Privacy Policy
What we collect when you use Devora Pitch, why we hold it, who else sees it, and what you can ask us to do about it.
Last updated 11 August 2026Who we are
Devora Pitch is operated by DevoraHub. This policy explains what we collect when you use the service, why, who else sees it, and what you can do about it. Questions go to contact@devorahub.com.
What we collect
Account details — your name, email address, password (stored only as a PBKDF2 hash, never in readable form), and the times you sign in.
Your professional profile — the overview, positioning, skills, hourly rate, availability, weekly hours, timezone, Upwork profile URL, and the kinds of work you have told us you will not take.
Work you add — portfolio projects, documents you upload, and past proposals you save as writing-voice references. Uploaded documents are converted to text in your browser; we store the extracted text, not the original file.
What you do in the product — job postings you paste for analysis, the analyses returned, proposals generated, applications you track, and their outcomes.
AI usage records — for each request: which feature, which model, token counts, duration, and whether it succeeded. Used for cost accounting and plan limits.
Administrative records — an audit log of significant actions, so account changes can be traced.
Why we can use it
We process your account details, profile, work and product activity to perform the contract you enter when you sign up — without them the service cannot function.
We process AI usage records and audit logs under our legitimate interests in running the service safely, enforcing plan limits, and accounting for cost.
Where we send you a message that is not required to operate your account, we rely on your consent, which you can withdraw.
Who else processes it
Cloudflare hosts the application, database and file storage, and provides the AI models. Your profile and the job postings you submit are sent to Cloudflare Workers AI to produce analyses and proposal drafts. We do not use a third-party model provider outside Cloudflare.
Stripe processes payments. We never see or store your card details; we store the customer, subscription and checkout identifiers Stripe gives us.
Our email provider delivers verification codes, sign-in codes and account notices over SMTP.
We do not sell your data, and we do not share it with advertisers.
Your content and AI training
Your profile, portfolio and proposals are sent to the AI model only to produce a result for you, in that request. We do not use your content to train models, and we do not pool one account's content into another account's results.
How long we keep it
Account and profile data are kept while your account exists.
Tracked applications are removed automatically once they pass the retention period your plan sets — 365 days on current plans. Plans marked unlimited keep them until you delete them.
Invoices and payment records are kept for as long as tax and accounting law requires, even after an account is deleted.
Failed sign-in records are kept for 15 minutes and then discarded.
Your rights
Get a copy — Settings has an export that downloads your account, profile, proposals, applications and AI history as JSON. It is available on every plan.
Delete your account — Settings schedules permanent deletion after a 14-day grace period, during which you can cancel by signing in. When it runs, your profile, portfolio, documents, analyses, proposals, applications, AI history and sessions are removed. Invoices are kept as above.
Correct or object — you can edit your profile at any time, or write to us to correct anything else, object to processing, or ask us to restrict it.
To exercise any of these, or to complain, write to contact@devorahub.com. If you are in the UK or EU you may also complain to your national data protection authority.
Security
Passwords are hashed with PBKDF2-SHA256. Sign-in requires a one-time code sent to your email in addition to your password. Provider credentials we hold on your behalf are stored encrypted. Sign-in attempts are rate limited, and you can sign out other devices from Settings.
No system is perfectly secure. If a breach affects your data we will tell you and the relevant authority as the law requires.
Children
The service is for people aged 18 and over and is not directed at children.
Changes
We will post any change here and update the date above. If a change materially affects how we handle your data we will tell you by email before it takes effect. Last updated 11 August 2026.