Back to Pitchly

    Notice 2026-09-12

    Privacy and data handling

    This page describes Pitchly's current product behaviour: what it retains, how account export and deletion work, and when external services receive data. It is not a claim of legal or regulatory certification.

    Signed-in users can combine server and current-browser data in one export, or request confirmed account deletion, from Account and data controls. This isolated path remains available to an existing session when alpha product access is removed. Browser data on other devices or profiles must be handled separately.

    Site activity and support

    Pitchly counts browser sessions using a random key stored in the current tab. The activity system records fixed page labels, successful logins and confirmed payments so the team can understand usage and operate the service. Anonymous visits are kept separate from your account. This system does not store full URLs, search parameters, authentication links, IP addresses or document contents.

    When owner alerts are enabled, Resend delivers activity messages to Pitchly's configured owner inbox. Login and purchase alerts may include your account email; purchase alerts include the plan, amount and currency. Activity records expire after 90 days, and account-linked records are included in account export and removed with account deletion. Inbox copies follow the operator's email retention. You can contact Pitchly with feedback, problems or a request concerning those messages.

    Job Scout browser extension

    Job Scout brings the job listing you choose into Pitchly for job preparation and interview practice.

    What Job Scout reads

    On supported job sites, Job Scout reads page text and job metadata on your device to detect a listing and show its capture card. This can include the job URL, title, employer, location, salary and description. If a page has no structured job description, other page text may be included. The toolbar action can also read a careers page you choose to capture.

    When a job goes to Pitchly

    Choosing Send to Pitchly or Practice AI Interview sends the captured job to the Pitchly site connected in the extension popup. Simply viewing a job does not send its URL or description to Pitchly. Imported details are saved in that browser's Pitchly workspace; later account saving or AI features follow the data handling and processor notices below. The capture itself does not call an AI provider or submit an application.

    Your connected site

    Job Scout remembers the connected Pitchly site and browser tab on this device. Opening another supported Pitchly site in the focused window can change this connection. The popup shows the destination. Production and staging use HTTPS; local previews use localhost or 127.0.0.1 on the same computer. A job captured for one connected site is not redirected to a different site.

    Waiting jobs on this device

    Job Scout stores waiting job details, the destination site, browser tab, delivery identifier and capture time in the extension's local Chrome storage. Waiting jobs remain across browser restarts until the destination confirms that it saved them. The extension then removes its waiting copy. There is no automatic expiry for an undelivered job. These extension copies are separate from Pitchly's website storage and account records.

    Removing extension data

    Removing Job Scout from Chrome removes its local waiting jobs and connection settings. Disabling it stops its activity but keeps its stored data. Clearing Pitchly website data or deleting a Pitchly account does not clear extension storage. Removing the extension does not erase jobs already imported into Pitchly: use Account and data controls or the browser's site-data controls for those copies, and repeat on other browser profiles or devices.

    Retention, export, and deletion

    account profile

    Data
    Profile, preferences, onboarding and account settings
    Retention
    For the account lifetime
    Deletion
    Deleted with the account, except a non-identifying 30-day deletion receipt
    Export
    Included

    resumes and documents

    Data
    Resume text, generated resumes/cover letters and document metadata
    Retention
    Until account deletion, unless a supported individual record is deleted or a browser-local copy is cleared earlier
    Deletion
    Owned database rows and private objects are deleted with the account; browser-local copies follow the browser-local-data category
    Export
    Server data is included; the protected account export also includes current-browser copies

    applications and career memory

    Data
    Jobs, applications, timelines, outcomes, ATS estimates and career memory
    Retention
    Until the user deletes the account
    Deletion
    All owned rows, including application children, are deleted
    Export
    Included with score provenance

    interviews and feedback

    Data
    Questions, transcripts, journal entries, feedback and coaching telemetry
    Retention
    Until the user deletes the account
    Deletion
    Owned interview and feedback rows are deleted
    Export
    Included

    audio video and screenshots

    Data
    Interview audio, job screenshots, synthesized audio and avatar video
    Retention
    Request memory only; Pitchly does not persist these request payloads
    Deletion
    Released when request processing finishes; provider-side handling is governed by the configured provider account and terms
    Export
    Not present unless a future persisted private object appears in the export manifest

    headshots

    Data
    User-uploaded avatar headshots and profile metadata
    Retention
    Until the user deletes the headshot or account
    Deletion
    Deleted from private object storage before account database deletion
    Export
    Included as base64 private-object content

    credentials and sessions

    Data
    Magic-link records, sessions and connected-provider credentials
    Retention
    For authentication/connection lifetime; expired credentials are unusable
    Deletion
    Local records are deleted and the completed-deletion receipt blocks old bearer/session tokens
    Export
    Credential secrets and token material are excluded; connection metadata is included

    gmail synchronized content

    Data
    Gmail message/thread metadata, selected content and generated drafts copied into Pitchly
    Retention
    Until the user deletes the Pitchly account; disconnect only revokes and removes Gmail credentials
    Deletion
    Deleted with the Pitchly account; disconnect does not delete already synchronized threads or drafts
    Export
    Included; OAuth access/refresh tokens and token ciphertext are excluded

    browser local data

    Data
    Current-browser resumes, cover letters, job/interview context, companion history, page activity, agent memory, onboarding/name and workspace handoff
    Retention
    Until cleared in that browser profile or the browser's site data is removed
    Deletion
    The signed-in flow clears known current-user keys after server deletion succeeds; pre-auth crash recovery cannot guess an account ID, and every other device/profile must be cleared separately through site-data controls
    Export
    The protected account export combines current-browser values with the server export; the server-only endpoint cannot read browser storage

    approximate location and weather

    Data
    Browser-provided coordinates minimized before current-weather lookup, or a timezone-derived place/timezone fallback
    Retention
    Short-lived bounded process cache only; expired entries are swept and the cache is not account data
    Deletion
    Expires automatically and is removed by bounded cache eviction; never persisted to the account database
    Export
    Not retained in the account export

    billing

    Data
    Plan/subscription state and processor identifiers
    Retention
    For the account lifetime locally; Stripe may retain records for legal obligations
    Deletion
    Account deletion is blocked until the subscription is terminal/inactive; local state is then deleted
    Export
    Local subscription state is included

    operational logs

    Data
    Redacted request, security and reliability telemetry
    Retention
    Configured in the production monitoring provider; target maximum 30 days for application logs
    Deletion
    Not stored in the account database; operator-assisted requests are required where a trace can be identified
    Export
    Not included in synchronous account export

    site activity and owner notifications

    Data
    Anonymous browser-session counts and fixed page labels; successful account logins and confirmed paid invoices; owner email delivery status
    Retention
    Activity records are retained for up to 90 days and removed by a recurring cleanup; the anonymous browser-session key lasts until the tab closes
    Deletion
    Account-linked activity is deleted with the account. Anonymous visits are not linked to an account. Copies of alerts or support messages in the operator's inbox require operator-assisted handling
    Export
    Account-linked activity is included; anonymous visits cannot be attributed to the exporting account

    External services and recipients

    Provider-side handling is governed by the exact production account, configuration, contract, and destination terms. Pitchly operators must verify those settings before release.

    OpenAI

    Purpose: resume, cover-letter and job analysis or drafting; plain-language offer review; interview coaching and transcription; job screenshot text extraction; Gmail message analysis and draft assistance; assistant/scout responses; grounded browser-operator application answers

    Data: resume, cover-letter, job and scorecard text; offer or contract text for an optional plain-language explanation; interview transcript or audio when transcription is needed; uploaded job screenshot; selected Gmail message content and draft context; assistant page/scout/session/conversation context and the user's prompt; application-page questions plus profile name, email, phone and city when the user enables AI answer suggestions

    When sent: The user invokes the corresponding AI feature after the applicable disclosure or current-version consent control

    Pitchly handling: Request payload is not retained as a separate processor copy by Pitchly

    ElevenLabs

    Purpose: optional premium live interview transcription, turn-taking and speech synthesis; optional premium text-to-speech

    Data: the text to be spoken and selected voice identifier; candidate live microphone audio, live transcript and conversation messages; selected interviewer persona and bounded role, company, job and resume context used by the premium interview brain

    When sent: The user selects ELEVENLABS_PREMIUM, accepts the current versioned disclosure and starts a private, provider-bounded WebRTC interview; FREE_LOCAL never sends audio or speech requests to ElevenLabs

    Pitchly handling: Live provider audio is streamed and returned rather than persisted by Pitchly; bounded transcripts and interview evidence follow the interviews-and-feedback retention category

    Replicate

    Purpose: optional cloud whole-face avatar rendering

    Data: selected/uploaded headshot; speech audio; render settings

    When sent: The user selects a cloud-rendered avatar mode and explicitly consents

    Pitchly handling: Returned video is not persisted by Pitchly

    Google

    Purpose: optional Gmail connection and message access selected by the user

    Data: OAuth account identity; granted scopes; Gmail messages/threads needed for the chosen inbox mode

    When sent: The user explicitly connects Gmail and grants Google consent

    Pitchly handling: Connection secrets are encrypted and removed on disconnect; synchronized threads/drafts remain until Pitchly account deletion

    Open-Meteo

    Purpose: optional current-weather context on the application dashboard

    Data: timezone-derived place label and timezone for the default city-level lookup; minimized approximate latitude and longitude only when the user enables more precise local weather

    When sent: The application dashboard loads for the city-level lookup; browser coordinates are requested and sent only after the user explicitly enables the more precise option

    Pitchly handling: Coordinates are held only in a short-lived bounded process cache and are not stored in the account database

    Supabase

    Purpose: database and private object storage; optional external identity administration

    Data: account and product records; private objects such as headshots; account identifier and privacy-minimal receipt metadata

    When sent: Production persistence is configured

    Pitchly handling: Controlled by Pitchly retention and deletion workflows

    Microsoft Azure Monitor

    Purpose: production reliability, security and request diagnostics

    Data: request ID, route, method, status, duration and user agent; authenticated Pitchly account identifier on selected request traces; redacted error class and performance/trace telemetry

    When sent: Production monitoring is enabled; request bodies and credentials must not be logged

    Pitchly handling: Configured by operators with a target maximum of 30 days for application logs

    Stripe

    Purpose: subscription billing

    Data: billing identity and subscription/payment records

    When sent: The user starts or manages a paid subscription

    Pitchly handling: Pitchly keeps local subscription state until account deletion, which requires terminal/inactive billing; Stripe legal retention may continue

    Resend

    Purpose: magic-link and account email delivery; site-owner alerts for visits, successful logins and confirmed paid invoices

    Data: email address; message delivery content; short-lived single-use magic-link URL and signed return state; event time, fixed page label, account email for login/purchase alerts, and plan, amount and currency for paid invoices

    When sent: The user requests an authentication or account email, or owner alerts are enabled and a recorded activity event occurs

    Pitchly handling: Pitchly does not copy provider delivery logs into account data; provider-side handling follows the configured Resend account and terms

    Jina AI

    Purpose: retrieving public company, news and search pages for user-requested research

    Data: company name embedded in requested public-source URLs; requested source URL and Pitchly service user agent

    When sent: The user requests company research in the workspace

    Pitchly handling: Returned snippets may become account workspace content; provider-side request handling follows the configured service terms

    Job boards, employer sites and public web sources

    Purpose: user-requested job search and scraping; company research; supervised application navigation

    Data: search terms, approximate search location and requested URLs; approved employer-site form data and ordinary network/request metadata

    When sent: The user searches, imports, researches or approves a supervised browser action

    Pitchly handling: Returned job/application data may be stored with the account; each destination controls its own server logs and submitted data