Plain-English Summary
- Foundry collects the information needed to generate startup artifacts, run accounts, process credits and payments, prevent abuse, send operational emails, and improve the product.
- We process user inputs and generated outputs with AI systems and supporting infrastructure. Do not submit confidential, regulated, or highly sensitive information unless you are comfortable with that processing.
- Some artifacts are public by default. If an artifact is public, anyone with the link may view it, and public pages may be indexed by search engines. Eligible logged-in users can change artifact visibility where the product offers that control.
- We do not sell personal information for money. We do use service providers for hosting, AI processing, payments, email, analytics, product observation, support, security, and legal compliance.
- You can contact hello@foundrystart.com to request access, correction, deletion, export, unsubscribe help, or other privacy assistance.
1. Information We Collect
We collect information directly from you, automatically from your browser or device, from payment and referral providers, and from the AI-generated outputs created through the service.
| Category | Examples |
|---|---|
| Account and contact information | Email address, name if you provide it, authentication session identifiers, account preferences, subscription tier, credit balance, and default artifact visibility. |
| Startup profile and generation inputs | Roles, interests, time commitment, budget, preferred language, custom idea text, selected AI model preference, and other information you submit to generate a niche, plan, brand kit, or launch asset. |
| Generated content and artifacts | Niche recommendations, debates, scores, business plans, brand kits, launch content, share cards, PDFs, exports, and related generation metadata. |
| Usage, device, and technical data | IP address or proxy-derived IP, browser and device information, pages viewed, clicks, feature usage, timestamps, logs, rate-limit keys, cookies, local storage values, and approximate location inferred from technical data. |
| Payment and commercial data | Selected plan or credit pack, amount, currency, provider, invoice/payment identifiers, payment status, subscription status, credit ledger entries, and confirmation email records. |
| Referral and anti-abuse data | Referral code or slug, referral cookie, invited-user status, and a hashed browser fingerprint built from browser/device signals for referral fraud prevention. |
| Communications | Support requests, replies to emails, unsubscribe preferences, product notifications, and records showing whether certain operational emails were sent. |
We do not intentionally ask for government identifiers, full payment card numbers, bank account credentials, health records, biometric data, or other highly sensitive information. If you place sensitive information in free-text prompts, support messages, or generated artifacts, we will process it as part of providing the service.
2. How We Use Information
- Create, store, display, export, and share AI-generated startup artifacts.
- Operate accounts, authentication, magic links, dashboards, credits, subscriptions, and artifact visibility controls.
- Process payments, issue receipts, manage credits, reconcile webhooks, prevent fraud, and maintain billing records.
- Send transactional emails, product notifications, generation updates, reminders, and messages you request.
- Measure product usage, conversion, performance, reliability, and errors.
- Prevent abuse, enforce rate limits, detect suspicious activity, protect accounts, debug issues, and maintain service security.
- Improve Foundry, including through aggregated or de-identified usage patterns, quality signals, and support feedback.
- Comply with law, enforce terms, resolve disputes, and protect the rights, property, and safety of Foundry, users, and others.
3. AI Processing
Foundry is an AI product. When you ask the service to generate a niche, plan, brand kit, launch asset, or related output, we may send your inputs, relevant account or session context, generated drafts, and validation prompts to AI model providers and generation infrastructure.
AI outputs may contain assumptions, inferences, rankings, scores, market estimates, names, brand assets, copy, strategies, and other recommendations. We store those outputs so you can view, export, continue, share, or regenerate your work.
We do not use AI output to make decisions that produce legal or similarly significant effects about you, such as credit, employment, housing, insurance, or eligibility for public benefits. Foundry generates startup materials for your review.
4. Public Artifacts and Sharing
Foundry creates artifacts such as niche pages, business plans, brand kits, share cards, PDFs, exports, and launch assets. Some artifacts may be public by default. Public means that anyone with the URL can view the artifact, and public pages may be crawled or indexed by search engines.
- Anonymous artifacts are treated as public because there is no verified account owner to manage private visibility.
- Logged-in users may have visibility controls for eligible artifacts, depending on product tier and feature availability.
- Changing an artifact to private restricts access through Foundry, but it cannot remove copies already saved, shared, cached, indexed, screenshotted, or exported by others.
- If you believe an artifact exposes information that should not be public, contact us at hello@foundrystart.com.
7. Payments and Billing
Paid features, subscriptions, credit packs, and crypto payments are processed by third-party payment providers such as Polar and NOWPayments. We store payment metadata needed to confirm purchases, credit your account, send receipts, prevent fraud, reconcile webhooks, provide support, and maintain tax, accounting, and legal records.
Foundry does not intentionally store full credit card numbers, bank account credentials, private wallet keys, or complete payment instrument details. Payment providers process payment information under their own terms and privacy notices.
8. Emails and Communications
We send transactional and operational emails such as magic links, payment confirmations, generation queued/completed/failed messages, credit notifications, account notices, and security-related messages. These messages are necessary for the service and may not include an unsubscribe option.
We may also send product updates, reminders, weekly digests, renewal reminders, feature announcements, or other non-essential emails where permitted. Those emails include unsubscribe or preference controls, or you can contact hello@foundrystart.com.
9. Retention
We keep information for as long as reasonably necessary for the purposes described in this policy, unless a longer period is required or permitted by law.
- Account information is generally kept while your account exists.
- Generated artifacts are kept while they remain associated with an account, session, public URL, export, or operational record.
- Authentication sessions are designed to expire after a limited period, and magic links expire after a short period.
- Referral cookies may last up to 90 days. Generation recovery and anonymous-session cookies may last up to 30 days unless cleared sooner.
- Payment, credit, tax, fraud-prevention, security, and legal records may be kept for longer periods when needed for legitimate business or legal reasons.
- Backups and logs may persist for a limited period before being overwritten or deleted according to operational schedules.
If you request deletion, we will delete or de-identify information where reasonably possible, subject to legal, security, billing, backup, dispute, and abuse-prevention limits.
10. Your Privacy Rights and Choices
Depending on where you live, you may have rights to access, correct, delete, export, restrict, object to, or opt out of certain processing of your personal information. You may also have the right to withdraw consent where processing is based on consent.
- To make a request, email hello@foundrystart.com from the email address connected to your account or provide enough information for us to verify control.
- We may ask you to verify your identity through login, magic link, email confirmation, account details, or other reasonable verification steps.
- You may unsubscribe from non-essential emails through the link in the email or through available email preference controls.
- You may change eligible artifact visibility using the product controls when available.
- You may block or delete cookies through your browser, but some service features may stop working.
We will not discriminate against you for exercising privacy rights, but some requests may limit our ability to provide the service.
11. California Notice at Collection
This section is intended to provide additional notice for California residents. It describes categories of personal information we may collect, examples, and categories of recipients to whom information may be disclosed for business purposes.
| Category | Examples | Disclosed |
|---|---|---|
| Identifiers | Email, user ID, session ID, IP address, referral identifiers, payment provider IDs. | Infrastructure, email, payment, analytics, security, and support providers. |
| Commercial information | Plans, credit packs, purchases, subscription state, credits, invoices, payment status. | Payment, infrastructure, accounting, email, security, and support providers. |
| Internet or electronic network activity | Pages viewed, clicks, feature usage, referral visits, device/browser data, logs. | Hosting, analytics, security, and infrastructure providers. |
| Approximate location | Approximate location inferred from IP address or timezone; not precise GPS. | Hosting, analytics, security, and infrastructure providers. |
| User-generated and professional/commercial content | Startup ideas, business profile inputs, generated artifacts, support messages. | AI, hosting, infrastructure, email, export, and support providers; public visitors if the artifact is public. |
| Inferences | Generated scores, recommendations, rankings, audience assumptions, and product usage segments. | AI, hosting, analytics, and infrastructure providers. |
We collect these categories from you, your browser or device, payment providers, referral interactions, AI generation workflows, and service providers. We use them for the purposes described above, including service delivery, billing, security, analytics, communications, support, compliance, and product improvement.
We do not knowingly sell or share personal information of consumers under 16. We do not use sensitive personal information to infer characteristics about you. If you submit sensitive information in free-text content, we process it only as needed to provide, secure, support, or comply with obligations related to the service.
California residents may request to know, access, correct, delete, and receive information about disclosure of personal information, and may opt out of sale or sharing where applicable. To exercise these rights, contact hello@foundrystart.com.
12. EU and UK Users
If the GDPR, UK GDPR, or similar law applies, Foundry acts as the controller for personal information we process to operate the service, manage accounts, process payments, communicate with users, secure the product, and improve Foundry.
Our legal bases may include performance of a contract, legitimate interests, consent where required, compliance with legal obligations, and protection of vital or legal interests. Our legitimate interests include operating and improving Foundry, preventing abuse, securing the service, measuring usage, providing support, and communicating about the product.
We may process and transfer information in the United States and other countries where we or our providers operate. Where required, we rely on appropriate safeguards for international transfers. You may have rights to access, rectification, erasure, restriction, objection, portability, withdrawal of consent, and complaint to a supervisory authority.
13. Security
We use reasonable technical, organizational, and administrative safeguards designed to protect personal information, including encrypted transport where supported, access controls, provider security measures, webhook verification, rate limiting, and abuse detection.
No internet service is perfectly secure. You are responsible for keeping your email account secure because Foundry authentication uses email-based magic links.
14. Children
Foundry is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child provided personal information to Foundry, contact us and we will take appropriate steps.
15. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will update the "Last updated" date and may provide additional notice where required by law or appropriate for the change.
16. Contact Us
For privacy questions, rights requests, deletion requests, artifact visibility concerns, or legal operator information, contact us at hello@foundrystart.com.
Please include enough context for us to locate your account, session, artifact, or request. Do not send highly sensitive information by email unless necessary.