Pitchpoint

Privacy notice

What Pitchpoint collects about you, why, who else sees it, and how to get a copy of it or have it deleted.

Last updated: 12 September 2026

Who we are

Pitchpoint is a service that drafts a tailored CV and cover letter for a job you are applying for, using your own CV, your own writing samples and your own drafting rules.

For the purposes of UK data protection law, the operator of Pitchpoint is the controller of the personal data described in this notice. That means we decide what is collected and why, and we are responsible to you for it.

Pitchpoint is run by Maria Silva, a sole trader in the United Kingdom, at 38 Marlborough Road, Maidenhead SL6 4G. Maria Silva is the controller of the personal data described in this notice.

For any privacy question, or to use any of the rights set out below, email mariafgsilva10@gmail.com. We answer within five working days.

What we collect

Almost everything Pitchpoint holds about you is something you typed in or uploaded yourself. Here is the complete list.

Your account

  • Your email address and your password. The password is never stored in a readable form: it is held only as a salted hash by Supabase Auth, our authentication provider, and neither we nor you can read it back.
  • The name you gave when signing up.
  • The dates your account was created, last signed in, and confirmed its email address.

The contact block you enter

  • Your full name, email address, phone number, postal address, LinkedIn URL and portfolio or website URL, plus the accent colour you pick for your documents.
  • This block is inserted verbatim into the CVs and cover letters Pitchpoint produces for you. It is never written or altered by the AI.

Your CV and writing

  • The full text of your base CV, as you paste it or as extracted from a CV file you upload.
  • The CV file itself, if you upload one, kept in private file storage under a folder specific to your account.
  • Up to three writing samples, each labelled by type (an essay, an application answer, and a personal note): the original file, its file name and file type, and the text extracted from it.
  • Your drafting rules: any rules document you upload, its extracted text, and any rules you paste in directly.
  • Your voice settings: your description of your own tone, and the list of hard rules you want followed.
  • A derived voice and style analysis: a written description of how you write, produced by an AI model from the writing samples you uploaded, and the date it was produced.

Jobs and drafts

  • Job listings you paste in or fetch: title, employer, location, salary, source, link and the full job description text.
  • Every draft Pitchpoint produces for you: the cover letter text and the structured adapted CV, including any edits you make to them afterwards.
  • The date and time of each generation, so we can count your usage against your monthly allowance.

Job search settings and your own API keys

  • The job titles and locations you want to search for.
  • If, and only if, you choose to enter them: your own Reed API key and your own Adzuna application ID and key. These belong to your own free accounts with those services. They are held in our database, readable only by you under database-level access rules, and used only inside our server code to run a search you asked for. They are never sent to your browser other than to let you edit your own settings, and they are redacted from your data export.

Subscription and billing

  • Your subscription status, the start and end dates of your current billing period, whether it is set to cancel, and the identifiers Stripe uses for your customer record and subscription.
  • We never see, receive or store your card number, expiry date or security code. Those go directly to Stripe on Stripe's own hosted payment pages.

Technical information

  • Standard server and platform logs generated when you use the site, such as request times and error messages. These are produced by our hosting and database providers as part of running the service securely.

Server logs. Our database and hosting providers generate technical logs when you use the site — the time of a request, which part of the service it reached, and any error it produced. These can include your IP address, which is personal data, so we are naming it here rather than calling them “standard logs”. We do not read these logs for any purpose other than keeping the service working and investigating faults, and we cannot use them to build any picture of you.

Supabase keeps these logs for one day on the plan we use, after which they are deleted automatically. Authentication audit logs are kept for one hour. If we move to a larger plan those periods get longer, and we will say so here.

Sensitive information in CVs and writing samples

Please read this before you upload anything

A CV, a personal note or an application answer can easily contain special category data: information about your health or a disability, your religion or beliefs, your ethnic origin, your political opinions, your trade union membership, your sex life or sexual orientation, or your biometric or genetic data. A career break explained by an illness, a religious school or charity in your history, a union role, a diversity network you helped run: all of these count.

Please do not include anything you would rather was not processed. You do not need it for Pitchpoint to work. You can remove it from the text you paste, or from the document you upload, before you give it to us.

If you do include it, we treat it as follows. We do not ask for it, we do not use it to profile you, and we do not use it for any purpose other than drafting the documents you asked for. It is stored and shared with our processors in exactly the same way as the rest of your CV text, which includes being sent to Anthropic's API to produce your drafts. You can remove it at any time by editing your base CV, deleting a writing sample, or deleting your account entirely.

Our condition for processing it. Special category data needs a condition under Article 9 of the UK GDPR as well as a lawful basis. We rely on Article 9(2)(a), your explicit consent. When you create an account you are asked to agree, separately and in terms, that if you choose to include this kind of information in your CV or writing samples we may process and store it in order to draft your documents. You do not have to agree in order to apply for jobs — you can simply leave that information out — and you can withdraw your consent at any time by editing it out, deleting the document, or deleting your account. Withdrawing consent does not undo processing that has already happened.

Why we use your data, and our lawful basis

To run the service
Storing your CV, voice settings, drafting rules and job listings, generating tailored CVs and cover letters from them, letting you edit and download those drafts, and keeping your history. Lawful basis: performance of a contract (UK GDPR Article 6(1)(b)). You cannot use Pitchpoint without this.
To take payment
Creating and managing your subscription, taking recurring payments, and handling failures and cancellations. Lawful basis: performance of a contract (Article 6(1)(b)).
To keep billing records
Retaining invoices and payment records for as long as UK tax and accounting law requires. Lawful basis: legal obligation (Article 6(1)(c)).
To keep the service secure and working
Counting generations against your allowance, preventing abuse and runaway costs, investigating errors, and improving how the service works. Lawful basis: our legitimate interests (Article 6(1)(f)) in running a service that is safe, reliable and financially sustainable. We have considered your interests here: this processing uses the minimum data needed, and none of it involves reading your CV content for our own purposes.
Searching job boards
Sending your search terms to Reed or Adzuna, using your own API keys, when you press search. Lawful basis: performance of a contract (Article 6(1)(b)), and entirely optional. If you do not enter API keys, nothing is ever sent to those services.

We do not sell your data, we do not share it with advertisers, and we do not use it to train AI models of our own.

How the AI drafting works, and what it sees

Pitchpoint uses Anthropic's Claude models through Anthropic's API. Two things trigger a call to Anthropic, and both are actions you take deliberately.

When you generate an application

We send Anthropic:

  • The full text of your base CV, exactly as you provided it. If your CV text contains your name and contact details, those are sent as part of it.
  • The job's title, employer, location and description.
  • Your tone description, your hard rules, any short writing samples saved in your voice settings, your derived voice and style analysis, and your drafting rules.

When you ask us to analyse your writing voice

We send Anthropic the text extracted from the writing samples you uploaded, so it can produce the written description of how you write. This happens only when you press the analyse button, not automatically when you upload a sample.

Anthropic processes this to return the text we asked for and acts as our processor. We do not send your password, your payment details, or your Reed or Adzuna API keys to Anthropic, ever.

What Anthropic does with it. We have accepted Anthropic’s data processing agreement, so they act as our processor and may use what we send only to return the result we asked for. Anthropic does not train its models on data submitted through the API by default. Under their published terms they automatically delete API inputs and outputs within 30 days — with the exceptions that anything their automated systems flag as a possible breach of their usage policy may be kept for up to two years, and they may keep data longer where the law requires it.

These figures were checked against Anthropic’s published terms on 15 September 2026. If they change, we will update this section and the date at the top of this notice.

Who else processes your data

We use a small number of service providers to run Pitchpoint. They act as our processors: they handle your data on our instructions and are not allowed to use it for their own purposes. These are all of them.

Anthropic
Generates your cover letters and adapted CVs, and derives your voice analysis. Receives your base CV text, your writing samples (during analysis), your voice settings and drafting rules, and the job descriptions you are applying to.
Supabase
Provides our database, our authentication (your email address and password hash), and the private file storage holding your uploaded CV, writing samples and rules documents. Effectively everything described in this notice is stored with Supabase.
Netlify
Hosts and serves the application. Handles the web requests you make to the site, including the data in them as it passes through.
Stripe
Takes and manages your payments. Receives your email address and an internal reference to your Pitchpoint account, and collects your card details directly from you on its own hosted pages. Your card details never reach Pitchpoint.
Reed and Adzuna
Only if you choose to enter your own API keys for them. When you run a search, we send those services your search keywords, the location you entered, and your own API credentials. We do not send them your CV, your writing, or anything about your account.

We may also disclose your data if we are legally required to, for example in response to a valid court order, or to establish or defend legal claims. If Pitchpoint were ever sold or transferred, your data could be transferred as part of that, and we would tell you first.

We have a written data processing agreement in place with each of these providers, as Article 28 requires. If we add a service that touches your data — an email sender, an error tracker, a support inbox — we will add it to this list and change the date at the top of this notice before it processes anything.

International transfers

Several of the providers above are based outside the United Kingdom, principally in the United States, and your data may be processed there or in other countries where they operate.

Where personal data leaves the UK, it must be protected by one of the safeguards UK data protection law recognises. In practice that is one of the following: the country has been granted UK adequacy status, meaning its protection is considered equivalent; the provider is covered by the UK Extension to the EU-US Data Privacy Framework; or the transfer is made under the UK International Data Transfer Agreement, or the EU Standard Contractual Clauses with the UK Addendum. We rely on these safeguards and on the transfer terms in each provider's data processing agreement.

Pitchpoint serves customers in the United Kingdom, but not all of the providers we use are in the United Kingdom. Here is where each one processes your data and what covers it.

  • Supabase — your database, your login and your uploaded files are stored in Ireland. Transfers to the EEA are covered by the UK's adequacy regulations, which means no additional safeguard is needed.
  • Anthropic — processes in the United States and other countries outside the UK and EEA. Covered by the Standard Contractual Clauses in its data processing terms.
  • Netlify — hosting, processed in the United States and other countries. Covered by the Standard Contractual Clauses, and Netlify is also certified under the UK Extension to the EU-US Data Privacy Framework.
  • Stripe — we contract with Stripe Payments Europe Limited in Ireland, and your data may be transferred to Stripe in the United States. Covered by the UK International Data Transfer Addendum and the Standard Contractual Clauses in Stripe's data processing agreement.
  • Reed and Adzuna — only if you choose to enter your own API keys for them. Both are UK companies, and we send them only your search terms and your own credentials, never your CV.

These positions were checked against each provider’s published terms on 12 September 2026. If one of them changes where it processes data, we will update this section and the date at the top of this notice.

How long we keep it

  • Your account data, CV, writing samples, drafting rules, voice analysis, jobs and drafts are kept for as long as your account exists.
  • If you delete something inside the app (a writing sample, your CV text, a saved API key), it is removed from our database when you do.
  • If you delete your account, everything above is erased: your uploaded files, all of your rows in our database, and the login itself. Any active subscription is cancelled at the same time. This is immediate and cannot be undone.
  • Billing records held by Stripe (invoices and payment records) are kept for as long as UK tax and accounting law requires, which is currently six years. Deleting your Pitchpoint account does not and cannot erase those.

We do not delete dormant accounts on a timer. This is a deliberate choice rather than an oversight: you can delete any item, or your whole account, yourself at any time and it happens immediately, so nothing is kept because it is difficult to remove. If you would rather we did not hold your CV any longer, delete it — you do not need to ask us, and you do not need to wait.

How we protect it

  • Every table in our database enforces row-level security: the database itself refuses to return one user's rows to another user, rather than relying on the application to hide them.
  • Uploaded files live in a private storage bucket, in a folder named after your account, with the same rule applied at the storage layer.
  • Your subscription status can only be written by our payment webhook, which verifies a cryptographic signature from Stripe on every message. No signed-in user can grant themselves a subscription.
  • Our Anthropic key, our Stripe keys and our administrative database key exist only on the server and are never sent to your browser.
  • Your password is never stored in a readable form.

One thing we want to be straightforward about: if you choose to save a Reed or Adzuna API key, it is stored in our database as ordinary text, protected by the access rules above and by the encryption our database provider applies to its storage, rather than being separately encrypted by us with a key of our own. If that is not acceptable to you, do not save those keys. The rest of the service works without them.

No service can promise perfect security. If we ever suffer a breach that is likely to risk your rights and freedoms, we will report it to the Information Commissioner's Office within 72 hours and tell you without undue delay where the law requires it.

Your rights, and how to actually use them

Under UK GDPR you have the following rights over your personal data.

Access
Get a copy of the data we hold about you. You can do this yourself, immediately, at any time: go to Settings, then Account and data, and choose "Download my data". It returns a JSON file containing everything listed in this notice.
Rectification
Correct anything inaccurate. Every field is editable by you in Settings: your contact details, base CV, writing samples, drafting rules, voice settings and job search settings.
Erasure
Have your data deleted. You can do this yourself too: Settings, then Account and data, then "Delete my account". It erases your files, all your database records and your login, and cancels any subscription. You can also delete individual items (a writing sample, a job, your CV text) without deleting the account.
Portability
Receive your data in a structured, commonly used, machine-readable format. The same export gives you this: it is JSON, and you can take it elsewhere.
Restriction
Ask us to stop using your data while a dispute about it is resolved. Contact us using the details at the top of this notice.
Objection
Object to processing we carry out on the basis of our legitimate interests. Contact us and tell us why, and we will stop unless we have compelling grounds not to.
Withdraw consent
Where we rely on your consent, including any explicit consent for sensitive information you chose to include, you can withdraw it at any time by removing that content or deleting your account. Withdrawing consent does not affect processing that already happened.

Using any of these rights is free, and we will respond within one month. We may ask you to confirm your identity first.

If you are not happy with how we handle your data

Please tell us first, so we have a chance to put it right. You also have the right to complain to the UK's data protection regulator, the Information Commissioner's Office, at ico.org.uk or on 0303 123 1113. You do not need our permission and you do not have to come to us first.

Automated decision-making

Pitchpoint does not make any solely automated decision about you that produces a legal effect or a similarly significant effect. The AI writes a draft. It does not score you, rank you, screen you, decide whether you get a job, or decide anything at all about your account. Every draft it produces is yours to read, edit, discard or send, and no employer receives anything from us.

The only automated checks we run are administrative: whether your subscription is active, and how many drafts you have used this billing period.

Cookies

Pitchpoint uses strictly necessary cookies only. There are two kinds:

  • Authentication cookies set by Supabase, which keep you signed in as you move between pages. Without them you would have to log in on every page.
  • Cookies set by Stripe on Stripe's own checkout and billing portal pages, needed to process your payment securely and to prevent fraud.

We do not use analytics. We do not use advertising or tracking pixels. We do not use a tag manager, a session recorder, a heatmap tool, or any third-party embed that could observe you. There is no cookie consent banner on this site because there is nothing here that requires consent: strictly necessary cookies are exempt under the Privacy and Electronic Communications Regulations.

Changes to this notice

If we change how we handle your data, we will update this page and change the "last updated" date at the top. If the change is significant — a new processor, or a new purpose — we will post it here at least 14 days before it takes effect, so it is worth checking this page if you want to know about changes. We do not currently have a way to email every registered user, so we do not promise to.

We keep a dated copy of every previous version of this notice, so you can always ask what it said on the day you signed up.

See also our terms of use.