BackPinPiner

Privacy Policy

Last updated 30 September 2026

This Privacy Policy explains what PinPiner collects, why we use it, who receives it, how long we keep it, and the choices available to you. It applies to pinpiner.com, our web application, the PinPiner apps for iPhone and Android, and the related PinPiner services that link to this policy.

1. Who is responsible for your information

PinPiner is operated by PICH RATHA, doing business as PinPiner. PICH RATHA is the controller of the personal information described in this policy.

Contact: [email protected], +1 689-204-1200, or 2817 Shadwell Place, Greenwood, Indiana 46143, United States.

2. Notice at collection: information we collect

Account and identity information.

  • Email address, username, display name, password hash, account role, account status, and verification status.
  • Confirmation that you are at least 14 years old and the time of that confirmation. Current signup forms do not require your full date of birth. A birthday previously provided or voluntarily added in Settings remains private.
  • Gender, if you choose to provide it. It is optional, private, and is not currently used to rank or recommend content.
  • Profile photo, biography, website or Telegram details, and badge or creator status that you choose to add.

Content and social activity.

  • Videos, images, titles, captions, hashtags, comments, profile shares, and other content you submit.
  • Follows, likes, saves, shares, notifications, creator-support activity, and the people or posts connected to those actions.
  • Reports, appeals, support messages, and information reviewed or recorded by our safety and moderation team.

Media and upload information.

  • Uploaded files and their metadata, including file name, type, size, duration, upload status, storage identifiers, thumbnails, and processing results.
  • Your confirmation that you own or have permission to distribute uploaded content.

Usage, device, and security information.

  • IP address, request times, browser and device information supplied with requests, session and security identifiers, and server logs.
  • Video views, watch time, completion, replay, save, and share signals. A watch session may be linked to your account when you are signed in.
  • Upload-resume records and display preferences kept in your browser, such as theme, contrast, and reduced-motion choices.

Stars and transaction information.

We record your Stars balance, creator-support transfers, badge purchases, adjustments, references, and resulting balances in an auditable ledger. PinPiner does not currently process real-money purchases through the service.

Information from Apple, Google or Meta.

If you choose Sign in with Apple, Google or Facebook sign-in, we receive the provider account identifier, the email address made available for sign-in (Apple may give us a private relay address instead of your real one), and the name you agree to share. We do not receive your Apple, Google or Facebook password and do not post to those accounts for you.

Mobile app permissions and device information.

  • Camera and microphone access to record, and photo library access to pick media or save a clip to your phone, each only when you allow it.
  • A push notification token for your device when you turn notifications on, so we can deliver them.
  • Beauty effects analyse the face in the viewfinder on your phone. That face geometry stays on the device and is not sent to PinPiner; only the finished photo or clip you choose to post is uploaded.

We do not intentionally collect precise geolocation, contact lists, government-issued identifiers, or biometric identifiers, and we do not buy personal information from data brokers. We do not sell or share any category above for cross-context behavioural advertising.

3. Why we use information

  • Provide the service: create and secure accounts, publish and deliver content, operate feeds, process uploads, save preferences, and provide social and creator-support features.
  • Personalise and improve PinPiner: rank content using activity and watch signals, measure reliability, diagnose errors, and improve performance.
  • Protect people and the service: verify accounts, prevent spam, fraud, abuse, malicious uploads, unauthorised access, and manipulation of Stars or engagement counts.
  • Moderate content and enforce our Terms: investigate reports, restrict harmful content, suspend accounts, preserve evidence, and document privileged actions.
  • Communicate with you: send verification, password-reset, security, support, service, and legally required messages.
  • Comply with law: respond to valid legal process, protect rights and safety, keep required records, and make legally required reports.

4. Legal bases for EEA and UK users

Where the GDPR or UK GDPR applies, we process personal data under these legal bases:

  • Contract: information needed to create your account and provide the features you request.
  • Legitimate interests: service security, fraud prevention, moderation, product analytics, content ranking, service improvement, and protecting PinPiner and its users. We balance these interests against your rights.
  • Legal obligation: records and actions required by applicable law or valid legal process.
  • Consent: where we specifically ask for it. You may withdraw consent at any time, without affecting earlier processing.

PinPiner does not make decisions based solely on automated processing that produce legal or similarly significant effects. Feed ranking decides the order of content, not your legal rights or access to essential services.

5. What other people can see

Your username, display name, profile photo, bio, public badge information, public website or Telegram link, follower information, posts, comments, and profile shares may be visible to other users and visitors. Public information can be copied, reshared, downloaded, or indexed by search engines outside our control.

Your email address, password hash, full date of birth, gender, IP address, private session information, and Stars balance are not displayed publicly by PinPiner.

6. When we disclose information

We do not sell personal information or share it for cross-context behavioural advertising.

We disclose information only as needed to:

  • Cloudflare, which provides network delivery, caching, security, and abuse protection.
  • Our infrastructure providers, which host the application, database, Redis services, and operational logs in Singapore.
  • Cloudflare R2 (Asia-Pacific region), which stores private media objects and receives uploads directly from your browser or app through time-limited authorised URLs.
  • Zoho ZeptoMail, which sends account verification, password-reset, security, and service emails.
  • Apple, Google or Meta, when you choose their sign-in option. Their handling of information is also governed by their own privacy policies.
  • Apple Push Notification service and Google Firebase Cloud Messaging, which deliver push notifications to the mobile apps.
  • Professional advisers and service providers bound by confidentiality and data-protection obligations.
  • Authorities or other parties when reasonably necessary to comply with law, valid legal process, protect safety or rights, investigate fraud or abuse, or make a legally required report.
  • A buyer, successor, or other participant in a merger, financing, reorganisation, or sale, subject to appropriate confidentiality protections and notice where required.

7. Cookies, local storage, and third-party sign-in

PinPiner uses strictly necessary cookies to keep you signed in, rotate sessions, and protect state-changing requests against forgery. These include secure session cookies and a security token readable by the application for CSRF protection. Session credentials are not available to browser scripts when secure cookie authentication is enabled.

We use browser storage for interface preferences and unfinished upload or series-upload resume information. In development or where secure cookie authentication is unavailable, browser storage may also hold session credentials. Apple, Google and Meta may use their own cookies or similar technologies when you load or use their sign-in features.

We do not currently use advertising cookies or third-party cross-site behavioural advertising. Browser signals such as Global Privacy Control will be treated as an opt-out where legally required; because PinPiner does not sell or share personal information for behavioural advertising, no separate sale or sharing opt-out is presently needed.

8. How long we keep information

We keep personal information only for as long as reasonably necessary for the purposes described here, including providing the service, resolving disputes, protecting safety, preventing fraud, and meeting legal, accounting, and audit obligations. The criteria below determine the period for each category:

  • Account, profile, social graph, and active content: while your account remains open or the content remains published. We then delete, de-identify, or restrict it unless a longer period is required for safety, disputes, or law.
  • Deleted media: access is revoked promptly and storage objects are deleted or queued for retry if a storage provider is temporarily unavailable. Limited database tombstones may remain to enforce deletion and document moderation actions.
  • Unfinished uploads: authorised upload URLs expire after one hour; abandoned draft uploads are scheduled for cleanup after the configured abandonment window, currently 24 hours.
  • Verification, password-reset, and staff-security codes: codes expire after 10 to 15 minutes and are stored only as cryptographic hashes. Related records are retained only as long as needed for security and abuse investigation.
  • Sessions and security records: active refresh sessions expire after 14 days. Rate-limit records last only for their short enforcement window; staff trusted-IP entries expire after 30 days. Security and server logs are retained according to operational security needs.
  • Views, watch sessions, recommendations, and product analytics: retained while needed to rank content, maintain accurate aggregate counts, prevent manipulation, and improve the service, then deleted or de-identified.
  • Stars ledger, fraud, moderation, report, and legal records: retained as long as needed to preserve ledger integrity, establish or defend legal claims, meet accounting duties, and protect users and the service.
  • Backups: removed through the normal backup rotation rather than immediately. Restored backup data remains subject to this policy and is not put back into ordinary use after a valid deletion request.

9. Security

We use encryption in transit, one-way password hashing, hashed one-time codes and refresh tokens, private object storage, short-lived upload and playback authorisations, role-based administration, staff sign-in safeguards, rate limits, and audit records. No system can be guaranteed completely secure. If a breach creates a legally reportable risk, we will notify affected people and authorities as required by law.

Never send a password, verification code, API key, or other secret to PinPiner through a post or comment. Report suspected account compromise to [email protected] immediately.

10. Children and minimum age

PinPiner is a general-audience service and is not directed to children under 13. You may not create an account if you are under 14. If local law requires a higher age to use an online service or consent to data processing on your own, you must meet that higher age or have any legally required parent or guardian authorisation.

We do not knowingly collect personal information from a child under 13. If we learn that an underage child created an account, we will restrict the account and delete the child's personal information as required. A parent or guardian may contact [email protected] to request review and deletion.

11. Your privacy rights

Depending on where you live, you may have rights to access, know, correct, delete, or receive a portable copy of your personal information; restrict or object to processing; withdraw consent; and appeal a refusal of your request. You may also have the right to opt out of sale, sharing, targeted advertising, or qualifying profiling. PinPiner does not currently engage in those opt-out activities.

You can delete your account yourself at any time from Settings in the PinPiner app. Deletion is permanent and removes your profile, posts and comments from the service as described in section 8.

To exercise a right, email [email protected] with the subject “Privacy Request” or write to the address in section 1. Tell us the username or email connected to the account and the right you want to exercise. We may verify your identity and authority before responding. An authorised agent may submit a request where applicable law permits it.

We will respond within the period required by applicable law and will not discriminate against you for exercising a privacy right. If we deny a request, you may reply to appeal. EEA and UK users may also complain to their local data protection authority, including the UK Information Commissioner's Office where applicable.

12. California disclosures

The categories collected during the preceding 12 months are the categories described in section 2: identifiers; account and profile records; internet or network activity; user content; social and interaction information; commercial or Stars-ledger records; and inferences used for content ranking. Date of birth, account credentials, and security data may be treated as sensitive personal information under some laws. We use sensitive information only for the purposes described in this policy, including service delivery, age eligibility, security, and fraud prevention.

We collect these categories directly from you, automatically from your use of PinPiner, and from Apple, Google or Meta when you choose social sign-in. Purposes, recipient categories, and retention criteria are described in sections 3, 6, and 8. We have not sold personal information or shared it for cross-context behavioural advertising during the preceding 12 months, including information we know belongs to a person under 16.

13. International data transfers

PinPiner is operated by a United States business, application infrastructure is hosted in Singapore, and media is stored and processed in the Asia-Pacific region. Cloudflare and other providers may process information through globally distributed systems. If you use PinPiner elsewhere, your information may be transferred to countries with different data-protection laws.

Where transfer safeguards are required, we use the lawful mechanisms made available by applicable law and our providers, such as adequacy decisions or approved contractual protections. Contact [email protected] to request available information about relevant safeguards.

14. External links and third-party services

Posts and profiles may link to websites, Telegram accounts, or other services that PinPiner does not control. Their privacy practices are governed by their own notices. A clickable link does not mean that PinPiner endorses or is responsible for the destination.

15. Changes to this policy

We may update this policy as PinPiner changes or the law requires. We will update the date at the top and provide additional notice by email or in the service before a material change takes effect when required. We will not use previously collected information for a materially different purpose without the notice or consent required by law.

16. Contact us

Privacy questions, rights requests, and child-safety privacy requests: [email protected]. Postal mail: PICH RATHA / PinPiner, 2817 Shadwell Place, Greenwood, Indiana 46143, United States. Telephone: +1 689-204-1200.

See also our Terms of Service and our Support page.