StartupFlow AI

Privacy Policy

Last updated July 27, 2026

You are about to tell us what stage your company is at, what you are building, and, if you use the Data Room, hand us your pitch deck and your numbers. That deserves a straight answer about what happens to it. This page is that answer. It is longer than we would like, because the law requires certain things to be spelled out, but there is nothing buried in it.

Short version: we do not sell anything about you, we run no advertising trackers, and you can take everything with you or delete the lot from Settings without asking us first.

Who is responsible for your data

StartupFlow AI is operated by StartupFlow AI, registered at Vogue Towers, MM Alam Road, Block C2, Gulberg III, Lahore 54000, Pakistan. We are the data controller: the ones who decide what gets collected and why, and the ones you can hold to it.

We are based in Pakistan, outside the European Economic Area, and we serve founders inside it, so Article 27 of the GDPR requires us to name a representative in the EU. We are in the process of appointing one and will publish their name and address here as soon as it is in place. In the meantime, write to us directly at privacy@startupflowai.com; we would rather tell you this is outstanding than leave you to discover it.

For anything at all to do with your data, email privacy@startupflowai.com. A real person reads it.

What we collect, and why we are allowed to

Under the GDPR we need a lawful basis for each thing we do with your data. Here is every category, in full.

Your account

Your email address and a hashed password. We never store the password itself, only an Argon2 hash of it, which cannot be reversed. Lawful basis: contract. We cannot give you an account without it.

Your startup profile

Stage, country, industry, team size, funding raised, the tech stack you run, and what you are looking for. This is the input to the matching, without it we would be showing you the same directory as everyone else. Lawful basis: contract.

What you do in the product

Programs you save, applications you track, credits you record in the wallet, questions you ask the assistant, and the recommendations we generate for you. Lawful basis: contract. This is the product working.

Your Data Room

Whatever you upload: pitch decks, financials, cap tables, incorporation documents. Tax identifiers you enter are encrypted at rest with AES-256-GCM. The storage bucket is private, and every file is served through a signed link that expires in a couple of minutes. Lawful basis: contract. Nobody sees a Data Room file unless you create a share link for it.

Payment details

Your subscription status and the customer id our payment provider gives us. Card numbers never touch our servers. Polar handles that end. Lawful basis: contract, and legal obligation for the records tax law requires us to keep.

Security and error logs

When something crashes we get a stack trace and the page it happened on. Email addresses, session tokens and cookies are stripped out before anything leaves your browser or our servers. Lawful basis: legitimate interest. We cannot fix what we cannot see, and we have written down the balancing test that gets us there.

Session replay

Only if you switch it on. It records clicks and page movements so we can watch a bug back instead of guessing; text is masked before it leaves the browser. Lawful basis: consent. You can withdraw it from cookie settings at any moment, and it stops immediately.

Product emails

News about new features. Off unless you ask for it, and one click to turn back off. Lawful basis: consent. Service messages (a deadline reminder, a password reset, a note that your share links were paused) are a different thing and run on the contract, though you can still switch most of them off in Settings.

What the AI does with your profile

Your profile text is sent to Google’s Vertex AI to rank programs and write the reason we show beside each match. Two things worth knowing. First, whether you are eligible for a program is decided by our own code against the program’s published rules: the AI only orders and explains what you already qualify for. Second, nothing here makes an automated decision with legal or similarly significant effects on you under Article 22: we do not approve or reject anyone, and every application goes to the provider directly, by you.

Cookies

We set four things, three of which are cookies, and the site does not work without them: your sign-in tokens, your light-or-dark choice, and a record of the cookie decision you made so we stop asking. There are no advertising cookies and no third-party trackers. The only optional item is session replay. Every one of them is listed by name, purpose and lifespan on the cookie policy.

How long we keep things

These are enforced by a job that runs every night, not by good intentions. The numbers below are read from the same constants that job uses.

WhatHow long
Your account and everything in it: profile, saved programs, applications, credit wallet, Data Room, assistant historyUntil you delete your account, then 30 days
Messages you send us through the contact form24 months
Data Room view records, so you can see that a share link was opened12 months
Expired sign-in tokens, password reset links and extension pairing codes30 days after they stop working
Our own log of admin actions24 months
Your cookie choices, kept as proof of what you agreed to3 years
Your email address on our launch list, after you unsubscribe (we hold it briefly so an import cannot add you back)30 days

Invoices are the exception. Tax law requires our payment provider to keep billing records for several years, and we cannot delete those on your behalf even after your account is gone.

Who else sees your data

We do not sell personal data and we never will. A short list of companies process it for us so the product can exist at all:

  • Amazon Web Services (AWS), Runs the whole platform: the application servers, the database and the object storage your Data Room files sit in. (United States (N. Virginia))
  • Google Cloud (Vertex AI), The AI that ranks programs against your profile and writes the plain-English reason next to each match. (United States (us-central1))
  • Polar Software Inc., Takes payments and manages subscriptions. Also our merchant of record. (United States)
  • Google LLC (Google Analytics 4), Counts visits and shows us which pages founders actually use, so we can see where people give up. Only runs if you switch analytics on in the cookie banner. (United States)
  • Sentry (Functional Software, Inc.), Tells us when something breaks. If you turn on session replay, it also records that session so we can watch the bug back. (United States)
  • Our email provider (SMTP), Delivers the mail we send you: password resets, deadline reminders, match alerts, deletion confirmations. (United States)

The full table, with what each one can see and what makes the transfer lawful, is on the sub-processors page.

Your data leaves the EU. Here is exactly how

There is no polite way to phrase this, so plainly: our servers are in Virginia and our team works from Pakistan. If you are in the EEA or the UK, your data is transferred outside it twice over.

StartupFlow AI is run from Pakistan. A very small number of us can reach production data when we have to. Debugging something you have reported, or acting on a request you have made. Access needs a named admin account, everything an admin does is logged, and those logs are kept for 24 months. For the hosting and AI side, we rely on Standard Contractual Clauses with each provider, and on the EU–US Data Privacy Framework where the provider is certified under it. Pakistan has not been found adequate by the European Commission, so our own access rests on those clauses and on the access controls described above rather than on an adequacy decision.

How we protect it

  • HTTPS everywhere, with certificates renewed automatically.
  • Passwords hashed with Argon2. Sign-in and reset tokens stored only as hashes.
  • Tax identifiers encrypted at rest with AES-256-GCM.
  • The Data Room bucket is private. Files are only ever served through signed links that expire in minutes.
  • Every query for your data is filtered by your user id in the service layer.
  • Nightly encrypted database backups.
  • Admin actions are logged with the account that took them.

No system is perfect. If we ever suffer a breach that puts you at risk, we will tell the relevant supervisory authority within 72 hours and tell you without undue delay.

What you can do

These are your rights under the GDPR, and most of them are buttons rather than requests.

  • See it all (Art. 15) and take it with you (Art. 20). Settings gives you the whole thing as JSON or as a page you can actually read. No waiting on us.
  • Fix it (Art. 16). Edit your profile directly. Email us for anything you cannot reach.
  • Delete it (Art. 17). One button in Settings. We sign you out everywhere straight away and erase everything 30 days later. The window is there so a mis-click is recoverable, and you can cancel any time inside it.
  • Pause it (Art. 18). Ask us to stop processing while a dispute is sorted out.
  • Object (Art. 21). Anything we do on legitimate interest, you can object to.
  • Take back consent (Art. 7(3)). Session replay and product emails are both one toggle away, and withdrawing is exactly as easy as agreeing was.
  • Complain. If we get it wrong, you can go to the data protection authority in your country. In the EU that is your national supervisory authority; in the UK it is the ICO. We would rather you emailed us first, but it is your call and you do not need our permission.

Requests that come by email get answered within 30 days, free of charge. We may ask you to confirm who you are first, handing someone else’s Data Room to a stranger would be the worse failure.

Children

StartupFlow AI is for people running companies, and it is not intended for anyone under 16. We do not knowingly collect data from children. If you think a child has signed up, email us and we will remove the account.

Changes to this policy

This is version 2026-07-27. If we change anything material (a new category of data, a new purpose, a new sub-processor, a shorter retention period), we will bump the version, update the date at the top, and tell you in the app before it takes effect. Typo fixes we will just make.

Contact

privacy@startupflowai.com for anything on this page. There is also a contact form if that is easier. By post: StartupFlow AI, Vogue Towers, MM Alam Road, Block C2, Gulberg III, Lahore 54000, Pakistan.