PitchloomClosed beta · legal
PrivacyTerms

Legal · privacy

Privacy policy.

last updated · 2026-07-06 · closed beta terms apply

on this page

01Who we are02What we collect03How we use it04Who we share it with (subprocessors)05Data retention06Data hosting07Your rights08Security09Children10Early access and changes to this policy11Governing law12Contact
Placeholder pending counsel review. This is an early-access draft written to describe our current data practices honestly. It has not been reviewed by a lawyer and will be replaced by a counsel-reviewed version before general availability.

01 · Who we are

Pitchloom is operated by Mana Investments Pte Ltd. The contact for privacy questions and data requests is jamie@mana.partners.

02 · What we collect

We process the following categories of data:

  • Account data: your name and email address, used to authenticate you and identify your workspace membership.
  • Tenant workspace content: the briefs, proposals, brand assets, and other material you and your team upload or generate inside your workspace. This content belongs to you (see our Terms of Service) and is stored to provide the service.
  • Shared proposal link analytics: when a proposal is sent via a shareable link, we record view timestamps, scroll depth, which sections were viewed, and whether the call-to-action was clicked, so the sender can see engagement on their own proposals. We record browser user-agent for forensic context. We do not record IP addresses.

03 · How we use it

We use the data above to:

  • Operate your account and workspace, including authentication
  • Generate proposals, renders, and analytics you request
  • Send transactional email (magic links, invites, share notifications)
  • Diagnose and fix technical issues
  • Improve the product based on aggregate, de-identified usage patterns

We do not sell your data. We do not use your tenant workspace content to train third-party AI models beyond what is required to generate the output you requested in that session.

04 · Who we share it with (subprocessors)

We use the following subprocessors to run Pitchloom. Each processes a subset of the data above strictly to provide their part of the service:

  • Supabase: database, auth, and file storage for all workspace content
  • Vercel: hosting for the web application
  • Anthropic: AI generation for proposal narrative, fit diagnostics, and other AI-assisted outputs
  • Fly.io: rendering services (compositing and document export)
  • Resend: transactional email delivery (magic links, invites, proposal-share notifications)
  • Inngest: background job orchestration
  • Firecrawl: web crawling, used only when you run the Brand Intelligence feature against a brand's public web presence

We may add or change subprocessors as the product evolves and will update this list when we do.

05 · Data retention

We retain account and workspace data for as long as your account is active. If you close your workspace, we will delete or anonymise your data within a reasonable period, except where retention is required for legal, security, or legitimate business reasons (for example, financial records once billing launches).

Proposal share analytics are retained for the life of the share record, including expired shares, so senders retain a historical view of engagement. Expired shares are not deleted automatically; they become unopenable to the recipient.

06 · Data hosting

Workspace data is hosted on Supabase infrastructure in Singapore (ap-southeast-1) during early access. If you need a different region for compliance reasons, contact us before signing up.

07 · Your rights

You can access, correct, export, or request deletion of your account data and workspace content at any time by contacting jamie@mana.partners. Depending on your jurisdiction you may have additional rights over your personal data; this section will be expanded with a full statutory rights list (e.g. GDPR, CCPA) as part of the counsel-reviewed version.

08 · Security

Access to tenant data is enforced through row-level security policies scoped to your workspace. Data in transit is encrypted via TLS. We do not query production data using client-side credentials; server-side access uses service-role credentials confined to server actions and route handlers.

09 · Children

Pitchloom is a B2B product not directed at children and is not intended for use by anyone under 18.

10 · Early access and changes to this policy

Pitchloom is in early access and this policy will be replaced by a counsel-reviewed version before general availability. We will notify account admins by email of material changes. Continued use after an update takes effect means you accept the revised policy.

11 · Governing law

This policy is governed by the laws of Singapore. Any dispute arising from it is subject to the exclusive jurisdiction of the courts of Singapore.

12 · Contact

Questions about this policy or requests regarding your data: jamie@mana.partners.

PitchloomPrivacyTermsBuilt by Mana