BBiocord

Privacy Policy

Last updated: 7 August 2026

This policy describes how the Biocord content publishing tool («the Service») handles data. Biocord is a brand of dietary supplements and vitamins; brand information is published at biocord.space.

The Service is an internal tool used by Biocord to schedule and publish product content to Pinterest accounts that the company owns or is authorised to manage. It is not offered to the general public and has no end-user sign-up.

1. Who processes the data

Biocord is the operator and data controller. The Service runs on a private server controlled by the company. Contact: steamdss1@gmail.com.

2. What data the Service processes

Pinterest account data. When an operator connects a Pinterest account through Pinterest OAuth, the Service stores the account's numeric identifier, username, follower count, and the list of boards on that account.

Access credentials. OAuth access and refresh tokens issued by Pinterest are stored encrypted at rest with AES-256-GCM. They are used only to call the Pinterest API on behalf of the connected account and are never displayed, exported, or transmitted anywhere other than to Pinterest.

Content supplied by the operator. Product photographs, article numbers (SKUs), titles, descriptions, prices and links uploaded by Biocord staff.

Generated content. Images and texts produced for pins, and the prompts used to produce them.

Performance metrics. Impressions, saves, pin clicks and outbound clicks for pins published by the Service, together with follower counts, retrieved from the Pinterest API for the connected accounts.

Operational logs. Timestamps, account identifiers and error messages produced by the publishing pipeline.

3. What the Service does not process

The Service sets exactly one cookie, pa_session, which holds a signed session marker for the operator's own login to the control panel. It contains no personal data.

4. Why the data is processed

5. Third parties

Pinterest. Pin content — image, title, description, alt text and link — is transmitted to Pinterest for publication, and performance metrics are retrieved back. This is governed by the Pinterest Privacy Policy.

OpenRouter and AI model providers. ByteDance Seed receives a text prompt and generates only the lifestyle background. Original product photographs are processed locally and are not sent to the image model. Product attributes are sent through OpenRouter to Google Gemini to prepare the pin copy. This is governed by the OpenRouter Privacy Policy and the applicable upstream provider terms.

No data is sold, rented, or shared with any other party. There is no advertising network involved.

6. Storage and security

7. Retention

Account records, product data and published-pin records are kept for as long as the account remains connected and the operator needs the publishing history. Operational logs are kept for troubleshooting and pruned periodically. Disconnecting an account removes its stored tokens.

8. Deleting data

An operator can delete any connected account, product, or generated pin from the control panel at any time; deletion removes the associated database records and stored image files. To request full deletion of all data relating to a Pinterest account, write to steamdss1@gmail.com and it will be carried out within 30 days.

Access granted to the Service can also be revoked at any time from the Pinterest account settings, which immediately invalidates the stored tokens.

9. Changes

If this policy changes, the updated version will be published at this address with a new «last updated» date.