Trust Center
Pitchko holds your agency's client work — briefs, decks, brand research. This page sets out where that data lives, who can reach it, and which providers process it on our behalf. Every statement here describes what is in place today.
Where your data lives
The primary database and file storage run on Supabase in the EU (Frankfurt, eu-central-1). The application is served by Vercel's edge network. Data is encrypted in transit with TLS and at rest by the storage provider.
Tenant isolation
Every table holding agency data is protected by database-level row security policies, so one agency's records are unreachable from another agency's session — the isolation is enforced by the database itself, not only by application code. Access to production credentials is limited to the operator.
Application hardening
Responses carry an enforced Content Security Policy (not report-only), HTTP Strict Transport Security, and framing and content-type protections. Public forms are protected against automated abuse, and request bodies are size-capped to prevent resource exhaustion.
Payments
Payments are processed by iyzico. Card numbers, expiry dates and security codes are submitted directly to iyzico and never reach Pitchko's servers, logs or database — Pitchko stores only the transaction result and invoice record.
Email authenticity
Pitchko's sending domain publishes SPF, DKIM and a DMARC policy set to reject, fully enforced. Mail that fails authentication is rejected outright, so a message that appears to come from Pitchko can be trusted to have come from Pitchko.
Credential handling
No credential is committed to the codebase. Automated secret scanning runs before every commit and blocks it on detection. Production credentials are held in the deployment platform's encrypted environment store.
Error monitoring
Application errors are collected to diagnose faults. Events pass through a scrubbing layer that removes personal data, tokens and credentials before they leave the application.
Retention and deletion
You can request deletion of your account and its data at any time. Deletion runs as an automated sweep that removes database records and purges stored files, rather than a manual step someone has to remember. Retention periods and your rights are set out in the privacy, KVKK and GDPR notices.
How changes reach production
Every change passes an automated gate chain before it can ship: type checking, linting, unit and end-to-end tests with a minimum coverage floor, plus purpose-built checks for authorization on API routes and server actions, dependency vulnerabilities, and public API response shape. A failing gate blocks the release.
Third-party providers
The complete list of providers Pitchko sends data to. It is generated from the application's own configuration, so a new integration cannot go undisclosed.
Providers that process personal data
These providers can see data identifying you or your clients, and act as processors on Pitchko's behalf.
| Provider | Purpose and data shared | Established in |
|---|---|---|
| Supabase | Your account, agency data, decks and uploaded files. The primary database is hosted in Frankfurt (eu-central-1). | United States |
| Vercel | The infrastructure the application runs on — request logs and IP address. | United States |
| iyzico | Payment processing. Card details go directly to iyzico and never pass through Pitchko's servers. | Türkiye |
| Customer.io | Transactional email (sign-up, password reset, billing notices) — your email address and name. | United States |
| Crisp IM SAS | Live chat support — the messages you write and the contact details you share. | EU |
| Gamma | Rendering the finished deck — deck title and section content. | United States |
| Google (Gemini API) | Generating deck content — the brief and brand details you enter. | United States |
| Anthropic | Content generation and AI-visibility measurement — brief text and queried brand names. | United States |
| OpenAI | Content generation and AI-visibility measurement — brief text and queried brand names. | United States |
| Upstash (Redis, QStash) | Job queue and rate limiting — the request identifier and IP address. | United States |
| Sentry | Error monitoring. Personal data is redacted before events are sent. | United States |
| PostHog | Product usage analytics. Events are processed in the EU region (eu.posthog.com). | United States |
| Cloudflare (Turnstile) | Bot protection on public forms — IP address and browser signals. | United States |
| Google Tag Manager | Tag management — analytics events, subject to your cookie consent. | United States |
Operational services
These services only ever receive publicly available web data — a domain to crawl, a page to measure. They receive no personal data.
| Provider | Purpose and data shared | Established in |
|---|---|---|
| Perplexity | Measuring how brands appear in AI search engines — public brand and domain queries only. | United States |
| DataForSEO | Crawl and ranking data for SEO audits — only the domain being audited. | United States |
| Apify | Collecting publicly available web data. | EU |
| Scrape.do | Fetching publicly available web pages. | Türkiye |
| Google Cloud (BigQuery) | Core Web Vitals from the Chrome UX Report — domain only. | United States |
| Google PageSpeed Insights | Page speed measurement — the audited page address only. | United States |
Legal notices
Privacy policy, KVKK notice, GDPR notice and cookie policy set out the legal basis, retention periods and your rights in full.
Read the legal noticesReporting a security issue
If you believe you have found a vulnerability, please report it privately before disclosing it publicly. We will confirm receipt and keep you informed while we investigate.
Reporting a security issue