remember your dark/light mode preference. Contains no personal data.
  • No advertising cookies. We do not use Google Analytics, Facebook Pixel, or any advertising network tracking.

9. Your rights

You have the following rights regarding your personal data:

  • Access: Request a copy of all data we hold about you
  • Correction: Request correction of inaccurate data
  • Deletion: Request deletion of all your data ("right to be forgotten")
  • Portability: Request your data in a machine-readable format (CSV)
  • Objection: Object to certain processing activities
  • Restriction: Request restriction of processing while a dispute is resolved
  • Withdraw consent: Withdraw consent at any time (this will not affect the lawfulness of prior processing)

To exercise any of these rights, email us at privacy@pinforgeai.com with the subject line "Data Rights Request". We will respond within 30 days.

You may also disconnect PinForge AI from your Pinterest account at any time via Pinterest's security settings, which immediately revokes our ability to post on your behalf.

10. GDPR (EU/EEA users)

If you are located in the European Union or European Economic Area, you have additional rights under the General Data Protection Regulation (GDPR).

Legal basis for processing:

  • Contract performance: Processing necessary to provide the PinForge AI service you signed up for
  • Legitimate interests: Security monitoring, fraud prevention, service improvement
  • Consent: Marketing emails (you may withdraw at any time)
  • Legal obligation: Compliance with applicable laws (e.g., retaining billing records)

You have the right to lodge a complaint with your local data protection authority (DPA) if you believe we have not handled your data appropriately.

11. Children's privacy

PinForge AI is not directed to children under the age of 13 (or 16 in the EU). We do not knowingly collect personal information from children. If we become aware that a child under 13 has provided us with personal information, we will delete it immediately. If you believe a child has provided us with their data, please contact us at privacy@pinforgeai.com.

12. Changes to this policy

We may update this Privacy Policy from time to time. When we make material changes, we will:

  • Update the "Last updated" date at the top of this page
  • Notify registered users via email at least 14 days before changes take effect
  • Show a notice in the PinForge AI dashboard

Your continued use of PinForge AI after the effective date of changes constitutes acceptance of the updated policy.

13. Contact us

For any privacy-related questions, requests, or concerns:

  • Email: privacy@pinforgeai.com
  • General contact: Contact form
  • Mailing address: Available upon request

We aim to respond to all privacy inquiries within 5 business days and no later than 30 days as required by law.

PinForge AI

AI-powered Pinterest automation using the official API v5.

Product

  • Features
  • Pricing
  • FAQ

Company

  • About
  • Contact

Legal

  • Privacy Policy
  • Terms of Service

Support

  • Help Center
  • Contact

© 2026 PinForge AI. All rights reserved.

PrivacyTerms