Legal
Privacy Policy
PitchMachine helps freelancers and small agencies find prospects, audit their public online presence, and draft outreach emails. This page sets out exactly what we store, who we share it with, and how you remove it.
Last updated 9 August 2026
1. Who this policy covers
This policy applies to everyone who creates a PitchMachine account and uses the web application. It covers both your own account data and the prospect information the app collects on your behalf.
2. Information we collect
Account information. When you sign up with Google or with an email address and password, we receive and store your user ID, email address, and — if your provider supplies them — your display name and profile photo URL. Passwords are handled entirely by Firebase Authentication; we never see or store them.
Profile you enter. Your name, headline, industry background, years of experience, specialisms, services, phone number, and the website, LinkedIn, portfolio, and booking links you choose to add. This is used to sign and position your outreach emails.
Your provider API keys. The AI and search keys you supply are encrypted with AES-256-GCM before being written to the database and are decrypted only on our server, only at the moment a request needs them. They are never sent to your browser. Where a key is displayed back to you, only the last four characters are shown.
Prospect data. For each lead you discover we store the business name, website, location, business type, publicly listed contact details, the audit findings, the generated pitch, and any report you produce. We fetch prospect websites to run the audit but we do not retain the raw page source — the audit result is extracted and the rest is discarded.
Operational logs. Server-side logs record events needed to run and debug the service. They never contain API keys, tokens, or full request bodies.
We do not use advertising trackers, and we do not run third-party analytics that profile you across other websites.
3. Google user data and Limited Use
Connecting Gmail is optional. PitchMachine works without it; you simply copy the drafted email out of the app instead.
If you do connect Gmail, we request a single scope: https://www.googleapis.com/auth/gmail.compose.
- What we do with it: create a draft in your Gmail account containing the email PitchMachine generated for a prospect you chose.
- What we never do: send email on your behalf, read your inbox, read existing messages or threads, access your contacts, or delete anything. The scope does not permit it and the app does not attempt it.
- What we store: an OAuth refresh token, encrypted at rest, plus the Gmail address the connection belongs to. The draft content itself is the pitch you already have in the app.
You can disconnect Gmail at any time from Settings inside the app, which deletes the stored refresh token. You can also revoke access directly at myaccount.google.com/permissions.
4. Who we share data with
PitchMachine does not sell your data and does not share it for advertising. Data reaches third parties only where the feature you are using requires it:
- Your chosen AI provider (OpenAI, Google Gemini, or OpenRouter) receives the prospect information needed to generate an audit summary or a pitch, sent with your own API key under your own account with that provider.
- Your chosen search provider (Apify, Searlo, or Scrape.do) receives the search terms needed to discover prospects, again using your own key.
- Google provides authentication and, if you connect it, the Gmail Drafts API.
- Google Firebase hosts the authentication service and the Firestore database where your data is stored.
- Prospect websites receive an ordinary server-side HTTP request from us when we audit them.
Because you bring your own provider keys, your use of those providers is also governed by their own terms and privacy policies.
We may disclose information where we are legally required to, or where it is necessary to investigate abuse or protect the security of the service.
5. How your data is protected
- All traffic is served over HTTPS.
- Your session is held in an httpOnly, Secure, SameSite=Lax cookie that your browser scripts cannot read. It expires after five days.
- Provider API keys and the Gmail refresh token are encrypted with AES-256-GCM before storage, using a key held only on the server.
- Database rules deny access by default and permit a record to be read or written only by the account that owns it. The same check is enforced again in server code.
- Secrets are never included in the code sent to your browser.
No system is perfectly secure, but we design on the assumption that any single layer can fail.
6. How long we keep it
Leads, audits, pitches, and reports are kept until you delete them or close your account. Raw prospect website source is never retained. Operational logs are short-lived and contain no secrets.
7. Your choices and how to delete your data
- Delete individual leads, audits, pitches, and reports from inside the app at any time.
- Remove a stored API key from Settings; it is erased from the database.
- Disconnect Gmail from Settings, which deletes the stored refresh token.
- Request full deletion of your account and everything associated with it using the contact route below. We action these within 30 days.
Depending on where you live you may also have rights to access, correct, export, or object to the processing of your personal data. Contact us and we will help.
8. Children
PitchMachine is a business tool and is not directed at children under 16. We do not knowingly collect their data.
9. Changes to this policy
If we change how data is handled we will update this page and move the date at the top. If the change is material we will tell account holders directly.
10. Contact
Questions, data requests, or security reports can be raised from the Settings page once you are signed in.
See also our Terms of Service.