Your decks and your buyers' data, handled carefully.
This page says plainly what PitchWire does with what you upload and what your viewers do. If something you need isn't here, email info@getpitchwire.com — we reply within a business day.
- TLS in transit
- Encrypted at rest
- GDPR — DPA available
- SOC 2 — not yet
- US hosted on Render
Where PitchWire runs
PitchWire is hosted on Render in the United States (Ohio region). The app, the viewer your buyers open, the alert worker and the Claude & ChatGPT connector are separate services, each deployed automatically from a reviewed main branch. Render, the platform underneath, is SOC 2 Type II certified.
Encryption
Every connection — yours and your viewers' — runs over TLS. At rest, our database (Neon) and object storage (Cloudflare R2) encrypt by default. Stored CRM and Slack credentials get an extra layer: they're sealed with AES-256-GCM under a key that lives only in our hosting environment.
Signing in
Authentication runs on Stytch, a dedicated identity provider. PitchWire keeps only a salted scrypt hash of your password, never the password itself. Sessions last 30 days, and signing out ends yours server-side. SSO and MFA are not available yet.
Who can open a link
Each recipient gets their own link. Set an expiry — the workspace default is 90 days — or leave it open, and revoke any link at any time: the deck stops loading immediately (images already open in a viewer's browser can keep working for up to ten minutes).
What we record about your viewers
PitchWire records how a deck is read: which slides were opened, how long each was viewed, revisits, and when a link is opened by a new viewer. Viewers don't need an account and nothing is installed on their device. Deleting a deck deletes its links and their engagement history with it. Want a full export or deletion of your account's data? Email support@getpitchwire.com from your account address and we'll take care of it.
AI and your deck content
When you upload a deck, PitchWire sends each slide as an image to Anthropic's Claude to read its layout and text so the deck can be personalised. Refine sends a slide's text the same way. This goes over Anthropic's API, where inputs aren't used to train models under its commercial terms. Nothing else sends deck content anywhere — except that if you connect Claude or ChatGPT yourself, that connector can read your decks on your instruction, and you can revoke it at any time. Slack, HubSpot and Salesforce receive engagement events only, never deck content.
GDPR and data processing
PitchWire acts as a processor for the viewer data you collect. A data processing agreement (DPA) is available on request for any plan — email info@getpitchwire.com and we'll send it back.
Our subprocessors, in full:
- Render — application hosting (US, Ohio)
- Neon — the PostgreSQL database holding your account, decks and engagement history
- Cloudflare R2 — object storage for deck page images and logos
- Stytch — authentication and session management
- Anthropic — deck derivation and AI refinement, when you upload a deck or use refine
- Resend — transactional email (alerts, invitations, support replies)
- Stripe — subscription billing and payment processing
Used only if you connect them yourself: Slack (alerts), HubSpot and Salesforce (engagement write-back to your CRM). Nothing reaches these until you complete the connection, and disconnecting deletes the stored credential.
SOC 2
We have not started a SOC 2 audit. When we do, this page will say so — the badge appears only when a report exists.
Security questionnaires
Send yours to info@getpitchwire.com. We answer them ourselves, in writing. The engineering-level answers live in a security overview we can share on request.