Security
What happens to your deck after you upload it, in plain language.
This page describes how PitchBoost, operated by ARK Holdings, LLC, stores and protects customer data as of 2026-09-17. It is written to be checked, not to reassure. If something here is unclear or you need a specific answer for a vendor review, email support@pitchboost.ai.
Where your data lives
Accounts, deals, deck content and analytics live in a Postgres database hosted by Neon in the United States, encrypted at rest and backed up continuously. Files (uploaded images, deck exports, thumbnails) live in Vercel's file storage. Everything moves over TLS. There is no self-hosted option today.
Sign-in
Authentication is handled by Auth0. PitchBoost never sees or stores your password. You can sign in with Google or with an email and password; sessions are cookie based and cleared on sign-out. API keys for the REST API and the MCP server are shown once and stored only as a SHA-256 hash. Connecting PitchBoost to ChatGPT or Claude uses OAuth with PKCE; you can revoke it from those apps at any time.
Your deck content
When you upload a PowerPoint, PitchBoost reads the slide text, images and chart data it needs to rebuild the deck, and keeps the extracted content with the deal so the fact check can compare the rebuilt deck to your original. The .pptx file itself is not kept after extraction. Generated decks belong to your account; you can delete a deal, make a deck private, or ask us to delete the whole account, which removes personal data and deck content within 30 days except where law requires retention.
We do not use your content to train models. Deck text is sent to Anthropic to generate and revise your deck, and to Google only if you turn on AI images. Both providers process it to produce your output under their API terms.
Sharing and viewer data
A published deck is an unlisted link: anyone with the link can view it, nobody can find it by browsing, and it can carry a password or be taken offline from the share screen. Viewer analytics record opens and time on each slide against a hashed identifier; a viewer's email is stored only if they enter it in the deal room. Free plan decks carry a small PitchBoost badge, and unlisted deck links are marked noindex so search engines do not list them.
Who processes your data
| Provider | What it does with your data | Region |
|---|---|---|
| Vercel | Application hosting, edge network and file storage for deck exports, thumbnails and uploaded images. | United States |
| Neon | Postgres database: accounts, deals, deck content, analytics events. Encrypted at rest, continuous backups. | United States |
| Auth0 (Okta) | Sign-in and account security. Passwords are stored by Auth0, never by PitchBoost. Google sign-in supported. | United States |
| Anthropic | Claude models write and revise decks. Deck text you upload is sent to generate your deck. Anthropic's commercial API terms do not permit training on this data. | United States |
| Gemini image model, only when you turn on AI images for a deck. Receives the image prompt derived from the slide. | United States | |
| Microlink | Renders slide screenshots for PowerPoint exports and email thumbnails. Receives a time-limited link (valid for about a day) to the slide being rendered. | United States |
| Stripe | Payments and subscriptions. Card numbers never touch PitchBoost servers. | United States |
| Resend | Transactional email: deck-ready notices, viewer notifications, account emails. | United States |
| Sentry | Error monitoring. Receives stack traces and request metadata, not deck content. | United States |
| Cloudflare | DNS and edge proxy for the application hostname. | Global |
Payments
Checkout and subscriptions run on Stripe. PitchBoost stores a Stripe customer id and the plan you are on, never card numbers. Invoices, plan changes and cancellations are handled in the app under Settings or by email.
What we do not have
PitchBoost does not hold SOC 2, ISO 27001 or similar certifications today, and does not offer single sign-on, data residency outside the United States, or a signed data processing agreement on the self-serve plans. If your organisation needs any of these, tell us what the review requires and we will answer specifically rather than generally.
Reporting a security issue
Email support@pitchboost.aiwith "Security" in the subject line. Include the URL or feature involved and steps to reproduce. We acknowledge reports within two business days and do not pursue legal action against good-faith research that avoids customer data and service disruption. See also the privacy policy and terms of service.