← Back

Privacy

This page is maintained by the Bottleneck team to answer common questions about how founder information is handled on the platform. It reflects the current product; it is not an independent certification.

What we collect

  • Account details you provide (name, email, role).
  • Startup profile you enter (stage, industry, metrics you type in).
  • Assessment and diagnostic answers you submit.
  • Mentor session notes — split into founder-visible summaries and separate private mentor notes.
  • Files you upload to your data room.
  • Operational logs needed to run the service (sign-ins, admin actions).

What we do not do

  • We do not share founder information with investors, mentors, partners, or other users without an explicit permission grant recorded against your account.
  • We do not sell personal data.
  • We do not use your private data to train third-party models.
  • We do not make marketing claims like "bank-grade security" — we describe the specific controls that are actually in place, below.

AI use

The diagnostic, coach, action-plan, pitch review, and summary features send the relevant text you enter to a third-party language model (Google Gemini, via the Lovable AI Gateway) to generate drafts. Outputs are drafts to review, not advice. We do not attach persistent user identifiers to those requests beyond what is required to process them.

Sharing & permissions

  • Mentors see only the founders and sessions they are matched with.
  • Admins and success managers can see founder profiles for pipeline support; every admin read/write of a founder record is logged in the audit trail.
  • Private mentor notes are never shown to founders; founder-visible summaries are separate rows a mentor explicitly sends.

Security controls in place

  • Role-based access (founder / mentor / admin / success manager).
  • Row-level security on every user-owned table.
  • TLS in transit for all traffic to the app and database.
  • Secrets held in the platform secret store; never checked into code.
  • Server-side input validation with schema checks on every write.
  • Parameterised queries via the Supabase client (no string-built SQL).
  • React auto-escapes rendered content; no raw HTML from user input.
  • Audit logs for admin actions and account-lifecycle events.

We do not currently hold SOC 2, ISO 27001, HIPAA, or PCI attestations. If your organisation requires one before onboarding, contact us.

Your controls

  • Export your data from the Profile page — returns a JSON file of everything you own.
  • Delete your account from the Profile page. Data is removed within 7 days of confirmation, except records we are legally required to retain (see retention below).
  • Notification preferences are configurable per event and channel.

Retention

  • Active accounts: retained while the account is active.
  • Deleted accounts: personal data purged within 7 days; anonymised aggregate metrics may be kept.
  • Audit logs: retained for 12 months for security and compliance.
  • Backups: rolling 30-day window; deletions propagate on the next rotation.

Incidents

If we discover a security incident affecting your data, we will notify affected accounts by email within 72 hours of confirmation and post an update on the Trust page describing what happened, what was affected, and what we did about it.

Contact

Questions or requests: privacy@bottleneck.fit