Privacy Policy

Your fundraising materials are confidential. This product is designed around that assumption.

Last updated: June 6, 2026

The short version

  • We don’t sell your documents.
  • We don’t publish them.
  • We don’t share them with other users or with third parties for marketing.
  • We don’t train AI models on your materials.
  • Uploaded materials are used only to generate the review you requested.

Who we are

Roast My Startup (“Roast My Startup,” “we,” “us”) is an investor-readiness tool that reviews fundraising materials (pitch decks, financial models, forecasts, business models, and data room files) and returns structured, investor-style feedback. This policy explains what we collect, how we use it, and the choices you have.

Information we collect

We keep this deliberately narrow:

  • Account information. When you sign up we collect your name, email address, and a password (which is hashed; we never store it in plain text).
  • Materials you upload. The decks, models, forecasts, and documents you submit for review, plus any context notes you add.
  • Your AI provider key.If you bring your own Anthropic or OpenAI API key, we store it encrypted (see “How we protect your data” below).
  • Billing information. If you purchase run credits, payments are processed by Stripe. We do not receive or store your full card details, only a customer reference and your credit balance.
  • Basic usage data. Standard, largely non-identifying technical data needed to operate and secure the service (e.g. request and error logs).

How your uploaded materials are handled

This is the part founders care about most, so we’re explicit:

  • Parsed in your browser. Decks, models, and forecasts are read and converted to text in your browser. Only the extracted text needed to run the review is sent to our server, not the original binary file.
  • Used only for your review. Your materials are processed to produce the feedback you asked for, and for nothing else.
  • Private to your account. Saved sessions are scoped to your account. Other users cannot see them.
  • Not training data. We do not use your materials to train, fine-tune, or build any model, and we do not sell or share training data.

Prefer not to share a full data room yet? You can start with a deck-only roast or upload a redacted version.

AI processing and subprocessors

Generating a roast means sending the extracted text of your materials to a large language model for analysis. Depending on your setup, that provider is:

  • Anthropic and/or OpenAI, for the AI analysis itself, via their APIs. Both providers state that data sent through their APIs is not used to train their models by default.
  • Stripe, for payment processing, if you buy credits.
  • Our hosting and database providers, to run the application and store your saved sessions.

We rely on these providers’ own security and privacy commitments for the data they process on our behalf. We encourage you to review their API data policies, especially if you handle highly sensitive information.

How we protect your data

  • Encrypted API keys.If you store an Anthropic or OpenAI key, it is encrypted at rest, tied to your account, never returned to your browser, and never used for anyone else’s runs.
  • Scoped access. Saved runs are readable only by the account that created them, enforced on the server.
  • Signed sessions. Sign-in uses signed session cookies. No system is perfectly secure, but we aim to collect little and protect what we keep.

Data retention and deletion

If you’re signed in, your roasts are saved so you can return to them. You stay in control:

  • Delete any session. You can delete any saved roast at any time from Past sessions. Deleting a session removes its stored reports, memos, revised documents, and the extracted material it was built from.
  • Remove your key. You can clear a stored API key from your account settings whenever you like.
  • Delete your account.From the account menu you can permanently delete your account and everything tied to it (saved sessions, stored keys, and billing records) yourself, anytime. It’s immediate and irreversible, with no need to ask us.

What we will never do

  • Sell your documents or personal information.
  • Publish your materials or make them public.
  • Share them with other users or with third parties for marketing.
  • Use your confidential materials to train AI models.

Changes to this policy

We may update this policy as the product evolves. When we make material changes, we’ll update the “Last updated” date above and, where appropriate, notify you.