Security overview
How we protect your data
Last updated: 20 July 2026
Pitch Aide is an early-stage product built with security as a first-order concern. This page summarises how customer data is stored, protected, and processed. For questions or a security review, contact privacy@pitchaide.dev.
Data hosting & residency
All customer data is stored in the European Union (Ireland) on managed cloud infrastructure running on Amazon Web Services (AWS), provided through Supabase.
Encryption
Data is encrypted in transit using HTTPS/TLS, and encrypted at rest by the underlying managed database and object storage.
Access control & tenant isolation
Every account's data is isolated at the database level using row-level security policies. A sender can only access their own proposals, clients, knowledge bases, and engagement data — no customer can read another customer's data. Uploaded files (slides, documents, videos) are held in private storage and served only through short-lived signed URLs.
Authentication
Sender accounts are authenticated through Supabase Auth. Proposal viewers do not create accounts; they enter a name and are shown a clear notice of what is recorded before any data is captured.
AI processing
The in-proposal assistant, suggested-prompt generation, and session summaries are produced by a third-party large language model (Google Gemini), accessed via the Lovable AI Gateway. Relevant proposal content and questions are sent to this provider at the time a response is generated and processed under the provider's terms. This content is not used by Pitch Aide to train its own models. Storage remains in the EU; AI inference is processed by the provider.
Data collection, retention & deletion
For proposal viewers we record only what is disclosed and consented to on the viewer screen: the name entered, which slides are viewed, time per slide, links clicked, questions asked, and comments left. Senders control how long this engagement data is retained per proposal (default 90 days), after which it is automatically deleted, and can delete a proposal's data on demand. Deleting a proposal removes its associated data.
Abuse & availability protection
Public endpoints are rate-limited to protect against abuse and runaway cost, and request sizes are bounded. The application sets no cross-origin (CORS) access to its APIs, which are same-origin only.
Sub-processors & certifications
We rely on a small set of sub-processors: Supabase, running on AWS (hosting, database, storage, authentication); Google (AI inference via the Lovable AI Gateway); and an email delivery provider. Our infrastructure providers maintain their own independent security certifications (for example, Supabase and AWS are SOC 2 Type II compliant). Pitch Aide does not yet hold its own SOC 2 attestation; this is on our roadmap as we scale, and an enterprise deployment path (via Microsoft Copilot Studio within a client's own tenant) is available for organisations with stricter in-tenant requirements.
Compliance & your rights
Our data practices are aligned with the UK GDPR. Individuals can exercise their rights of access, rectification, erasure, and others as described in our Privacy Policy.
Reporting a vulnerability
If you believe you have found a security issue, please email privacy@pitchaide.dev with details. We appreciate responsible disclosure and will respond promptly.