Legal
Privacy Policy
Last updated: July 2026
The short version: Pinolo exists to keep your working memory — not to exploit it. We store what you give it, on EU infrastructure, isolated per account. We don’t sell it, don’t advertise on it, and don’t train models on it.
Who we are
Pinolo (“we”) is operated by Rivamont, Principality of Monaco. Contact: info@pinolo.ai.
What Pinolo is
A personal AI chief of staff. You connect your own AI assistant to Pinolo; Pinolo keeps your working memory and delivers briefs, coaching and suggestions built from it.
What we store
- The working memory you build by using the product: meeting transcripts and content you push or connect, and the commitments, people, projects, notes and documents derived from them.
- Your account email address (used to sign in and to deliver your briefs).
- Operational records: job metadata, audit logs, delivery ledgers.
Every account’s data is isolated per tenant, enforced at the database level and tested continuously.
Credentials for connected services
We keep credential custody to a minimum. Most integrations work through your own assistant, with credentials Pinolo never sees. Where a feature does require us to hold an API key — for example the transcript services you connect — the key is stored per account, envelope-encrypted, entered only through the web portal, and never readable back through any interface, API or log.
Your AI conversations
Conversations with your own assistant stay with your assistant, under your subscription and its provider’s terms. Pinolo stores the memory you build — not your chats.
Where your data lives, and who helps us process it
Your service data is stored on servers operated by Hetzner in Germany — EU infrastructure. Transactional email (sign-in links, briefs) is delivered through Resend. As the product evolves, we may use additional service providers — including AI model providers that process content on our behalf to deliver features — and we will list any such providers on this page before introducing them.
Why we process it
Solely to provide the service you signed up for. No sale of data, no advertising, no model training on your content.
Retention and deletion
Operational exhaust (finished jobs, old logs) is swept automatically on a schedule. Your memory is retained while your account is active. To delete your account and its data, write to info@pinolo.ai; we complete the deletion within 30 days and confirm it to you.
Your rights
Access, rectification, erasure, portability and objection — under Monaco’s data protection law (Law no. 1.565) and, for EU users, the GDPR. Write to info@pinolo.ai. You may also lodge a complaint with your supervisory authority. While Pinolo is in invite-only early access we process data on a limited scale; an EU representative under Art. 27 GDPR will be appointed as the service opens more widely.
Security
Tenant isolation enforced by the database (row-level security, forced), append-only evidence, least-privilege access roles, encrypted transport everywhere, per-tenant encrypted provider keys. No design is zero-risk; ours is tested on every change we ship.
Changes
We’ll post any changes here with a new date. Material changes will be announced by email.