Privacy Policy

Last updated: April 10, 2026

1. Information We Collect

Account information: email address, display name, and hashed password (we never store plaintext passwords). Usage data: evaluation history, scores, and timestamps. Payment information: processed by Stripe; we store only your Stripe customer ID, not card details.

2. Submitted Content

When you submit a pitch deck, text description, or questionnaire responses for evaluation, this content is processed to generate your evaluation. Submitted content is sent to the Anthropic Claude API for analysis. Anthropic does not use API submissions for model training. When Confidential Mode is enabled, we strip company names, founder names, specific financial figures, and other identifying details before sending content to the API.

3. How We Use Your Data

To provide evaluations and display your portfolio. To authenticate your account and manage billing. To improve the evaluation methodology through aggregate analysis (never individual pitch content). To send transactional emails (verification, password reset, receipts).

4. Data Storage

Data is stored on Railway's infrastructure (PostgreSQL database). Evaluation results are stored associated with your account. We do not sell, rent, or share your personal information or submitted content with third parties except as required to provide the Service (Anthropic API for evaluation, Stripe for payments, Resend for email).

5. Data Retention

Account data is retained while your account is active. Evaluation results are retained in your portfolio indefinitely unless you request deletion. You may request deletion of your account and all associated data by contacting us.

6. Security

Passwords are hashed with PBKDF2-SHA256 (600,000 iterations). All connections use TLS/HTTPS encryption. Authentication uses JWT tokens with 72-hour expiry. Rate limiting and account lockout protect against brute-force attacks.

7. Third-Party Services

Anthropic (Claude API): processes submitted content for evaluation. Stripe: processes payments. Resend: sends transactional emails. Railway: hosts the application and database. Each service is subject to its own privacy policy.

8. Your Rights

You may access, correct, or delete your personal data at any time. You may export your evaluation results. You may delete your account by contacting us. We will respond to data requests within 30 days.

9. Cookies

We use localStorage (not cookies) to store your authentication token. We do not use tracking cookies or third-party analytics.

10. Contact

Privacy questions: joel@teamweaver.ai