Skip to main content
Platform Review
PricingSign in
Pipedream assessment

privacy data use · Privacy Policy

Pipedream policy finding

When you link an account from a third party application, you may be asked to either authorize a Pipedream OAuth application access to your account, or provide an API key or other credentials. This section describes how we handle these grants and keys. When a third party application supports an OAuth integration , Pipedream prefers that interface. The OAuth protocol allows Pipedream to request scoped access to specific resources in your third party account without you having to provide long-term credentials directly. Pipedream must request short-term access tokens at regular intervals, and most applications provide a way to revoke Pipedream’s access to your account at any time. Some third party applications do not provide an OAuth interface. To access these services, you must provide the required authorization mechanism (often an API key). As a best practice, if your application provides such functionality, Pipedream recommends you limit that API key’s access to only the resources you need access to within Pipedream. Pipedream encrypts all OAuth grants, key-based credentials, and environment variables at rest in our production database. That database resides in a private network. Backups of that database are encrypted. The key used to encrypt this database is managed by AWS KMS and controlled by Pipedream. KMS keys are 256 bit in length and use the Advanced Encryption Standard (AES) in Galois/Counter Mode (GCM).
Document
Privacy Policy
Captured
2026-06-08
Location
Privacy Policy › “Third party OAuth grants, API keys, and environment variables”
Snapshot SHA-256
9fa6bed77625ce41ee746a598bdb9d8d3e7d33b7eef2c0b97f247abbbac11c07
Open captured source

Informational only, not legal advice. Terms change; verify the source and capture date.

Canonical permalink: https://airinetwork.com/platform/pipedream/finding/privacy-data-use-77d237292198d4615c01

📢 POLICY UPDATES ALERT

AIRIN Brief

Built for compliance officers, legal counsel, and SaaS founders. Subscribe to the email digest — one short brief when a tracked vendor materially changes its terms, training policy, or risk rating. Prefer in-app? Watch platforms in your alerts inbox instead.