Provider-side handling is governed by the exact production account, configuration, contract, and destination terms. Pitchly operators must verify those settings before release.
OpenAI
Purpose: resume, cover-letter and job analysis or drafting; plain-language offer review; interview coaching and transcription; job screenshot text extraction; Gmail message analysis and draft assistance; assistant/scout responses; grounded browser-operator application answers
Data: resume, cover-letter, job and scorecard text; offer or contract text for an optional plain-language explanation; interview transcript or audio when transcription is needed; uploaded job screenshot; selected Gmail message content and draft context; assistant page/scout/session/conversation context and the user's prompt; application-page questions plus profile name, email, phone and city when the user enables AI answer suggestions
When sent: The user invokes the corresponding AI feature after the applicable disclosure or current-version consent control
Pitchly handling: Request payload is not retained as a separate processor copy by Pitchly
ElevenLabs
Purpose: optional premium live interview transcription, turn-taking and speech synthesis; optional premium text-to-speech
Data: the text to be spoken and selected voice identifier; candidate live microphone audio, live transcript and conversation messages; selected interviewer persona and bounded role, company, job and resume context used by the premium interview brain
When sent: The user selects ELEVENLABS_PREMIUM, accepts the current versioned disclosure and starts a private, provider-bounded WebRTC interview; FREE_LOCAL never sends audio or speech requests to ElevenLabs
Pitchly handling: Live provider audio is streamed and returned rather than persisted by Pitchly; bounded transcripts and interview evidence follow the interviews-and-feedback retention category
Replicate
Purpose: optional cloud whole-face avatar rendering
Data: selected/uploaded headshot; speech audio; render settings
When sent: The user selects a cloud-rendered avatar mode and explicitly consents
Pitchly handling: Returned video is not persisted by Pitchly
Google
Purpose: optional Gmail connection and message access selected by the user
Data: OAuth account identity; granted scopes; Gmail messages/threads needed for the chosen inbox mode
When sent: The user explicitly connects Gmail and grants Google consent
Pitchly handling: Connection secrets are encrypted and removed on disconnect; synchronized threads/drafts remain until Pitchly account deletion
Open-Meteo
Purpose: optional current-weather context on the application dashboard
Data: timezone-derived place label and timezone for the default city-level lookup; minimized approximate latitude and longitude only when the user enables more precise local weather
When sent: The application dashboard loads for the city-level lookup; browser coordinates are requested and sent only after the user explicitly enables the more precise option
Pitchly handling: Coordinates are held only in a short-lived bounded process cache and are not stored in the account database
Supabase
Purpose: database and private object storage; optional external identity administration
Data: account and product records; private objects such as headshots; account identifier and privacy-minimal receipt metadata
When sent: Production persistence is configured
Pitchly handling: Controlled by Pitchly retention and deletion workflows
Microsoft Azure Monitor
Purpose: production reliability, security and request diagnostics
Data: request ID, route, method, status, duration and user agent; authenticated Pitchly account identifier on selected request traces; redacted error class and performance/trace telemetry
When sent: Production monitoring is enabled; request bodies and credentials must not be logged
Pitchly handling: Configured by operators with a target maximum of 30 days for application logs
Stripe
Purpose: subscription billing
Data: billing identity and subscription/payment records
When sent: The user starts or manages a paid subscription
Pitchly handling: Pitchly keeps local subscription state until account deletion, which requires terminal/inactive billing; Stripe legal retention may continue
Resend
Purpose: magic-link and account email delivery; site-owner alerts for visits, successful logins and confirmed paid invoices
Data: email address; message delivery content; short-lived single-use magic-link URL and signed return state; event time, fixed page label, account email for login/purchase alerts, and plan, amount and currency for paid invoices
When sent: The user requests an authentication or account email, or owner alerts are enabled and a recorded activity event occurs
Pitchly handling: Pitchly does not copy provider delivery logs into account data; provider-side handling follows the configured Resend account and terms
Jina AI
Purpose: retrieving public company, news and search pages for user-requested research
Data: company name embedded in requested public-source URLs; requested source URL and Pitchly service user agent
When sent: The user requests company research in the workspace
Pitchly handling: Returned snippets may become account workspace content; provider-side request handling follows the configured service terms
Job boards, employer sites and public web sources
Purpose: user-requested job search and scraping; company research; supervised application navigation
Data: search terms, approximate search location and requested URLs; approved employer-site form data and ordinary network/request metadata
When sent: The user searches, imports, researches or approves a supervised browser action
Pitchly handling: Returned job/application data may be stored with the account; each destination controls its own server logs and submitted data