Privacy Policy
Last updated: May 20, 2026
Introduction
Pitchko ("we", "us", "Pitchko") operates pitchko.io and the Pitchko platform. This Privacy Policy explains what personal data we process, why, and on which legal basis. If you reside in Turkey, our [KVKK Notice](/legal/kvkk-notice) also applies. If you reside in the EU, our [GDPR Notice](/legal/gdpr-notice) also applies.
Data we collect
Data we collect from you directly: name, email, agency/company name, payment data (via iyzico — we never store card numbers on our servers), and content you upload (prospect URLs, briefs, deck preferences). Data we collect automatically: IP address, browser type, pages visited, interaction events, and device info.
How we use your data
We process your data for: (i) contract performance — account management, deck generation, invoicing; (ii) legal obligations — tax law, KVKK; (iii) legitimate interest — product improvement, security, fraud prevention; (iv) your explicit consent — for marketing communications and optional analytics only. We do not use your personal data or your client-specific content to train our AI models.
Sharing with third parties
We do not sell your personal data. Data is shared with the following providers strictly to the extent necessary to deliver the service: Supabase (data storage, EU region), Vercel (application infrastructure), Sentry (error monitoring), Customer.io (transactional email), Crisp IM SAS (live chat and customer support messaging, Nantes / France — EU region), iyzico (payments, Turkey), Google and Anthropic (AI model APIs). GDPR/KVKK-compliant Data Processing Agreements (DPAs) are in place with every provider. Data may also be disclosed to competent public authorities when required by law.
International data transfers
Pitchko is headquartered in Turkey. Transfers from the EU rely on appropriate safeguards under KVKK Art. 9 (as amended March 2024) and GDPR Art. 46 — Standard Contractual Clauses (SCCs) or Binding Corporate Rules (BCRs). See the [GDPR Notice](/legal/gdpr-notice) for details.
Retention
After your account deletion request, your data is processed in three classes: (1) DELETED — account profile, presentations, feedback, team memberships; automatically purged after the 90-day cancellation window by the sweep cron. (2) ANONYMIZED — API cost logs and token transaction history; the user identifier is set to NULL, audit trail retained. (3) RETAINED — invoice and commercial ledger records, kept under Turkish Commercial Code Art. 82 (10 years) and Tax Procedure Law Art. 253 (5 years); the stricter period applies. Marketing-consent data is deleted immediately upon withdrawal. Detailed retention matrix available on request.
Cookies
We use cookies for session management, preference storage and anonymous analytics. See our separate [Cookie Policy](/legal/cookie-policy) for the full list. We do not use third-party advertising or cross-site tracking cookies.
Data security
We use TLS 1.3 encryption in transit, server-side encryption at rest, role-based access control, audit logging, and regular security reviews. Passwords are stored as one-way bcrypt hashes. In case of a data breach we notify within 72 hours per KVKK Art. 12/5 and GDPR Art. 33.
Children's data
Pitchko is not directed at users under 16. We do not knowingly collect data from children under 16. If you are a parent and you believe your child has provided us with data, email info@pitchko.io and we will delete it immediately.
Your rights
Depending on where you live, you have rights of access, rectification, erasure, restriction of processing, data portability, objection, and opt-out from automated decision-making. See [KVKK Notice](/legal/kvkk-notice) (Turkey) or [GDPR Notice](/legal/gdpr-notice) (EU) for the full list and legal bases. We respond within 30 days.
Changes to this policy
We may update this policy from time to time. Material changes (processing purposes, provider list, data categories) will be announced via email or in-app notification. The "Last updated" date above is bumped on every revision.
Contact
For any privacy or data-related questions: info@pitchko.io. Response time does not exceed 30 days.