Informational translation. The German version (link in the footer) is binding under GDPR and German law.
1. Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) is:
Sole Proprietorship
Owner: Justus Langowsky
Nicodéstraße 13
01465 Dresden
Germany
Email: contact@dailypitch.io
2. General notes on data processing
We generally process personal data of our users only insofar as this is necessary to provide a functional website and our content and services. Processing of personal data of our users is regularly carried out only with the consent of the user.
An exception applies in cases where prior consent cannot be obtained for factual reasons and the processing of the data is permitted by law.
3. Which data we process
3.1 When visiting the website (server logs)
When you visit our website, our hosting provider (Vercel Inc.) automatically collects information that your browser transmits:
- IP address (truncated / anonymised)
- Date and time of the request
- Content of the request (the specific page)
- Access status / HTTP status code
- Referrer URL
- Browser, operating system and its surface, language and version of the browser software
Legal basis: Art. 6 (1) lit. f GDPR (legitimate interest in the secure and stable provision of the website).
Storage period: 14 days, then automatic deletion.
3.2 On registration and use of the tool
For the use of the pitch-deck generator we process the following data:
- Email address (for magic-link login)
- Company name, branding details, contact email, booking URL
- Briefings entered and decks generated
- Uploaded files (reference decks, logos)
Legal basis: Art. 6 (1) lit. b GDPR (performance of contract).
Storage period: Until deletion of the user account. Generated decks and related data are permanently deleted 30 days after account deletion.
3.3 When opening a shared deck
When you open a share link to a deck, we collect, aggregated and without plain-text IP:
- Salted hash of the IP address (SHA-256 with rotating server-side salt, truncated to 16 characters, not reversible to the original IP, used solely for deduplication of views within a 24-hour window)
- User agent
- Referrer (where the access came from)
- Which sections of the deck were viewed, dwell time, scroll depth
Legal basis: Art. 6 (1) lit. f GDPR (legitimate interest of the deck author in engagement analytics). The recipient cannot disable this function as it is an integral part of the product; however, no identifying data is stored.
Storage period: 12 months, then automatic aggregation at daily level.
3.4 When using the MCP connector
Our MCP connector lets you link an AI chat client (e.g. Claude.ai, ChatGPT, Claude Code or Codex) to your Dailypitch account. The connection uses OAuth; of the access and refresh tokens we store only SHA-256 hashes, never the tokens in plain text. Briefings and instructions submitted through the connector are processed the same way as regular tool use (see 3.2).
Please note: content you enter in your AI client is first processed by that client’s provider under its own privacy policy before it reaches our MCP server. For ChatGPT this is OpenAI (OpenAI, L.L.C. or OpenAI Ireland Ltd.); for Claude clients, Anthropic, PBC.
Legal basis: Art. 6 (1) lit. b GDPR (performance of contract).
Storage period: Token hashes until you revoke the connection (possible any time in the dashboard under “Connected apps”).
3.5 Push notifications (optional)
If you enable push notifications, we store your push subscription (endpoint address and cryptographic keys) so we can deliver notices (e.g. about finished decks). Technical delivery runs through the push service of your browser or operating system (e.g. Google, Apple or Mozilla).
Legal basis: your consent (Art. 6 (1) lit. a GDPR), revocable at any time with effect for the future.
Storage period: until you revoke it or the push service reports the subscription as invalid.
4. Recipients of the data
We pass on data only to the following processors:
- Vercel Inc., 340 S Lemon Ave #4133, Walnut, CA 91789, USA: hosting of the website and application. We have entered into a data-processing agreement (DPA) with Vercel. Vercel is certified under the EU-US Data Privacy Framework (DPF); in addition, data transfer to the US is based on the EU Commission’s standard contractual clauses. Server region: Frankfurt (fra1).
- Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (where applicable Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA): conversion tracking for Google Ads (Google tag / gtag.js) to measure and optimise the performance of our ads, only with your consent (Google Consent Mode v2). Usage data may be transferred to the US; Google LLC is certified under the EU-US Data Privacy Framework (DPF), supplemented by the EU standard contractual clauses (Art. 46(2)(c) GDPR). More information: Google Privacy Policy.
- Anthropic, PBC, 548 Market St PMB 90375, San Francisco, CA 94104, USA: AI-powered generation of deck content. Submitted briefings are transmitted to Anthropic for generation and are not used for training purposes (Anthropic’s API customer terms). A data processing agreement is in place; transfers to the US rely on the EU Commission’s standard contractual clauses (Art. 46(2)(c) GDPR) or, where certified, the EU-US Data Privacy Framework.
- Resend, Inc., 2261 Market Street #4990, San Francisco, CA 94114, USA: delivery of transactional emails (login, verification, cancellation confirmations). Transfers to the US are based on the EU Commission’s standard contractual clauses (Art. 46(2)(c) GDPR).
- Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland: processing of payment transactions for paid plans. We have entered into a data processing agreement (DPA) with Stripe. Where Stripe transfers data to the US, Stripe, Inc. is certified under the EU-US Data Privacy Framework (DPF); standard contractual clauses apply in addition. The data transmitted includes: name, email address, billing address, payment data (card or account details are collected directly by Stripe and are not visible to us). To calculate and state statutory VAT, Stripe additionally processes the country or billing address and any VAT identification number you provide (Stripe Tax).
- Neon, Inc., USA: hosting of the Postgres database in which the account and usage data mentioned above is stored. Where data is transferred to the US, this is based on the EU Commission’s standard contractual clauses (Art. 46(2)(c) GDPR).
- Upstash, Inc., USA: rate limiting and abuse protection. Short-lived counters bound to the user or account identifier are stored. Transfers to the US are based on the EU Commission’s standard contractual clauses.
- Unsplash, Inc., Canada: image search. When you use the integrated image search, your search term is transmitted to Unsplash to load matching image suggestions. Canada has an adequacy decision from the EU Commission (Art. 45 GDPR).
5. Cookies and similar technologies
Technically necessary cookies (session cookies for login functionality) are permitted under § 25 (2) no. 2 TDDDG without consent.
To measure the performance of our Google Ads campaigns we use the Google tag (gtag.js, Google conversion tracking): we measure whether a visit that arrived via an ad led to an action (e.g. sign-up or subscription) and optimise our campaigns accordingly. Advertising cookies may be set and usage data transmitted to Google.
We use Google Consent Mode v2: without your consent no advertising or analytics cookies are set. Only when you choose “Accept” in the cookie banner are these cookies set and conversion tracking activated. The legal basis is your consent (Art. 6(1)(a) GDPR, § 25 (1) TDDDG), which you can withdraw at any time with effect for the future. We use no social-media pixels.
To improve the website we use Vercel Web Analytics and Vercel Speed Insights: cookieless, aggregated reach and performance measurement without cross-device tracking and without storing clear-text IP addresses. The legal basis is our legitimate interest in analysing and improving the service (Art. 6(1)(f) GDPR). No personal profiles are created.
6. Your rights
You have the following rights vis-à-vis us at any time:
- Information about the data stored about your person (Art. 15 GDPR)
- Rectification of inaccurate data (Art. 16 GDPR)
- Erasure of your data (Art. 17 GDPR): “right to be forgotten”
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR): export of your data in a structured format
- Objection to processing (Art. 21 GDPR)
- Withdrawal of consent already given, with effect for the future (Art. 7 (3) GDPR)
To exercise these rights, an informal email to contact@dailypitch.io is sufficient. We respond within 30 days.
7. Right to lodge a complaint with the supervisory authority
You have the right to lodge a complaint with a data-protection supervisory authority about our processing of your personal data (Art. 77 GDPR). The competent authority is the supervisory authority of your habitual place of residence or the authority responsible for our registered office:
Devrientstraße 1
01067 Dresden
Phone: +49 351 85471 101
Email: saechsdsb@slt.sachsen.de
Web: www.saechsdsb.de
8. Data security
We use exclusively encrypted connections (HTTPS / TLS 1.3) for the secure transmission of your data. Databases are protected by strong authentication. Processors are carefully selected and contractually obliged to comply with the GDPR.
9. Changes to this privacy policy
We reserve the right to adapt this privacy policy if legal requirements or our data processing change. The current version is always available on this page.