Support, Retention & Data Requests

Last updated: 2026-09-04

Product support

StartWith is a cloud-based SaaS platform for founders and small teams to turn project hypotheses into coordinated marketing assets, landing pages, blog posts, social posts, images, email content, subscriber journeys, and campaigns. It includes AI-assisted generation, public publishing, analytics, collaboration, and an authenticated hosted MCP for ChatGPT and Codex.

For product and account support, contact support@startwith.xyz.

Users are responsible for providing accurate account information, protecting their credentials, and ensuring they have the rights needed for all content and data they submit. StartWith may suspend or terminate access in cases such as terms violations, security risks, non-payment where applicable, or legal requirements.

Privacy and data requests

To make a privacy or data request, contact privacy@startwith.xyz.

Requests may relate to privacy rights that apply to you, including (where applicable): access and a copy of personal data; correction; deletion (subject to lawful exceptions); restriction or objection to certain processing; portability for eligible data; withdrawal of consent (where consent is the basis); opting out of marketing communications; and lodging a complaint with the relevant data-protection authority.

StartWith is intended for business users with legal capacity and is not directed to children. A parent or guardian who believes a child submitted personal data should contact privacy@startwith.xyz.

International transfers may occur. Where a safeguard is required for international transfers, StartWith uses an applicable lawful mechanism such as adequacy decisions, contractual protections including Standard Contractual Clauses, or another valid transfer mechanism.

Identity verification and response target

How to submit a deletion or privacy request:
Email privacy@startwith.xyz with the subject “Privacy Request (StartWith)” from an address associated with the account where possible.

To protect users and workspaces, StartWith may take reasonable steps to verify your identity and authority (including workspace authority where relevant) before acting on a request.

Response target: Without undue delay and within the period required by applicable law; GDPR rights requests are generally answered within one month, subject to permitted extensions.

Retention schedule

StartWith retains data according to the criteria below. Retention and deletion are distinct: retention describes how long information may be kept; deletion describes how information is removed or rendered inaccessible when deletion is requested or the account/project ends, subject to exceptions.

  • Account, workspace, project, and generated content: For the life of the account or project and afterwards only as needed to complete deletion, comply with law, resolve disputes, enforce agreements, or protect the service.
  • Billing and transaction records: For the period required by accounting, tax, fraud-prevention, and other applicable legal obligations.
  • Support and privacy request records: For as long as needed to handle the request, demonstrate the response, resolve disputes, and comply with applicable law.
  • Security, usage, diagnostic, and MCP audit data: For the shortest period reasonably needed for security, abuse prevention, troubleshooting, audit integrity, and legal obligations; raw credentials and OAuth secrets are excluded from bounded MCP diagnostics.
  • Backups and disaster-recovery copies: Until rotated out under managed backup and disaster-recovery cycles, unless preservation is legally required.
  • Marketing preferences: Until consent is withdrawn or the user opts out, with a limited suppression record retained to honour the choice.

Deletion, backups, and legal holds

You can request deletion by emailing privacy@startwith.xyz as described above. Deletion requests are handled subject to verified authority and lawful exceptions.

Deletion may be limited or declined where exceptions apply, including:

  • Records required for accounting, tax, regulatory, or other legal obligations.
  • Information needed to prevent fraud, abuse, or security incidents.
  • Information needed to establish, exercise, or defend legal claims or enforce agreements.
  • Residual encrypted backup copies until they rotate out under the normal backup cycle.
  • Organisation-controlled data where the relevant workspace administrator must action the request.

Backups and disaster-recovery copies are maintained separately from live systems and are kept until rotated out under managed backup and disaster-recovery cycles, unless preservation is legally required.

MCP disconnect and revocation when enabled

StartWith provides an authenticated hosted MCP for ChatGPT and Codex at https://app.startwith.xyz/api/mcp.

What the MCP can access and do (in summary):

  • After you complete browser sign-in and OAuth consent, the MCP can read and write project-scoped content and settings, generate AI drafts requested by you, and help manage publishing workflows.
  • Access is limited to the signed-in account’s authorised workspaces and projects, with live checks on organisation membership and project authority on every operation.
  • Sensitive actions use additional controls such as exact versions, idempotency bindings, and short-lived single-use action intents. Social provider actions require native current-user confirmation bound to the exact prepared request.
  • StartWith stores project-scoped content, immutable versions, usage records, and bounded action or diagnostic receipts needed to provide, secure, and audit the service. Bounded MCP diagnostics exclude raw OAuth tokens, authorization codes or headers, cookies, client secrets, verifier or state values, full request bodies, tool arguments, document bodies, and unrelated customer data. The host provider (Codex or ChatGPT) stores the revocable OAuth credential under the host provider’s controls.

Disconnecting and revocation:

  • OAuth expiry, revocation, or disconnecting the server in ChatGPT or Codex ends access. Reconnecting creates a new credential binding and invalidates prior intents.
  • Disconnecting the MCP does not itself delete StartWith project data. Account, project, and personal-data deletion requests must be submitted via privacy@startwith.xyz and remain subject to verified authority and lawful retention exceptions.

Organisation and contact

Controller: A8 Innovation Consultancies LLC
Address: Dubai, United Arab Emirates
Website: https://startwith.xyz

Support: support@startwith.xyz
Privacy: privacy@startwith.xyz

StartWith is available in: United Arab Emirates, European Economic Area, and United Kingdom. The governing law is the laws of the United Arab Emirates as applicable in the Emirate of Dubai, subject to mandatory consumer and data-protection laws that apply to the user.

© 2026 StartWith