Privacy Policy
🔒 PRIVACY POLICY
“Pin your inspiration. Own your value.”
At Omnipins, we deeply believe that privacy is the foundation of tranquility and creative freedom. We do not just build a complete Marketplace of Completed Artifacts — we forge Trust as a Feature.
Distinctly different from traditional storage platforms, our core philosophy is "We do not hold your original files — We protect your trust and copyright". This Privacy Policy is transparently and rigorously designed to explain how we safeguard your personal information and cloud integration data as an Orchestrator of Value.
☁️ 1. ZERO-STORAGE POLICY & BYOS
The strength and reliability of Omnipins lie in its Bring Your Own Storage (BYOS) infrastructure model.
- No Original File Ownership: We absolutely do not store, cache, or duplicate any original physical files (images, audio, video, or documents) of creators on Omnipins server systems.
- Full Control: All your artwork is stored securely under your personal ownership on public cloud providers linked by you (Google Drive, Microsoft OneDrive, Dropbox, AWS S3, Cloudflare R2).
- Civil Liability: You retain 100% control (rights to modify, delete, or disconnect sharing) over your assets and bear ultimate legal responsibility for file authenticity.
🛡️ 2. SUPREME DATA SECURITY ENCRYPTION ARCHITECTURE (ENCRYPTION-AT-REST)
To safely operate the intermediary connection flow between the system and your cloud account, Omnipins applies the strictest data security standards:
A. AES-256-CBC Encryption Standard
All sensitive configuration information, including API connection keys, Webhook secrets, Client IDs, Client Secrets, and Refresh Tokens, must be one-way encrypted using the AES-256-CBC algorithm before writing to the system database.
We utilize the system's root security key (AUTH_KEY) as the Passphrase and the salt code (AUTH_SALT) as the Initialization Vector (IV) for encryption. Absolutely no cloud connection or sensitive API info is stored in plaintext.
B. Strict Context Isolation
We design an absolute storage partition architecture separating Administrators and Users (Admin-Space completely isolated from User-Space). Admins and engineering teams are strictly prohibited from accessing, using, or extracting end-user personal API keys or tokens.
C. Input Field Masking
When accessing your account configuration or payment wallet interface, all password and API key fields are automatically masked, displaying only placeholder values to completely eliminate data leakage risks on source HTML.
📊 3. INFORMATION WE COLLECT & USE
To ensure platform integrity and optimize user experience, we collect limited information categories:
- Account Info: Email, Display name, and @username to establish a unique Profile connecting with readers.
- Interaction Logs: Preview listens, Likes, and Pins as input data for the ZDA intelligent distribution algorithm.
- IP & Security Audit: We automatically log login IP addresses to prevent unauthorized account sharing (detecting and warning if Premium/Gold accounts exceed 5 simultaneous IPs).
- Payment Info: Transaction history recorded securely in payment_logs. We do not store credit card details; all transactions are encrypted and processed directly by trusted partners (Lemon Squeezy, PayOS, SePay).
🚪 4. SECURE DISCONNECTION & DATA RELEASE (CLIENT-STATE CLEAR)
We respect your absolute autonomy over personal resources through two automated mechanisms:
A. Client-State Clear
Whenever you click Disconnect for Google Drive, OneDrive, or Dropbox on your profile, the system immediately deletes database connection sessions and cleans up browser Local Storage and Session Storage.
B. Automatic Cleanup on Tier Downgrade
If your Pro/Premium membership expires and shifts to Free, an Automatic Tier Expiry Worker background process safely disconnects cloud accounts exceeding Free limits.
🔒 5. TRANSACTION SECURITY & SECURE DOWNLOAD LINKS
To completely prevent original link leaks or unauthorized file sharing, Omnipins runs a Secure Proxy Download mechanism. Buyers never see the original link; the server issues a temporary Download Session Token and handles file delivery via download.php using an 8KB data stream.
⚖️ 6. GDPR COMPLIANCE & DMCA SHIELD (SAFE HARBOR)
Right to be Forgotten: You have the right to request permanent deletion of your Omnipins account anytime. Upon approval, all metadata and encrypted access tokens are immediately wiped.
DMCA Shield: Valid infringement reports sent to copyright@omnipins.com trigger a temporary display lock on reported works within 24 hours for verification.
Pin your inspiration. Own your value.

