Trust & security
Last updated July 27, 2026
You are being asked to upload your pitch deck and your financials to a company you found on the internet. Healthy instinct says do not. So rather than a badge and a promise, here is what we actually do, specific enough that you can check most of it yourself.
What “GDPR compliant” means here
It is a phrase people put in footers without meaning much by it. When we use it, we mean six concrete things, all of which are live:
- Nothing optional runs without your say-so. No tracker, no session recording, nothing. Rejecting is one click and it is the same-sized button as accepting.
- You can take everything with you. One button in Settings, no request, no waiting on us, as machine-readable JSON and as a document you can actually read.
- You can delete everything. Also one button. Also no request. Thirty days later it is gone for good, and you can cancel any time inside that window.
- We delete things on a schedule, automatically. Not when we get round to it: a job runs every night and applies the table below.
- We tell you who else can see your data. Every one of them, by name, on one page.
- We keep the paperwork. A record of processing activities, a retention schedule, a 72-hour breach plan, a legitimate-interest assessment for error monitoring, and a written procedure for handling requests.
What we are not claiming: we hold no ISO 27001 certificate and no SOC 2 report. Those are audits, they cost money we would rather spend on the product right now, and pretending otherwise would be the exact kind of thing this page exists to avoid.
How your data is protected
- In transit. HTTPS everywhere, with certificates renewed automatically.
- Passwords. Hashed with Argon2. We could not tell you your password if we wanted to.
- Tokens. Sign-in tokens, password reset links and Data Room share links are stored only as hashes. A database dump would not let anyone log in as you.
- Data Room files. The storage bucket is private with no public access. Every file is served through a signed link that expires within minutes.
- Tax identifiers. Encrypted at rest with AES-256-GCM under a key held outside the database.
- Isolation. Every query for user-owned data is filtered by your user id in the service layer, not just in the UI.
- Error reports. Emails, tokens and cookie values are stripped out before anything is sent to our monitoring provider.
- Backups. Encrypted, nightly.
- Admin access. Named accounts only, every action logged, logs kept 24 months.
Who can see your Data Room
You, and anyone you deliberately create a share link for. Links can be labelled, given an expiry, revoked instantly, and set to hide individual sections. You can see when each one was opened. Nobody at StartupFlow AI opens a founder’s Data Room as a matter of course. The only reason would be you asking us to look at something.
How long we keep things
| What | How long |
|---|---|
| Your account and everything in it: profile, saved programs, applications, credit wallet, Data Room, assistant history | Until you delete your account, then 30 days |
| Messages you send us through the contact form | 24 months |
| Data Room view records, so you can see that a share link was opened | 12 months |
| Expired sign-in tokens, password reset links and extension pairing codes | 30 days after they stop working |
| Our own log of admin actions | 24 months |
| Your cookie choices, kept as proof of what you agreed to | 3 years |
| Your email address on our launch list, after you unsubscribe (we hold it briefly so an import cannot add you back) | 30 days |
Who processes your data
6 companies, all named on the sub-processors page along with what each can see and where it runs. No advertising networks, no data brokers, no analytics vendor of any kind. We do not sell personal data and we do not intend to build a business that would want us to.
Where it lives, and who reaches it
Servers in the United States. Team in Pakistan. If you are in the EU or the UK, that means your data leaves your jurisdiction, and we would rather say so on the trust page than leave you to find it in clause 14. The safeguards we rely on (Standard Contractual Clauses, the EU–US Data Privacy Framework where a provider is certified) are set out in the privacy policy.
If something goes wrong
We have a written incident procedure. If a breach puts you at risk, we notify the relevant supervisory authority within 72 hours of becoming aware, and we tell affected founders without undue delay: what happened, what data, what we have done, and what you should do. We will not wait until we have a complete picture to tell you something is wrong.
Reporting a vulnerability
If you have found a security issue, email privacy@startupflowai.com with enough detail to reproduce it. We will confirm receipt within two working days. We do not have a paid bounty programme yet and will not pretend we do, but we will credit you if you want, and we will not threaten anyone who reports something in good faith.
Your controls, in one place
- Settings: export your data, delete your account, change notification and cookie choices.
- Cookie policy: every cookie by name, and the switch to change your mind.
- Privacy policy: the full legal notice, including your rights and how to complain.
- Sub-processors: who else touches your data.
- Data Processing Addendum: the Article 28 terms, if your legal team asked for them.
Anything not covered here: privacy@startupflowai.com.