pinpost
Privacy Policy

Privacy Policy

Last updated: 2026-01-19

This Privacy Policy explains what information may be processed when you use pinpost (“Service”), and how it may be used and shared.

1. Who controls the data

The Service operator (website owner/administrator on the north3.ru domain). Privacy contact: north@gmail.com.

2. Information we may process

Account data: user ID, username, role (client/admin), email (if OTP sign‑in is enabled), and Telegram login identifiers (e.g., Telegram ID/username) if Telegram sign‑in is enabled.

Configuration and integrations: routing configuration, connected platform accounts/pages, API tokens/keys where applicable, proxy configuration, and AI provider settings if you enter them. Sensitive keys may be encrypted at rest where implemented.

Content and queue data: content you submit for publication (text, links, media), generated variants (e.g., AI captions), queue items, delivery status, and error details.

Technical data: IP address, user agent, timestamps, session identifiers, security logs, and login attempt records (for abuse prevention).

Billing data (if billing is enabled): selected plan, subscription status, and payment/invoice identifiers from payment providers (e.g., Stripe or crypto payment processors). We do not receive full card details; they are handled by the provider.

3. Purposes of processing

We process information to: (a) provide and operate the Service (authentication, queueing, publishing, status); (b) secure the Service (abuse prevention, incident investigation); (c) provide support and troubleshooting; (d) manage billing and subscriptions (if applicable); and (e) comply with legal obligations and lawful requests.

4. Legal bases (where applicable)

Where required by applicable law, we rely on: (a) contract performance (providing the Service); (b) legitimate interests (security, abuse prevention, and service improvement); and (c) consent for certain optional features when needed.

5. Sharing and disclosures

We may share information with: (a) connected platforms you choose (when publishing/connecting accounts); (b) infrastructure providers (hosting, storage, email) to operate the Service; (c) AI providers if you enable AI features that send data to a provider; (d) payment providers for billing; and (e) authorities or other parties when required by law.

Third‑party platforms process data under their own policies. You are responsible for complying with their requirements when connecting accounts.

6. Cookies and local storage

We use cookies (or similar storage) mainly for authentication, session management, and security protections (e.g., CSRF). We do not aim to use third‑party advertising trackers on these pages.

7. Retention

We retain information as needed to operate the Service, maintain security, and meet legal obligations. Typical retention targets (may vary by settings/plan): logs ~14 days, media ~30 days, queue items ~60 days, after which data may be deleted as part of maintenance and retention policies.

8. Security

We use reasonable technical and organizational measures (access controls, session protections, login rate limiting, and encryption of sensitive keys where implemented). However, no method of transmission or storage is 100% secure.

9. Your rights and requests

Depending on your location and applicable law, you may request access, correction, deletion, or restriction of processing. Send requests to north@gmail.com with enough information to identify your account and request.

10. International transfers

Connected platforms and providers (including AI and payments) may be located in other jurisdictions. By connecting such services and using related features, you understand that information may be transferred internationally as necessary to provide the Service.

11. Changes to this Policy

We may update this Policy. The updated version becomes effective as of the “Last updated” date on this page.