Privacy policy
Last updated 6 October 2026
This policy says what personal data Pinework handles, why, who else gets it, how long we keep it, and what your rights are.
1. Who we are
Netarkauf SRL, a company registered in Romania, runs Pinework. It is the controller of the personal data this policy covers.
Write to contact@pinework.ai about anything in this policy.
2. Our two roles
Controller. We decide how to use your account, billing, support, security and analytics data. This policy covers that data.
Processor. Your company decides what goes into its workspaces: tasks, comments, files, wiki pages, instructions, code and run transcripts. If that content holds personal data about other people, your company is the controller. We process that data for your company, under section 16 of our terms of service.
3. What we collect
- Account: your email, your name and your sign-in details. If you sign in with Google, we get the email and basic profile Google shares.
- Company and billing: your company name, its billing contact and its plan. Our payment provider holds your card details. We never see your full card number.
- Workspace content: what you and your agents put into Pinework, as listed in section 2. This includes the repositories and services you connect.
- Credentials you store: keys, tokens and secrets you give Pinework so your agents can work. We store them encrypted and use them only to run your work.
- Devices: when you connect a device, its name and registration.
- Usage records: each run's tokens, cost and timing.
- Technical data: your IP address and request logs, for security and to stop abuse.
- Analytics: when you are signed in, product events such as "run started", and page views with their path, tied to account ids, never to your name or email. We use them only for genuine business needs: to learn how Pinework is used and to improve it. Analytics are on by default, and you can turn them off in settings.
- Error reports: technical details of an error and the account it hit, so we can fix it.
We do not track visitors who are not signed in.
We do not ask for special category data, such as health data. Do not put it into Pinework unless your work needs it.
4. Why we use it, and on what legal basis
- To create your account, sign you in, run your agents and store your work: our contract with you.
- To bill you and keep invoices: our contract with you, and our legal obligations.
- To send sign-in, invite and account emails: our contract with you.
- To keep Pinework secure, stop abuse, and find and fix errors: our legitimate interest in a safe, working service.
- For product analytics: our legitimate interest in learning how Pinework is used, so we can improve it. You can turn it off in settings at any time.
- To answer your requests and legal demands: our legal obligations.
We do not sell or rent personal data. We show no ads. We make no automated decisions about you.
We do not train AI models on your content. The model vendor your agents use handles your prompts and output under its own terms, including how it uses that data.
5. Who else gets it
We use service providers to run Pinework. Each gets only the data its job needs.
- Hosting: Fly.io, Vercel and Supabase run our servers, database, file storage and cloud sandboxes.
- Payments: Stripe.
- Email: Resend delivers our emails. Our emails load fonts from Google Fonts, which sees the reader's IP address.
- Error monitoring: Sentry.
- Product analytics: PostHog, in the EU, for signed-in users who have not turned analytics off.
- Providers of AI features we run for you, such as search.
- Push notification services, such as Apple's, which carry the text of the notifications you get.
- Google, if you choose to sign in with Google.
Email us for the full current list of providers.
Services you choose. Your agents send prompts, files and code to the model vendor you pick, with your own key or subscription. Services you connect get data through your own access. Those vendors act under your account and their own terms, not ours.
We give data to authorities only when the law requires it.
6. Where your data goes
Some providers handle data outside the European Economic Area, including in the United States. When data leaves it, we rely on an adequacy decision, such as the EU-US Data Privacy Framework, or on the European Commission's Standard Contractual Clauses. Ask us for a copy.
7. How long we keep it
While you have an account, we keep your data so Pinework works.
When you delete your account, we delete your user account and every company you own alone, with all its workspaces and content. We finish deleting within 30 days.
Some data stays after that:
- In a company you share with others, what you wrote stays. It belongs to that company, and it no longer shows your name or email.
- Invoices and billing records stay as long as Romanian tax and accounting law requires.
- Backup copies stay until they expire on their normal cycle.
We delete these records after the time shown, even if you still have an account:
| Data | How long |
|---|---|
| IP addresses and request logs | 1 year |
| Error reports | 1 year |
| Analytics events | 1 year |
Your provider keys stay live at your model vendor after you leave. Rotate them there.
8. Security
We protect personal data with technical and organisational measures that fit the risk. Data travels over encrypted connections. Only the people and systems that need data can reach it. No system is perfectly secure.
If a breach puts your data at risk, we tell the Romanian data protection authority within 72 hours and tell you without undue delay, as the GDPR requires.
Report a security problem to contact@pinework.ai.
9. Cookies
We use cookies and similar browser storage to keep you signed in, keep Pinework secure and remember your settings, including your analytics choice. We send no analytics events for signed-out visitors.
We use no advertising cookies or tracking pixels.
10. Your rights
You can ask us to:
- give you a copy of your data
- correct it
- delete it
- restrict or object to how we use it
- send it to you or to another service in a common format
- stop analytics, by turning it off in settings or by email.
Email contact@pinework.ai. We answer within one month. We may ask you to prove who you are.
If your data sits in a company's workspace, we pass your request to that company, because it decides about that data.
You can complain to the Romanian data protection authority, ANSPDCP (www.dataprotection.ro), or to the authority where you live or work.
11. Age
Pinework is for people 18 and over. We do not knowingly collect data from anyone younger.
12. Changes
We email account holders before a material change to this policy takes effect. The date at the top shows the last change.
Contact
Netarkauf SRL, Romania. contact@pinework.ai