PitchBeacon.ai
Login Sign Up
PitchBeacon.ai

Privacy Policy

How we collect, use, and protect your information

Effective: January 1, 2025 Last Updated: May 2025

Summary: PitchBeacon.ai is a professional SaaS tool for PR outreach. We collect the data needed to provide the service, we never sell your personal information to third parties, and you can request deletion at any time. Read on for the full details.

Contents

  1. Who We Are
  2. Information We Collect
  3. How We Use Your Information
  4. Legal Basis for Processing
  5. Data Sharing & Disclosure
  6. Third-Party Services
  7. Cookies & Tracking
  8. Data Security
  9. Data Retention
  10. Your Rights
  11. International Transfers
  12. Children's Privacy
  13. Changes to This Policy
  14. Contact Us

1. Who We Are

PitchBeacon.ai ("PitchBeacon," "we," "us," or "our") is a software-as-a-service platform that helps PR professionals, agencies, and businesses craft press releases, discover media contacts, manage outreach campaigns, and track journalist engagement. This Privacy Policy applies to your use of our website and platform.

We act as the data controller for information you provide to us as an account holder. For contact data you import or discover through the platform (e.g., journalist contacts), you act as the data controller and we act as the data processor on your behalf.

2. Information We Collect

Account & Registration Data

  • Name, email address, and password (hashed) when you register
  • Google account information if you sign in via Google OAuth (name, email, profile picture)
  • Company name, job title, and phone number if provided in your profile

Billing Data

  • Subscription plan and billing history (managed by Stripe — we do not store raw card numbers)
  • Billing email and country for tax/invoice purposes

Platform Usage Data

  • Press releases, campaign content, and email templates you create
  • Contact lists and found journalist/media contacts associated with your account
  • Email sending history, campaign statistics (opens, clicks, replies, bounces)
  • IMAP/SMTP credentials you provide for inbox integration (stored encrypted)
  • Auto-settings, scheduled sends, and suppression lists

Technical & Log Data

  • IP addresses, browser type, and operating system
  • Pages visited, features used, and session duration
  • Error logs and performance metrics for service improvement

Communications

  • Support tickets, emails, or chat messages you send us

3. How We Use Your Information

  • Service delivery: Operate, maintain, and improve the PitchBeacon.ai platform
  • AI features: Pass your press release content and instructions to AI providers (OpenRouter/OpenAI-compatible APIs) to generate pitches, analyse contacts, and draft emails — no training is performed on your content
  • Email outreach: Send emails on your behalf using the SMTP credentials or Resend integration you configure
  • Account management: Send transactional emails (welcome, password reset, billing receipts, plan changes)
  • Platform communications: Occasional product updates and newsletters (you can unsubscribe at any time)
  • Billing: Process payments and manage subscriptions via Stripe
  • Security & fraud prevention: Detect abuse, enforce rate limits, and protect users
  • Legal compliance: Meet our obligations under applicable law

4. Legal Basis for Processing (GDPR)

For users in the European Economic Area (EEA), United Kingdom, or Switzerland, we rely on the following legal bases:

  • Contract performance: Processing necessary to provide the service you have subscribed to
  • Legitimate interests: Security monitoring, fraud prevention, service improvement, and aggregate analytics
  • Consent: Marketing emails and optional analytics cookies (withdraw at any time)
  • Legal obligation: Retaining billing records as required by applicable law

5. Data Sharing & Disclosure

We do not sell your personal data. We share data only in the following circumstances:

  • Service providers: Third-party vendors who help us operate the platform (see Section 6), bound by data processing agreements
  • Legal requirements: When required by law, court order, or governmental authority
  • Business transfers: In connection with a merger, acquisition, or sale of assets, with notice to you
  • With your consent: In any other circumstance where you have explicitly consented
  • Aggregated data: Non-identifiable, aggregated statistics that cannot be used to identify you

6. Third-Party Services

We use the following third-party services to operate PitchBeacon.ai:

  • Stripe — payment processing and subscription management (Stripe Privacy Policy)
  • Resend — transactional and platform email delivery (Resend Privacy Policy)
  • OpenRouter / AI providers — AI text generation for pitch writing and contact analysis (your content is processed but not stored for training)
  • Google — optional OAuth sign-in and optionally Gmail IMAP/SMTP integration (Google Privacy Policy)
  • DigitalOcean — cloud hosting and managed database infrastructure (DigitalOcean Privacy Policy)

Each of these providers is contractually bound to handle data securely and in accordance with applicable privacy law.

7. Cookies & Tracking

We use a small number of cookies necessary to operate the service:

  • Session cookie: Keeps you signed in across page loads (essential — expires at session end or after 30 days if "remember me" is selected)
  • CSRF token: Protects against cross-site request forgery attacks (essential)
  • Theme preference: Stores your dark/light mode choice in localStorage (not a cookie, not transmitted to our servers)

We do not use third-party advertising cookies, Facebook Pixel, Google Ads tracking, or any other behavioural advertising technology. Open and click tracking on emails sent by you through campaigns is an optional feature you control.

8. Data Security

We implement industry-standard security measures to protect your data:

  • All data in transit is encrypted using TLS 1.2 or higher
  • Passwords are hashed using bcrypt with a per-user salt
  • IMAP/SMTP credentials are encrypted at rest
  • Database access is restricted to authenticated application processes
  • API keys and secrets are stored as environment variables, never in source code
  • Regular dependency updates and security patches are applied

No method of transmission over the internet is 100% secure. If you discover a security vulnerability, please contact us at security@pitchbeacon.ai before public disclosure.

9. Data Retention

  • Active accounts: Data is retained for as long as your account is active
  • Cancelled accounts: Account data is deleted or anonymised within 90 days of account closure, unless we are required to retain it for legal or billing purposes
  • Billing records: Retained for 7 years as required by financial regulations
  • Email logs: Campaign send logs are retained for 2 years for deliverability analysis, then deleted
  • Backups: Encrypted database backups may contain your data for up to 30 days after deletion

10. Your Rights

Depending on your location, you may have the following rights:

  • Access: Request a copy of the personal data we hold about you
  • Rectification: Correct inaccurate or incomplete data (most data can be updated in Account Settings)
  • Erasure: Request deletion of your account and associated personal data
  • Portability: Receive your data in a structured, machine-readable format
  • Restriction: Ask us to limit how we process your data in certain circumstances
  • Objection: Object to processing based on legitimate interests
  • Withdraw consent: For any processing based on consent (e.g., marketing emails), withdraw at any time via the unsubscribe link or Account Settings

To exercise any of these rights, email privacy@pitchbeacon.ai. We will respond within 30 days. If you believe we have not handled your data appropriately, you have the right to lodge a complaint with your local data protection authority.

11. International Data Transfers

PitchBeacon.ai is hosted in the United States. If you access our service from outside the US, your data will be transferred to and processed in the US. For EEA/UK users, we rely on Standard Contractual Clauses (SCCs) and adequacy decisions where applicable to ensure adequate protection of transferred data.

12. Children's Privacy

PitchBeacon.ai is a professional business tool and is not directed at children under the age of 16. We do not knowingly collect personal data from minors. If you believe a child has provided us with personal data, contact us at privacy@pitchbeacon.ai and we will delete it promptly.

13. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email (to the address associated with your account) or by displaying a prominent notice in the platform at least 14 days before the changes take effect. Continued use of the service after the effective date constitutes acceptance of the updated policy.

14. Contact Us

If you have questions, concerns, or requests related to this Privacy Policy or our data practices, please contact us:

  • Email: privacy@pitchbeacon.ai
  • General support: support@pitchbeacon.ai

← Back to PitchBeacon.ai  ·  Terms of Service  ·  Privacy Policy

© 2026 PitchBeacon.ai. All rights reserved.

Map CSV Columns
Detected ? columns and ? data rows. We've auto-suggested matches — review them and adjust any that look wrong. Fields marked Required must be mapped.
Field to import Column in your CSV Sample value
Preview first 3 rows of your CSV
Add to Home Screen
Use PitchBeacon.ai as a native app