Privacy Policy for Calm Glow Finds Content Operations

Effective date: 9 August 2026

Calm Glow Finds Content Operations is an owner-operated workflow for the Calm Glow Finds Pinterest Business account. AutoPoster OS is the internal system name for the private workflow tool used to plan, review, manually publish today, and measure approved content.

Information Processed Today

Future Trial Data Boundary

Pinterest API and OAuth are disabled today. If Pinterest grants Trial access and the owner separately activates the reviewed safeguards, the first phase may process transient authorization state and status, a permitted-board lookup for the owner's account, the outbound fields for one owner-approved Sandbox Pin, and minimal success, failure, and rate-limit categories.

The first Trial phase does not collect follower data, automatic Pinterest API analytics, unrelated-account data, passwords, session cookies, or Pinterest API engagement data. It does not schedule or publish Pins through unattended Pinterest/API actions and does not perform batch publishing. Internal content-calendar dates may still support the owner's manual workflow.

How We Use Information

Cookies, Trackers, and Analytics

This static public site does not set optional cookies, include third-party analytics scripts, or use fingerprinting code. The hosting provider may still process technical request logs needed to serve and protect the site.

Affiliate Links and Referral Data

Calm Glow Finds may use affiliate links. Clicking an external product or platform link may send referral information to the destination website according to that destination's own policies. Calm Glow Finds does not guarantee that every link is an affiliate link.

Pinterest API Access

Pinterest API publishing and OAuth are disabled in the current build. If Trial access is approved later, AutoPoster OS will use it only for an owner-authorized workflow connected to the owner's own Pinterest Business account: transiently list permitted boards if needed and create one individually approved Sandbox Pin at a time.

The app does not collect Pinterest passwords or session cookies. It does not scrape Pinterest, automate engagement, sell or share Pinterest API data, publish without approval of the exact Pin, or use Pinterest Materials to train, fine-tune, or develop an AI or machine-learning model.

Information Sent To Pinterest

If the future Trial path is explicitly activated, the app may send only the fields needed for one exact owner-approved Sandbox Pin: a permitted board reference, Pin title, Pin description, destination link, media source, and alt text if supported. Internal approval and compliance metadata stays inside AutoPoster OS.

An owner-visible dry-run request preview may be constructed transiently before confirmation. Raw transport request bodies are not persisted or written to logs; only a non-reversible fingerprint and redacted operational status may be retained.

Information Received From Pinterest

The first API phase is limited to authorization status, transient board lookup for the authorized account, and minimal redacted outcome categories for one owner-approved Sandbox Pin. Automatic analytics collection is not part of this phase.

Raw API responses and returned account, board, or Pin data stay in request memory only and are discarded when the request completes. Raw response bodies, follower data, authorization codes, access tokens, refresh tokens, client secrets, cookies, and passwords are never written to Google Sheets, Google Drive, source code, HTML, public documents, logs, screenshots, or demo fixtures. Persistence of any Pinterest-derived Pin identifier or confirmation field remains blocked until a separate policy and implementation review.

Data Sharing

We do not sell personal data or Pinterest API data. We do not share Pinterest API data with advertisers or unrelated third parties, and we do not combine Pinterest account information with other users' accounts or unrelated services.

Information may be processed only by the services needed for the described purpose: the selected static hosting provider for public-page delivery and security logs; owner-controlled Google Sheets and Google Drive for private operational records; Pinterest after future owner authorization; the monitored email provider for support requests; and a retailer or affiliate destination only when a visitor chooses to follow an external link. Each provider applies its own terms and privacy practices.

Storage, Retention, and Security

Operational workflow data may be stored in private, owner-controlled Google Sheets and Google Drive. Owner-created campaign records, manually captured public Pin URLs, and manually entered metrics are retained until the owner deletes them or completes a verified deletion request. Support and privacy correspondence is retained only as long as needed to respond, verify completion, and meet narrow legal or security obligations.

The current build does not store Pinterest OAuth tokens. If a later reviewed Trial activation enables token storage, tokens must be held only in server-side secret storage while the authorized connection is active. They must never enter Sheets, source files, fixtures, logs, screenshots, public documents, or Operator UI payloads.

Authorization codes are one-time and are not retained. OAuth state expires after at most 10 minutes and is one-time use. Raw Pinterest API request and response payloads are discarded when the request completes. Redacted Pinterest integration audit metadata may be retained for up to 90 days for security, duplicate prevention, and incident review.

Supported safeguards include owner-controlled access, least-privilege scope selection, server-side secret handling, exact human approval, kill switches, duplicate and stale-approval checks, redacted logs, and no raw API-payload persistence. The public site is designed for HTTPS hosting and intentionally avoids forms, optional cookies, analytics scripts, and client-side credential handling. No website or workflow can guarantee perfect security.

Data Deletion and Access Revocation

Monitored support address: [email protected]. Identity or ownership verification may be requested when needed to protect the account or prevent unauthorized changes.

After identity or account ownership is verified, API access will be blocked immediately and a deletion request will be completed within 30 days. If an API connection is enabled in the future, disconnect or Pinterest-side revocation will stop further API use immediately and locally stored token material will be deleted within 24 hours. Pinterest app access can also be revoked from Pinterest account settings at any time.

Third-Party Services

The workflow uses owner-controlled Google services for private operational records, the selected static hosting provider for this public site, the monitored email provider for support, and Pinterest only after the owner authorizes a reviewed API connection. Visitors may choose to open retailer or affiliate destinations. No Pinterest API data is sold or shared with unrelated third parties.

Contact

Calm Glow Finds Content Operations · AutoPoster OS · Owner-operated

Monitored support address: [email protected]