Prospektor
  • What we build
  • How it works
  • Who we work with
AI_FIRST Apply to work with us
privacy

What we do with data.

This covers two things: this website, and Prospektor Partner Studio — the tool where a sales team researches a target company and drafts the material to approach it. It's written to be read. Where the honest answer is unflattering, it's here anyway.

Last updated 15 August 2026 · Questions or requests: privacy@prospektor.ai
Contents 01 Who we are 02 If you have a studio account 03 If you applied to work with us 04 If your name came up in research 05 If you opened a shared pitch 06 Cookies, tracking and providers 07 How long we keep it 08 Your rights, and how to use them 09 Keeping workspaces apart 10 Changes to this page
01

Who we are

Prospektor builds go-to-market infrastructure for funded startups. Part of that is Prospektor Partner Studio: a client's sales team enters a target company, the studio researches it, scores it as a partner, drafts sales material, and lists the people worth approaching there.

We decide how this website and the studio itself handle personal data, so for that we're the data controller. For the research and drafts produced inside a client's workspace, we're acting on that client's instructions — they choose which companies to research and what to do with the result. We're settling the formal split of responsibility with each client in writing; if you need to know where that stands for a particular workspace, ask us.

There's no data protection officer. privacy@prospektor.ai reaches a person.

02

If you have a studio account

You sign in with Google. There's no password to set — we never see one — and there's no other way in. Google tells us your email address, your full name, your given and family name, and the URL of your profile picture. We link to that picture; we don't copy or re-host it.

Your email address is your account identifier, and it's written onto the records you create so the workspace can show who did what:

  • who started each research run
  • who saved each edit
  • who created each share link — email and first name, because the link greets the reader by the sender's first name
  • who archived or deleted a pitch

Everything else in a workspace is the work itself: the target company, the website, any notes typed in, a point of contact if someone entered one, the research result, the drafted material, the progress log and later edits.

03

If you applied to work with us

The application form at app.prospektor.ai asks for your name, work email and company, then nine questions about your business. Your answers are handled by Netlify's form service and reach us as an email. We read them to decide whether we're a fit and to reply to you — that's it.

We don't add you to a mailing list, because we don't run one. There's no automatic deletion here either: applications stay until someone removes them. Ask us and we'll delete yours.

04

If your name came up in someone's research

This section is for people who never signed up for anything. If you've been told, or suspect, that your name is in a Prospektor research result, this is the part that applies to you.

When a client researches a target company, the studio produces a list of the people worth approaching there. For each person it may hold:

  • name
  • job role
  • a LinkedIn profile URL, where a source actually contained one
  • a sentence on why that person is the right one to approach now
  • a confidence rating, and the URL of the source the name came from

Where it comes from

Publicly available web sources, found by an AI model running up to ten web searches during a single run. We don't buy contact lists and we don't take anything from behind a login. The studio is instructed never to invent a person: if it can't attach a credible source to a name, it returns the role with the name left blank.

The research itself doesn't collect personal email addresses or phone numbers. A user can type free-text notes into a run, though, so anything they choose to type is stored with it.

Why we think we're allowed to

We rely on legitimate interests — ours and our client's interest in working out who to approach about a business partnership. What we hold is professional information, published in a professional context, about your job rather than your private life, and limited to what's needed to decide whether to contact you. Weighed against that, we think the intrusion is small. You're entitled to disagree, and the balance is yours to challenge: see your rights.

How you'd know

We don't write to people to tell them they've appeared in a run. We usually hold no way to reach them — no email address, no phone number — and doing it at the volume the studio produces would mean contacting far more people than any client ever approaches. This page is the notice instead. If you want to know whether you're in there, ask and we'll look.

Who sees it

The list is visible to the client's team inside their own workspace. It isn't sold, published, or shared with anyone else — except that a pitch containing it can be shared with a named person by link, which is covered in section 05. It's processed by the providers in section 06, and it isn't deleted on a schedule: see section 07.

object

If you'd rather not be in a decision-maker list, email privacy@prospektor.ai with your name and employer and we'll remove you. We won't ask you to justify it.

05

If you opened a pitch someone shared with you

A finished pitch can be shared as a link. To read it you sign in with Google, so you end up with an account too — but you came for someone else's document, and this is the part you're least likely to expect:

We record your email address, your name, when you first opened the link, when you last opened it, and how many times you've opened it. The team that sent the link can see all of that, listed under their shared links.

So the sender can tell whether you read it once or five times, and when. If you'd rather they couldn't, don't open the link — or email us and we'll remove your row.

A share link shows one pitch and nothing else. Everything else in the studio refuses a share-link account, and an account created this way doesn't get a workspace of its own. A link can be revoked, which stops it working immediately for everyone including people who already read it — but the record of who opened it survives revocation.

06

Cookies, tracking, and who else touches the data

No analytics. No advertising. No third-party trackers, no session recording, no fingerprinting. There's no cookie banner because there's nothing to ask you to consent to.

The studio sets three cookies, all of them functional:

  • pps_session — signed, HttpOnly, Secure, SameSite=Lax, expires after 12 hours. Your name, email and picture URL sit inside the cookie itself; there's no session database behind it.
  • pps_oauth_state — 10 minutes, protects the sign-in against cross-site request forgery.
  • pps_share — 10 minutes, remembers which share link sent you to the sign-in page.

The last two are cleared as soon as sign-in finishes.

This website serves its fonts from its own server, so loading any page here makes no third-party request at all — nothing about your visit reaches anyone but us. The studio still loads its fonts from Google Fonts, which means your browser fetches them from Google and Google sees your IP address. That's the one remaining third-party request anywhere in the product, and the same fix is coming to the studio.

Providers who process data for us

WhoWhat reaches themWhy
Anthropic As prompts to the Claude API: the client's brief, the target company name and website, the user's notes, and any brand-voice examples. The model runs up to 10 web searches per run through Anthropic's search tool. The research and the drafting
Netlify Hosting, the code that runs the studio, all stored data, DNS for prospektor.ai, and the application form on this site. Infrastructure
Google Sign-in through OAuth. Separately, Google Fonts receives the IP address of anyone loading a studio page — not this website, which hosts its own fonts. Authentication, typography

Not used, so you can rule them out: no payment processor, no CRM integration, no marketing email tool, no analytics or advertising vendor of any kind.

Anthropic and Netlify both process data outside the European Economic Area, mainly in the United States. That's an international transfer, and it needs a documented safeguard — we're working that through with both providers, and you're welcome to ask us where it stands.

07

How long we keep it — and what "delete" actually does

Nothing expires on its own. There is no automatic deletion and no retention limit in the product today. A run from January is still there in December unless somebody removed it.

What a user can do from inside the studio:

  • Archive a pitch — hidden from the list, fully recoverable.
  • Delete a pitch — removed from storage.
  • Revoke a share link — stops working immediately for everyone, including people who already opened it. The share record and its list of viewers are kept, stamped with the time of revocation.

Two things that catch people out:

  • Deleting a pitch doesn't delete everything derived from it. Drafts a user edited may have been kept as brand-voice examples so future runs sound like that team, and those examples outlive the pitch. It's deliberate — un-learning a writing style is its own decision — but it means "delete the pitch" is not "delete everything".
  • Share links can carry an expiry date in the underlying API, but nothing in the interface sets one. Every link created today stays open until someone revokes it.

There is no self-service account deletion and no export button. Both exist only as a person doing it by hand, on request. We'd rather say that than imply a button that isn't there.

08

Your rights, and how to use them

If you're in the UK or EU, you have the right to see what we hold about you, correct it, have it deleted, object to us holding it at all, get a copy in a portable form, and complain to your national data protection authority. We apply the same to everyone wherever they are, because running two standards is more work than running one.

To use any of them, email privacy@prospektor.ai. Tell us what you want and enough to find you: for section 04, your name and employer; for section 05 or an account, the email address you signed in with. If we can't identify you from that, we'll ask for more rather than refuse.

What then actually happens: a person goes and does it by hand. We'll confirm when it's done, and we'll come back to you within a month at the outside — normally much sooner. Where the data sits inside a client's workspace, we'll act on it and tell that client.

09

Keeping workspaces apart

Every stored record is namespaced by client, and the workspace is resolved fresh from your signed-in email on every single request. One client's data isn't addressable from another client's session, and removing somebody from a client's allowlist takes effect immediately rather than at their next sign-in. That behaviour is covered by automated tests.

Signing in at all needs one of three things: being on a client's email allowlist, an invitation to create a workspace, or a live share link. A share link gets you sight of one pitch — every other part of the studio refuses it. Speaker notes, compliance findings and the internal progress log never leave the workspace they were made in.

No system is perfect, and we'd rather describe what we actually do than promise it can't be broken.

10

Changes to this page

If we change what we collect, we change this page and move the date at the top. Where it's a material change for people with accounts, we'll say so in the studio rather than hope you re-read this.

Also Terms of service → privacy@prospektor.ai
Prospektor
The AI-first GTM agency
  • Privacy
  • Terms
hello@prospektor.ai