Privacy Policy
What PitchLab collects when you practise a pitch, who else receives it, and how long it is kept.
Effective 7 October 2026 · version 2026-10-07.1
Who we are
PitchLab is operated by Center Leader Academy LLC ("we"), registered at [[REGISTERED ADDRESS]]. Questions about this policy, or a request about your own data, go to [[PRIVACY CONTACT EMAIL]].
PitchLab is sold to organizations — university entrepreneurship centers, accelerators and funds — whose members use it. Where your account belongs to such an organization, that organization administers it and this policy explains what that means in practice.
What we collect
Your account details: your name, email address, role and the organization you belong to. Authentication is handled by Supabase; we never store your password.
The pitches you submit: the audio or video you record or upload, the transcript produced from it, and everything the analysis produces — concept tags, findings, scores, verdicts and reports.
Your practice history: Q&A sessions including recorded answers, live coaching sessions and their transcripts, and Mirror sessions including each round of what you said and what the listener reflected back.
Operational records: your IP address and browser user agent on security-relevant actions, a log of emails we attempted to send you and what our provider said about them, and product analytics events describing how the application was used.
Who else receives your pitch
Analysing a pitch means sending it outside PitchLab. We think you should know exactly where it goes before you upload anything confidential.
Your recording is sent to Deepgram, which converts speech to text. In live coaching mode the audio is streamed to Deepgram as you speak.
The resulting transcript is sent to Revelry, which runs the evaluation agents that produce your findings, scores and report. This happens for every analysis, every Q&A evaluation, every live interruption and every Mirror round.
We also use Supabase to store your data, Vercel to host the application and collect its logs, Resend to send email, and Sentry to record errors. Our error reports are scrubbed before transmission to remove credentials and the content of evaluation prompts.
All of these providers are United States based. We do not sell your data, and we do not use your pitch content to train models of our own.
| Who | What they receive | Why |
|---|---|---|
| Deepgram | Your pitch audio, as a file or a live stream | Speech-to-text transcription |
| Revelry | Your transcript and the analysis inputs built from it | Running the evaluation agents |
| Supabase | Your account, pitches, recordings and all application data | Database, sign-in and file storage |
| Vercel | Requests to the application and its logs | Hosting |
| Resend | Your email address and the message we send you | Invitations and notifications |
| Sentry | Error reports, with credentials and prompt content removed | Diagnosing faults |
Who can see your pitch inside PitchLab
You can always see your own work.
An administrator of your organization can see the pitches, reports and practice history of members of that organization. This is deliberate — it is how a center tracks the ventures it supports — and it means your pitch is not private from the institution that gave you access.
Our own staff can access organization and user data to support you and to investigate faults. Consequential actions are recorded before they happen, with the reason the operator gave, and an action whose record cannot be written does not proceed.
Links you share
You can create a link that shares a report outside PitchLab. Anyone who has that link can read that report — there is no further check on who they are, so treat the link itself as the key. Links expire, and we remove expired links and their records afterwards.
Where an event sponsor is recorded for a competition, that sponsor’s name and logo appear on shared reports for it.
How long we keep it
A daily job removes data once these periods have passed. Note that pitch recordings are measured from the last time the recording was accessed, not from when you uploaded it — so a pitch you keep revisiting is kept.
Application logs are kept for 30 days in production and 7 days in staging.
| What | Kept for | Measured from |
|---|---|---|
| Pitch recordings | 365 days | last access |
| Q&A answer recordings | 180 days | the session |
| Replaced recordings | 30 days | being replaced |
| Deleted records | 90 days | deletion |
| Expired invitations | 90 days | expiry |
| Expired share links | 30 days | expiry |
| Analysis job records | 180 days | creation |
| Product analytics events | 730 days | creation |
Your choices, and what we can do today
You can edit your account details in the application, and you can control which notification emails you receive.
To get a copy of your data, or to ask us to delete it, email [[PRIVACY CONTACT EMAIL]]. We handle these requests manually at present — there is no self-service export or deletion in the product yet, and we would rather say so than imply a button exists.
When we delete your pitch content we also remove the recordings from storage. We keep records of what our staff did to an account, and of the emails we sent you, because those records exist to hold us accountable and deleting them on request would defeat that. We keep them no longer than we need them.
If your account belongs to an organization, deleting your work may affect records that organization relies on — for example a pitch entered into a competition it ran. We will tell you if that applies before acting.
Children and students
PitchLab is not intended for children. Where an organization uses PitchLab with enrolled students, that organization is responsible for any consents its own rules require, and should contact us before doing so if it has specific obligations about student records.
Security
Access to your data is enforced in the database itself, not only in the application: each row is scoped to you, to your organization, or to our platform operators, and a request outside that scope returns nothing rather than relying on a screen to hide it.
Credentials, access tokens and evaluation prompt content are removed from our logs and error reports before they are written.
Changes to this policy
This policy carries a version and an effective date, shown at the top. When we change it materially we will update both, and we will tell account holders rather than relying on you to notice.