Pinkflow company policy
Privacy Policy
Last updated: 2026-07-18
This Policy was last updated on 2026-07-18.
1. Who we are and how to reach us
Pinkflow is operated by Miro Mal, an individual based in Tel Aviv, Israel. Miro Mal is the controller responsible for personal data under applicable data protection law, including the Israeli Privacy Protection Law and the EU General Data Protection Regulation (GDPR) where it applies.
Email: hello@pinkflow.ai. Location: Tel Aviv, Israel.
2. Scope and the important product difference
This Policy covers pinkflow.ai and any future launch or invitation access Pinkflow grants for Namescape and Gateway.pink. Their data contracts are not identical: if Namescape access opens, it will be able to store work a person chooses to save to an account; Gateway is designed not to persist caller payloads.
3. Data Namescape will process when access opens
Namescape access is not currently open. If launch or invitation access is granted, Namescape will process the following data categories.
- Account data: If Namescape account access opens, it will process your email address, authentication-provider identifiers, profile settings, and account role. Pinkflow will not receive your Google or Microsoft password.
- Service data: When signed-in access is granted, Namescape will process prompts, generated domain suggestions, saved names, search history, balances, and usage-ledger entries needed to provide that workflow.
- Planned signed-out attempt: At launch, a privacy-preserving network/browser fingerprint and usage counter will be used to enforce the one-attempt allowance.
- Domain checks: When a domain check is requested through granted access, Namescape will send candidate domain names to public registry, RDAP, registrar, or verification sources. Your account identity will not be included in those lookups.
4. Data collected by Gateway.pink
Gateway.pink public API and documentation access is closed. The following data contract applies if Pinkflow grants invitation-preview access to a participant.
Gateway does not log or persistently store request or response bodies.It records billing and operations metadata such as organization or API-key identifier, endpoint, time, status, latency, request identifier, settled credits, token counts, provider cost, and a non-payload failure code.
Routes marked cached-ttl may briefly cache a public upstream result to respect source limits and improve reliability. That result can include the public lookup key or coordinates returned by the source; it remains bounded, short-lived, and is not retained as account history. The route contract shared with an invited participant is the source of truth for whether short-lived public-result caching applies.
Provider-backed Gateway routes transmit the input required to perform the requested operation to the provider named in the route contract shared for that preview. Local compute routes do not send input to an upstream provider. AI requests ask OpenRouter to deny provider data collection, but OpenRouter's own processing terms still apply.
5. Payments and support
- Payment data: Paddle receives the payment and contact details needed for an eligible purchase. Pinkflow receives transaction status, product, amount, tax, and identifiers, but not your full card number.
- Support data: the email and information you send us, used to investigate and answer your request.
- Security data: IP address, user-agent, authentication events, and rate-limit counters needed to prevent abuse and investigate security incidents.
6. Why we use data
- Prepare for and, once enabled, provide accounts, saved work, API access, usage balances, and support — performance of a contract.
- Process eligible purchases and maintain required transaction records — performance of a contract and legal obligations.
- Prevent abuse, secure services, and diagnose reliability — our legitimate interests in operating safe services.
- Send essential account, policy, security, and billing messages — contract, legal obligation, or legitimate interests.
7. When an account is required
At launch, Namescape is planned to offer one limited signed-out generation attempt. An account will be required to buy packs, hold a balance, save names, view account history, or use authenticated features once purchase access opens.
Gateway public API and documentation access is not currently open. If Pinkflow invites you to a private preview, the Gateway data handling described in this Policy applies to that invitation-preview access.
8. Service providers and recipients
Depending on the product and route, data is processed by:
- GitHub Pages for the public pinkflow.ai company site.
- Supabase for Namescape authentication and account data.
- Paddle as merchant of record / authorized reseller for eligible payments.
- OpenRouter and its selected model providers for Namescape generation and Gateway AI routes.
- Public registry and domain-data sources for Namescape availability and price signals.
- Abstract, Twilio, and ScreenshotOne for the corresponding Gateway validation, lookup, and screenshot routes when configured.
- Cloudflare Browser Rendering for preview screenshot, PDF, and Markdown routes. Gateway sends the public target URL and fixed rendering options; it does not accept or forward caller cookies, credentials, or raw HTML for these routes.
- Amazon Textract for single-page OCR and invoice/receipt extraction. Gateway sends one PNG or JPEG image page directly to Textract in US West (Oregon), does not place it in S3, and does not persist the image or OCR response. The adapter remains disabled until Pinkflow confirms the AWS AI-services data-use opt-out; AWS processing terms still apply.
- Have I Been Pwned (HIBP) for password-exposure checks. Gateway sends only the first five characters of a caller-supplied SHA-1 digest with response padding enabled; plaintext passwords and full hashes are not accepted or transmitted.
- Hosting and email providers needed to run services and deliver essential messages.
We do not sell personal data or use advertising networks or advertising trackers.
9. International transfers
Pinkflow is based in Israel. Providers may process data in other countries. Where applicable law requires safeguards for a transfer, we rely on adequacy decisions, standard contractual clauses, or another lawful transfer mechanism offered by the provider.
10. Cookies and local storage
The company site uses no advertising or analytics cookies. Product applications use the session cookie or local-storage value needed to keep you signed in and secure the session when account access is enabled. We do not use third-party advertising tags or a marketing tag manager.
11. Retention
- Account and saved Namescape data: retained while the account is active and deleted or de-identified after a valid deletion request, subject to backups, fraud prevention, disputes, and legal obligations.
- Gateway operations metadata: retained only as needed for billing, reliability, abuse prevention, disputes, and legal records; caller payloads are not part of this record.
- Transaction records: retained for the period required by tax, accounting, anti-fraud, and payment rules.
- Support and security records: retained as long as reasonably needed to resolve the issue and protect the services.
12. Automated decisions
Pinkflow does not make automated decisions that produce legal or similarly significant effects about you. Generated names, summaries, and classifications are service outputs, not decisions about eligibility, employment, credit, insurance, or legal rights.
13. Your rights
Subject to applicable law, you may have the right to access, correct, delete, port, object to, or restrict processing of your personal data, and to withdraw consent where processing relies on consent.
Email hello@pinkflow.ai to exercise a right. If you are in a jurisdiction with a data-protection regulator, you may also lodge a complaint with your local supervisory authority.
14. Children
Pinkflow services are not intended for children under 16, and we do not knowingly collect their personal data.
15. Changes and contact
We may update this Policy and will revise the date above. For a material change, we will provide reasonable notice through the relevant service or account email. Questions or requests can be sent to hello@pinkflow.ai or through thecontact page.