At a glance
- We do not sell your data.
- We do not train models on your validation inputs.
- Passwords are hashed with bcrypt; 2FA secrets are encrypted with AES-GCM.
- Analytics is opt-in and disabled until you consent.
- You can export or delete your data any time from Settings.
Who we are
StartupDeckAI is the data controller for personal data processed through the Service. Contact privacy@startupdeck.in for any privacy request.
Information we collect
- Account data: email, display name, hashed password, optional avatar, encrypted TOTP secret, hashed recovery codes.
- Validation inputs: the startup ideas, markets, ICPs, financials, and wizard answers you submit.
- Validation outputs: generated reports, scores, citations, memos, PDFs.
- Usage data: pages viewed, feature interactions, referrer, device metadata, approximate location derived from IP.
- Session data: session cookie identifiers, active devices, IP addresses.
- Billing data: handled by our payment processor; we store only invoices, plan level, and the last four digits of your card.
- Support data: messages and attachments you send us.
How we use your information
- To operate the Service — run validations, store reports, authenticate you.
- To protect against fraud, abuse, and account takeover.
- To send transactional email (verification, password reset, receipts, security alerts).
- To respond to support requests.
- To improve the platform using aggregated, de-identified metrics only.
- To comply with legal obligations.
Legal bases for processing (GDPR / DPDP)
- Contract: providing the Service you signed up for.
- Legitimate interests: fraud prevention, security, product improvement.
- Consent: optional analytics, marketing communications.
- Legal obligation: tax records, lawful requests.
AI training
We do not use your Customer Content to train, fine-tune, or improve foundation models. Prompts are transmitted to model providers strictly to generate the specific Output you requested and are subject to the providers' zero-retention APIs where available.
Subprocessors
- Cloud infrastructure & database: hosting, database, edge compute.
- OpenRouter & model providers: your prompt content is transmitted to LLM providers to generate reports.
- Resend: transactional email delivery.
- Payment processor: card payments and invoices.
- Error monitoring: anonymised error events (no Customer Content).
A current subprocessor list is available on request to privacy@startupdeck.in.
International transfers
We are headquartered in India and process data with subprocessors in the EU and the US. Cross-border transfers rely on Standard Contractual Clauses and equivalent safeguards.
Data retention
- Account & validation data — for the life of your account.
- Logs & security events — 90 days.
- Billing records — 7 years (statutory).
- On account deletion — personal data purged within 30 days, except where retention is required by law.
Your rights
Depending on your jurisdiction (GDPR, CCPA, DPDP Act), you have rights to access, correct, export, restrict, and delete your data, and to object to processing. Exercise any right by emailing privacy@startupdeck.in. We respond within 30 days. You may also lodge a complaint with your local data protection authority.
Security
We encrypt sensitive columns at rest (AES-GCM for 2FA secrets and recovery codes), hash passwords with bcrypt, enforce TLS 1.3 in transit, isolate tenants with row-level security, and maintain a documented incident response plan. See our Security page.
Children
StartupDeckAI is not intended for children under 18 and we do not knowingly collect their data. If we learn we have, we will delete it.
Changes to this policy
We may update this policy from time to time. Material changes will be announced by email or in-product notice at least 14 days in advance.
Contact
Privacy questions: privacy@startupdeck.in. Security: security@startupdeck.in.