Privacy Policy
Last updated: September 9, 2026
1. Introduction
PINBOARD LLC, a New York limited liability company ("Pinboard," "we," "our," or "us"), operates the Pinboard platform at pinboard.ai. This Privacy Policy explains how we collect, use, store, and protect your personal information when you use our website, work platform, desktop and mobile apps, recording features, APIs, and integrations.
This policy provides information about our processing; it does not replace consent where consent is required for a particular activity. When your organization provides a workspace, it determines how work content is used and who may access it. Contact your organization about its own policies and instructions for that content.
2. Information We Collect
Account Information
When you create an account, we collect your name, email address, and optionally a profile picture. If you sign in via a third-party provider (Google, GitHub, or Microsoft), we receive basic profile information from that provider.
Usage Data
We collect information about how you interact with our platform, including pages visited, features used, and actions taken. This helps us improve the product experience.
Content You Provide
This includes projects, tasks, comments, files, notes, and any other content you create or upload to Pinboard. This data is stored to provide the service to you and your workspace.
Communication Data
If you request access or contact support, we receive the contact details and information you submit. Billing records can include subscription details, invoices, and payment status. Security and diagnostic records can include IP address, browser or device details, errors, and account activity.
We send transactional emails related to your account activity (sign-in links, workspace invitations, task notifications). We retain email delivery metadata to maintain deliverability and comply with anti-spam regulations.
Recordings and Connected Services
Meeting features can store audio, transcript segments, speaker labels, and summaries in the workspace. Participants should receive the notices and consent choices required for the recording. If you connect an external service, we process credentials and the records imported, synchronized, or sent through that integration according to its permissions. You can also provide personal information about others through customer records, support tickets, invitations, and shared work.
3. How We Use Your Information
- Provide, maintain, and improve the Pinboard platform
- Authenticate your identity and manage your account
- Send transactional emails (sign-in links, invitations, notifications)
- Power AI features such as intelligent task suggestions and insights
- Monitor and prevent abuse or security threats
- Comply with legal obligations
4. Data Storage and Security
Your data is stored on secure infrastructure hosted by Amazon Web Services (AWS) in the United States. We implement industry-standard security measures including:
- Encryption in transit (TLS) and at rest
- Role-based access controls
- Regular security reviews and monitoring
- Secure authentication with multi-factor authentication (MFA) support
5. Third-Party Services
Content is accessible to collaborators according to workspace, project, and sharing permissions. Publicly published content and public sharing links can be accessed by their intended audience, which may include people outside your organization. Connected services receive information when you authorize features that send it to them.
We use the following third-party services to operate Pinboard:
- Amazon Web Services (AWS) — Infrastructure, database hosting, and file storage (S3)
- Resend — Email delivery. Receives the recipient address, the subject and body of the message, and any file attached to it.
- Cloudflare — Content delivery and protection. Sits in front of Pinboard, so it processes request metadata including your IP address.
- Stripe — Payment processing for subscriptions. Card details are entered on Stripe’s own hosted page and never pass through Pinboard.
- AI model providers — OpenAI, Google, xAI and Anthropic. See the section below for what is sent and when.
- Nominatim / OpenStreetMap — Geocoding for the CRM territory map. When you import or map accounts, the account name and state are sent to look up map coordinates.
- CARTO — Map basemap tiles for the CRM territory map. Your browser loads tiles directly from CARTO, so it receives your IP address and the area of the map you are viewing.
- OAuth Providers (Google, GitHub, Microsoft) — Sign-in profile information for authentication. Separately enabled integrations may access additional data under their own permissions
- Apple — Push notifications, if you enable them on a mobile device. Receives a device token and the notification text, which names the sender and what happened but never the contents of a message.
We do not sell your personal information to third parties.
We may also disclose information where required by law or necessary to investigate abuse, protect rights and safety, or respond to legal claims. Our infrastructure is hosted in the United States; service providers may process information in other countries. Contact us about processing locations and contractual safeguards relevant to your use.
5a. AI providers and what reaches them
Pinboard uses several AI providers — currently OpenAI, Google, xAI and Anthropic — and may route a given request to any of them, including automatically falling back to a different provider if one is unavailable. We list them all because we cannot promise which one handles a particular request.
Two different things send content to these providers, and it is worth being clear about the difference:
- When you use an AI feature. Asking the assistant a question, generating a summary or a recap, or letting a bot reply sends the relevant content for that request.
- Automatically, to make your content searchable.When you upload a document or create a note, wiki page, task, ticket or knowledge article, its text is sent to a provider to build the search index. This happens as part of saving, without any further action from you.
Chat messages are treated differently: they are not indexed this way, and reach an AI provider only when you explicitly invoke a bot by mentioning it or messaging it directly.
Meeting features may also look a term up on the web. When the meeting assistant needs to define an unfamiliar term, it sends that term plus a short disambiguating phrase — never the meeting transcript itself — to OpenAI’s web search tool to fetch a brief definition and its sources.
AI requests can include relevant workspace content and conversation context, and diagnostic records may contain prompts and responses. Pinboard does not use your content to train AI models. Provider retention and handling depend on the applicable service terms and account configuration; this policy does not promise zero retention across all providers.
6. Cookies and Browser Storage
Pinboard uses essential cookies for authentication and session management. We do not use third-party advertising or tracking cookies.
- access_token: authenticates requests; expires after 30 minutes.
- refresh_token: renews your session; expires after seven days.
- pb_sessions: supports switching between signed-in accounts; expires after seven days and is renewed when used.
- csrf_token: helps protect against forged requests; a session cookie without a fixed expiry.
We also use local storage for account switching, preferences, and interface state, such as your timezone and dismissed update notices. Local storage can persist until cleared by the application or your browser. You can clear or block cookies and site storage in your browser settings; doing so may sign you out or reset preferences. External services you open, such as payment and sign-in pages, use their own storage policies.
The application does not change its behavior in response to the browser's Do Not Track signal. This signal is different from legally recognized opt-out preference signals, such as Global Privacy Control; applicable privacy rights are described below.
7. Data Retention
We retain your account data for as long as your account is active. Deleting your account starts a 30-day grace period, after which we remove the details that identify you — your name, email address, username, profile picture and authentication credentials — and disconnect any linked sign-in providers.
Work you created inside a shared workspace stays with that workspace: tasks, tickets, comments, documents, files and chat history belong to the team, and removing them would destroy records other people rely on. After your account is removed, that content is no longer attributed to your account by name or email. Names, email addresses, or other personal information written into the content itself may remain; account removal does not redact the text of shared records.
Security and audit records are kept longer, because they exist to tell us what happened: sign-in events and session records, including IP address and browser, are retained for up to 90 days, and workspace audit logs are retained for as long as the workspace exists. We may also retain data where the law requires it or where it is necessary for a legitimate purpose such as fraud prevention.
You can request a copy of your data, or ask us to delete it, at any time — see “Your Rights” below.
Email delivery metadata (bounce and complaint records) is retained to comply with anti-spam regulations and protect our sender reputation.
8. Your Rights
You may make the following requests. Available legal rights and exceptions depend on your location and our role in processing the data:
- Access the personal data we hold about you
- Request correction of inaccurate data
- Request deletion of your data
- Export your data in a portable format
- Withdraw consent where processing is based on consent
- Object to or request restriction of processing where applicable
To exercise any of these rights, please contact us at support@pinboard.ai.
We may need to verify your identity and authority before disclosing or changing data. Requests concerning organization-controlled workspace content may need to be handled with that organization. Where applicable, you may complain to your local data protection authority or request review of our response by contacting us with the subject “Privacy request review.”
9. Children's Privacy
Pinboard is not intended for use by children under the age of 13. We do not knowingly collect personal information from children.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new policy on this page and updating the "Last updated" date.
11. Contact Us
If you have questions about this Privacy Policy, please contact us at:
- Mail: PINBOARD LLC, 30 Woodridge St, Albany, NY 12203, USA
- Email: support@pinboard.ai
- Website: https://pinboard.ai