20% off your first month —
ends in47:59:59

Privacy Policy

Last updated: March 11, 2026

1. Information We Collect

We collect information you provide directly to us, including when you create an account, purchase a subscription, or use our services. This may include:

  • Name and email address (via Google Sign-In)
  • Payment information (processed securely by LemonSqueezy)
  • Blog URLs you submit for pin generation
  • Generated pin data (titles, descriptions, keywords)
  • Usage statistics (pins generated, remaining balance)
  • Device and browser information
  • IP address and location data

2. How We Use Your Information

We use the information we collect to:

  • Provide, maintain, and improve our services
  • Process your transactions and manage subscriptions
  • Generate Pinterest-optimized content using AI
  • Track your monthly usage limits and pin generation
  • Send you technical notices, updates, and support messages
  • Respond to your comments, questions, and support requests
  • Analyze usage patterns to improve our service
  • Prevent fraud, abuse, and unauthorized access
  • Comply with legal obligations

3. Authentication & Account Data

🔐 Google Sign-In:

We use Google OAuth for secure authentication. When you sign in with Google, we receive your name, email address, and profile picture. We do not have access to your Google password. Your Google account credentials remain with Google.

If you use a license key instead of Google Sign-In, we store your email address and license key to manage your subscription and usage limits.

4. Your Pinterest Data

🔒 Important Privacy Notice:

PinsMachine NEVER connects to your Pinterest account. We do not ask for, store, access, or process any data from your Pinterest account. All pin generation happens on our servers, and we provide you with a CSV file that you upload to Pinterest yourself. We never see your Pinterest credentials, account data, or have any access to your Pinterest boards.

5. AI-Generated Content

When you use our service, we process your blog URLs through AI services to:

  • Extract content and analyze your blog posts
  • Generate SEO-optimized titles and descriptions
  • Extract relevant keywords
  • Create AI-generated Pinterest pin images (paid plans only)

Your blog URLs and extracted content are processed temporarily and are not permanently stored after pin generation is complete. Generated pins, titles, and descriptions are delivered to you via CSV download.

6. Data Security

We take reasonable measures to help protect your personal information from loss, theft, misuse, unauthorized access, disclosure, alteration, and destruction:

  • All data transmission is encrypted using SSL/TLS
  • Payment information is processed securely by LemonSqueezy (PCI-DSS compliant)
  • We never store your credit card details
  • Database access is restricted and monitored
  • Regular security audits and updates

7. Third-Party Services

We use the following third-party services:

  • Google OAuth: For secure user authentication
  • OpenAI GPT-4: For AI-powered pin title and description generation
  • Replicate (Flux/Ideogram): For AI-generated Pinterest pin images
  • LemonSqueezy: For secure payment processing and subscription management
  • Supabase: For secure database hosting
  • Vercel: For website hosting and content delivery
  • Resend: For transactional email delivery

These services have their own privacy policies governing how they handle data. We recommend reviewing their policies. We only share the minimum data necessary for each service to function.

8. Data Retention

We retain different types of data for different periods:

  • Account Information: Retained while your account is active and for 90 days after deletion
  • Blog URLs: Processed in real-time and not permanently stored
  • Generated Content: Delivered via CSV download and not stored on our servers
  • Usage Statistics: Retained for 12 months for billing and analytics
  • Payment Records: Retained for 7 years for tax and legal compliance
  • Support Communications: Retained for 2 years

9. Your Rights

Depending on your location, you may have the following rights:

  • Access: Request a copy of your personal data
  • Correction: Request correction of inaccurate data
  • Deletion: Request deletion of your data (subject to legal requirements)
  • Export: Request a machine-readable copy of your data
  • Opt-out: Unsubscribe from marketing communications
  • Object: Object to processing of your data for certain purposes
  • Restrict: Request restriction of processing in certain circumstances

To exercise any of these rights, please contact us at support@pinsmachine.com

10. Cookies and Tracking

We use cookies and similar tracking technologies to:

  • Keep you signed in across sessions
  • Remember your preferences (dark mode, settings)
  • Analyze how you use our service
  • Prevent fraud and abuse

You can instruct your browser to refuse all cookies or to indicate when a cookie is being sent. However, if you do not accept cookies, you may not be able to use all features of our service.

11. International Data Transfers

Your information may be transferred to and processed in countries other than your country of residence. These countries may have data protection laws that are different from the laws of your country. We ensure appropriate safeguards are in place to protect your data in accordance with this Privacy Policy.

12. Children's Privacy

Our service is not intended for children under 18. We do not knowingly collect personal information from children under 18. If you become aware that a child has provided us with personal information, please contact us and we will take steps to delete such information.

13. California Privacy Rights

If you are a California resident, you have specific rights under the California Consumer Privacy Act (CCPA). This includes the right to know what personal information we collect, the right to delete your personal information, and the right to opt-out of the sale of your personal information. We do not sell your personal information.

14. GDPR Compliance

If you are located in the European Economic Area (EEA), you have certain rights under the General Data Protection Regulation (GDPR). We process your data based on your consent, contractual necessity, legal obligations, or our legitimate interests. You have the right to withdraw consent, lodge a complaint with a supervisory authority, and exercise other GDPR rights described in Section 9.

15. Changes to This Policy

We may update our Privacy Policy from time to time. We will notify you of any material changes by posting the new Privacy Policy on this page and updating the "Last updated" date. We may also notify you via email. Your continued use of the service after changes constitutes acceptance of the updated Privacy Policy.

16. Contact Us

If you have any questions about this Privacy Policy or our data practices, please contact us: