Legal
Privacy
What we collect, who else touches it, how long it stays, and how to get rid of it. Written to be checkable rather than comprehensive-sounding.
Who we are
PATL is operated by PivotPt Capital Corp. For anything on this page, including a request to see or delete your data, write to phil@patl.app.
PivotPt Capital Corp
390 NE 191st St STE 61321
Miami, FL 33179
What we collect
| What | Why it exists |
|---|---|
| Account details | Your name, email, organisation name and a hashed password. Needed to have an account at all. |
| What you upload | Offering memoranda and supporting files. Read to extract operating figures, then stored against the deal. |
| What you model | Deals, assumptions, model runs and exports. This is the product. |
| Consent records | Which terms version you accepted and whether benchmarking is on, each with the user and a timestamp. Kept so both answers are provable. |
| Site analytics | Google Analytics on the public pages: pages viewed, referrer, approximate location, device. Used to see which parts of the site are read. |
| Operational logs | Request logs and error traces from the hosting platform, for keeping the service up and debugging it. |
We do not sell your data, we do not run advertising, and we do not use one customer's material to serve another.
Who processes it
| Processor | What it sees |
|---|---|
| Google Cloud | Hosting, database and file storage (us-east1). Everything the product stores lives here. |
| Anthropic | The PDFs you upload for extraction, and the deal facts behind a staffing proposal or a drafted narrative. |
| Stripe | Billing. Card details go to Stripe directly; we never see or store a card number. |
| Brevo | Transactional email — verification, onboarding, notifications. Your email address and the message. Your name, email and firm name are also kept there as a contact record for the account. |
| Google Analytics | Public marketing pages only. Not loaded inside the signed-in application. |
Analytics is deliberately kept off the application itself. Deal URLs and page titles identify what you are working on, and sending those to an analytics vendor to learn which tab is popular is a bad trade.
How long it stays
- Uploaded documents: 90 days, then purged. The row recording that an extraction ran survives as provenance; the contents are emptied.
- Deals, assumptions and model runs: for the life of the account. A stored run has to keep reproducing, which is the point of versioning them.
- Consent records: kept as history. A record that could be edited would not be evidence of anything.
- Analytics: per Google Analytics' own retention settings.
Your choices
- Benchmarking: on or off under Settings, withdrawable at any time, and the history of that decision is visible to you.
- Marketing email: off unless you asked for it. The box at signup starts empty, and turning it off under Settings removes you from the mailing list itself rather than only setting a preference. Declining is recorded too, so what you were asked and what you answered are both on the record. The email your account needs — verification, setup, and the follow-up on a deal you underwrote — is not marketing and is sent either way.
- Access, correction, deletion: email phil@patl.app and we will action it for your organisation's data.
- Documents: can be removed from a deal before the 90-day purge reaches them.
Security
Every organisation's data is isolated at the database level by row-level security, not only by application code, so a query that forgets its tenant returns nothing rather than someone else's deals. Passwords are hashed. Traffic is encrypted in transit.
If you believe you have found a vulnerability, please write to phil@patl.app before disclosing it publicly.
Changes
This notice carries a version. When it changes materially, the version changes with it and account holders are told; the old version stays what it was.