Draft Drills
Privacy Policy
Last updated: February 2026
Draft Drills (“the App”, “we”, “us”) is a browser-based creative workflow tool that integrates with Pinterest through Pinterest OAuth and the official Pinterest API. This Privacy Policy explains what data we access, how we use it, what we store, and what choices you have.
1) Overview
The App helps you browse and shuffle through Pins from your own Pinterest boards for creative inspiration. You authorize access through Pinterest, choose one or more of your boards, and the App displays a set of Pins in-session so you can decide what to open on Pinterest.
The App is designed to be lightweight and does not require you to create a separate user account with us.
2) Pinterest data usage (read-only)
When you connect your Pinterest account, the App requests read-only access and uses Pinterest data only to provide the core functionality: showing your boards, loading Pins from boards you select, and generating/shuffling a reference set for you to browse.
What we access (read-only): your boards and Pins from boards you select (including Pin image URLs and basic metadata such as title/description when available).
What we use it for: displaying a grid of Pins, reshuffling selections, and providing a link to open Pins on Pinterest.
What we do NOT do: we do not create, post, save, edit, or delete boards or Pins; we do not message other users; we do not use your Pinterest data for advertising.
No Pinterest content storage: we do not store Pinterest content (Pins, images, or board data) on our servers. Pinterest data is processed in-session to render the user interface.
3) Data we access from Pinterest
After you connect your Pinterest account, we access only the data you authorize via Pinterest’s OAuth permissions and only to provide the App’s functionality for you (the authenticated user). Depending on the permissions you approve, this may include:
- Basic account/profile identifiers returned by the API
- Your boards (e.g., names and IDs)
- Pins from the boards you select
- Pin metadata needed to render the grid (e.g., title/description and image URLs)
4) What we store (and what we don’t)
We do not store Pinterest content (Pins, images, or board data) on our servers.
Authentication tokens: to keep you signed in, we store a Pinterest access token (and, if applicable, a refresh token) in secure, httpOnly cookies. These cookies help the App make authorized API requests on your behalf. We do not expose tokens to client-side JavaScript.
Tokens/cookies persist until they expire or you disconnect/revoke access. If you use the App’s disconnect option, the App clears the authentication cookies.
We do not sell, rent, or share Pinterest data with third parties for advertising or marketing purposes.
5) Link-back and attribution
Pins displayed in the App are shown for quick browsing. Where applicable, the App provides a way to open a Pin on Pinterest so you can view the full context on Pinterest.
Pinterest content remains the property of its respective owners and is subject to Pinterest’s terms and policies.
6) Cookies and local storage
The App may use cookies strictly for functionality, such as maintaining an authenticated session (Pinterest OAuth tokens stored as secure httpOnly cookies) and supporting security controls (e.g., OAuth state/PKCE during login). We do not use cookies for advertising.
7) Service logs and diagnostics
Like most websites, our hosting provider and application services may process basic technical logs to operate and secure the App (for example: timestamps, IP address, user-agent, and request paths). These logs are used for reliability, abuse prevention, and debugging—not for advertising.
8) Third-party services
The App relies on third-party services to operate, including:
- Pinterest (OAuth authentication and API access)
- Hosting provider (Vercel), which serves the website infrastructure
9) International data processing
Pinterest and our hosting infrastructure may process data in countries outside Chile. We use these services to operate the App and apply reasonable safeguards appropriate for a lightweight tool.
10) Security
We use reasonable safeguards such as HTTPS, secure cookies, and minimal data handling. However, no method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
11) Data retention and revoking access
The App is designed to avoid retaining Pinterest content. Pinterest content is processed in-session to render the UI and is not stored on our servers.
You can revoke the App’s access at any time from your Pinterest account settings, which will stop future access to your Pinterest data. You can also disconnect within the App (if available), which clears the App’s authentication cookies.
12) Your choices
- Disconnect Pinterest access at any time in Pinterest settings
- Use the App’s disconnect option to clear authentication cookies
- Clear browser cookies/storage to remove locally stored data
- Stop using the App at any time
13) Children’s privacy
The App is not intended for children under 13. We do not knowingly collect personal information from children.
14) Changes to this policy
We may update this Privacy Policy from time to time. Updates will be posted on this page with a new “Last updated” date.
15) Contact
Questions? Contact: isaavedra.creative@gmail.com