1. Controller and scope
For the hosted Pinar service, the data controller is Djalma Júnior, an individual in Brazil. Privacy contact: contact@pinar.dev. This Policy does not govern local-only data that never leaves your device; you control that data locally.
2. Data we process
Depending on your use, we process: account email and authentication records; policy-acceptance evidence; billing identifiers and plan status received from Stripe (not full card details); device and extension identifiers; IP address, request, security, and diagnostic logs; projects, collections, page URLs and titles, screenshots, annotations, comments, selectors, and sharing metadata you submit; storage and AI-credit usage; and prompts, inputs, outputs, model usage, and error details when you invoke an AI feature.
Avoid capturing secrets or unnecessary sensitive personal data. A screenshot may contain information about you or third parties, and you are responsible for having an appropriate basis to submit it.
3. Purposes and legal bases
We process data to provide accounts and contracted features; authenticate users; store and share content at your direction; process billing and entitlements; operate AI features; prevent fraud and abuse; secure and troubleshoot the service; comply with law; establish or defend legal claims; and communicate service or policy changes. Under the LGPD, the applicable bases may include contract performance, compliance with legal obligations, legitimate interests subject to safeguards, regular exercise of rights, fraud prevention, and consent where specifically requested.
4. Sharing and international transfers
We share data only as needed with the providers listed in the Service Providers and Subprocessors page, with professional advisers under confidentiality, in a corporate transaction subject to appropriate protections, or with authorities when legally required. Cloud infrastructure and payment processing may involve processing outside Brazil. We use provider contracts and legally recognized safeguards appropriate to the transfer.
5. Retention and deletion
Retention depends on plan, content type, legal duties, security needs, and account status. The current periods and recovery windows are described in the Data Retention Policy. Backups and fraud, billing, tax, security, and legal records may remain for a limited period after deletion when required or reasonably necessary.
6. Security
We use measures designed for the nature of the service, including scoped tokens, access controls, origin validation, rate limits, encrypted transport, isolated production resources, and restricted provider access. No online system is completely secure. Contact us promptly if you believe your account or data was compromised.
7. Your rights
Subject to applicable law, you may request confirmation and access; correction; information about sharing; portability where regulated; anonymization, blocking, or deletion of unnecessary or unlawfully processed data; deletion of consent-based data subject to legal exceptions; information about consent choices; withdrawal of consent; and review of a decision based solely on automated processing that affects your interests. We may verify your identity before acting. Requests are free and may be sent to contact@pinar.dev.
8. Children, changes, and complaints
Pinar is not directed to children. Do not submit a child's personal data without the authority and safeguards required by law. We will publish material changes and request renewed acceptance when legally or contractually necessary. You may also lodge a complaint with Brazil's National Data Protection Authority (ANPD) or another competent authority.