Privacy Policy

Pinkale values your privacy and strictly enforces a 100% client-side Local-First architecture.

Core Commitment: 100% Client-Side Local-First Processing

At Pinkale, all input data, uploaded files, and calculation results remain strictly within your browser’s local memory and are never transmitted to our servers. We cannot view, access, or store your documents, photos, or text inputs under any circumstances. However, if you explicitly generate a share link in calculators or unit converters, the selected numbers and options are embedded in the link URL (Article 2).

Article 1 (Purpose of Processing & Legal Basis)

Pinkale ('the Service') processes only the minimum personal data necessary for the following purposes. Personal data processed will not be used for purposes other than those specified below without prior consent:

Processing of accounts, personalization, and inquiries is within the scope necessary for service provision (contract performance), while visit analytics and rate limiting are conducted to ensure infrastructure stability.

  • User registration, authentication, and session management
  • Personalization features (cross-device synchronization of favorites, recent tools, and recent searches)
  • Abuse prevention, rate limiting against automated attacks, and service quality optimization
  • Reading, reviewing, and answering inquiries sent to contact@pinkale.com
  • Receiving, reviewing, and responding to feature requests and inquiry forms

Article 2 (Data We Process & Data We Never Collect)

1. Account & Membership Data (Optional)
  • Email & Password Registration: username, nickname, email address, one-way scrypt password verification hash (plaintext passwords are never stored), and terms acceptance record (timestamp, terms version, privacy policy version).
  • Google Sign-In: Google-verified email address and terms acceptance record (upon first sign-up).
  • Personalization Data: bookmarked tool IDs (up to 200), tool usage activity records (up to 200 stored documents, up to 12 recent tools displayed, up to 200 completion counters), likes, and recent search queries (up to 8 clicked search terms, max 60 characters each).
2. Data Automatically Collected or Generated During Service Use
  • Anonymous Quality & Telemetry Events: server-hashed session identifier (sessionIdHash), tool ID used (toolId), event type across 8 categories (eventType), execution engine (engine), processing duration in milliseconds (durationMs), input size bucket (sizeBucket), item count bucket (itemCountBucket), device class (deviceClass), browser family (browserFamily), success flag (success), and error code (errorCode). User input content, filenames, search queries, raw IP addresses, and User-Agent strings are strictly excluded.
  • Abuse Prevention & Rate Limiting: cryptographic one-way HMAC-SHA256 hash of the client IP address, HMAC-SHA256 hash of attempted login ID/email, HMAC-SHA256 hash of feature request account IDs, and corresponding attempt counts. Raw IPs and account IDs are never stored, and records expire automatically within 15 minutes.
  • Visit Statistics (Cloudflare Web Analytics): visited page URL and referring URL (query parameters after '?' and fragments after '#' are stripped prior to transmission), browser, operating system, device type, and page-load performance metrics. No tracking cookies or persistent client identifiers are used, and tool inputs/files are never captured.
  • Cloudflare Operational Logs: when accessing the website, Cloudflare records request URLs, HTTP methods, response codes, and associated network telemetry for 7 days. Application logs recorded by the Service contain only URLs and status codes, without any user inputs.
  • Share Links: when a user explicitly clicks "Copy Link" (or shares via external apps) in calculator or unit converter tools, the current numerical values and configuration options are serialized into the URL query parameters (after '?'). Accessing such share links may result in these parameters appearing in the aforementioned Cloudflare operational logs. By default, no input data is in the URL, and operation tools processing text or files do not support share links.
3. Inquiries Sent to contact@pinkale.com
  • Sender email address, name, reply-to address, subject, message body, and attachment metadata (filename, MIME type, size). Inbound emails are received by Cloudflare, stored in the Service database, and accessed solely via the admin console; attachment contents and original email messages are not retained, and messages are not forwarded to external inboxes.
4. Feature Requests & Inquiry Form (/request, requires account login)
  • Inquiry type, request summary (up to 1,000 characters), detailed description (optional, up to 1,000 characters), reply contact info (optional), and related tool ID. Account IDs are not stored alongside request submissions.
5. Data We Never Collect (Zero Transmission)

All files (PDFs, images, documents, audio), text input content, encryption keys, JWT tokens, calculation outputs, and raw search query statistics remain strictly inside your web browser memory and are never transmitted to or retained on any remote server.

Article 3 (Retention and Use Period)

The Service retains and processes personal data strictly within the retention periods stipulated by relevant laws or authorized by the user upon collection:

CategoryRetention Period
User accounts, favorites, likes, activity history, and recent searchesDeleted immediately upon account deletion
Terms acceptance records (timestamp, terms version, privacy policy version)Deleted immediately upon account deletion
Feature requests and inquiry form submissionsAutomatically deleted after 1 year via database TTL
Inquiry emailsAutomatically deleted after 1 year (may be deleted sooner after resolution)
Anonymous raw telemetry logsAutomatically deleted after 30 days via database TTL
Daily aggregated metrics (tool usage count and time distribution)Indefinite (aggregated statistical data containing no personal identifiers)
Sign-up, login, and feature request rate-limit countersAutomatically deleted after window expiration (up to 15 minutes via database TTL)
Cloudflare operational logs (request URLs, methods, status codes)Deleted by Cloudflare after 7 days
Visit statistics (Cloudflare Web Analytics)Raw logs retained for 7 days, aggregated reporting retained for up to 6 months by Cloudflare
Cookies and local storageRefer to Article 7
Backup copiesNone — deleted records cannot be recovered

Article 4 (Destruction Procedures and Methods)

Personal data is promptly destroyed once the retention period expires or the purpose of processing has been fulfilled.

  • Automated Database TTL Purging: Records with designated expiration periods are automatically and permanently purged via MongoDB Atlas Time-To-Live (TTL) indexes. This applies to raw telemetry (30 days), rate limit tokens (up to 15 minutes), inquiry emails (1 year), and feature request submissions (1 year).
  • Immediate Account Purge: When a user requests account withdrawal via My Account (/account), the user account, favorites, likes, tool activity history, and recent searches are immediately and irreversibly erased.
  • Destruction Method: Electronic records are permanently deleted using irreversible technical mechanisms. No paper records are created or stored.
  • No Backup Replicas: The Service maintains no offline backups or snapshot archives of deleted data; purged records cannot be restored under any circumstances.
  • Third-Party Logs: Cloudflare operational logs and Web Analytics data are destroyed directly by Cloudflare in accordance with their standard data retention policies (Article 3).

Article 5 (Data Entrustment and Cross-Border Transfers)

To maintain reliable web infrastructure and secure hosting, the Service entrusts personal data processing to specialized cloud providers:

1. Data Processing Entrustment

TrusteeEntrusted ScopeStorage LocationContact
Cloudflare, Inc.Web application hosting, DNS, inbound email routing, operational logs, and cookie-less web analyticsUnited States & global data centersdpo@cloudflare.com
MongoDB, Inc. (Atlas)Database storage for accounts, personalization, consent records, feature requests, inquiry emails, and anonymous telemetryRepublic of Korea (Seoul Region)privacy@mongodb.com
Google LLCGoogle Sign-In authentication service (when chosen by the user)United Stateshttps://policies.google.com/privacy

2. Cross-Border Data Transfers

(MongoDB, Inc. stores and maintains all database records in the Republic of Korea Seoul Region and is not subject to cross-border transfer.)

Recipient (Contact)Transferred ItemsCountryTiming & MethodPurposeRetention Period
Cloudflare, Inc.
(dpo@cloudflare.com)
Network connection data (request URL, method, status code), visit analytics fields, inquiry emailsUnited States & countries hosting Cloudflare data centersTransmitted via network during site visits and email transmissionsHosting, email receipt, and traffic analyticsAs described in Article 3 (operational logs 7 days, web analytics 7 days to 6 months; email content is passed directly to the Worker and not retained by Cloudflare)
Google LLC
(policies.google.com/privacy)
Email addressUnited StatesTransmitted via network upon initiating Google Sign-InIdentity authentication via Google accountSubject to Google Privacy Policy

Right to Refuse and Consequences: Users may decline personal data processing by refraining from creating an account or using Google Sign-In; all tools on Pinkale remain 100% free and fully functional without an account. Network transmission inherent to web hosting cannot be refused while accessing the website.

Article 6 (Advertisements and Behavioral Information)

To maintain free services, the Service may display advertisements via Google AdSense. Third-party vendors, including Google, use cookies to serve ads based on prior visits to this or other websites. Google’s use of advertising cookies enables it and its partners to serve ads based on your visits to our site and/or other sites on the Internet.

  • Collecting Entity: Google LLC and third-party advertising partners (the Service does not directly harvest or store advertising profile data).
  • Information Collected: Cookies, advertising identifiers, website visit records, ad interaction telemetry, and browser/device metadata.
  • Purpose: Ad delivery, interest-based personalization, fraud detection, and aggregate performance measurement.
  • Retention Period: Defined in accordance with Google’s Privacy Policy.
  • Details regarding Google's use of partner data are available at How Google uses information from sites or apps that use our services.
Ad-Free Protected Tools

Advertisements are strictly prohibited on pages handling sensitive inputs, including cryptography, hash/HMAC generators, password/passphrase generators, JWT tools, key derivation, PDF password tools, national identifier tools, stamp and signature creator tools (all creator engine tools, stamp/signature extractors, and PDF stamp insertion), as well as login, registration, account management, and admin consoles. Tool contents and uploaded files are never provided to advertising networks.

Opting Out of Personalized Advertising
  • Visit Google Ads Settings to disable personalized ads.
  • Opt out of third-party advertising cookies at www.aboutads.info or www.youronlinechoices.eu.
  • Configure browser settings to block or delete cookies. All tools continue to work flawlessly with third-party cookies disabled.
  • Users residing in the EEA, UK, and Switzerland will be presented with an explicit consent dialog via a Google-certified Consent Management Platform before personalized ads are rendered.

Article 7 (Automated Data Collection Devices: Cookies & Local Storage)

The Service utilizes HTTP cookies and browser localStorage to maintain authenticated sessions, preserve user theme preferences, and provide cross-device synchronization.

1. HTTP Cookies

Cookie NamePurposeRetention
__Secure-authjs.session-tokenSession authentication maintenance30 days from most recent activity
__Host-authjs.csrf-tokenCross-site request forgery (CSRF) mitigationUntil browser closure
__Secure-authjs.callback-urlPreserving redirection target after authenticationUntil browser closure
__Secure-authjs.pkce.code_verifier, __Secure-authjs.stateGoogle Sign-In authorization verification15 minutes
pinkale-localePreserving selected language preference1 year
pinkale-locale-dismissedPreserving dismissal state of locale notice banner30 days

2. Browser Local Storage (localStorage — never sent to servers)

Storage KeyPurposeRetention
pinkale-themeDark / light mode theme preferenceUntil manually cleared or altered
pinkale:favorites:v1Guest favorite tools listUntil manually cleared
pinkale:recent-tools:v1Guest recent tools historyUntil manually cleared
pinkale:tool-frequency:v1Guest tool execution frequencyUntil manually cleared
pinkale:recent-searches:v1Guest recent search historyUntil manually cleared
pinkale:local-migration-dismissed:v1Dismissal state of local-to-cloud migration bannerUntil manually cleared

Opting Out: Users can configure their browsers to reject cookies or purge stored local data. Blocking session cookies will only disable account login features; all tools remain fully accessible and free for guests without an account.

Article 8 (Security Measures)

The Service implements comprehensive administrative and technical safeguards to ensure the integrity and protection of personal data:

  • One-Way scrypt Password Hash: Passwords are cryptographically transformed via scrypt with salted hashes; plaintext credentials are never stored or accessible.
  • Rate Limiting & Abuse Prevention: Excessive, brute-force, or abusive requests targeting login, registration, or feature requests are blocked via automated per-IP and per-account rate limiting.
  • Non-Retention of Raw IPs: Client IP addresses are converted to one-way HMAC-SHA256 hashes solely for transient rate limiting; raw IPs are never stored in the database.
  • Strict Admin Console Access Control: Administration consoles are isolated on dedicated host configurations and restricted to authorized administrative accounts.
  • Isolated Secret Storage: Database credentials and operational secrets are separated from source code and managed securely via cloud Worker Secrets.
  • Zero User Content in Logs: System logs, telemetry, and error alerts are programmatically sanitized to ensure that user inputs, filenames, and payloads are never recorded.
  • Encrypted Transport: All data transmissions between clients and the Service are secured using modern TLS/HTTPS encryption protocols.

Article 9 (Data Subject & Legal Representative Rights)

  • You can inspect, update, or permanently delete your account and personal data at any time via My Account (/account).
  • You may also request access, rectification, erasure, or suspension of processing by contacting the operator via email at contact@pinkale.com; requests will be handled within 10 days. Rights may be exercised directly or through an authorized legal representative.
  • No Age Restriction: Anyone may freely use all tools and register an account. Legal representatives of children under the age of 14 may exercise all statutory data subject rights on behalf of the child.
  • You may also lodge a complaint with the data protection supervisory authority in your country of residence.

Article 10 (Privacy Officer)

The Service designates the operator as the privacy officer responsible for overseeing personal data processing and handling inquiries and complaints:

Service Name: pinkale (Pinkale)

Operating Entity: Pinkale (Individual Operator, Unregistered Business)

Privacy Officer: the operator

Contact Email: contact@pinkale.com

Article 11 (Dispute Resolution & Redress Agencies)

Data subjects may contact the following statutory agencies in the Republic of Korea for dispute resolution, consultation, or reporting infringements:

  • Personal Information Dispute Mediation Committee: 1833-6972 (www.kopico.go.kr)
  • Personal Information Infringement Report Center (Korea Internet & Security Agency): 118 (privacy.kisa.or.kr)
  • Supreme Prosecutors' Office Cybercrime Investigation: 1301 (www.spo.go.kr)
  • National Police Agency Cyber Bureau: 182 (ecrm.cyber.go.kr)

Article 12 (Amendments to the Privacy Policy)

This Privacy Policy is effective as of September 16, 2026. Notice of amendments will be announced on the Service Updates page (/updates) at least 7 days prior to implementation (or 30 days prior for material changes affecting user rights). This current revision takes effect concurrently with its publication, and subsequent amendments will adhere to the aforementioned notice period.