Privacy Policy
Last updated 19 August 2026
This describes what FounderKit collects, why, who else touches it, and how you get it back or delete it. It reflects what the product actually does — if you find something here that does not match the software, treat that as a bug and tell us.
Who we are
FounderKit ("we") operates founderkit.app, an AI workspace that helps founders take an idea to its first paying customers. For anything in this policy, reach us at support@founderkit.app.
What we collect
Everything below is either given to us by you or produced by you using the product.
- Account — email address, and optionally your name, role, short bio and avatar.
- Venture data — the ideas, one-liners, customer profiles, offers, journey progress, evidence, tasks and notes you create.
- Mentor conversations — the messages you exchange with the AI mentor, kept so the mentor remembers your context between sessions.
- People you record — contacts, interviews, network contacts and investors that you enter. This is information about other people, and you are responsible for having a lawful basis to record it.
- Waitlist signups — when you publish a waitlist page, the email address and any answers your visitors submit are stored in your workspace. Those people are your audience, not ours: see "Data you collect from others" below.
- Billing — your Stripe customer id, subscription status and renewal date, plus a ledger of credits granted and spent. We never see or store your card details — the card is entered on Stripe's own checkout page and stays with Stripe.
- Operational records — server logs and short-lived rate-limit counters used to keep the service up and stop abuse.
We do not run advertising trackers, we do not sell personal data, and we do not buy personal data about you from anyone else.
Why we are allowed to use it
To provide the service you asked for (performing our contract with you); to take payment and prevent fraud (contract and our legitimate interests); to keep the service reliable and secure (legitimate interests); and to meet tax and accounting obligations (legal obligation). Where consent is the basis — for example optional product emails — you can withdraw it at any time.
Who else processes your data
These are our subprocessors. Each one only receives what it needs to do its job.
| Provider | Purpose | What it receives |
|---|---|---|
| Supabase | Database, authentication, file storage | All workspace data, email |
| Vercel | Application hosting and delivery | Request metadata, IP address |
| OpenRouter | AI model access (routes to OpenAI and Google models) | Mentor messages and the venture context sent with them |
| Tavily | Live web search for market research | Your research query terms |
| Firecrawl | Reading competitor pages | The page URLs being analysed |
| Stripe | Payments and subscription management | Email, billing details, card data |
| Google Fonts | Web fonts | IP address when a page loads |
Worth being explicit about: your mentor conversations leave our systems. To answer you, we send your message and the relevant venture context to OpenRouter, which routes it to the underlying model provider. Do not paste anything into the mentor you would not want processed by a third-party AI provider.
Data you collect from others
When you publish a waitlist page and people sign up, you decide what to ask and what to do with the answers. For that data you are the controller and we are your processor — we store and display it to you, and we act on your instructions.
That means you are responsible for telling your signups what you are collecting and why, for having a lawful basis to contact them, and for honouring their requests. If one of your signups asks us directly, we will point them to you.
How long we keep it
- Workspace data — until you delete it, or 30 days after you delete your account.
- Mentor conversations — until you delete the venture they belong to.
- Billing records — seven years, because tax law requires it.
- Server logs — 30 days.
- Rate-limit counters — two hours.
Your rights
You can ask for a copy of your data, correct it, delete it, restrict or object to how we use it, and take it elsewhere in a portable format. Waitlist signups export as CSV and workspace progress exports as PDF from inside the app; for anything else, email us and we will respond within 30 days.
Deleting your account removes your workspace data within 30 days. Billing records survive that, because we are legally required to keep them.
If you are in the UK or EEA and think we have got this wrong, you can complain to your local data protection authority. We would rather you told us first.
Where your data lives
Our providers operate globally, so your data may be processed outside your country, including in the United States. Where that involves a transfer out of the UK or EEA, it relies on the receiving provider's standard contractual clauses or an equivalent safeguard.
Security
Data is encrypted in transit. Every workspace row is protected by database-level row-level security, so one account cannot read another's. Billing state and credit balances are writable only by our server, never by the browser. No system is perfect — if you find a weakness, please tell us at support@founderkit.app before disclosing it publicly.
Children
FounderKit is not intended for anyone under 16, and we do not knowingly collect their data.
Changes
If we change this policy in a way that materially affects you, we will email you before it takes effect. The date at the top always reflects the current version.