Trust & Security

A concise overview for builders, ops leads, and IT reviewers. For full legal detail, see our Privacy Policy.

GDPR-aligned by default

Pindown is built with European data protection in mind. Workspace data is processed in isolated contexts, never mixed with other customers' content, and you retain full export and deletion rights.

Encryption everywhere

Data is encrypted in transit (TLS) and at rest on Google Cloud / Firebase infrastructure. Industry-standard controls protect authentication, sessions, and API access.

No training on your content

Your pins, agent runs, and workspace content are yours. We do not use your data to train our own or third-party foundation models. AI features process your content only to deliver the service you asked for.

Workspace isolation

Each workspace is a separate boundary. Sharing is explicit—private by default, team-scoped when you choose, and live links only when you publish.

RBAC for teams

Workspace plans include role-based access control for teams and communities—granular permissions so operators and leads control who sees boards, pages, and pins.

Questions from your security team?

Email contact@pindown.ai with “Security review” in the subject line. We're happy to walk through architecture, subprocessors, and data flows.