← Back to askOdin Crucible
The Crucible

Privacy Policy

Effective Date: August 21, 2026
Service: crucible.askodin.app
Operator: askOdin Pte Ltd

1. Introduction

askOdin Pte Ltd ("askOdin," "we," "us," or "our") operates Crucible, an AI-powered pitch deck analysis service. This Privacy Policy explains how we collect, use, disclose, and protect information when you use our Service.

We value the trust you place in us. While our business involves analyzing data to improve the Judgment Graph™, we are committed to protecting your proprietary information against public disclosure.

By using Crucible, you consent to the data practices described in this Policy. This Policy should be read in conjunction with our Terms of Service.

2. Information We Collect

2.1 Content You Upload (The "Pitch Data")

When you upload a pitch deck for analysis, we collect:

Important: Your raw pitch deck is Confidential Information. We do not publish it, sell it, or share it with investors. No customer document enters any training corpus — not ours, and not our model vendor's.

2.2 Account Information

If you create an account, we collect:

2.3 Information from Third Parties (Team Members)

Your pitch deck likely contains personal data of your co-founders, employees, or advisors (e.g., photos, bios). We collect this information strictly for the purpose of analyzing the "Team" component of your pitch.

Your Responsibility: As the uploader (Data Controller), you represent that you have obtained the necessary consent from these individuals to share their data with us (Data Processor).

2.4 Automatically Collected Usage Data

3. How We Use Your Information

We use your data for two distinct purposes, relying on specific legal bases under the PDPA (Singapore) and GDPR (EU).

3.1 Service Delivery (Performance of Contract)

3.2 How the Analysis Actually Works

Extraction runs against an external model API under a paid-tier agreement that prohibits training use; the deterministic engine does the analysis. Concretely:

We do not train models on your data. We do not fine-tune, and we do not send your documents to any vendor that trains on them.

3.3 Product Improvement (Legitimate Interest / Deemed Consent)

Legal Basis: We rely on "Deemed Consent" (PDPA) and "Legitimate Interest" (GDPR) for product improvement.

4. How We Share Your Information

4.1 Internal Use Only

We do NOT sell, rent, or publicly display your raw pitch deck.

4.2 Aggregated & Anonymized Data

We MAY share or commercialize Aggregated and Anonymized Data.

Example: We may sell a report to investors stating, "In 2025, 40% of Singaporean Fintechs emphasized AI in their opening slide." Your specific startup cannot be identified from this data.

4.3 Sub-Processors

These are the third parties that process data on our behalf. This list is exhaustive as of the effective date above.

Confidentiality: All sub-processors are bound by confidentiality and data protection obligations. We do not use OpenAI or Anthropic models, and we do not host on AWS directly — earlier versions of this policy said otherwise and were incorrect.

4.4 Legal Requirements

We may disclose your information if required by law, court order, or governmental regulation (e.g., inquiries from the Singapore Police Force, MAS, or PDPC).

5. Data Retention & Anonymization

5.1 Raw Documents

Raw documents are held no longer than 30 days under a documented retention ceiling. What persists beyond that is derived — the verdict, the judgment analysis, and structural data in the Judgment Graph™ benchmark corpus. No customer document enters any training corpus.

Please read this precisely. The 30-day figure is a ceiling under a documented policy, not a guarantee that a file is destroyed on day 30. Automated enforcement of this ceiling is in progress and ships alongside our SOC 2 Type I process; until it does, deletion is a documented policy carried out on request. To request deletion of your uploaded file, email [email protected].

5.2 What the Judgment Graph™ Retains

After analysis, we retain derived records indefinitely as a benchmark corpus. This is not a training dataset and is not used to train any model. It currently contains, for each analysis:

We are not going to call this anonymized, because it is not. Company and founder names are personal data under the PDPA and GDPR, and your rights under section 7 apply to them in full. If you ask us to erase your Judgment Graph™ record, we will erase it. Reducing this corpus to genuinely de-identified structural data is planned work — see section 5.3.

5.3 Which of These Are Implemented, and Which Are Policy

A stated policy is not an implemented control, and an implemented control is not an evidenced one. Here is where each of our data-handling commitments actually sits. We would rather you know than assume.

Implemented In Progress Planned
No training on customer documents (there is no fine-tuning or training pipeline in our system at all).

Paid-tier model API under a no-training agreement.

Deterministic engine performs all judgment; the model only extracts.

Encryption in transit; access controls on production systems.

Raw files are never published, sold, or shared with investors.
Automated enforcement of the 30-day retention ceiling. Today the ceiling is policy; deletion is performed on request. Ships with SOC 2 Type I.

Logging of staff access to customer documents. Not currently in place.

SOC 2 Type I readiness.
Reducing the Judgment Graph™ to genuinely de-identified structural data (see 5.2).

Requesting Google's Zero Data Retention option for our Gemini API project.

Customer-facing deletion controls in the product, so you do not have to email us.

On staff access: as a matter of policy, we do not read customer documents. This is a procedural rule, not an architectural guarantee — our engineers hold credentials that would technically permit access, and that access is not yet logged. We are telling you this because a policy you cannot verify is worth less than one you can, and we would rather be accurate than reassuring.

6. International Data Transfers

askOdin is based in Singapore. If you are accessing the Service from the EU, US, or other jurisdictions, you acknowledge that your data will be transferred to, stored, and processed in Singapore and/or the United States. We utilize standard contractual clauses (SCCs) or comparable mechanisms to ensure data protection compliance.

7. Your Rights

Depending on your jurisdiction (Singapore PDPA, EU GDPR), you may have the right to:

To exercise these rights: Email us at [email protected].

Note: Deletion requests cover your raw file, your account data, and your Judgment Graph™ record, because that record contains personal data (section 5.2). We may retain aggregate statistics in which you cannot be identified — for example a sector-level median score computed across thousands of analyses.

Honest note on timing: deletion is currently performed manually on request rather than by an automated job. We action requests within 30 days.

8. Data Security & Breach Notification

We implement industry-standard security measures (encryption, access controls) to protect your data.

Breach Notification: In the event of a data breach affecting your personal data that is likely to result in significant harm, we will notify you and the relevant authorities (including the PDPC) in accordance with applicable laws.

9. Data Protection Officer (DPO)

In accordance with the Singapore Personal Data Protection Act (PDPA), we have appointed a Data Protection Officer to oversee our privacy practices.

Data Protection Officer
askOdin Pte Ltd
Email: [email protected] (Subject: "Attn: DPO")

10. Changes to This Policy

We may update this Privacy Policy to reflect changes in our practices. We will notify you of material changes by posting the new Policy on this page with a new "Effective Date."

11. Contact Us

If you have questions about this Policy or our data handling practices, please contact us at:

askOdin Pte Ltd
Email: [email protected]
Website: crucible.askodin.app


Last Updated: August 21, 2026 | Version: 3.0

← Back to askOdin Crucible