Back to Home

Privacy Policy

Last Updated: September 1, 2026 | Version 4.0

KRTR.ai, operated by KRTR, Inc., a Delaware corporation ("Company," "we," "us," or "our"), respects your privacy. This Privacy Policy explains how we collect, use, disclose and safeguard your information when you use our platform and services (the "Service").

This policy is designed to comply with the California Consumer Privacy Act (CCPA), the California Privacy Rights Act (CPRA), the EU General Data Protection Regulation (GDPR), the UK GDPR and other applicable privacy laws.

1. Our Role: When We Are a Controller, and When We Are a Processor

This is the first thing to understand, because it determines who you ask about what.

1.1 We are a controller for

  • Your account: name, email, credentials, profile, role, billing relationship.
  • Your use of the Service: usage events, device and log data, cookies.
  • Founder Workspaces — a company's pitch materials and the analyses generated from them — where we provide analysis directly to that founder.
  • Sourced Deals — deal records we compile and maintain ourselves.
  • Our own business records, security monitoring and legal compliance.

For all of the above, we decide the purposes and means of processing, and you exercise your rights directly with us.

1.2 We are a processor for

  • Data held within a firm's or an individual investor's account: their records, notes, memoranda, diligence materials, private workspaces (deal vaults), configuration, member roster, and the dispositions, signals, tags and assessments recorded there.

For this data our customer is the controller. We process it on their documented instructions, we do not decide what it is used for, and our commitments to them are set out in the KRTR Data Terms for Investors and Firms and in any negotiated agreement.

What this means for you if you are a firm member. If you want to know what your firm holds about you within its account, or to have it corrected or removed, that request goes to your firm. We will support your firm in answering it, and we will forward a request you send us. Requests about your own KRTR account — the account itself, your login, your personal data outside your firm's account — come to us directly.

1.2a Workspaces created about a company that has not claimed them

A customer may create and analyse a workspace about a company whose founder has never signed in. Until that founder is linked to the workspace, we are the controller of it and a request about it comes to us. Once the founder is linked, the workspace is theirs, they control its visibility, and we remain the controller in that capacity. We tell a founder what exists about them when they claim a workspace, and Section 10 applies either way.

1.3 A data processing agreement is available

Firms and investors may request a data processing agreement, our current sub-processor list, and a copy of the transfer safeguards we rely on, by contacting privacy@krtr.ai.

1.4 Which document governs

Three documents apply to you, and where they conflict this order decides, highest first:

1. a negotiated written agreement signed by KRTR and a customer, as to the subject matter of that agreement; 2. the KRTR Data Terms for Investors and Firms, as to any matter they address; then 3. the Terms of Service and this Privacy Policy.

Where this Policy and the Data Terms differ as to data we hold as a processor under 1.2, the Data Terms govern. So, for example, this Policy offers an opt-out from training our own models (Section 5.4) — but for data under the Data Terms we do not train on it at all, which is the better position and the one that applies.

2. The Three Layers, and How Each Moves

The Service holds three kinds of thing, and they travel very differently:

Owned byHow it travels
Founder Workspace — a company's pitch materials and the analyses generated from themThe founderPortable by design. The founder sets its visibility, and it moves between founders, investors and firms on that basis.
Sourced Deals — deal records we compile and maintainKRTRAvailable to users of the Service generally. The same record may appear in many pipelines at once.
Your own work — the notes, memoranda, diligence, dispositions, signals, tags, assessments and pipeline placement you record, and the private workspaces you keepYou, or — where you work inside a firm's account — your firmPrivate by default. It leaves your account only as Section 6 permits, and a new feature does not change that.

3. Information We Collect

3.1 Information you provide directly

  • Account information: name, email address, password, profile photo, phone number, company or firm name, job title.
  • Uploaded material: pitch decks, business plans, financial data, market research, team information, memoranda, diligence documents and other files you upload or enter.
  • Your own work product: notes, assessments, dispositions, signals, tags, pipeline placement and private workspace contents.
  • Professional profile data: if you connect a professional network account, we access your profile, work history, education and skills as permitted by that network. We do not access your connections or network graph.
  • Communications: what you provide when contacting support or giving feedback.
  • Payment information: processed by our third-party payment processor and not stored on our servers.

Sensitive personal information. Under California law, account credentials in combination with a password are sensitive personal information. We collect them only to authenticate you and secure your account, use them for no other purpose, and do not sell or share them — so the "limit the use of my sensitive personal information" right in Section 10.1 is already satisfied by our practices.

3.2 Information collected automatically

  • Usage data: pages visited, features used, actions taken, time spent, interaction patterns.
  • Device information: browser, operating system, device type, screen resolution, language.
  • Log data: IP address, access times, referring URLs, error logs.
  • Cookies and similar technologies: see Section 9.

Where we hold data about you that you did not give us. Sections 3.3 below describes three such sources: a roster supplied by a firm, publicly available professional profiles, and the deal records we compile ourselves. Where GDPR Article 14 applies, we provide this Policy as the required notice at the point of first contact with you, and otherwise rely on Article 14(5)(b) where individual notice would involve disproportionate effort — in which case this Policy, our public disclosure of these sources, and your rights under Section 10 are the compensating measures. You may always ask us what we hold about you and where it came from, and we will tell you, including which firm supplied a record.

3.3 Information from third parties

This Section changed materially in v4. Read it if you did not sign yourself up.

  • Sign-in providers. When you sign in with a third-party identity provider, we receive basic profile information as authorised by you.
  • From a firm you belong to. A firm that uses the Service may provide us with a roster of its members — typically name, business email address, role and membership status — drawn from the firm's own records or its customer relationship management system. This means we may hold a record about you before you have ever signed in, and that record came from your firm, not from you. The firm is the controller of that roster; we hold it as a processor under Section 1.2. If you want to know why we hold your details, or to have them corrected or removed from a firm's roster, that request goes to the firm. We will tell you which firm provided a record about you if you ask.
  • Single sign-on connections. Where a firm operates a sign-on connection, we receive the identity attributes that connection asserts.
  • Publicly available business information, collected to support analysis features.
  • Publicly available professional profiles of team members identified in uploaded materials, used solely to generate the requested analysis. No private profile data is accessed for people who are not users of the Service.
  • Systems you connect. Where you authorise us to read a system you control — for example a customer relationship management system — we receive the records that authorisation covers. We read only; we do not write to those systems.

4. How We Use Your Information

  • Providing the Service: creating and managing accounts; processing and analysing uploaded material; generating assessments, reports and recommendations; enabling collaboration and sharing features you use; supporting you.
  • AI processing: see Section 5.
  • Benchmarks: computing de-identified range, benchmark and peer-standing statistics across the Service. These do not identify you, your company, your firm, your positions or any individual deal. Where we hold data as a processor under 1.2, we compute these only as our customer's Data Terms authorise, and never below a cohort size at which a statistic could describe a single deal.
  • Improving our models: using anonymised and aggregated content, which you may opt out of — see Section 5.4. This does not apply to data we hold as a processor under 1.2, which is never used this way.
  • Analytics and security: understanding usage, detecting and preventing abuse and security threats.
  • Communication: service notifications; responding to you; marketing only with separate opt-in consent.

5. AI Processing

5.1 What happens to material you submit for analysis

Analysis on the Service — scoring, reports, screening and related outputs — is performed by third-party foundation-model providers we engage. Material you submit for analysis is transmitted to those providers for the sole purpose of generating the output you requested.

5.2 The standard we hold providers to

We engage only providers that (a) operate under enterprise terms restricting the use of customer data to train or improve their models absent the customer's permission, (b) maintain a recognised independent security certification such as SOC 2 Type II, and (c) are bound by confidentiality obligations no less protective than our own.

Analysis processing runs within the managed infrastructure of our cloud provider, including partner and third-party publisher models served inside that infrastructure as a managed service. We operate a failover cascade, so the specific model serving an individual request may vary within the set meeting that standard.

5.3 Private workspaces are excluded by default

Contents of a private workspace (deal vault) are not indexed and are not transmitted to a model provider, with the following exceptions:

  • Per-run selection. You or a user you authorised explicitly selects specific items to inform a single analysis run. Only those items are transmitted, for that run alone; the selection is not retained and does not make the material indexed or searchable. Facts drawn from those items are recorded in the workspace's analysis record and inform later runs.
  • Promotion to active materials. You explicitly move an item out of the private workspace into a deal's active materials. From that point it is treated like any other uploaded material — it is retained, later analyses read it, it may be indexed, and a report that quotes it carries the quote if that report is shared. This is a deliberate action, not a default.
  • A model provider you chose yourself, as described in 5.5.

5.4 Training

We do not grant any provider permission to use your material to train, fine-tune or improve that provider's models, and we do not enable any setting having that effect.

Separately, we may use anonymised and aggregated content to train and improve our own models. Identifiers are removed first and content is combined across users so no individual project can be reconstructed. You may opt out by contacting privacy@krtr.ai; opting out does not affect your access. Content already anonymised into a training dataset cannot be withdrawn, because it is no longer identifiable.

Data we hold as a processor under 1.2 is never used to train any model, other than a model built for that customer's own use on the platform, as their Data Terms permit.

5.5 Models you choose yourself

If you connect an external agent client or supply your own model credentials, data within your authorised view is transmitted to the provider you selected. That provider is not engaged by us and is outside the standard in 5.2. You are responsible for that choice.

6. How We Share Information

We do not sell personal information.

6.1 Service providers (sub-processors)

We share information with providers who help us operate the Service. Each is bound by contract to protect it and to use it only to provide services to us. The categories are:

PurposeWhat is shared
Cloud infrastructure, authentication, database and file storageAccount data, uploaded material, all stored Service data
AI model processing (served as a managed service within our cloud provider's infrastructure, including partner and third-party publisher models)Material submitted for analysis
Application hosting and deliveryRequest and log data
Caching and background job queueingTransient operational data and identifiers
Transactional and notification emailRecipient email address and message content
Payment processingBilling details, handled by the processor and not stored by us
Product analytics (EU-hosted, consent-gated — see Section 9.1)Usage events; never the content of your documents, notes or assessments
Anonymous website analytics on public marketing pagesAnonymous pageview data; no identifiers, no tracking cookies
Error monitoring and performance diagnosticsError reports, stack traces, request paths, recent-action trails and diagnostic logs. Share tokens are stripped from URLs before transmission. Session recordings only where you accepted analytics cookies, with text masked and media blocked
Inbound email processingThe full contents and attachments of email sent to a KRTR-hosted address, including the sender's address and authentication results
Team messaging used for our own operational alertsDeal and company identifiers in internal notifications
A messaging or communications system you connectRead access to the messages your authorisation covers, used as deal signal
AI providers engaged directly by us, outside our cloud providerMaterial submitted for analysis on internal, staff-operated tooling
External tool servers you connect yourselfData your request sends to the server you authorised. That server is chosen by you and is not engaged by us
URL content extraction used by research featuresA URL you provide, which the provider then fetches itself. Do not paste a link to material you would not want that provider to retrieve
Web search and research used by research featuresSearch terms and company identifiers derived from the material being analysed. Your uploaded documents are not transmitted to these providers
Public research and patent databasesSearch terms only
Professional profile lookupNames and profile identifiers of people named in materials being analysed
A customer relationship system you connectRead-only access to the records your authorisation covers

The named list is published at krtr.ai/subprocessors and is also available on request at privacy@krtr.ai, so that it stays accurate between versions of this policy. A change to the list is not a change to this policy and does not reduce any commitment in it.

Two different standards apply, and they are not the same. Foundation-model providers must meet the standard in 5.2, and we will give notice before engaging one that does not. Our other sub-processors — search, research, profile lookup, error monitoring, messaging and similar services — are held to a lower but real bar: a written data-protection agreement, purpose limitation to the service they provide for us, no onward sale, and confidentiality obligations no less protective than our own. Not all of them hold an independent security certification, and 5.2 does not represent that they do.

6.2 With your consent, and through features you use

We share information where you cause it — through the Service's sharing and access controls, through your firm's configuration, or by opting in to a feature. A feature that would cause your own work to leave your account in identifiable form requires your consent first, and consent to one such feature is not consent to another.

6.3 Anonymised rendering across accounts

Where a deal is shared beyond your account, other users may see the substance of an assessment rendered without attribution — no individual name and no organisation identity. Private workspace contents do not circulate by default or as a side effect of an analysis; they leave an account only by the named actions in Section 5 of the Terms of Service, and within a firm they are visible as that firm's configuration provides (Section 6.4).

6.4 Within a firm

If you use the Service as a firm member, what you record within your firm's account is visible inside that account according to your firm's configuration. Your firm sets that configuration; we act on it.

6.5 Legal requirements

We may disclose information where required by law, regulation, legal process or governmental request, or to protect the rights, property or safety of KRTR, our users or the public. Where we are legally compelled to disclose a customer's data and are lawfully able to do so, we will give that customer prompt notice.

6.6 Business transfers

In a merger, acquisition or sale of assets, information may transfer as part of the transaction. We will notify you. A change of control does not of itself reduce commitments we have made to a firm or investor customer, and any successor assumes them.

7. Data Security

We implement appropriate technical and organisational measures, including:

  • Encryption of data in transit (TLS/SSL) and at rest.
  • Access controls and authentication.
  • Account-scoped isolation of stored data.
  • Access by our personnel restricted to those with a need to know.
  • Monitoring and regular security assessment.

Breach notification. Where we are the controller, we notify the competent supervisory authority within 72 hours of becoming aware of a personal data breach, as GDPR Article 33 requires, and notify affected individuals without undue delay where Article 34 or applicable state law — including California Civil Code §1798.82 — requires it.

Where we are a processor under 1.2, we notify our customer without undue delay, and in any event within 72 hours, so they can meet their own deadline.

Every notice describes the nature of the breach, the categories and approximate number of records involved, the likely consequences, and the measures taken or proposed to address it.

No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

8. Data Retention

  • Account data (name, email, profile): for the life of the account; deleted within 30 days of account deletion.
  • Uploaded material and your own work: for the life of the account; deleted within 30 days of account deletion, or earlier if you delete it.
  • Private workspace deletions: moved to a recoverable trash for a retention window before permanent deletion.
  • Usage and analytics data: up to 24 months in identifiable form, then aggregated or deleted.
  • Log and security records: up to 12 months.
  • Payment records: 7 years, as required by financial regulation.
  • De-identified aggregate statistics: retained indefinitely; not traceable to any individual and therefore not subject to deletion.
  • Backups: purged on a rolling 90-day schedule.
  • Data held as a processor: retained and deleted per our customer's instructions and the Data Terms, which give them export and deletion on request within 30 days.
  • Data we are required to retain by law is kept for the mandated period.

Records that are not deleted by your request. A Founder Workspace is the founder's, and a Sourced Deal is ours; both may sit in other users' accounts. Deleting your account removes your layer — your notes, assessments and pipeline placement — and leaves the underlying record.

9. Cookies, Tracking and Product Analytics

  • Essential cookies (session): required for authentication, security and basic functionality. Cannot be disabled without affecting the Service. No consent required.
  • Analytics cookies (persistent): help us understand usage. Up to 12 months. We obtain your consent before setting them.
  • Preference cookies (persistent): remember your settings. Up to 12 months. We obtain your consent before setting them.

We do not use cookies for cross-site tracking or targeted advertising. A consent banner is presented on your first visit and your choice can be changed at any time. EEA and UK users: non-essential cookies are set only with your prior consent under the ePrivacy Directive and applicable national law.

9.1 Product analytics and behavioural telemetry

To understand how the platform is used and improve it, we capture usage events (pageviews, feature interactions, time on page, pipeline outcomes) once you are signed in.

We also capture limited anonymous engagement on our public marketing pages before you sign in or answer the cookie banner — pageviews, scroll depth, dwell time, call-to-action clicks, and the campaign parameters in the link you followed. We rely on our legitimate interest (GDPR Art. 6(1)(f)) in measuring whether our own outreach works. That layer stores no IP address, creates no person profile for an anonymous visitor, and never captures page content. You can opt out of it at any time via the link in our footer. Events carry identifiers, durations and dimensions — they do not include the substantive content of pitch decks, documents, notes, assessments or firm-internal comments.

  • Internal analytics store. All authenticated usage events are written to our own store under the legitimate-interest basis (GDPR Art. 6(1)(f)), used for product improvement, abuse detection and operational health. No third party other than our cloud infrastructure provider, which hosts that store on our behalf (Section 6.1), receives this data. You may request access, correction or deletion under Section 10.
  • Third-party analytics processor (EU-hosted, Frankfurt). If you accept analytics cookies, we additionally send the same events to an EU-based analytics processor, which avoids onward transfer for EEA and UK users. It is configured with autocapture off (we never harvest element text from KRTR pages), IP capture off, and session replay off in that processor.
  • Anonymous website analytics on public marketing pages: privacy-preserving pageview counts, no tracking cookies, no personal identifiers.

Opting out. Open the cookie banner from the footer link and select "Essential only." New events go to our internal store only. You may also request deletion of your third-party analytics record under Section 10.

9.2 Do Not Track and opt-out preference signals

Some browsers transmit "Do Not Track" signals, including the Global Privacy Control (GPC). We do not sell personal information and do not share it for cross-context behavioural advertising, so there is no sale or sharing for an opt-out preference signal to opt you out of, and we do not act on GPC or other DNT signals. For other DNT mechanisms there is no industry standard for how to respond. If we ever begin selling or sharing personal information as those terms are defined under California law, we will process opt-out preference signals as the law requires and will update this Policy before doing so.

Backfill on opt-in. If you initially declined and later opt in, we perform a one-time replay of your historical events into the analytics processor so dashboards are immediately useful. Later toggles do not trigger further replays.

10. Your Privacy Rights

Where to send a request. For your KRTR account and anything we hold as a controller (Section 1.1), contact us. For data held inside a firm's or investor's account (Section 1.2), the customer is the controller — send the request to them, and we will support them in answering it. If you are unsure, write to privacy@krtr.ai and we will tell you which applies.

10.1 California residents (CCPA/CPRA)

Right to know; right to delete; right to correct; right to opt out of sale or sharing (we do not sell personal information); right to limit use of sensitive personal information; non-discrimination for exercising these rights. Contact privacy@krtr.ai. We verify identity before processing a request and aim to respond within 45 days.

10.2 EEA and UK residents (GDPR / UK GDPR)

Access (Art. 15); rectification (Art. 16); erasure (Art. 17); restriction (Art. 18); portability (Art. 20); objection (Art. 21); rights related to automated decision-making (Art. 22, see Section 11); withdrawal of consent.

Contact privacy@krtr.ai or our EU Representative (Section 15). We respond within 30 days, extendable by two further months for complex requests, and we will tell you if an extension is needed.

You may lodge a complaint with your local supervisory authority, or with the authority in your country of residence or place of work.

10.3 Lawful bases (EEA/UK)

  • Contract performance (Art. 6(1)(b)): providing the Service — accounts, processing material you submit, generating analyses, support.
  • Legitimate interests (Art. 6(1)(f)): analytics and usage monitoring to improve the Service; security and fraud prevention; computing de-identified benchmark statistics; processing publicly available professional profiles for team analysis; maintaining Sourced Deals. We have assessed these and concluded our interests are not overridden by your rights.
  • Consent (Art. 6(1)(a)): marketing; non-essential cookies. Withdrawable at any time without affecting prior lawful processing.
  • Legitimate interests, with a right to object (Art. 6(1)(f) and Art. 21): training and improving our own models on anonymised, aggregated content. The opt-out offered in Section 5.4 is that right to object, and we honour it on request without asking for a reason. We do not rely on this basis at all for data we hold as a processor under 1.2, which is never used to train any model.
  • Legal obligation (Art. 6(1)(c)): compliance with applicable law, lawful requests and breach notification duties.

Where we act as a processor, our customer determines the lawful basis for their processing.

11. AI-Generated Assessments and Automated Processing

  • Nature. Our models analyse submitted material and generate assessments across multiple dimensions. These are produced automatically, without human review of each output.
  • Purpose. They are analytical tools, not investment decisions, endorsements or binding evaluations.
  • Significance. They are informational, but we acknowledge they may influence decisions made about a company.
  • Human review. EEA/UK users may request human review of an AI-generated assessment they believe significantly affects them. Where we control the assessment — an analysis we generated for a founder's own workspace — write to privacy@krtr.ai and we will arrange for a team member to review the underlying data and the output. Where the assessment was generated inside a customer's account — a firm's or investor's own screening of a deal — that customer is the controller and the request goes to them; write to us and we will identify them and support them in answering it.
  • No solely automated consequential decisions. We do not make solely automated decisions producing legal or similarly significant effects without the ability to request human intervention.
  • Assessments recorded by other users are the judgments of those users, not of KRTR. Where they are rendered beyond the account that made them, it is without attribution (Section 6.3).

12. Children's Privacy

The Service is for users aged 18 and older. We do not knowingly collect personal information from anyone under 18, and will promptly delete it and terminate the account if we learn we have. Contact privacy@krtr.ai.

13. International Data Transfers

Your information may be transferred to and processed in the United States, where our servers and primary providers are located. The United States has not received an adequacy decision from the European Commission.

For transfers from the EEA or UK we rely on appropriate safeguards, including the European Commission's Standard Contractual Clauses for EEA transfers and the UK International Data Transfer Addendum for UK transfers, each incorporated into our providers' data processing agreements, together with our providers' own transfer compliance programmes, including certification under the EU–US Data Privacy Framework where a provider holds it. Where we act as a processor, our customer is the exporter and we are the importer, and the clauses sit between us accordingly. Our EU-hosted analytics processor is configured so that those events are processed within the EU.

You may request a copy of the relevant transfer safeguards at privacy@krtr.ai.

14. Third-Party Links and Services

The Service may link to third-party sites or services. We are not responsible for their privacy practices. Review their policies before providing information.

15. Changes, and Contact

We may update this Policy. We will notify you of material changes by posting the updated policy and, where appropriate, by email, at least 30 days before they take effect. Continued use after the effective date constitutes acceptance. No update reduces a commitment we have made to a firm or investor customer under the Data Terms or a negotiated agreement as to data already held.

  • KRTR, Inc., 1111B S Governors Ave, Ste 58459, Dover, DE 19904, United States
  • Privacy: privacy@krtr.ai · General: info@krtr.ai · Support: support@krtr.ai
  • EU Representative (Art. 27 GDPR): Milan Saes, Marcus Aurelius 34, Born, 6121NX, Netherlands — [milan@crossoceanfund.com](mailto:milan@crossoceanfund.com)

Upgrade required

Buy credits

Top up your credit wallet — covers every founder tool, never expires.

You're on our top tier. Buy credits above for more runs.