Privacy Policy
Last updated: January 8, 2025
At Pitchora ("we", "us", or "our"), we take your privacy seriously. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our personalized video generation platform at pitchora.ai (the "Service").
1. Information We Collect
1.1 Account Information
When you create an account, we collect:
- Email address
- Full name (optional)
- Profile picture (optional)
- Authentication data from third-party providers (Google) if you choose to sign in with them
1.2 Payment Information
When you subscribe to our Service, payment processing is handled by Stripe. We do not store your full credit card details. We receive and store:
- Billing name and address
- Last four digits of your payment card
- Card expiration date
- Transaction history
1.3 Video Content
When you use our video generation features, we collect and store:
- Webcam recordings (facecam videos) you create
- Rendered personalized videos
- Video thumbnails and GIF previews
- Campaign configurations (scene URLs, durations, landing page settings)
1.4 Lead and Prospect Data
When you upload CSV files or enter prospect information for video personalization, we process:
- Names and email addresses
- Company names and websites
- Job titles and phone numbers
- LinkedIn profile URLs
- Any custom fields you include in your uploads
Important: You are responsible for ensuring you have the right to use any prospect data you upload and that your use complies with applicable laws, including data protection regulations.
1.5 Usage Data
We automatically collect certain information when you use the Service:
- IP address and device information
- Browser type and version
- Pages visited and features used
- Video view analytics (who watched your videos, for how long)
- Click-through rates on landing pages
1.6 Integration Data
If you connect third-party services (CRM, email platforms), we store:
- OAuth access and refresh tokens (encrypted)
- Connection metadata and preferences
- Contact mappings for synchronization
2. How We Use Your Information
We use your information to:
- Provide, maintain, and improve the Service
- Process your videos and generate personalized content
- Process payments and manage subscriptions
- Send transactional emails (account verification, password resets, billing notifications)
- Provide customer support
- Analyze usage patterns to improve our product
- Detect and prevent fraud or abuse
- Comply with legal obligations
3. How We Share Your Information
We may share your information with:
3.1 Service Providers
- Supabase: Database hosting and authentication
- Stripe: Payment processing
- Resend: Transactional email delivery
- Cloud storage providers: Video and file storage
3.2 Third-Party Integrations
When you connect integrations (HubSpot, Salesforce, Outreach, Salesloft, etc.), data is shared according to your configuration. You control what data is synchronized.
3.3 Video Recipients
When you share personalized videos, recipients can view the video content and landing pages you create. Video view analytics are collected and shared back to you.
3.4 Legal Requirements
We may disclose information if required by law, court order, or government request, or if we believe disclosure is necessary to protect our rights, your safety, or the safety of others.
4. Data Security
We implement industry-standard security measures:
- Encryption in transit (TLS/HTTPS) and at rest
- Row-level security (RLS) for database access control
- Encrypted storage for OAuth credentials (AES-256)
- Regular security audits and monitoring
- Secure authentication with magic links and OAuth
While we strive to protect your data, no method of transmission or storage is 100% secure. We cannot guarantee absolute security.
5. Data Retention
We retain your data as follows:
- Account data: Until you delete your account
- Video content: Until you delete it or your account is terminated
- Lead data: Until you delete the associated campaign
- Payment records: As required for tax and legal compliance (typically 7 years)
- Usage logs: 90 days for operational purposes
6. Your Rights
Depending on your location, you may have the following rights:
- Access: Request a copy of your personal data
- Correction: Update inaccurate or incomplete data
- Deletion: Request deletion of your data ("right to be forgotten")
- Portability: Receive your data in a structured, machine-readable format
- Objection: Object to certain processing activities
- Restriction: Request limited processing of your data
To exercise these rights, contact us at privacy@pitchora.ai.
7. GDPR Compliance (European Users)
If you are in the European Economic Area (EEA), we process your data under the following legal bases:
- Contract: To provide the Service you requested
- Consent: Where you have given explicit consent
- Legitimate interests: For fraud prevention, security, and service improvement
- Legal obligation: To comply with applicable laws
8. CCPA Compliance (California Users)
California residents have additional rights under the California Consumer Privacy Act (CCPA):
- Right to know what personal information is collected
- Right to delete personal information
- Right to opt-out of the sale of personal information (we do not sell your data)
- Right to non-discrimination for exercising your rights
9. Cookies and Tracking
We use cookies and similar technologies for:
- Essential cookies: Authentication and session management
- Analytics: Understanding how you use the Service
- Preferences: Remembering your settings
You can control cookies through your browser settings, but disabling essential cookies may affect functionality.
10. Children's Privacy
The Service is not intended for users under 18 years of age. We do not knowingly collect personal information from children. If you believe we have collected data from a child, please contact us immediately.
11. International Data Transfers
Your data may be transferred to and processed in countries other than your own. We ensure appropriate safeguards are in place, including standard contractual clauses where required.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email or by posting a notice on the Service. Your continued use of the Service after changes constitutes acceptance of the updated policy.
13. Contact Us
If you have questions about this Privacy Policy or our data practices, contact us at: