1. Introduction

Pinforge (also known as Pinterest Money Machine) is a SaaS tool that helps creators and marketers automate Pinterest content creation and publishing. It is operated by Pinforge and accessible at https://pinforge.net.

This Privacy Policy explains what personal data we collect, why we collect it, how we use and protect it, and what rights you have over it. By creating an account or using our service you agree to this policy.

If you have questions about anything in this policy, email us at [email protected]. We respond within 30 days.

2. What data we collect

Account data — When you register we collect your email address and a hashed version of your password. We never store your password in plaintext.

Payment data — Payments are handled entirely by Stripe. We never see or store your card number, CVV, or full payment details. We receive a Stripe customer ID and subscription status so we know which plan you are on.

Pinterest data — When you connect a Pinterest account, you authorise us to receive an API access token via Pinterest OAuth. We store this token (encrypted) to post pins on your behalf. We also fetch your board names and IDs via the Pinterest API to let you choose where to post.

Content data — We store the pin titles, descriptions, image paths, and affiliate links that you create or that we generate for you. This is the core content the service produces.

Usage data — We record how many pins you have posted, your AI credit consumption, login timestamps, and other service-usage metrics. This lets us enforce plan limits and show you analytics.

Technical data — Our servers record standard access logs including your IP address, browser user-agent, and the pages you visit. These logs are retained for 90 days.

Cookie data — We use session cookies for authentication and optional affiliate referral cookies (see Cookies section).

3. How we use your data

We do not sell your personal data to third parties.
We do not use your content or data to train AI models.

4. Third-party services

We share data with the following providers only to the extent necessary to deliver the service. Each has its own privacy policy:

Provider Purpose Privacy policy
Stripe Payment processing and subscription management stripe.com/privacy
Resend Transactional email delivery resend.com/privacy
OpenAI AI-generated pin titles and descriptions openai.com/privacy
fal.ai AI image generation fal.ai/privacy
Pexels Stock photo library pexels.com/privacy-policy
Pinterest Pin publishing via official API policy.pinterest.com/privacy-policy
Hetzner Cloud hosting (servers located in EU) hetzner.com/legal/privacy-policy
Cloudflare CDN and DDoS protection cloudflare.com/privacypolicy

5. Data storage and security

We take security seriously and apply industry-standard practices. However, no service can guarantee absolute security. If you discover a vulnerability please report it to [email protected].

6. Data retention

Data type Retention period
Account data (email, profile) Until you delete your account
Payment records 7 years (legal requirement)
Posted pin history 2 years
Server access logs 90 days

When you delete your account, all personal data associated with it is permanently deleted within 30 days, except payment records which we are required to retain by law for 7 years.

7. Your rights (GDPR)

Our servers are in the EU and we serve EU users, so the General Data Protection Regulation (GDPR) applies. You have the right to:

To exercise any of these rights, email [email protected]. We will respond within 30 days.

8. Cookies

We use the following cookies:

Cookie Purpose Expiry
access_token Session authentication — required for you to stay logged in Expires on logout / short-lived
refresh_token Refreshes your session without requiring you to log in again 30 days
ref Affiliate referral code — tracks which partner referred you for commission attribution 60 days

We do not use advertising cookies, third-party tracking pixels, or analytics cookies (such as Google Analytics).

Session cookies are strictly necessary for the service to function and do not require your consent. Affiliate cookies are set only if you arrive via a referral link.

9. Children

Pinforge is not directed at children under the age of 16. We do not knowingly collect personal data from children. If you believe a child has created an account on our platform, please contact us at [email protected] and we will delete the account promptly.

10. Changes to this policy

We may update this policy from time to time. When we do, we will:

Continued use of the service after changes are published constitutes your acceptance of the updated policy.

11. Contact

For any privacy-related questions, requests, or concerns: