Legal

Privacy Policy

Last updated: 15 June 2026

This policy explains what data Fit My Deck collects, how we process it, and your choices — with specific information for UK and European users under GDPR.

Who we are

Fit My Deck is operated by B-Side Tech Limited (“we”, “us”). We help founders match pitch decks to investors using AI-assisted analysis.

Questions or privacy requests: paul@fmd.vc.

What we collect

  • Account data — email address, name, optional profile fields (job title, company, country, website), and optional Google sign-in details (profile image).
  • Pitch deck content — PDF files you upload, extracted company/raise context, and any edits you make to that context.
  • Product usage — investor match results, pipeline status, outreach drafts you generate, and related metadata (URLs, scores, timestamps).
  • Authentication & security — session tokens, and basic connection data (IP address, browser user agent) used to keep your account secure.
  • Billing — purchase history and a Stripe customer reference. Payment card details are handled by Stripe; we do not store card numbers.
  • Support — if you use in-app chat, messages and profile details you share there.
  • Analytics — aggregated, privacy-oriented usage metrics via Vercel Analytics (no advertising profiles).

How we use your data

  • Provide the service: deck analysis, investor matching, pipeline, and outreach tools.
  • Authenticate you and manage your account and credits.
  • Process payments and fulfil purchases.
  • Send transactional email (e.g. sign-in codes).
  • Operate, secure, and improve the product.
  • Respond to support requests and legal obligations.

AI and automated processing

Core features send your deck content and company context to AI providers (primarily Anthropic) to extract information and score investor fit. Public investor websites may be retrieved via search tools to enrich analyses.

We do not use your pitch deck to train public AI models. Processing is limited to delivering the features you request.

Who we share data with

We use trusted subprocessors to run the service. They process data only on our instructions:

  • Vercel — hosting, file storage (deck PDFs), and analytics
  • Neon — database
  • Stripe — payments
  • Resend — transactional email
  • Google — optional OAuth sign-in
  • Anthropic — AI analysis
  • Crisp — optional support chat

We do not sell your personal data. We may disclose information if required by law or to protect rights, safety, and security.

How long we keep data

We retain account and product data while your account is active and as needed to provide the service, resolve disputes, and meet legal obligations. You can delete decks and matches from the app; to delete your entire account and associated data, email paul@fmd.vc.

Security

We use industry-standard measures including encrypted connections (HTTPS), access controls, and secure cloud infrastructure. No method of transmission or storage is 100% secure; we work to protect your data and will notify you of significant breaches where required by law.

For users in the UK & EEA (GDPR)

If you are in the United Kingdom or European Economic Area, B-Side Tech Limited is the data controller for your personal data.

Legal bases we rely on:

  • Contract — to provide Fit My Deck when you sign up and use paid features.
  • Legitimate interests — to secure the platform, prevent abuse, and improve reliability (balanced against your rights).
  • Legal obligation — where tax, accounting, or regulatory rules require retention.
  • Consent — where you choose optional sign-in methods or contact us voluntarily.

Your rights include access, correction, erasure, restriction, portability, and objection to processing based on legitimate interests. You may also withdraw consent where processing is consent-based, without affecting prior lawful processing.

To exercise these rights, contact paul@fmd.vc. We respond within one month. You may lodge a complaint with your local supervisory authority (e.g. the ICO in the UK, or your national EEA data protection authority).

International transfers: some subprocessors are based outside the UK/EEA (notably in the United States). Where required, we rely on appropriate safeguards such as Standard Contractual Clauses or equivalent mechanisms offered by those providers.

Changes

We may update this policy from time to time. Material changes will be posted on this page with an updated date. Continued use after changes means you accept the revised policy.