Skip to main content
FOUNDERDNA

Privacy

Privacy Notice

Effective July 17, 2026

FounderDNA.ai (“FounderDNA,” “we,” “our”) offers a short, reflective assessment that summarizes patterns detected in the answers you provide. This notice describes what we collect, how we use it, and the choices you have. It is written in plain English. Where a statement is qualified (“may”), the qualification is deliberate.

1. What FounderDNA is

FounderDNA is an educational and reflective tool. It generates a 0–100 FounderDNA Score and a narrative Mindprint from your assessment answers. It is not a medical, mental-health, psychological, clinical, intelligence, or hiring assessment, and it is not a prediction or guarantee of business, financial, or personal outcomes. See our Terms & Assessment Disclosure for the full limitations.

2. Information you provide

Please do not submit passwords, government identifiers, financial account details, trade secrets, medical records, or other highly sensitive information. Your answers are used to generate your result and may be processed by AI services described below.

3. Information generated from the assessment

4. Essential cookies and session storage

We use a small number of strictly necessary, first-party browser mechanisms so the assessment works:

We do not use advertising cookies, third-party marketing pixels, or cross-site tracking.

5. How your information is used

6. AI and voice services

To generate narrative interpretation we send question and answer text to third-party AI providers via the Lovable AI Gateway. When voice playback is enabled, short text lines from the interview are sent to ElevenLabs to synthesize the spoken-word audio, and the resulting audio may be cached to avoid regenerating the same line. When voice input is enabled, your audio is sent to a speech-to-text provider for transcription; the transcript is what we retain and use as your answer. Providers may process this content under their own terms.

7. Storage and security

Assessment attempts, results, share records, and operational logs are stored in our managed database (Supabase). Audio assets we cache are stored in managed object storage. Access is protected by row-level security policies and by server-verified session cookies. We use industry-standard transport encryption. No system can promise perfect security, and we make no such guarantee.

8. Sharing and public links

Your result is private by default. Nothing about your assessment appears on a public URL unless you press the Publish action inside the share sheet. When you publish, we create a frozen snapshot containing only the fields you selected (name or anonymous, score visible or hidden, modeled connections visible or hidden). Anyone who receives the link can view the snapshot. You can unpublish or revoke a share at any time. Search engines and social platforms may cache preview images or text for a short period after you change or revoke a link.

8a. Ask [Name] and account-gated questions

When a founder enables sharing, their Personal AI can be reached at a public URL such as founderdna.ai/[handle]/ask. Anyone can view the page while signed out, but you must have a FounderDNA account to send a question. If you type a question while signed out, we hold that draft on our server for up to 30 minutes so it survives the sign-in round-trip — it is never placed in the URL, in analytics, or in your browser's storage. Drafts expire after 30 minutes and are bound to the first account that claims them.

Every question you successfully send creates a private activity record that only you (the asker) can read from your dashboard. The founder who owns the Personal AI receives the question through their AI's runtime but does not see your identity by default. The conversation transcript is stored under the founder's Personal AI but is scoped to the two of you. Deleting your account removes or anonymizes your activity records and your side of the conversation.

9. Modeled Legendary profiles

Legendary Mind connections use publicly available information to model comparison patterns. They are not endorsements by, participation in, or affiliation with the referenced people or their estates. See our Terms for the full disclosure.

10. Operational logs and abuse prevention

We record limited operational events — AI and voice usage counters, cost estimates, rate-limit events, cache keys, and request identifiers — to keep the service reliable and to prevent abuse. Where an IP address is involved in a security control we store it in hashed form.

10a. Contact requests

When you submit the Contact form we store the request type, your reply email, an optional name, your message, an abuse-prevention hash of your IP address, and a short summary of your browser user-agent string. Once received, a request may also carry an internal status and private owner notes used to track resolution. We use these submissions only to respond to your request, handle privacy, access, correction, or deletion requests, resolve technical or product issues, and prevent abuse. We do not use contact submissions for marketing, and we do not add you to any mailing list.

Contact submissions are rate-limited server-side. We may need additional information to verify that you control the relevant assessment or share record before acting on a privacy, access, correction, or deletion request. Submitting a request does not by itself guarantee deletion, and we do not promise a fixed response time.

11. Data retention

We retain assessment attempts, results, share records, and operational logs for as long as needed to provide the service, maintain security, and operate FounderDNA. Retention periods may vary by record type. We do not currently enforce a fixed automatic-deletion schedule. To request access, correction, or deletion of your information, contact us via the Contact page.

11a. Permanent account and data deletion

You may permanently delete your FounderDNA account and personal data from the account settings area at any time. Deletion is user initiated, requires a recent interactive sign-in, and requires you to type DELETE and explicitly acknowledge that the action cannot be undone.

When you complete deletion:

Locally retained billing fields. After deletion, our local records keep only the minimum billing fields required for billing reconciliation, tax, audit, refund, dispute, and legal recordkeeping: our internal subscription identifier, the billing provider name, the provider subscription, customer, and transaction identifiers, the terminal status (for example canceled), the price identifier, and the cancellation timestamp. These are pseudonymous billing identifiers — not anonymous and not non-identifying — retained solely for the purposes above. Locally, they are disconnected from your FounderDNA profile, your FounderDNA Sequence answers, your FounderDNA Score, your assessment results, your Personal AI, your Personal AI knowledge, your conversations, and your public identity. We do not claim to erase records that the billing provider (Stripe) is legally or operationally required to retain; provider-side records are governed by their own retention policy and applicable law.

If you are the sole owner of a team workspace that has other members, you must transfer ownership or delete the workspace before your account can be deleted. This protects the other members' access to their shared work.

12. Your choices

13a. Feedback you send us

When you send feedback through the in-app Feedback control, we store the message text you write, the category you choose, the page you were on (with any tokens or invitation identifiers removed), your device category, and a coarse app version. If you are signed in, we associate the feedback with your account so we can follow up and derive your current FounderDNA Sequence score and archetype server-side for context. We do not store your IP address or email from this form, and we do not use feedback to change your assessment result. You may request deletion of feedback you have sent via the Contact page.

13c. Enterprise sales inquiries

When you submit the Enterprise contact form at /enterprise/contact, we collect the fields you provide — first and last name, work email, optional phone, company name, optional company website, role or title, company size, optional country or region, primary interest, optional estimated users, optional timeline, optional preferred contact method, message, referral source, and UTM parameters — solely to respond to your inquiry and coordinate an Enterprise conversation. We record a one-way HMAC hash of your IP address and a truncated user-agent summary for abuse control; we do not store your raw IP address. Submitting the form records consent to be contacted about your inquiry; it does not subscribe you to any marketing list, and no marketing checkbox is preselected. We retain Enterprise inquiries for up to 24 months from submission for follow-up, audit, and legal recordkeeping, and may delete them sooner when they are no longer needed. A scheduled retention job removes inquiries older than the configured retention period. Archived inquiries remain subject to this retention period — archiving is an operational status, not a permanent preservation. If you submitted the inquiry while signed in and it is linked to your account, it is handled through account deletion. If you submitted the inquiry while signed out, removal requires a separate verified request via the Contact page identifying the work email you provided. Enterprise inquiry information is not anonymous; it is identifying business contact information handled under this Privacy Notice. Owner notification and confirmation emails are delivered through our email provider (Resend); provider-side processing is governed by their own policy.

13b. Owner-side AI activity dashboard

When someone asks your Personal AI a question, we record an entry the asker can see in their own private Ask activity log. As the AI's owner, we show you an aggregated, anonymized view only: total questions all-time, questions in the last seven days, and the number of unique askers. You cannot see who asked, their full question, or the AI's answer. If you turn on anonymized previews, we additionally show a sanitized excerpt of the first user message per conversation with URLs, email addresses, phone numbers, @handles, and long identifiers removed, along with the day (not the exact time) it was sent. You can turn previews off at any time — counts continue to update. Owners never receive asker identity from this dashboard.

We also send owners aggregated weekly digests and permanent milestone notifications (for example, when an AI reaches its 10th, 50th, or 100th question). Digests and milestones contain only bucketed counts (like "1–4 questions" or "10+ askers") — never asker identity, question text, or exact timestamps. Owners can choose which activity emails they receive (weekly, milestones, both, or off); in-app notifications and security notices are unaffected.

When you send feedback through the in-app Feedback control, we store the message text you write, the category you choose, the page you were on (with any tokens or invitation identifiers removed), your device category, and a coarse app version. If you are signed in, we associate the feedback with your account so we can follow up and derive your current FounderDNA Sequence score and archetype server-side for context. We do not store your IP address or email from this form, and we do not use feedback to change your assessment result. You may request deletion of feedback you have sent via the Contact page.

13. Children and minors

The current FounderDNA assessment is intended for adults and is not designed for children under 13. Please do not use the assessment on behalf of a child.

14. Creator payout onboarding

Creator payout onboarding is available at launch only to eligible United States adults, and only for USD payouts. When you begin creator payout setup, our payment provider Stripe collects and verifies identity, banking, tax, and payout information directly. FounderDNA stores only a limited set of provider identifiers and safe status fields (such as whether verification is in progress, whether requirements remain due, and whether earnings are paused). FounderDNA does not store bank account numbers, routing numbers, tax identifiers, identity documents, or full dates of birth. Completing onboarding does not guarantee approval, sales, earnings, or payouts. Paid marketplace sales remain disabled at launch. Records held by Stripe may be retained under provider, legal, tax, fraud, or financial obligations.

15. Marketplace question balances and Ask [Name]

Every signed in visitor receives five free questions per Personal AI they Ask. Free questions are tracked server side and reserved before inference runs, so a submitted question is consumed even if the reply is interrupted. Paid Ask Packs are not offered to buyers at launch. When paid balances become available they will be tracked separately, drawn only after free questions are used, and shown with a nearest expiration date. FounderDNA stores the reservation, commit, and release state needed to prevent double charging, plus aggregate usage counters. Owners see anonymous activity totals for their AI; they never see the identity of individual askers on the Ask page. Question text you type before signing in is stored server side under an opaque draft handle so it can be restored after sign in. That handle expires automatically.

16. Changes to this notice

We may update this notice as the product changes. The effective date above will reflect the latest version.

17. Contact

Privacy questions, access requests, and deletion requests can be sent through our Contact page.

This notice is provided for launch transparency and should receive independent legal review before broader commercial use. It does not create a legal relationship beyond the Terms.