Skip to content
Back to home

Privacy Policy

Last updated · July 2026

1. Who we are

BulkoPin is operated by OCYHEAN TECH, the trading name of Hüseyin Memiş, an individual sole trader. For any personal data we collect about you, Hüseyin Memiş (trading as OCYHEAN TECH) acts as the data controller. Contact: support@bulkopin.com.

2. Our approach

BulkoPin is privacy-first by design. The Chrome extension does not ask for your Pinterest username or password. It does not request the cookies or identity Chrome permissions — instead, while an export is running, it reads one Pinterest cookie (a CSRF security token) directly from the page you already have open, the same way your browser would, to make requests to Pinterest on your behalf. That token stays on your device and is never sent to BulkoPin's servers. Exports run in your own logged-in Pinterest tab and are limited to content you can already see in that session. Image, video and ZIP/PDF/CSV files are assembled on your machine and are never uploaded to BulkoPin.

3. Personal data we collect

Email address (account)

Purpose
Create and authenticate your BulkoPin account, send transactional messages (sign-in, billing, security)
Legal basis
Performance of contract

Subscription status and plan

Purpose
Determine which features you have access to (Free, Lifetime); enforce plan limits
Legal basis
Performance of contract

Quota / usage events (board URL, pin count, format, timestamp)

Purpose
Enforce plan limits, debug, prevent abuse
Legal basis
Legitimate interest

Product analytics (opt-in)

Purpose
If you accept the analytics cookie banner on the web app, or turn on analytics in the extension's own settings, PostHog (EU-hosted) records anonymized product-usage events (pages viewed, features used) tied to a randomly-generated identifier, not your name or email. Off until you opt in; you can withdraw at any time. See our Cookie Policy.
Legal basis
Consent

Site-performance metrics

Purpose
Vercel Analytics and Speed Insights measure aggregate page-load performance and traffic counts. Both are cookieless and do not use any persistent identifier, so they run without requiring consent.
Legal basis
Legitimate interest

Opt-in error reports

Purpose
If you enable "Send error reports", a redacted event name, app version and stack trace hash are uploaded. URLs, emails, JWTs and raw HTML are stripped client-side and rejected server-side. Off by default.
Legal basis
Consent

Server logs (IP address, request metadata)

Purpose
Security, fraud prevention, rate limiting
Legal basis
Legitimate interest, legal obligation

Support correspondence

Purpose
Respond to your inquiries
Legal basis
Legitimate interest

Billing data (card details handled by our payment institution)

Purpose
Card payments are processed by a licensed payment institution on our behalf. BulkoPin does not see or store your payment card details. We receive only a payment reference, the amount, the currency and whether the payment succeeded.
Legal basis
Performance of contract

We do not collect your Pinterest username or password, do not run third-party advertising trackers, and do not sell or rent personal data. The one Pinterest cookie the extension reads (a CSRF token, used only to talk to Pinterest on your behalf) never leaves your device or reaches our servers.

Data we never collect:

  • Your Pinterest password, or any Pinterest cookie beyond the single, on-device CSRF token described above.
  • The images, videos, or files you download — they go from Pinterest's CDN straight to your device and are never uploaded to us.
  • Your local files or folder contents.
  • Automatic content categorization, tagging, or classification of any kind — BulkoPin has no such feature, and none of your content is ever sent to a third-party classification service.
  • IP addresses beyond what security and abuse-prevention require, and never for tracking or profiling.

4. Recipients and sharing

  • Our payment institution — processes the card payment on our behalf and holds the card data. BulkoPin remains the seller and handles billing, receipts, refunds and disputes.
  • Subprocessors — Vercel (hosting), Supabase (database and authentication), and Sentry (opt-in crash/error reporting). Bound by data-processing agreements.
  • Authorities — only where required by valid legal process.

We do not share personal data with any party for advertising or profiling.

5. International transfers

Our infrastructure providers may process data outside your country of residence (including within the EU/EEA and the United States). Transfers are protected by appropriate safeguards such as the EU Standard Contractual Clauses or adequacy decisions where applicable.

6. Retention

  • Account data — kept while your account exists; deleted within 30 days of account closure.
  • Subscription / billing metadata — kept while the subscription is active and for 12 months after the last renewal for dispute and chargeback handling.
  • Quota / usage events — kept for up to 90 days.
  • Product-analytics events (PostHog, only if you accept the cookie banner) — retained per PostHog's standard retention, tied to an anonymized browser identifier, never your name or email.
  • Opt-in error reports — kept for up to 30 days, then purged.
  • Server / rate-limit logs — kept for up to 30 days.
  • Support correspondence — kept for up to 24 months.
  • Billing records — kept by us for the period required by tax law (typically 7–10 years).

To request account deletion or a copy of your personal data, email support@bulkopin.com from the address on your account.

7. Your rights

Depending on your country you have the right to access, rectify, delete, restrict, port, or object to processing of your personal data, to withdraw consent, and to lodge a complaint with your data-protection authority. To exercise these rights, email support@bulkopin.com. We respond within one month.

8. Security

We apply appropriate technical and organisational measures including TLS in transit, encryption at rest, access controls, audit logging, and row-level database security.

9. How the extension works

The Chrome extension runs in your own Pinterest tab using your existing logged-in session. When you start an export, it reads pin URLs from the page you are viewing, downloads the images and videos directly from Pinterest's CDN, and packages them into a ZIP, PDF or CSV file on your machine. The image and video bytes are never uploaded to BulkoPin servers. Exports are always user-initiated — there is no background or continuous automation.

10. Permissions

The extension requests only the Chrome permissions it actually needs. Notably, it does not request cookies or identity.

  • scripting — read pins from the Pinterest tab you're viewing, using the pinterest.com host permission below.
  • downloads — save the resulting ZIP, PDF or CSV to your Downloads folder.
  • storage, unlimitedStorage — remember your export preferences and cache thumbnails locally so retries don't re-download.
  • tabs, alarms — detect when a Pinterest tab finishes loading and keep the service worker alive during long exports.
  • offscreen — assemble the ZIP and PDF files in a hidden document, because a service worker cannot build them on its own.
  • contextMenus — add the right-click “Download with BulkoPin” entry on Pinterest pages.
  • host permissions for *.pinterest.com and *.pinimg.com — fetch pin pages and image/video files.
  • host permissions for bulkopin.com and the Supabase auth endpoint — check your subscription, log quota usage, and authenticate your BulkoPin account.
  • host permissions for the Sentry error-ingest endpoint — deliver a crash/error report only if you turn that setting on; off by default.

11. Cookies

See our Cookie Policy for the full list. In short: we set strictly necessary cookies for authentication and theme preference, and — only if you accept the cookie banner — PostHog stores an anonymized analytics identifier in your browser's local storage (not a cookie). No advertising cookies, ever.

12. Children

BulkoPin is not directed at children under 13 and we do not knowingly collect data from minors.

13. Changes

Material changes to this policy will be reflected by a new "Last updated" date and, where appropriate, by direct notice to account holders.

14. Language

This policy is written in English. Translations into other languages are provided for convenience only; if a translation and the English version conflict, the English version is authoritative and prevails.

Back to top