Visual Assistant

Privacy Policy

This Privacy Policy explains how Visual Assistant processes information when its operator connects a Pinterest account through Pinterest OAuth.

Visual Assistant is a private, non-commercial, single-user MCP connector. It is not offered for public registration or use.

Effective date: 1 August 2026

1. Controller and contact

Visual Assistant is operated under the personal project name Diana Studio.

Diana Studio is the name of a personal project operated by an individual and is not represented as a registered company.

Privacy contact:

For privacy requests, include “Visual Assistant privacy request” in the subject line.

2. Scope of this Policy

This Policy applies to the Visual Assistant website, its Pinterest OAuth connection, and the server-side connector used by the operator to access Pinterest API functions.

The connector is intended only for its operator's personal use. It does not provide public accounts, customer registration, advertising services, or access to unrelated Pinterest accounts.

3. Information processed

Depending on the permissions approved on Pinterest's OAuth screen and the functions enabled for the application, Visual Assistant may process:

Pinterest account information

Technical account identifiers and limited profile information supplied by Pinterest for authentication and connection management.

Boards and Pins

Board names and identifiers, board sections, Pin identifiers, Pin links, descriptions, media URLs or thumbnails, and other information returned by approved Pinterest API endpoints.

This may include publicly available Pin information when it is necessary to complete a specific request initiated by the authenticated account owner.

OAuth information

Access and refresh tokens and related technical information required to make authorized Pinterest API requests on behalf of the connected account.

Technical and security information

Limited operational logs, such as the time of a request, operation type, response status, and error information needed to maintain security and diagnose failures.

Visual Assistant does not collect Pinterest passwords or Pinterest browser session cookies. Credentials are entered only on Pinterest's own authentication pages.

4. Sources of information

Information is obtained:

  • directly from the operator when the operator submits a command or configuration;
  • from Pinterest through approved API endpoints after OAuth authorization;
  • automatically from the connector's server when it records limited security or error information.

Visual Assistant does not obtain Pinterest information through scraping, browser automation, CAPTCHA bypassing, or unofficial extraction methods.

5. Purposes of processing

Information is processed only to:

  • establish and maintain the OAuth connection;
  • identify the connected Pinterest account;
  • show boards, board sections, and Pins available to the authenticated account;
  • retrieve visual references through Pinterest API functions approved for the application;
  • organize boards or board sections when requested by the owner;
  • save or create specifically selected or confirmed Pins on the owner's account;
  • return operation results to the owner;
  • prevent abuse, protect credentials, diagnose errors, and maintain the connector.

Pinterest information is not used for advertising, behavioral profiling, data brokerage, competitor monitoring, or unrelated analytics.

7. AI interface and service providers

The operator accesses the connector through an AI interface selected and controlled by the operator.

Only the minimum information required to complete an explicit owner request may be returned through that interface. OAuth tokens, App Secret values, passwords, and session cookies must never be sent to an AI model or displayed in a chat response.

Pinterest information may also be processed by infrastructure providers used solely for hosting, networking, security, backups, or error monitoring, only to the extent necessary to operate the connector.

Visual Assistant does not sell or rent Pinterest information and does not provide it to advertising networks, data brokers, or unrelated third parties.

Pinterest information is not used to train, fine-tune, evaluate, or improve artificial intelligence or machine-learning models.

Implementation requirementEvery AI and infrastructure provider must be configured consistently with this statement. If a provider's settings or contract allow the provider to use submitted connector content for model training or unrelated purposes, Pinterest API information will not be sent to that provider.

8. International processing

Some technical providers selected by the operator may process limited information outside the operator's country. Where applicable law requires safeguards for international transfers, the operator will use providers and configurations that offer appropriate contractual or legal protections.

No provider is named here unless that provider is actually used. If the final implementation uses a named AI, hosting, logging, or backup provider, its name, role, privacy-policy link, processing location, and applicable transfer safeguard will be added before the relevant processing begins.

9. Retention and deletion

Pinterest board, Pin, description, link, and media information is not stored as a permanent independent database. The connector requests that information when needed for an owner-initiated task and discards temporary copies after the task is completed, except where a short technical cache is strictly necessary and permitted by Pinterest.

OAuth tokens may be retained securely while the connection remains active. They are deleted when the operator disconnects the integration, revokes access, or requests deletion.

Technical logs may be retained for no longer than 30 days, unless a longer period is strictly necessary to investigate a specific security incident. Logs do not contain OAuth tokens, App Secret values, Pinterest passwords, session cookies, full Pin images, or unnecessary Pin descriptions.

Pins and boards saved in the Pinterest account remain stored by Pinterest under Pinterest's own terms and privacy policy. They can be deleted through Pinterest.

10. Security

Visual Assistant uses reasonable technical measures appropriate to a private connector, including:

  • HTTPS;
  • Pinterest OAuth instead of password collection;
  • minimum necessary API scopes;
  • secrets stored outside source code;
  • restricted server permissions;
  • encrypted storage where persistent token storage is required;
  • log redaction;
  • rate limiting and request validation;
  • CSRF protection through OAuth state;
  • deletion of credentials when access is revoked.

No method of transmission or storage is completely secure, but reasonable steps are taken to reduce risk.

11. The operator's choices and control

The operator can:

  • decline requested OAuth permissions;
  • revoke Visual Assistant access in Pinterest's connected-app settings;
  • stop using the connector;
  • request deletion of connector-held tokens or logs by contacting dianaweerasuria@gmail.com;
  • delete Pins, boards, or board sections through Pinterest.

After OAuth access is revoked, Visual Assistant can no longer make new Pinterest API requests on behalf of the account.

12. Privacy rights

Where applicable, a person may have rights to request access, correction, deletion, restriction, or portability of personal information and to object to certain processing.

Requests can be sent to dianaweerasuria@gmail.com.

A person may also have the right to complain to the competent data-protection authority in their country.

Because Visual Assistant is a private single-user connector, most Pinterest account content remains under the direct control of the connected account owner and Pinterest. Requests concerning data stored only by Pinterest should be directed to Pinterest.

13. Automated decision-making

Visual Assistant does not make decisions that produce legal or similarly significant effects.

AI-assisted sorting or suggestions are used only to help the operator organize visual references. The operator remains responsible for approving Pinterest write actions.

14. Children's data

Visual Assistant is not intended for children and does not knowingly collect children's personal information.

15. Changes to this Policy

This Policy may be updated when the connector's functions, providers, Pinterest requirements, or applicable law change.

The current version will be published at this URL with an updated effective date. Material changes will not be applied retroactively where prohibited by law.

16. Relationship with Pinterest

Visual Assistant is an independent personal project. It is not affiliated with, endorsed by, or a product of Pinterest, Inc.

Pinterest and related marks belong to Pinterest, Inc. Use of Pinterest is also governed by Pinterest's own terms and privacy policy.

17. Contact

Privacy contact:

Operator/project:

Diana Studio — personal project operated by an individual