Privacy Policy

Effective May 9, 2026

1. Introduction

FounderDive ("we," "us," "our," or "Company") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and otherwise process your personal information when you use our website, application, and services (collectively, the "Service").

Please read this Privacy Policy carefully. By accessing or using FounderDive, you acknowledge that you have read, understood, and agree to be bound by all of the terms of this Privacy Policy.

2. Information We Collect

Information You Provide Directly

  • Account Registration: Email address, password, name, and profile information
  • Business Information: Company description, stage, industry, metrics you submit for Deep Dives
  • Communication: Messages sent through our chat interface with Prova
  • Payment Information: Processed through Lemon Squeezy; we do not store full credit card details
  • Feedback: Bug reports, feature requests, and support inquiries

Information Collected Automatically

  • Usage Data: Pages visited, features used, time spent, clicks, and interactions
  • Device Information: Browser type, operating system, IP address (anonymized), device identifiers
  • Cookies & Tracking: Session tokens, preferences, and analytics data
  • Local Storage: Chat history, sidebar preferences, draft content, and UI state are stored locally in your browser
  • API Calls: Logs of Deep Dives initiated, results generated, and completion status

Information from Third Parties

  • Supabase authentication services (email verification status)
  • Payment processor Lemon Squeezy (subscription status, plan tier)
  • External APIs (Perplexity, xAI/Grok, SerpAPI) for market research data

3. How We Use Your Information

  • Provide, maintain, and improve the Service
  • Generate personalized Deep Dives and market analysis
  • Process payments and manage your subscription
  • Send transactional emails (confirmations, password resets, billing updates)
  • Monitor usage patterns and fix bugs via Sentry error tracking
  • Comply with legal obligations and enforce our Terms
  • Prevent fraud, abuse, and security incidents

We do not sell your personal data to third parties. We do not use your information for marketing without explicit consent.

AI Training: We do not use your business data, chat messages, or personal information to train or fine-tune our AI models. Data sent to third-party AI providers (OpenRouter, Perplexity, xAI) is processed solely to generate your analysis and is not retained by those providers for their own model training.

4. Data Retention

  • Account Data: Retained while your account is active. Deleted within 30 days of account deletion.
  • Deep Dive History: Retained for 12 months to provide historical context, then archived
  • Chat Messages: Retained for Prova's memory layer (hot/warm/cold tiers); deleted on account deletion
  • Error Logs: Retained for 90 days in Sentry, then purged
  • Payment Records: Retained for 7 years per tax regulations

5. Data Security

We implement industry-standard security measures:

  • HTTPS encryption for all data in transit
  • Supabase Row-Level Security (RLS) ensures users can only access their own data
  • API keys and secrets stored securely in environment variables, never in code
  • Webhook signature verification for payment security
  • Regular security audits and monitoring via Sentry

Note: No security is 100% secure. We cannot guarantee absolute protection against all threats.

6. Your Data Rights (GDPR & CCPA)

If you are located in the EU, California, or other jurisdictions with privacy laws, you have the right to:

  • Access: Request a copy of all personal data we hold about you
  • Correction: Update inaccurate or incomplete information
  • Deletion: Request permanent deletion of your account and data ("Right to be Forgotten")
  • Portability: Export your data in a machine-readable format
  • Opt-Out: Disable cookies and tracking (though some features may not work)

To exercise these rights: Email [email protected] with "GDPR Request" in the subject. Include your account email and specify which right you are exercising. We will respond within 30 days.

California Residents (CCPA/CPRA): In addition to the rights above, California residents have the right to know what personal information is collected, used, shared, or sold; the right to opt out of the sale of personal information (we do not sell personal information); and the right to non-discrimination for exercising these rights. To exercise your California privacy rights, email [email protected]with "CCPA Request" in the subject line.

You can also delete your account directly in Settings → Account → Delete Account.

7. Third-Party Services

We share data with the following services:

Supabase (Database & Auth)

Hosts your profile, businesses, chat history, and Deep Dive data

Lemon Squeezy (Payments)

Processes subscriptions; we never see your credit card details

Perplexity, xAI/Grok, SerpAPI (Market Research)

We send your business description to these services to perform research. Data is not used for their training.

Sentry (Error Monitoring)

Captures error logs; we do not send personal data

Reddit / PRAW (Market Research)

Searches public Reddit content for community sentiment analysis; receives search queries only

Resend (Email)

Sends transactional emails; does not use your data for marketing

OpenRouter (AI Model Routing)

Processes business descriptions and chat history for AI analysis; data is not used for model training. See also our EULA and Data Processing Agreement.

Data Processing & Sub-processors

All AI model providers (OpenRouter, Perplexity, xAI/Grok) act as data processors under GDPR Article 28. We maintain Data Processing Agreements with key providers. Data sent to these services is used solely for providing the FounderDive Service, not for their own training or improvement. A full list of sub-processors is available in our Data Processing Agreement. You may also request a list at [email protected].

8. Children's Privacy

FounderDive is intended for adults and business professionals. We do not knowingly collect personal information from children under 13. If we discover we have done so, we will delete it immediately. If you believe a child's data has been collected, email [email protected].

9. Policy Updates

We may update this Privacy Policy as our Service evolves. Material changes will be communicated via email or in-app notification with 30 days' notice. Continued use of the Service after changes constitutes acceptance of the updated policy.

View the accompanying Terms of Service and End User License Agreement.

We may update this Privacy Policy as our Service evolves. Material changes will be communicated via email or in-app notification with 30 days' notice. Continued use of the Service after changes constitutes acceptance of the updated policy.

10. Cookie Policy

We use cookies and similar technologies to operate and improve the FounderDive Service.

Essential Cookies

Required for authentication, session management, and security. These cannot be disabled.

Functional Cookies

Remember your preferences (e.g., language, theme) and enable contextual features.

Analytics Cookies

Help us understand how users interact with the Service via Sentry (error tracking) and our internal analytics. Data is aggregate and pseudonymized.

Third-Party Cookies

Supabase (auth sessions), Lemon Squeezy (checkout), and Resend (email tracking) may set their own cookies subject to their respective policies.

You can disable non-essential cookies in your browser settings. Disabling functional or analytics cookies may reduce feature quality. For a full breakdown of all cookies we use, see our Cookie Policy.

11. California Privacy Rights (CCPA/CPRA)

This section applies specifically to California residents under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA).

Categories of Personal Information Collected

We collect the following categories: identifiers (name, email, IP), commercial information (subscription records), internet/electronic activity (usage data, chat messages), professional/employment information (business details), and inferences drawn from the above (archetype scores, analysis).

Sale of Personal Information

FounderDive does not sell personal information as defined by the CCPA. We do not share data for cross-context behavioral advertising.

Sensitive Personal Information

We do not collect sensitive personal information (SSN, driver's license, financial account numbers, precise geolocation, racial/ethnic origin) for the purpose of inferring characteristics.

Retention Periods

We retain each category of personal information for the duration described in Section 4 (Data Retention) above.

Your CCPA Rights

  • Right to Know: request disclosure of specific pieces and categories of personal information collected
  • Right to Delete: request deletion of personal information (subject to exceptions)
  • Right to Correct: request correction of inaccurate personal information
  • Right to Opt-Out: we do not sell data, but you may still submit an opt-out request
  • Right to Non-Discrimination: we will not deny service or charge different prices for exercising your rights
  • Right to Limit Use of Sensitive PI: we do not use sensitive personal information beyond what is necessary

Authorized Agent

You may designate an authorized agent to submit a request on your behalf. We will require proof of authorization and identity verification.

To exercise any CCPA right, email [email protected] with "CCPA Request" in the subject line, or use our Settings → GDPR/Data Request feature. We will verify your identity and respond within 45 days (extendable by another 45 days with notice).

12. Contact Us

Questions about this Privacy Policy?

Email: [email protected]

Website: founderdive.com