Skip to content
Pitchbox Italiano

Privacy policy

Last updated: 9 September 2026

Operator
Lorenzo Fiore
VAT number
IT12453190964
Email
support@pitchbox.app

Who this is about

This policy covers the hosted app at app.pitchbox.app and this website. If you run Pitchbox yourself, under the AGPL licence, none of it applies to you: your installation stores its data on your own infrastructure and you are its controller, not us.

For anything in this policy, including a request to see or delete your data, write to privacy@pitchbox.app. For everything else there is support@pitchbox.app.

What the app stores

Only what the product needs to do its job. There is no profiling, no advertising, and nothing is sold or shared for anyone else's marketing.

  • Your account: username, email address, a hashed password (never the password itself), and whether the address has been verified.
  • Your organization: its name, the spending cap and the concurrency limit that apply to your runs.
  • The platform accounts you connect: the handle and display name, plus the credential needed to act as that account. A Mastodon token is encrypted at rest with AES-256-GCM; a Reddit browser session is stored the same way.
  • Drafts and their history: the text the agent wrote, the source post it responded to, your edits, and whether you approved, rejected or sent it.
  • Contact history: which handle was contacted from which account and when, which is what stops the same person being contacted twice by mistake.
  • Posts the in-page companion observed on LinkedIn, when you enable it: the post URL and identifier, the author's handle and name, and the post text. Only from pages you opened yourself.
  • Run records: what the agent did, how long it took, and what it cost.
  • Security records: your sessions, and failed sign-in attempts stored against a username or an IP bucket so that brute force can be rate-limited.

What it does not do

This website sets no cookies, loads no third-party scripts and runs no analytics. Fonts are served from this domain, not from a font network.

The app has no analytics service, no session recording and no error-reporting service: there is no third-party SDK in it. Server logs stay on the server that produced them.

Nothing is ever sent on your behalf. Every message waits for you to approve it and, on Reddit and Hacker News, for you to send it yourself.

Who else processes it

The hosted app relies on these providers, and on no others:

  • Netcup (Germany): the server and the database that run the app.
  • Stripe, including Link: payments. Stripe is the merchant of record for a subscription, issues the invoice and receipt, and calculates and remits the tax. Card details are entered on Stripe's own page and never reach us.
  • Vercel AI Gateway, and through it the model provider that answers a given run: the prompt for a draft, which includes the source post and the campaign brief, is sent there to be generated.
  • Resend: transactional email such as a password reset or an address verification.
  • Cloudflare: DNS for the domain, and the routing behind the support address.

The platforms you connect

When you connect Reddit, Hacker News or Mastodon, the app reads the public content you have pointed it at, using that platform's own API or public pages, and writes only what you approve.

LinkedIn is different by design. There is no server-side access to LinkedIn at all. The browser companion reads the page you already have open, sends what it read to your own Pitchbox account, and never fetches from LinkedIn, never clicks or submits anything for you, and never reads LinkedIn cookies.

How long it is kept

Old rows are pruned automatically, every hour:

  • Observed LinkedIn posts: 3 days.
  • Run events: 30 days. Webhook deliveries: 30 days.
  • Draft events, and drafts that have been sent, rejected or replied to: 90 days.
  • Contact history is kept for as long as the project exists, because it is what the deduplication and the blocklist are built on. Deleting a project deletes it.
  • Your account, organization, projects, campaigns and connected accounts are kept until you delete them or ask us to.

Your rights

You can ask for a copy of your data, its correction, its export, or its deletion, and you can object to a particular processing. Write to privacy@pitchbox.app and you will get an answer within 30 days.

Deleting your account deletes your organizations, projects, drafts and connected accounts. Where a copy has already left our systems, for example an invoice held by Stripe because tax law requires it, that copy follows their own retention rules and we will tell you so.

The app's data lives in Germany. Stripe and the model providers may process data outside the European Union under their own transfer safeguards.

Changes

If this policy changes in substance, the date above changes and account holders are told by email before it takes effect.