Legal
Privacy Policy
Last updated: May 16, 2026
Overview
PitchKitchen ("we", "us") is an AI workspace for founders that helps you generate startup blueprints, talk to AI advisors, and run market research. This Privacy Policy explains what data we collect, how we use it, and how you can control it.
Data we collect
- Account data: your email address, display name, and password (stored hashed by our authentication provider).
- Content you create: ideas, questionnaire answers, blueprints, advisor chat messages, and saved research briefs.
- Subscription data: your plan tier, status, and billing period dates. We do not store full card numbers.
- Usage counters: anonymized counts of blueprints generated and advisor messages sent, used to enforce plan limits.
Authentication and account data
Authentication is handled via secure session tokens. Passwords are never stored in plain text. You can sign in with email and password or with Google OAuth. You may update your display name or sign out at any time from your account settings.
Payment processing (Stripe)
All payments are processed by Stripe. PitchKitchen never sees or stores your full card number, CVC, or bank credentials. We receive only the subscription metadata required to grant access — customer ID, subscription ID, plan, and billing period.
AI provider usage (OpenAI and Perplexity)
When you generate a blueprint, chat with an advisor, or run research, the relevant prompt (your input plus a system prompt) is sent to a third-party AI provider — currently OpenAI and Perplexity — to produce a response.
- We do not train any models on your data.
- Providers may temporarily process and log requests under their own privacy policies (OpenAI, Perplexity).
- Avoid pasting sensitive personal, financial, or medical information into prompts.
Cookies and sessions
We use first-party cookies and browser local storage strictly to keep you signed in and remember UI preferences (e.g. sidebar state, draft idea). We do not use third-party advertising cookies.
Analytics
We may collect privacy-respecting, aggregated usage analytics (page views, feature usage, error rates) to improve the product. No analytics provider receives your blueprint or chat content.
API keys are server-side only
AI provider API keys (OpenAI, Perplexity) and payment keys (Stripe) are stored exclusively as encrypted server-side secrets. They are never exposed to the browser, never embedded in client bundles, and never returned by any API response.
Data retention and deletion
Your blueprints and chat history remain available while your account is active. To request account deletion or data export, email us at the address below.
Contact
For privacy questions, data requests, or to report a concern, email atm250F@gmail.com.