Pinart

Privacy Policy

Version 2026-09-08 · Last updated: 8 September 2026

1. Data Controller

Pinart d.o.o., Mladinska ulica 63, 1000 Ljubljana, Slovenia Email: tina@pinart.si This policy explains how we handle your personal data. When you enter data about your clients or collaborators into the app, you are the controller of that data and we are the processor; that relationship is governed by the data processing agreement in the terms of business (section 4g).

2. Data We Collect

Depending on how you use the service, we process: – Contact form: first and last name, email, message content (at your initiative). – User account: email and name received from your sign-in provider (e.g. Google) when you log in. – Business data in the app: proposals, contracts, invoices, clients, projects, expenses and tasks you enter while using the service (stored to your account). – Communications: the content of project chat and project mail, if you use those features. – Authorship vault: file name, cryptographic fingerprint (SHA-256), date and work details; and, with the paid vault, the file itself. – Acceptance of the terms: version of the terms, time and method of acceptance, as proof of the contract. – Subscription: plan, period, subscription status and identifiers at the payment provider; we never receive payment card data. – Usage data (logged in): the number of visits and active days of your account, the time of your last sign-in and the total time the app is open and active (measured only while the tab is visible; counting stops after five minutes of inactivity). This is not anonymous (tied to your account) and is unrelated to the anonymous pricing statistics. – Technical data: IP address and browser and device information in the server logs of our hosting provider and in our own logs for security and abuse prevention. – Pricing questionnaire (if you fill it in): your field and your answers about prices, without name or email. – Anonymous pricing statistics: no personal data, cannot be linked to you (see the terms of business, section 5).

3. Purpose and Legal Basis

We process your data for: – providing your account and the platform features, performing the contract and support (Art. 6(1)(b) GDPR); – steps prior to entering into a contract and responding to inquiries (Art. 6(1)(b)); – meeting accounting, tax and other legal obligations (Art. 6(1)(c)); – security, abuse prevention, basic administration and improvement of the service on the basis of legitimate interest, where the interests and rights of the individual do not prevail (Art. 6(1)(f)); – sending marketing messages and using non-essential analytics cookies on the basis of consent, where consent is required (Art. 6(1)(a) GDPR and the rules on electronic communications). For Pupa we process the data you send to the AI function in order to carry out the function you explicitly requested (Art. 6(1)(b)). Where this involves personal data of third parties that you process as a business user and controller, Pinart processes it as your processor and uses the AI provider as a subprocessor under the data processing agreement.

4. Data Retention

We keep data according to the rules below. Deletion after the retention period is carried out by an automated job; we always notify you before your account is deleted. – Account and platform content (proposals, contracts, invoices, clients, projects, documents, communications, vault): for as long as the account is active or until you delete the data or request its deletion. When the account is closed we delete the data from active systems (database and file storage) without undue delay, as a rule within 30 days. Data may remain in backups for a limited time and is finally deleted when the backups are regularly overwritten, at the latest within 90 days. – Inactive accounts: if you do not sign in for 24 months and have no active paid subscription, we notify the email address of the account of the planned deletion. If you do not sign in within 30 days of the notice, we delete the account and its data under the rule above. Signing in cancels the deletion at any time. – Data we must keep under accounting, tax or other legal obligations (for example invoices and subscription payments): for the prescribed period, as a rule at least 10 years after the end of the year they relate to. – Record of acceptance of the terms: for as long as the account exists. – Contact inquiries that do not lead to a business relationship: at the latest 12 months after the end of the communication. If a contractual or other business relationship arises, we keep the data needed to prove that relationship and any claims for up to 5 years after it ends, unless a different statutory period applies to specific data. – Sign-up for marketing messages: until consent is withdrawn. Unconfirmed sign-ups are deleted after 14 days. After you unsubscribe we remove you from the active list; a minimal record of how consent was obtained and withdrawn may be kept for up to 5 years to demonstrate compliance. – Technical logs (email sending, Pupa usage, data requests) and pricing questionnaire answers: 12 months, then automatic deletion. Aggregate usage counters of the account (visits, active days) are kept for as long as the account exists. – Data passed through the Anthropic API: Anthropic's own retention policy also applies (section 9). – Analytics and session recordings (only with consent): according to the providers' settings described in sections 6 and 8.

5. Where Your Data Is Stored

Business data of logged-in users is stored in a cloud database and storage (Supabase, servers in the European Union). Data is tied to your account and protected by database-level access rules, so only you and the people you explicitly share content with can access it.

5a. Subprocessors

We do not sell or rent your data. To operate the service it is processed by the following subprocessors, strictly on our instructions: – Supabase — cloud database and storage (EU) – Vercel — hosting and application delivery – Resend — email sending – Google — sign-in with a Google account (OAuth) and a Google Sheets spreadsheet that records contact-form inquiries and sign-ups from the calculator (name, email, message) – Cloudflare — receiving and forwarding inbound email on @pinartflow.com addresses – Anthropic — the AI assistant Pupa (only when used; see section 9) – FreeTSA (freetsa.org) — independent timestamp authority for the vault under RFC 3161 (receives only the 32-byte fingerprint, never the file, its name or a description of the work) – Stripe — subscription payment processing as an authorised payment provider (Merchant of Record); we never see or store card data – PostHog (EU cloud, Frankfurt, server eu.i.posthog.com) — usage measurement on the marketing pages: heatmaps, session recordings and funnels. It runs only with your consent and only on the marketing pages, never inside the app or the calculator; input fields are masked in recordings – AJPES — lookups in the Slovenian business register and published annual reports; we send the registration number of the company you look up, not your personal data We also disclose data to third parties where required by law. The current list is always in this section. We notify signed-in users by email of any addition or replacement of a subprocessor before it takes effect; if you do not agree with the change, you may cancel the subscription (terms of business, section 8a).

5b. Authorship Vault

The Authorship vault stores a cryptographic fingerprint (SHA-256) of your work, a date and work details (e.g. file name, tool). The fingerprint is a unique digest; the content cannot be reconstructed from it. For an independent timestamp we use FreeTSA (freetsa.org) under RFC 3161: only the 32-byte fingerprint is sent to the authority, which returns a time token signed with its certificate. Your file, its name and the description of the work never reach the authority; it does not learn what you stamped, it only confirms that this fingerprint existed at a given time. Anyone can verify the token, even without Pinart Flow. We may switch the authority (for example to a qualified service under the eIDAS regulation); the current one is listed in section 5a. If you choose the paid cloud vault, the original file (and any source files) is stored in private cloud storage (Supabase, EU), accessible only to you. The vault proves the existence and priority of a work on a given day, not absolute authorship, and is not a substitute for official registration of rights.

5c. Security

We protect personal data with appropriate technical and organisational measures in line with the nature of the processing and the associated risks. These measures include in particular encrypted transport (TLS), protection of data at rest, access control and restriction according to user rights (each user sees only their own data), secure authentication through a trusted sign-in provider, regular backups, and procedures for data recovery and for responding to security incidents. We limit access to systems and personal data to the people who need it to perform their tasks, and we review and update the security measures as needed. No information system can guarantee complete security. You are also responsible for protecting access to your user account, devices and sign-in details.

6. Analytics (Google Analytics and PostHog)

This website uses Google Analytics to analyse site traffic. Google Analytics collects visit data (device type, country, pages visited), which we do not link to your personal identity. It loads only with your cookie consent; you can withdraw consent at any time in the cookie settings, and you can also block collection by installing the Google Analytics Opt-out Browser Add-on. On the marketing pages we also use PostHog (EU cloud, Frankfurt) to understand usage: click heatmaps, session recordings and funnels. A session recording is a record of your clicks, scrolling and path through the page; input fields are masked in it. Both run exclusively with your cookie consent and never inside the app or the calculator, where you enter your clients' data. When you withdraw consent, recording stops.

7. Your Rights

Under GDPR you have the right to: – access your personal data – rectify inaccurate data – erasure of your data – restriction of processing – data portability – object to processing Export of all your data (portability) and account closure (erasure) are available in My profile in the app; send other requests to tina@pinart.si. You also have the right to lodge a complaint with the Slovenian Information Commissioner (ip-rs.si).

8. Cookies

We use the following cookies and similar browser records. Without your consent, analytics cookies and session recording are not loaded; you can change your decision at any time in the cookie settings at the bottom of the page. Essential (for operation, no consent required): – sb-…-auth-token (Supabase) — sign-in session; until you sign out – flow_gate — closed-beta entry password; 30 days – pinart_cookie_consent (browser local storage) — your cookie decision; 1 year Functional: – NEXT_LOCALE — chosen language; 1 year – flow_next — return path after sign-in; 10 minutes – flow_ref — invitation code; 30 days Analytics (only with consent, only on the marketing pages): – _ga, _ga_* (Google Analytics) — traffic measurement; 2 years – ph_* (PostHog, server eu.i.posthog.com) — usage measurement and session recordings; 1 year Stripe sets no cookies on our domain, because payment takes place on its own pages.

9. Artificial Intelligence (Pupa) and Data Security

Pupa is an optional assistant powered by the Anthropic Claude API. Processing takes place server-side, so the API key is never exposed in your browser. The model provider has no access to the Pinart Flow database. For each reply it receives only the text of the individual request, which Pinart assembles: your message and those of your data that Pupa needs for the reply (for example the details of the open proposal or project). It cannot read, search or export the database, and under its contractual terms it does not use these contents to train models. Do not enter confidential information, trade secrets or clients' personal data into Pupa. If you do not use Pupa, no data is sent to Anthropic or any other external AI provider. The Pinart Flow tools work without AI, and prices are calculated with formulas and rules locally or on the Pinart Flow backend. Anthropic is a subprocessor. Under its current terms, commercial API inputs and outputs are by default not used to train models; they are retained for a limited time under its terms. Any transfer to the United States is covered by the EU-US Data Privacy Framework or by standard contractual clauses under the data processing agreement with Anthropic. More: https://privacy.anthropic.com/en/collections/10663361-commercial-customers. Your own AI provider: in Settings (My AI) you can connect your own AI provider with your own key. We store the key encrypted on the server. When your provider is selected, Pinart forwards the data you send to Pupa to that provider as a technical intermediary; the conversation always shows which provider is answering. Processing by that provider is governed by its own terms and privacy policy. Your own agent (MCP connection): if you connect your own agent through the MCP connection, it reads your Flow data on your instruction; it only reads and changes nothing. That is your decision and your agent; its handling of the data it reads is governed by your relationship with its provider.

10. Changes to This Policy

We may update this Privacy Policy. The date of the last update and the version are shown at the top of this page; we notify signed-in users of material changes in the app or by email.