Privacy Policy
Pin It reads one number and stores one number. This page explains exactly which one, and who else can see it.
The short version
Pin It has no sign-up, no password and no email address for you. It stores the latest value of each number you pin and nothing else about you. There is no analytics, no advertising, no tracking pixel and no third-party SDK in the app or on this site.
When you connect a service such as Stripe or GitHub, Pin It requests read-only access, reads one number from it, and throws away everything else in the response.
There is no account
On first launch the app generates a random session token and keeps it in the iOS keychain on your device. That token is how the server recognises your pins on later requests. We store only a SHA-256 hash of it, so the database never holds a value that could be replayed as your session.
We do not ask for, receive or store your name, email address, phone number, postal address, contacts, photos, location or device advertising identifier.
What we store
- Your pins. The source (Stripe, GitHub, a ticker symbol, a countdown date), the label you typed, which placements you enabled, and the single latest value with its change indicator and status.
- Connection tokens. The access token a provider issues after you approve the connection, encrypted at rest with AES-256-GCM. The encryption key lives in the server environment, not in the database.
- A push token for Live Activities, if you turn one on, so the number on your Lock Screen can change without you opening the app.
- A webhook token and secret if you use the personal webhook address to send your own numbers in.
What we never store
No history. Each refresh overwrites the previous value, so there is no time series to leak, subpoena or sell. There is no table of your customers, orders, charges, commits, issues or deployments — only the count or status that appears on your Lock Screen.
$4,218, the database row holds the text “$4,218”. It does not hold the charges that add up to it.Services you connect
Each connection uses the narrowest access the provider offers: Stripe is connected with the read_only scope, GitHub with read scopes, Vercel through its integration OAuth flow. Pin It cannot move money, publish, deploy, delete or change anything in an account you connect.
Disconnect a source under Settings → Connected services and three things happen at once: the stored token is deleted, the pins that relied on it are deleted, and the authorisation is revoked with the provider — so Pin It also disappears from their connected-apps list. You can still revoke from the provider’s own settings if you prefer.
Who else touches the data
These are the only companies involved in running Pin It:
- Vercel — hosting for this site and the API.
- Neon — the Postgres database holding the rows described above.
- Apple — delivers Live Activity updates via APNs, and processes any purchase you make.
- Finnhub and CoinGecko — market data for stock and crypto pins. They receive the ticker symbol you asked for, never anything about you.
- Upstash — short-lived counters used for rate limiting, keyed by a hashed identifier.
We do not sell, rent or share your data with anyone else, and we do not use it to train machine learning models.
Deleting your data
Deleting a pin in the app deletes its row and its stored value. Disconnecting a source deletes its encrypted token and every pin that used it — a pin with no token can never refresh, so it goes too. Both are immediate and permanent; there is no recycle bin.
Deleting the app removes the keychain token, which is the only key to your record. What remains is an anonymous row containing no information that identifies you. If you would like that row purged as well, email support@getpinit.app from the device before you uninstall and we will remove it.
Children
Pin It is a business metrics tool and is not directed at children under 13. We do not knowingly collect information from them — and since we collect no personal information from anyone, there is nothing to collect.
Changes and contact
If this policy changes materially, the date at the top of this page changes and the new version is published here before it takes effect. Questions, requests or complaints go to support@getpinit.app.