Foundry
Sign In

Legal

Privacy Policy

This Privacy Policy explains how Foundry collects, uses, shares, stores, and protects information when you use foundrystart.com. It is written for people who need the details, not as marketing copy.

Last updated: April 28, 2026Contact: hello@foundrystart.com

Plain-English Summary

  • Foundry collects the information needed to generate startup artifacts, run accounts, process credits and payments, prevent abuse, send operational emails, and improve the product.
  • We process user inputs and generated outputs with AI systems and supporting infrastructure. Do not submit confidential, regulated, or highly sensitive information unless you are comfortable with that processing.
  • Some artifacts are public by default. If an artifact is public, anyone with the link may view it, and public pages may be indexed by search engines. Eligible logged-in users can change artifact visibility where the product offers that control.
  • We do not sell personal information for money. We do use service providers for hosting, AI processing, payments, email, analytics, product observation, support, security, and legal compliance.
  • You can contact hello@foundrystart.com to request access, correction, deletion, export, unsubscribe help, or other privacy assistance.

1. Information We Collect

We collect information directly from you, automatically from your browser or device, from payment and referral providers, and from the AI-generated outputs created through the service.

CategoryExamples
Account and contact informationEmail address, name if you provide it, authentication session identifiers, account preferences, subscription tier, credit balance, and default artifact visibility.
Startup profile and generation inputsRoles, interests, time commitment, budget, preferred language, custom idea text, selected AI model preference, and other information you submit to generate a niche, plan, brand kit, or launch asset.
Generated content and artifactsNiche recommendations, debates, scores, business plans, brand kits, launch content, share cards, PDFs, exports, and related generation metadata.
Usage, device, and technical dataIP address or proxy-derived IP, browser and device information, pages viewed, clicks, feature usage, timestamps, logs, rate-limit keys, cookies, local storage values, and approximate location inferred from technical data.
Payment and commercial dataSelected plan or credit pack, amount, currency, provider, invoice/payment identifiers, payment status, subscription status, credit ledger entries, and confirmation email records.
Referral and anti-abuse dataReferral code or slug, referral cookie, invited-user status, and a hashed browser fingerprint built from browser/device signals for referral fraud prevention.
CommunicationsSupport requests, replies to emails, unsubscribe preferences, product notifications, and records showing whether certain operational emails were sent.

We do not intentionally ask for government identifiers, full payment card numbers, bank account credentials, health records, biometric data, or other highly sensitive information. If you place sensitive information in free-text prompts, support messages, or generated artifacts, we will process it as part of providing the service.

2. How We Use Information

  • Create, store, display, export, and share AI-generated startup artifacts.
  • Operate accounts, authentication, magic links, dashboards, credits, subscriptions, and artifact visibility controls.
  • Process payments, issue receipts, manage credits, reconcile webhooks, prevent fraud, and maintain billing records.
  • Send transactional emails, product notifications, generation updates, reminders, and messages you request.
  • Measure product usage, conversion, performance, reliability, and errors.
  • Prevent abuse, enforce rate limits, detect suspicious activity, protect accounts, debug issues, and maintain service security.
  • Improve Foundry, including through aggregated or de-identified usage patterns, quality signals, and support feedback.
  • Comply with law, enforce terms, resolve disputes, and protect the rights, property, and safety of Foundry, users, and others.

3. AI Processing

Foundry is an AI product. When you ask the service to generate a niche, plan, brand kit, launch asset, or related output, we may send your inputs, relevant account or session context, generated drafts, and validation prompts to AI model providers and generation infrastructure.

AI outputs may contain assumptions, inferences, rankings, scores, market estimates, names, brand assets, copy, strategies, and other recommendations. We store those outputs so you can view, export, continue, share, or regenerate your work.

We do not use AI output to make decisions that produce legal or similarly significant effects about you, such as credit, employment, housing, insurance, or eligibility for public benefits. Foundry generates startup materials for your review.

4. Public Artifacts and Sharing

Foundry creates artifacts such as niche pages, business plans, brand kits, share cards, PDFs, exports, and launch assets. Some artifacts may be public by default. Public means that anyone with the URL can view the artifact, and public pages may be crawled or indexed by search engines.

  • Anonymous artifacts are treated as public because there is no verified account owner to manage private visibility.
  • Logged-in users may have visibility controls for eligible artifacts, depending on product tier and feature availability.
  • Changing an artifact to private restricts access through Foundry, but it cannot remove copies already saved, shared, cached, indexed, screenshotted, or exported by others.
  • If you believe an artifact exposes information that should not be public, contact us at hello@foundrystart.com.

5. Cookies, Local Storage, Analytics, and Similar Technologies

We use cookies, local storage, scripts, and similar technologies to operate Foundry and understand how people use it.

  • Authentication cookies keep logged-in users signed in.
  • Generation and anonymous-session cookies help recover or claim generated work across page loads and sessions.
  • Referral cookies store referral codes for up to 90 days and support referral attribution.
  • Local storage may remember UI state, product-progress state, and analytics deduplication markers.
  • Google Analytics may collect event, page, browser, device, and usage data.
  • Microsoft Clarity may collect product-observation data such as clicks, scrolls, page interactions, heatmaps, session replay data, and related technical information.
  • Referral anti-abuse logic may create a hashed browser fingerprint from signals such as user agent, language, screen dimensions, timezone, hardware concurrency, and platform.

You can control many cookies and scripts through your browser, extension, or device settings. Blocking cookies may affect login, generation recovery, referrals, analytics, or other features.

6. How We Share Information

We share information only as needed to operate, improve, secure, and support Foundry, process transactions, comply with law, or honor your sharing choices.

RecipientPurpose
AI and generation infrastructureTo process prompts, context, and generated output so Foundry can create niches, business plans, brand kits, and launch assets.
Hosting, database, queue, storage, and infrastructure providersTo run the application, store account and artifact data, process jobs, serve pages, monitor reliability, and prevent abuse.
Payment providersTo create checkouts, process subscriptions or credit purchases, verify webhooks, prevent fraud, and send payment confirmations.
Email and communication providersTo send magic links, receipts, generation status messages, product notifications, reminders, and unsubscribe/preference links.
Analytics and product-observation providersTo understand traffic, product usage, conversion, errors, page interactions, and where the product needs improvement.
Legal, safety, and business recipientsTo comply with law, enforce our terms, protect rights and safety, respond to lawful requests, or complete a financing, merger, acquisition, or asset transfer.

We do not sell personal information for money, and we do not provide user contact lists to data brokers. If a privacy law treats certain analytics, measurement, or product-observation disclosures as a "sale" or "sharing," you may contact us to exercise any available opt-out rights.

7. Payments and Billing

Paid features, subscriptions, credit packs, and crypto payments are processed by third-party payment providers such as Polar and NOWPayments. We store payment metadata needed to confirm purchases, credit your account, send receipts, prevent fraud, reconcile webhooks, provide support, and maintain tax, accounting, and legal records.

Foundry does not intentionally store full credit card numbers, bank account credentials, private wallet keys, or complete payment instrument details. Payment providers process payment information under their own terms and privacy notices.

8. Emails and Communications

We send transactional and operational emails such as magic links, payment confirmations, generation queued/completed/failed messages, credit notifications, account notices, and security-related messages. These messages are necessary for the service and may not include an unsubscribe option.

We may also send product updates, reminders, weekly digests, renewal reminders, feature announcements, or other non-essential emails where permitted. Those emails include unsubscribe or preference controls, or you can contact hello@foundrystart.com.

9. Retention

We keep information for as long as reasonably necessary for the purposes described in this policy, unless a longer period is required or permitted by law.

  • Account information is generally kept while your account exists.
  • Generated artifacts are kept while they remain associated with an account, session, public URL, export, or operational record.
  • Authentication sessions are designed to expire after a limited period, and magic links expire after a short period.
  • Referral cookies may last up to 90 days. Generation recovery and anonymous-session cookies may last up to 30 days unless cleared sooner.
  • Payment, credit, tax, fraud-prevention, security, and legal records may be kept for longer periods when needed for legitimate business or legal reasons.
  • Backups and logs may persist for a limited period before being overwritten or deleted according to operational schedules.

If you request deletion, we will delete or de-identify information where reasonably possible, subject to legal, security, billing, backup, dispute, and abuse-prevention limits.

10. Your Privacy Rights and Choices

Depending on where you live, you may have rights to access, correct, delete, export, restrict, object to, or opt out of certain processing of your personal information. You may also have the right to withdraw consent where processing is based on consent.

  • To make a request, email hello@foundrystart.com from the email address connected to your account or provide enough information for us to verify control.
  • We may ask you to verify your identity through login, magic link, email confirmation, account details, or other reasonable verification steps.
  • You may unsubscribe from non-essential emails through the link in the email or through available email preference controls.
  • You may change eligible artifact visibility using the product controls when available.
  • You may block or delete cookies through your browser, but some service features may stop working.

We will not discriminate against you for exercising privacy rights, but some requests may limit our ability to provide the service.

11. California Notice at Collection

This section is intended to provide additional notice for California residents. It describes categories of personal information we may collect, examples, and categories of recipients to whom information may be disclosed for business purposes.

CategoryExamplesDisclosed
IdentifiersEmail, user ID, session ID, IP address, referral identifiers, payment provider IDs.Infrastructure, email, payment, analytics, security, and support providers.
Commercial informationPlans, credit packs, purchases, subscription state, credits, invoices, payment status.Payment, infrastructure, accounting, email, security, and support providers.
Internet or electronic network activityPages viewed, clicks, feature usage, referral visits, device/browser data, logs.Hosting, analytics, security, and infrastructure providers.
Approximate locationApproximate location inferred from IP address or timezone; not precise GPS.Hosting, analytics, security, and infrastructure providers.
User-generated and professional/commercial contentStartup ideas, business profile inputs, generated artifacts, support messages.AI, hosting, infrastructure, email, export, and support providers; public visitors if the artifact is public.
InferencesGenerated scores, recommendations, rankings, audience assumptions, and product usage segments.AI, hosting, analytics, and infrastructure providers.

We collect these categories from you, your browser or device, payment providers, referral interactions, AI generation workflows, and service providers. We use them for the purposes described above, including service delivery, billing, security, analytics, communications, support, compliance, and product improvement.

We do not knowingly sell or share personal information of consumers under 16. We do not use sensitive personal information to infer characteristics about you. If you submit sensitive information in free-text content, we process it only as needed to provide, secure, support, or comply with obligations related to the service.

California residents may request to know, access, correct, delete, and receive information about disclosure of personal information, and may opt out of sale or sharing where applicable. To exercise these rights, contact hello@foundrystart.com.

12. EU and UK Users

If the GDPR, UK GDPR, or similar law applies, Foundry acts as the controller for personal information we process to operate the service, manage accounts, process payments, communicate with users, secure the product, and improve Foundry.

Our legal bases may include performance of a contract, legitimate interests, consent where required, compliance with legal obligations, and protection of vital or legal interests. Our legitimate interests include operating and improving Foundry, preventing abuse, securing the service, measuring usage, providing support, and communicating about the product.

We may process and transfer information in the United States and other countries where we or our providers operate. Where required, we rely on appropriate safeguards for international transfers. You may have rights to access, rectification, erasure, restriction, objection, portability, withdrawal of consent, and complaint to a supervisory authority.

13. Security

We use reasonable technical, organizational, and administrative safeguards designed to protect personal information, including encrypted transport where supported, access controls, provider security measures, webhook verification, rate limiting, and abuse detection.

No internet service is perfectly secure. You are responsible for keeping your email account secure because Foundry authentication uses email-based magic links.

14. Children

Foundry is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child provided personal information to Foundry, contact us and we will take appropriate steps.

15. Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will update the "Last updated" date and may provide additional notice where required by law or appropriate for the change.

16. Contact Us

For privacy questions, rights requests, deletion requests, artifact visibility concerns, or legal operator information, contact us at hello@foundrystart.com.

Please include enough context for us to locate your account, session, artifact, or request. Do not send highly sensitive information by email unless necessary.