A password reset link will be sent to your email.
Enter the 6-digit code sent to
Sign In | Sign Up
PinealOS is built on the principle that your data belongs to you. Your chats stay on your device. Your files live in your accounts. Here is exactly how we protect you.
Your chat messages are stored locally on your device — computer, phone, or tablet — using IndexedDB technology. They are never transmitted to or stored on PinealOS servers. This means your conversations are as private as files on your own computer. You control when and if they sync to the cloud via optional encrypted R2 backup.
All data at rest — your files in Cloudflare R2 storage, database records in D1, and key-value data in KV — is encrypted using AES-256-GCM, the same standard used by governments and financial institutions. Encryption keys are managed by Cloudflare's secure infrastructure.
Your AI provider API keys are stored exclusively in your browser's localStorage. They are never sent to PinealOS servers. When you chat with AI, your browser communicates directly with the AI provider's API. PinealOS never sees, logs, or proxies your keys.
All connections between your browser, PinealOS, and all integrated services use 256-bit SSL/TLS encryption. Data in transit is always protected. Cloudflare's global network provides automatic SSL certificate provisioning and renewal.
Every project you build creates a repository in your GitHub account. Every deployment goes to your Cloudflare account. PinealOS is the orchestration layer — we do not hold your code or infrastructure. If you ever leave, everything is already in your accounts, fully operational.
PinealOS runs on Cloudflare Workers with enterprise-grade DDoS mitigation. All traffic passes through Cloudflare's security layer before reaching our infrastructure. Rate limiting protects all API endpoints from abuse.
Your personal data is processed under Turkish Personal Data Protection Law (KVKK No. 6698). You have the right to access, correct, and delete your data at any time. Full account deletion removes all associated data from our systems.
For users in the European Union, PinealOS complies with the General Data Protection Regulation (GDPR). We process minimal personal data and store it within Cloudflare's EU data centers (Frankfurt, Paris, Madrid). Data processing is limited to what is necessary for service delivery.
A comprehensive Data Processing Agreement (DPA) is available for business and enterprise users. It defines our role as a data processor, outlines sub-processor commitments, and specifies data handling procedures. View the DPA.
Chats stored on your device. Files in your GitHub. Deployments on your Cloudflare. API keys in your browser. PinealOS is the platform — your data stays yours.
Get StartedIntegrated Partners