Last updated August 25, 2026
The Privacy Policy explains your rights over personal data. This page is the more technical companion to it: what data categories exist in the system, which third parties touch them, and how long each is kept. It exists mainly for a fund's own security or compliance review.
When an application is submitted, the platform sends its content to an AI model to research the company against public sources and produce a score. Unless a fund has connected its own API key, this call is made through our own account with the AI provider, and is subject to that provider's own data handling terms as our subprocessor — not used by the provider to train their models on our plans with them.
A research run is bounded by a token budget per application, so cost and depth stay predictable; the resulting memo and score are stored against the application record for the fund to review.
We use a small number of subprocessors to run the platform. We will update this list as it changes, and a fund with a signed DPA is entitled to advance notice of a new subprocessor as described there.
Application data, research output, and uploaded files are stored on infrastructure we operate directly, not passed through additional third parties beyond those listed above. Backups are taken regularly and are subject to the same access controls as production data.
We keep application and research data for as long as a workspace is active, so a fund's history stays intact and research is not repeated needlessly. A fund can delete an individual application, or request deletion of an entire workspace, by writing to hello@pitchinfra.com; we remove the underlying records and files within a reasonable period, except where retention is required for tax, accounting, or legal reasons.
A fund may connect its own AI provider API key instead of using ours. When it does, application content sent for research is processed under that fund's own account and agreement with the provider, and we do not retain a copy of the provider's raw response beyond what is needed to render the memo in the console.
Every record in the system is scoped to a single workspace, and the application enforces that scoping on every query — a fund cannot see another fund's applications, team, or billing data through the product, whether through the console or the API.