Privacy Policy
Last updated 2026-08-18
This Privacy Policy explains how Venture Cortex collects, uses, and protects information about you when you use the Venture Cortex platform (the Service). We are committed to handling your data with care and transparency.
Information We Collect
We collect the following categories of information:
- Account information: Your name and email address, collected and managed by Clerk (our authentication provider) when you create an account.
- Venture data: Business ideas, session notes, proposals, decisions, and other content you enter into the platform.
- Session data: Records of AI council sessions, including model outputs, scores, and structured proposals.
- Usage data: Browser analytics about how you use the platform (pages visited, features used) are collected via PostHog only if you have consented to analytics cookies.
- Service events: Our servers also record a small number of account-lifecycle events — such as a trial starting or a session being created — against your account identifier, so we can operate and bill the Service. These are not cookie-based and are recorded whatever your cookie choice.
- Billing information: Payment method details handled directly by Stripe. We do not store full card numbers.
How We Use Your Data
We use your information to:
- Provide, operate, and improve the Service.
- Run AI council sessions by transmitting your venture data to AI providers.
- Process payments and manage your subscription.
- Send you service-related communications (account notices, billing receipts).
- Analyze usage patterns to improve features (only with analytics consent).
- Comply with legal obligations.
We do not sell your personal data to third parties. We do not use your data for advertising purposes.
AI and Research Providers
The core function of the Service requires sending your venture data to third-party AI providers for analysis. The council seats are:
- Anthropic (Claude Opus 5) — anthropic.com
- OpenAI (GPT-5.6 Sol) — openai.com
- Google (Gemini 3.1 Pro) — google.com
- xAI (Grok 4.5) — x.ai
- Moonshot AI (Kimi K3) — moonshot.ai
- OpenRouter — openrouter.ai. Used as a fallback routing layer for some of the models above when a direct provider connection is unavailable. When it is used, your prompt content passes through OpenRouter to reach the model.
Sessions also gather public context from the web. The following research providers receive search queries and research prompts derived from your venture data — which may include your company, product, market, or competitor names:
- Exa — exa.ai (semantic web search)
- Brave Search — brave.com (web search)
- Perplexity — perplexity.ai (research synthesis)
- Virlo — virlo.ai (company and founder enrichment)
- ScrapeCreators — scrapecreators.com (public social content from Reddit, YouTube, X)
We transmit only the data necessary for each session. We engage the AI providers under terms that prohibit them from using your data to train their models. However, each provider operates independently and you should review their respective privacy policies. Do not submit data that you are not authorized to share with third-party AI systems.
Infrastructure Subprocessors
We rely on the following providers to operate the Service. Each may process personal data on our behalf in the course of doing so:
- Convex — primary application database. Stores your account record, venture data, and session records.
- Clerk — authentication and account management. Holds your email, name, and credentials.
- Stripe — payment processing, subscriptions, and tax calculation. Holds your billing details and payment method; we store only a Stripe customer ID.
- Vercel — hosting and content delivery for the web application. All traffic to the site passes through Vercel, including IP addresses and request metadata.
- Railway — hosts the background worker that runs council sessions.
- Inngest — job orchestration. Receives session dispatch events containing session identifiers, topics, and scheduling metadata.
- Resend — transactional email delivery. Receives your email address, name, and the content of the emails we send you (such as digests and account notices).
- Sentry— error monitoring. Receives error messages, stack traces, and surrounding request and user context when something fails. Sentry's browser session replay is enabled only if you consent to analytics cookies.
- PostHog — product analytics, used only with your analytics-cookie consent. Receives usage events linked to your account identifier.
- Cloudflare— bot protection presented during sign-in, loaded as part of our authentication provider's flow.
If you choose to connect your own third-party account to a venture (for example your own PostHog project or Stripe account) to pull in metrics, we send requests to that service using the credentials you supply. That connection is under your control and you can remove it at any time.
The list above is our current subprocessor list. We will update it here when a subprocessor is added or replaced. If you need a Data Processing Agreement for your own compliance requirements, contact us and we will put one in place.
Data Storage and Security
Data is encrypted in transit and at rest by our infrastructure providers. Access to production data is limited to the operator of the Service.
We implement reasonable technical and organizational measures to protect your data. No system is completely secure, and we cannot guarantee absolute security. If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority and, where required, you.
International Data Transfers
We operate from Bulgaria (EU). Several of the providers listed above are established outside the European Economic Area, principally in the United States. Where personal data is transferred outside the EEA, we rely on the transfer mechanisms offered by those providers, such as the European Commission's Standard Contractual Clauses or an applicable adequacy decision.
If you need the specific transfer mechanism and hosting region for a particular subprocessor, contact us and we will confirm it in writing.
Data Retention
- Active accounts: Your data is retained for as long as your account is active.
- Account deletion: When you delete your account, your personal data and venture data are permanently purged within 30 days.
- Billing records: Financial transaction records may be retained longer where required by law.
Your Rights
Depending on your location, you may have rights under GDPR, CCPA, or other applicable privacy laws, including:
- Access: Request a copy of the personal data we hold about you.
- Correction: Request correction of inaccurate data.
- Deletion: Request deletion of your account and associated data.
- Export: Request an export of your venture data in a portable format.
- Opt-out: Opt out of analytics data collection via cookie preferences.
To exercise any of these rights, contact us at support@venturecortex.com. We will respond within 30 days.
Children's Privacy
The Service is not directed at children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us immediately.
Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes via email or an in-app notice. Continued use of the Service after changes take effect constitutes acceptance of the revised policy.
Contact
For privacy-related questions or requests, contact us at support@venturecortex.com.