Privacy.
Draft. This page is a draft and is still under review. Questions? Email [email protected].
This policy covers hosted pinthread at pinthread.dev. Questions about your data? Email [email protected].
What the hosted service stores
We store your comments, replies, reactions, selected element references and positions, page paths, project settings, approved site addresses, and timestamps. Element text and source file references may be included when you select an element. We do not upload your repository or automatically capture screenshots.
Google sign-in supplies a stable account identifier, verified email address, display name, and profile photo. Verified email addresses match private invitations and are visible to project owners. Guest accounts store the display name you choose. Profile changes can include an uploaded, resized avatar and accent color.
Why we use it
This information supports shared reviews, account authentication, ownership, usage limits, and abuse prevention. Sessions, hashed authentication tokens, rate-limit records, and service diagnostics support operation and troubleshooting.
The hosted service runs on our own server with a PostgreSQL database, behind Cloudflare’s network. Google processes Google sign-in. Their services have their own privacy policies.
Who can see feedback
Feedback is available to people who can access the configured review workspace. Display names, avatars, comments, and replies are visible to other reviewers. pinthread does not enforce your Git repository’s permissions.
Do not place secrets or sensitive personal information in comments or selected page content. Secure private previews using your own access controls.
Cookies and local storage
The widget stores a reviewer session in a cookie and local storage until you sign out, with the cookie capped at the browser’s 400-day maximum. It also stores preferences such as drawer position and emoji history. Sign-out revokes the current service session. Cookies are used for authentication, not advertising.
The animated walkthrough is scripted. Comments you leave on this website are public and shared with other visitors. The public demo keeps each reviewer’s latest three comments and removes older ones when they post again.
Retention and requests
Hosted feedback remains until removed by its owner or through service administration. Owners can export feedback, permanently clear resolved threads, or delete a hosted project. Deleting a comment in the widget replaces its text with a deletion marker; associated records may remain and continue counting toward quota. Resolved comments are retained.
For an account data copy, correction, or deletion request, email [email protected] from an address that can help establish ownership. We may need to verify your identity before fulfilling a request.
Self-hosted data belongs to the operator of that deployment. Contact that operator about its retention and access rules.