Privacy
Privacy Notice
Effective July 17, 2026
FounderDNA.ai (“FounderDNA,” “we,” “our”) offers a short, reflective assessment that summarizes patterns detected in the answers you provide. This notice describes what we collect, how we use it, and the choices you have. It is written in plain English. Where a statement is qualified (“may”), the qualification is deliberate.
1. What FounderDNA is
FounderDNA is an educational and reflective tool. It generates a 0–100 FounderDNA Score and a narrative Mindprint from your assessment answers. It is not a medical, mental-health, psychological, clinical, intelligence, or hiring assessment, and it is not a prediction or guarantee of business, financial, or personal outcomes. See our Terms & Assessment Disclosure for the full limitations.
2. Information you provide
- An optional first name and a role selection you enter at the start of the assessment.
- Your typed answers to assessment questions and any adaptive follow-up answers.
- If you choose to use voice input where offered, your spoken audio is transcribed and the transcript is used in place of typed text.
Please do not submit passwords, government identifiers, financial account details, trade secrets, medical records, or other highly sensitive information. Your answers are used to generate your result and may be processed by AI services described below.
3. Information generated from the assessment
- Your FounderDNA Score (0–100).
- A 16-dimension pattern vector derived from your answers.
- A Founder Type / archetype label and short observation.
- AI-authored narrative interpretation of your answers and suggested reflections. The scoring itself is deterministic and does not depend on AI.
- Modeled Legendary Mind connections — comparisons based on public information about widely known figures. These models are not verified by, endorsed by, or affiliated with the people they reference.
4. Essential cookies and session storage
We use a small number of strictly necessary, first-party browser mechanisms so the assessment works:
fdna_attemptand an HttpOnly ownership cookie so your in-progress attempt and completed result can only be viewed by your browser.- Session storage used to keep your draft answers, ambient preferences, and last-viewed result available across page refreshes on the same device.
We do not use advertising cookies, third-party marketing pixels, or cross-site tracking.
5. How your information is used
- To run the assessment and produce your Mindprint.
- To let you re-open your result on the same device.
- To generate a public share snapshot only when you explicitly create a share link.
- To operate the service securely (rate limiting, cost limits, abuse detection).
- To improve reliability by reviewing aggregated error and usage signals.
6. AI and voice services
To generate narrative interpretation we send question and answer text to third-party AI providers via the Lovable AI Gateway. When voice playback is enabled, short text lines from the interview are sent to ElevenLabs to synthesize the spoken-word audio, and the resulting audio may be cached to avoid regenerating the same line. When voice input is enabled, your audio is sent to a speech-to-text provider for transcription; the transcript is what we retain and use as your answer. Providers may process this content under their own terms.
7. Storage and security
Assessment attempts, results, share records, and operational logs are stored in our managed database (Supabase). Audio assets we cache are stored in managed object storage. Access is protected by row-level security policies and by server-verified session cookies. We use industry-standard transport encryption. No system can promise perfect security, and we make no such guarantee.
8. Sharing and public links
Your result is private by default. Nothing about your assessment appears on a public URL unless you press the Publish action inside the share sheet. When you publish, we create a frozen snapshot containing only the fields you selected (name or anonymous, score visible or hidden, modeled connections visible or hidden). Anyone who receives the link can view the snapshot. You can unpublish or revoke a share at any time. Search engines and social platforms may cache preview images or text for a short period after you change or revoke a link.
8a. Ask [Name] and account-gated questions
When a founder enables sharing, their Personal AI can be reached at a public URL such as founderdna.ai/[handle]/ask. Anyone can view the page while signed out, but you must have a FounderDNA account to send a question. If you type a question while signed out, we hold that draft on our server for up to 30 minutes so it survives the sign-in round-trip — it is never placed in the URL, in analytics, or in your browser's storage. Drafts expire after 30 minutes and are bound to the first account that claims them.
Every question you successfully send creates a private activity record that only you (the asker) can read from your dashboard. The founder who owns the Personal AI receives the question through their AI's runtime but does not see your identity by default. The conversation transcript is stored under the founder's Personal AI but is scoped to the two of you. Deleting your account removes or anonymizes your activity records and your side of the conversation.
9. Modeled Legendary profiles
Legendary Mind connections use publicly available information to model comparison patterns. They are not endorsements by, participation in, or affiliation with the referenced people or their estates. See our Terms for the full disclosure.
10. Operational logs and abuse prevention
We record limited operational events — AI and voice usage counters, cost estimates, rate-limit events, cache keys, and request identifiers — to keep the service reliable and to prevent abuse. Where an IP address is involved in a security control we store it in hashed form.
10a. Contact requests
When you submit the Contact form we store the request type, your reply email, an optional name, your message, an abuse-prevention hash of your IP address, and a short summary of your browser user-agent string. Once received, a request may also carry an internal status and private owner notes used to track resolution. We use these submissions only to respond to your request, handle privacy, access, correction, or deletion requests, resolve technical or product issues, and prevent abuse. We do not use contact submissions for marketing, and we do not add you to any mailing list.
Contact submissions are rate-limited server-side. We may need additional information to verify that you control the relevant assessment or share record before acting on a privacy, access, correction, or deletion request. Submitting a request does not by itself guarantee deletion, and we do not promise a fixed response time.
11. Data retention
We retain assessment attempts, results, share records, and operational logs for as long as needed to provide the service, maintain security, and operate FounderDNA. Retention periods may vary by record type. We do not currently enforce a fixed automatic-deletion schedule. To request access, correction, or deletion of your information, contact us via the Contact page.
11a. Permanent account and data deletion
You may permanently delete your FounderDNA account and personal data from the account settings area at any time. Deletion is user initiated, requires a recent interactive sign-in, and requires you to type DELETE and explicitly acknowledge that the action cannot be undone.
When you complete deletion:
- Any active Personal AI subscription is canceled immediately through our billing provider before the destructive step runs. Cancellation is not prorated.
- Your FounderDNA Sequence answers, results, Mirror, Personal AI, training material, corrections, public profile, FounderDNA Passport, Founder Universe entry, sharing links, selected-person grants, referral ownership, notifications, and personal contact information are removed.
- Recipient-visible conversation history may remain in the other person's own history, without your name, username, profile link, photo, email, phone, Personal AI route, or other identifiers. Retained conversations become read-only and cannot generate any new answer from your deleted Personal AI.
- Anonymous aggregate statistics may remain only where they cannot identify you (for example, dashboards that count deletions or completions).
Locally retained billing fields. After deletion, our local records keep only the minimum billing fields required for billing reconciliation, tax, audit, refund, dispute, and legal recordkeeping: our internal subscription identifier, the billing provider name, the provider subscription, customer, and transaction identifiers, the terminal status (for example canceled), the price identifier, and the cancellation timestamp. These are pseudonymous billing identifiers — not anonymous and not non-identifying — retained solely for the purposes above. Locally, they are disconnected from your FounderDNA profile, your FounderDNA Sequence answers, your FounderDNA Score, your assessment results, your Personal AI, your Personal AI knowledge, your conversations, and your public identity. We do not claim to erase records that the billing provider (Stripe) is legally or operationally required to retain; provider-side records are governed by their own retention policy and applicable law.
If you are the sole owner of a team workspace that has other members, you must transfer ownership or delete the workspace before your account can be deleted. This protects the other members' access to their shared work.
12. Your choices
- You may stop the assessment at any time.
- You may choose to leave voice input and playback off.
- You control whether to create a share link and what it contains.
- You may revoke published share links.
- You may permanently delete your account and personal data from account settings — see section 11a.
- You may contact us to request access or deletion of your data.
13a. Feedback you send us
When you send feedback through the in-app Feedback control, we store the message text you write, the category you choose, the page you were on (with any tokens or invitation identifiers removed), your device category, and a coarse app version. If you are signed in, we associate the feedback with your account so we can follow up and derive your current FounderDNA Sequence score and archetype server-side for context. We do not store your IP address or email from this form, and we do not use feedback to change your assessment result. You may request deletion of feedback you have sent via the Contact page.
13c. Enterprise sales inquiries
When you submit the Enterprise contact form at /enterprise/contact, we collect the fields you provide — first and last name, work email, optional phone, company name, optional company website, role or title, company size, optional country or region, primary interest, optional estimated users, optional timeline, optional preferred contact method, message, referral source, and UTM parameters — solely to respond to your inquiry and coordinate an Enterprise conversation. We record a one-way HMAC hash of your IP address and a truncated user-agent summary for abuse control; we do not store your raw IP address. Submitting the form records consent to be contacted about your inquiry; it does not subscribe you to any marketing list, and no marketing checkbox is preselected. We retain Enterprise inquiries for up to 24 months from submission for follow-up, audit, and legal recordkeeping, and may delete them sooner when they are no longer needed. A scheduled retention job removes inquiries older than the configured retention period. Archived inquiries remain subject to this retention period — archiving is an operational status, not a permanent preservation. If you submitted the inquiry while signed in and it is linked to your account, it is handled through account deletion. If you submitted the inquiry while signed out, removal requires a separate verified request via the Contact page identifying the work email you provided. Enterprise inquiry information is not anonymous; it is identifying business contact information handled under this Privacy Notice. Owner notification and confirmation emails are delivered through our email provider (Resend); provider-side processing is governed by their own policy.
13b. Owner-side AI activity dashboard
When someone asks your Personal AI a question, we record an entry the asker can see in their own private Ask activity log. As the AI's owner, we show you an aggregated, anonymized view only: total questions all-time, questions in the last seven days, and the number of unique askers. You cannot see who asked, their full question, or the AI's answer. If you turn on anonymized previews, we additionally show a sanitized excerpt of the first user message per conversation with URLs, email addresses, phone numbers, @handles, and long identifiers removed, along with the day (not the exact time) it was sent. You can turn previews off at any time — counts continue to update. Owners never receive asker identity from this dashboard.
We also send owners aggregated weekly digests and permanent milestone notifications (for example, when an AI reaches its 10th, 50th, or 100th question). Digests and milestones contain only bucketed counts (like "1–4 questions" or "10+ askers") — never asker identity, question text, or exact timestamps. Owners can choose which activity emails they receive (weekly, milestones, both, or off); in-app notifications and security notices are unaffected.
When you send feedback through the in-app Feedback control, we store the message text you write, the category you choose, the page you were on (with any tokens or invitation identifiers removed), your device category, and a coarse app version. If you are signed in, we associate the feedback with your account so we can follow up and derive your current FounderDNA Sequence score and archetype server-side for context. We do not store your IP address or email from this form, and we do not use feedback to change your assessment result. You may request deletion of feedback you have sent via the Contact page.
13. Children and minors
The current FounderDNA assessment is intended for adults and is not designed for children under 13. Please do not use the assessment on behalf of a child.
14. Creator payout onboarding
Creator payout onboarding is available at launch only to eligible United States adults, and only for USD payouts. When you begin creator payout setup, our payment provider Stripe collects and verifies identity, banking, tax, and payout information directly. FounderDNA stores only a limited set of provider identifiers and safe status fields (such as whether verification is in progress, whether requirements remain due, and whether earnings are paused). FounderDNA does not store bank account numbers, routing numbers, tax identifiers, identity documents, or full dates of birth. Completing onboarding does not guarantee approval, sales, earnings, or payouts. Paid marketplace sales remain disabled at launch. Records held by Stripe may be retained under provider, legal, tax, fraud, or financial obligations.
15. Marketplace question balances and Ask [Name]
Every signed in visitor receives five free questions per Personal AI they Ask. Free questions are tracked server side and reserved before inference runs, so a submitted question is consumed even if the reply is interrupted. Paid Ask Packs are not offered to buyers at launch. When paid balances become available they will be tracked separately, drawn only after free questions are used, and shown with a nearest expiration date. FounderDNA stores the reservation, commit, and release state needed to prevent double charging, plus aggregate usage counters. Owners see anonymous activity totals for their AI; they never see the identity of individual askers on the Ask page. Question text you type before signing in is stored server side under an opaque draft handle so it can be restored after sign in. That handle expires automatically.
16. Changes to this notice
We may update this notice as the product changes. The effective date above will reflect the latest version.
17. Contact
Privacy questions, access requests, and deletion requests can be sent through our Contact page.
This notice is provided for launch transparency and should receive independent legal review before broader commercial use. It does not create a legal relationship beyond the Terms.