Legal
Privacy policy
How Founder OS handles your data. Last updated 17 August 2026.
1. Who we are
Founder OS(“we”, “us”) is an independent software product operated from New Delhi, India. We are the data controller for the personal data described in this policy. For any privacy question or request, write to adityaastro.id2004@gmail.com.
2. Scope
This policy covers this website and the Founder OS application. It does not cover the third-party tools you choose to connect (your note app, calendar, code host and so on) — those remain governed by their own privacy policies and by your account settings with them.
3. What we collect
Account data
Authentication is handled by Clerk. When you sign up we receive your name, email address, and the authentication identifiers Clerk issues. We never see or store your password; if you sign in with a social provider we receive only the profile fields that provider releases.
Company content you connect or provide
When you connect a state source or upload a document, we process its contents to build your company state: goals, projects, tasks, decisions, metrics, people and meetings, plus the agent memories derived from them. This is the core of the service and can include business information, and incidentally personal data about people you work with (names in meeting notes, for example). It is stored against your account and is not shared with other users.
Integration credentials
Tokens for connected tools are stored encrypted and used only to read from and write to that tool on your behalf. You can disconnect a source at any time from the app, which revokes our further use of that token.
Billing data
Payments are processed by Stripe. Card numbers never reach our servers — we store only the subscription state and customer reference that Stripe returns.
Usage and device data
We collect product analytics events (pages viewed, features used), plus the technical data any web server receives: IP address, browser and operating system, and timestamps. Server logs are sanitised to redact secrets and tokens before they are written.
Support correspondence
If you email us or use the contact form, we keep the message and your email address so we can answer it and follow up.
4. How AI models process your data
This is the part founders ask about most, so it is stated plainly:
- Your data is never used to train models.Not ours, not a provider's.
- Founder OS is provider-pluggable. The default provider is a local Ollama instance, in which case prompts and company content are processed on your own infrastructure and are not transmitted to any model vendor at all.
- If you configure a hosted provider (Anthropic, Google, or an OpenAI-compatible endpoint), the specific prompt needed to answer your request — which may include excerpts of your company state — is sent to that provider to generate the response, and is subject to that provider's terms. Choosing the provider is your decision, and you can change it.
- Agent output is generated text. It can be wrong. Actions classified as irreversible or outward-facing are held at the approval gate until you approve them.
5. Why we process it (legal bases)
- Performance of a contract — to provide the service you signed up for: authentication, company state, agents, sync.
- Legitimate interests — to keep the service secure, debug failures, prevent abuse, and understand which features are used.
- Consent — for optional analytics cookies and any marketing email, withdrawable at any time.
- Legal obligation — to keep the tax and payment records we are required to keep.
6. Cookies and analytics
We use a small number of cookies and similar technologies:
- Strictly necessary — session and authentication cookies set by Clerk, and a local preference for your light/dark theme choice. The site does not work without these.
- Analytics — PostHog for product analytics and Google Analytics 4 for website traffic. These tell us which pages and features get used. Anonymous website visitors are not given a person profile in PostHog.
You can block analytics with your browser settings, an extension, or a Global Privacy Control / Do Not Track signal; the product itself will continue to work. We do not run advertising or cross-site tracking pixels.
7. Sub-processors
We use these providers to run the service. Each receives only what it needs for its function:
- Clerk — authentication and user identity
- Amazon Web Services (Mumbai region, ap-south-1) — application servers, Postgres database, encrypted backups
- Vercel — hosting and delivery of this website and the dashboard front end
- Stripe — payment processing and subscription management
- PostHog and Google Analytics — analytics
- Your chosen AI provider — inference, only if you configure a hosted one instead of local Ollama
8. International transfers
Our primary infrastructure is in India (AWS ap-south-1). Some sub-processors above operate in the United States and the EU, so data may be transferred outside your country. Those transfers rely on the providers' standard contractual clauses and equivalent safeguards.
9. Retention
- Account and company state — kept while your account is active. Deleted within 30 days of account deletion, except where we must keep records longer by law.
- Backups — encrypted database backups roll off on a fixed schedule; deleted data disappears from backups as they expire.
- Server logs — short-lived, and sanitised of secrets when written.
- Billing records — kept as long as tax law requires.
- Support email — kept while useful for context, and removed on request.
10. Security
Authentication is enforced on every non-public endpoint with signed JWTs. Traffic is encrypted in transit with TLS. Integration credentials are encrypted at rest, secrets live only in server environment configuration, logs are sanitised to strip tokens, and the API applies security headers, rate limiting and request validation. Dependencies are scanned automatically and static security analysis runs on every change. No system is perfectly secure; if you believe you have found a vulnerability, please email adityaastro.id2004@gmail.com rather than disclosing it publicly, and we will work with you on a fix.
11. Your rights
Depending on where you live — including under the EU/UK GDPR and India's Digital Personal Data Protection Act, 2023 — you can ask us to:
- confirm what personal data we hold about you and give you a copy;
- correct data that is wrong or incomplete;
- delete your account and the data associated with it;
- restrict or object to a particular use;
- export your data in a portable format — much of it is plain Markdown in your own connected tools by design;
- withdraw consent you previously gave.
Email adityaastro.id2004@gmail.com and we will respond within 30 days. You will not be charged and you will not be treated differently for asking. If you are unhappy with our response, you may complain to your local data protection authority.
12. Children
Founder OS is a business tool and is not directed at children under 16. We do not knowingly collect their data; if you believe we have, tell us and we will delete it.
13. Changes to this policy
We will update the date at the top when this policy changes, and will notify account holders by email before a material change takes effect.
14. Contact
Privacy questions, access requests and complaints: adityaastro.id2004@gmail.com. See also our terms & conditions and the contact page.
