Privacy Policy
This Privacy Policy applies to mindoor ("mindoor"), the design workspace presented at mindoor.app, and the workspace linked from this website. mindoor is operated by the developer responsible for this domain and the senseslofter Pinterest developer account. It explains the information handled by the current development preview and identifies the proposed Pinterest functionality that still requires approval.
1. Information we process
- mindoor account information: the account identifier, email address, and profile information supplied by the sign-in service to authenticate your account.
- Workspace content: projects, canvas content, screen source and revisions, conversations, and files you upload or select for a request.
- Connection credentials: when an approved connection is enabled and you choose to authorize it, its OAuth access token, refresh token, connection state, and timestamps.
- Service requests: ordinary request metadata, such as IP address, browser information, and error information, may be processed by the hosting and infrastructure providers to operate the service.
2. How we use information
We use account information to authenticate you and enforce access to your workspace. We use your projects, files, and conversations to provide the design functions you request, preserve your work, and respond to your messages. We use connection credentials only for the authorized account and the connection functions disclosed to you.
This public website does not include an advertising tracker. The workspace uses browser storage and authentication/session information for sign-in, local drafts, caching, and recovery of your work.
3. Pinterest connection and permissions
The Pinterest application has received Trial access for development. The connection remains unavailable to the public until the required production access and permissions are obtained. The proposed OAuth permissions are boards:read and pins:read. Each mindoor user would independently authorize their own Pinterest account. mindoor does not request publishing, editing, deletion, or advertising permissions for this connection.
Browsing would retrieve only the Pins and Boards available under that user's authorization. Pinterest credentials are encrypted on the server, bound to the authorizing mindoor account, and are not supplied to the design Agent or written into project source.
Our planned reference-image import and AI-assisted discussion features involve storing selected reference content or sharing it with a configured AI service. Those uses require the applicable Pinterest permissions and approval. Read scopes alone are not presented as permission for indefinite storage or third-party AI processing. We will not claim that these uses have been approved before receiving permission, and will update this policy and the product availability to reflect the permitted functionality.
mindoor does not use Pinterest content to train, fine-tune, or improve an AI model. We do not scrape Pinterest or combine Pinterest collections across users. Unknown image licensing is recorded as unverified rather than treated as a license for reuse.
4. AI processing and service providers
For ordinary design requests, the conversation and files you explicitly select may be sent to the configured AI service to produce the requested response. The service may include OpenRouter and its underlying model providers, depending on the selected model. Connecting an external account does not automatically send its entire library to an AI service. Pinterest-derived content is subject to the separate permission requirements described above.
mindoor uses infrastructure providers, including Supabase for authentication, database records, and object storage, and Vercel for hosted deployments. These providers process the information required to deliver those functions under their applicable privacy terms. We do not sell your personal information.
5. Retention and deletion
Workspace content is retained to preserve your projects and conversations until you remove the relevant content or project, or request deletion. Infrastructure backups and browser caches may take additional time to clear. Pinterest API-derived content is subject to Pinterest's applicable data-retention requirements and any separately approved use.
Connection credentials are retained while you keep the connection. Disconnecting removes the stored connection tokens and cancels pending authorization requests. You may also revoke access in the provider's own account settings. Disconnection stops further use of that grant; it does not itself delete the rest of your design project.
6. Access controls
mindoor validates workspace access and isolates connection credentials by the authorizing account. Connection tokens are encrypted on the server. Files obtained through a user's private Pinterest connection are restricted to that mindoor user. Hosting and infrastructure services provide the underlying storage and network protections.
7. Your choices and privacy requests
You can choose which files and references to include in a request, disconnect an external account, and use the product's available deletion controls. To request access, correction, or deletion of account or workspace information, contact the operator through the senseslofter Pinterest profile and identify the mindoor account and the request you want us to handle.
8. Policy updates
We may update this policy as the service develops. The effective date above identifies this version. New connection permissions or materially expanded processing will be explained before they are introduced.