Privacy
Last updated 30 August 2026
Who is responsible
Pinly is operated by Jonas Schmidt, Küssnachterstrasse 8, 6343 Risch ZG, Switzerland. That person is the controller under Art. 4(7) GDPR and the responsible party under the Swiss Federal Act on Data Protection (FADP).
For anything on this page, write to jonas.schmidt07@gmail.com.
Which law applies
The operator is in Switzerland, so the Swiss FADP applies. Where Pinly is offered to people in the EU or UK, the GDPR applies as well, and the rights described below are the ones it grants. Personal data is stored and processed on servers in Nuremberg, Germany — inside the EEA, so no transfer to a third country is involved.
What we store, and why
Your account. Email address, name and a hashed password, so you can sign in. If you sign in with Google, we store the provider account identifier instead of a password.
Your workspace. Brand kit, business profile, the pages we read from the website you asked us to analyse, your keywords, ideas, campaigns, Pin drafts and the images you upload. This is the content the product works on.
Your Pinterest connection. When you connect Pinterest we store the account identifier and username, your board names and identifiers, and OAuth access and refresh tokens. Tokens are encrypted at rest with AES-256-GCM before they are written to the database, are never sent to your browser, and are only ever used server-side.
Published Pins and their results. The Pins we created on your behalf, and a daily record per Pin of impressions, outbound clicks, Pin clicks, saves, comments, reactions, profile visits and follows, as reported by the Pinterest API. This is what the analytics in the product are computed from.
Saved references. If you use the library, we store the title, description, link and a thumbnail URL of Pins you saved to your own Pinterest boards, together with structural facts about them. The thumbnail is referenced from Pinterest and is not copied into our storage.
Operational records. An audit log of significant actions, product usage counters for your plan limits, and a record of each AI call (provider, model, token counts and cost — not a copy of the response).
Who else sees it
We use a small number of processors, and only the ones that are switched on for your deployment:
- Pinterest — to read your boards and analytics, and to publish the Pins you approved.
- An AI provider ([Anthropic or OpenAI]) — receives the text we ask it to work on: your page content, headlines, and computed statistics. It is never given your Pinterest tokens.
- Stripe — payment details, if you subscribe. We never see or store your card number.
- An email provider ([Resend]) — to deliver team invitations.
- Hetzner Online GmbH, Germany — the servers and the database run there, in their Nuremberg data centre.
We do not sell your data and we do not use it to train models.
Disconnecting and deletion
Disconnecting Pinterest revokes the token with Pinterest and deletes the stored credentials immediately. Deleting a workspace deletes everything belonging to it, including Pins, metrics, references and uploaded images. Write to jonas.schmidt07@gmail.com to have your account removed entirely.
Your rights
You have the right to access, correct, export and erase your data, and to object to processing — under the Swiss FADP wherever you are, and under the GDPR if you are in the EU or UK. Contact jonas.schmidt07@gmail.com and we will respond within one month.
Cookies
Pinly sets three cookies, all strictly necessary: a session cookie so you stay signed in, a cookie holding the workspace you last had open, and one remembering whether you chose the light or dark theme. There is no advertising or analytics tracking.
A note on this page
The sections above describe what the software actually does — they were written against the code, not adapted from a template. Anything still marked needs filling in, and this is a description of behaviour rather than legal advice. Have it reviewed before you rely on it.