Privacy Policy
Last updated: 9 October 2026
Overview
AutoPin ("AutoPin", "we", "us") is a web service available at www.autopin.app that helps you turn articles from your own website into Pinterest content. It reads articles from websites you add, uses AI to prepare Pin ideas and images, and can connect to your Pinterest account with your permission.
This policy explains what information we handle, why, who processes it, how long we keep it and what choices you have.
Information we collect
Account information. Your email address, an optional display name and your password. Passwords are handled by our authentication provider and are stored only as a one-way hash; we never see or store your password in readable form. We also store your organization (workspace) name, time zone, members and their roles.
Website information. The website URLs you add, their name, the RSS/Atom feeds or sitemaps we discover or you provide, and scan status information (for example when a scan ran and whether it succeeded).
Article content. For articles found on your websites we store the article URL, title, excerpt, author, category, tags, publication date, featured image URL and the extracted article text. We fetch only publicly reachable pages of websites you added and respect the site's robots.txt rules.
Results we generate. AI analysis results (topic, audience, Pin title and description, keywords, image ideas), generated images and their metadata, and usage and cost figures for those operations.
Pinterest account information. Described in the next section.
Technical and security records. Request and error logs (with secrets redacted), an activity log of important account events (for example connecting or disconnecting Pinterest), and the technical data our hosting provider processes to deliver the site, such as IP address and browser information.
Pinterest authorization and tokens
We access Pinterest data only with your authorization. You connect your account through Pinterest's official sign-in (OAuth) on pinterest.com; AutoPin never asks for or sees your Pinterest password, and we do not use scraping, browser automation or unofficial access.
What we receive and store when you connect:
- Your Pinterest account identifier, username, display (business) name and profile image address, read from Pinterest after you approve access.
- The permissions (scopes) you granted and when the access expires.
- An access token and a refresh token issued by Pinterest. They are encrypted before they are stored (AES-256-GCM, bound to your workspace and account), are used only by our servers to communicate with Pinterest on your behalf, and are never sent to your browser or shown in the interface, API responses or logs.
In its current version AutoPin requests only the Pinterest permission needed to identify the connected account (reading basic account information). It does not currently read your boards or Pins and does not create or publish Pins. If we add features that need further permissions, such as listing boards or creating Pins, Pinterest will show you exactly what is requested, they will only work after you approve them, and we will update this policy before they are enabled.
We use Pinterest data only to provide the connection you asked for. We do not sell Pinterest data, use it for advertising, or share it with other customers. Only owners and admins of your workspace can connect or disconnect Pinterest.
Disconnecting. You can disconnect at any time from the Pinterest page in AutoPin. Disconnecting immediately deletes the stored tokens and the connected-account record from our systems. You can also revoke AutoPin's access in your Pinterest account settings; if you do, the stored authorization stops working and AutoPin will ask you to reconnect.
AI processing
To prepare Pin content we send parts of your articles to OpenAI's API: the article title, excerpt, author, category, tags and a limited portion of the extracted text, together with fixed instructions. We then validate the returned suggestions before saving them. To create images, we send a short image description derived from that analysis to OpenAI's image API.
We do not send your password, your Pinterest tokens or other account secrets to OpenAI. OpenAI processes the content under its own terms and data policies, which we encourage you to review. AI output can be inaccurate or unsuitable; you remain responsible for the content you choose to publish. AI processing happens only when you request it for an article.
Generated images
Images created for your articles are stored in Cloudflare R2 object storage and are delivered to your dashboard through a public web address so that they can be displayed and, in the future, provided to Pinterest. The address contains random identifiers and is not listed anywhere, but anyone who has the exact link can open the image. Images are generated from your own article content; do not process content you are not entitled to use.
How we use information
- To create and secure your account and workspace and to authenticate you.
- To scan your websites, extract articles and prepare Pin suggestions and images you request.
- To connect to Pinterest at your request and keep that connection working (token refresh).
- To keep the service secure, prevent abuse, diagnose problems and keep an audit trail.
- To comply with legal obligations.
We do not sell your personal information and we do not use it for third-party advertising.
Data storage and service providers
We use the following providers to run AutoPin. They process data only to provide their service to us:
- Supabase — authentication and the PostgreSQL database that stores account, website, article, analysis, image and Pinterest connection records.
- OpenAI — AI analysis and image generation, as described above.
- Cloudflare R2 — storage and delivery of generated images.
- Pinterest — the service you connect; governed by Pinterest's own terms and privacy policy.
- A managed Redis service — a job queue for background work. It carries internal identifiers only, not article text or credentials.
- Our web hosting provider — serves the application and processes technical request data.
These providers may store or process data in countries other than your own. We may also disclose information when required by law or to protect rights, safety and the security of the service.
Security
- All traffic to the service uses HTTPS.
- Pinterest tokens are encrypted at rest with authenticated encryption; encryption keys are kept outside the database and never exposed to the browser.
- Each workspace's data is isolated from other workspaces by database-level access controls, and actions such as connecting Pinterest are limited to workspace owners and admins.
- The Pinterest connection flow uses single-use, short-lived authorization checks to protect against request forgery.
- Secrets, tokens and authorization codes are redacted from logs.
No system is perfectly secure. If you believe your account or data has been compromised, please contact us right away.
Retention and deletion
- We keep account, website, article, analysis and image data while your account is active.
- Disconnecting Pinterest deletes the stored Pinterest tokens and account record immediately. Deleting a website removes its stored articles, analyses and image records from our database.
- Security and activity logs are kept for as long as needed for security and troubleshooting. Backups kept by our database provider may retain deleted data for a limited period before they expire.
- Generated image files in storage are removed on request; until then an image may remain available to anyone who has its exact link, even if the related article or website was deleted.
Account deletion. A self-service "delete my account" option is not yet available in the app. To have your account and associated data deleted, contact us using the details below from the email address on your account; we will verify the request and delete your data, except where we must keep information to meet legal obligations.
Your choices and rights
You can disconnect Pinterest, delete websites and review your data inside AutoPin. Depending on where you live, you may also have the right to access, correct, export or delete your personal information, to object to or restrict certain processing, and to complain to your local data protection authority. To exercise these rights, contact us using the details below.
Children's privacy
AutoPin is intended for people who are old enough to enter into a service agreement and manage a business or personal website. It is not directed to children, and we do not knowingly collect personal information from children.
Changes to this policy
We may update this policy as the service changes, for example when new Pinterest features are added. The date at the top shows the latest version. If a change is material, we will provide notice in the service or by email.
Contact
For privacy questions, access or deletion requests, contact blackjack2490@gmail.com.