Public information
Privacy notice
This notice describes how Founder OS handles information for public visitors and free accounts. It distinguishes necessary service processing from optional services that may be introduced later.
Who is responsible
Founder OS is the product name. The operator's formal identity and country must be configured and published before advertising or paid services are activated.
Privacy questions: contact@getfounderos.app.
Information processed
- Technical request and security information needed to deliver and protect public pages, including a one-way keyed identifier used to limit contact-form abuse.
- Your name, email address, subject and message when you submit the public contact form. These records are isolated from private account messaging and are not used to send an automated notification.
- Your email address, authentication state and security events when you create or use an account.
- The opportunity research, assessments, notes, decisions, plans, messages and other workspace records you choose to create.
- Service configuration and operational records needed to maintain reliability and investigate errors or abuse.
Purposes and boundaries
Information is processed to provide the requested workspace, authenticate users, isolate records by owner, preserve decision history, deliver exports, respond to support conversations, secure the service and meet applicable obligations. Founder OS does not sell private workspace records or make them public.
AI and external research
A supported AI or research function runs only after an explicit user action. The interface identifies the bounded context sent for that function. Account credentials and unrelated records are excluded. Generated output remains advisory and cannot silently change governed records. Do not enter unnecessary personal, confidential or regulated information.
Cookies and browser storage
Necessary technologies support authentication, security, consent records and preferences you request, such as appearance. Optional analytics is disabled by default and may run only after the applicable choice. See the Cookie Policy for the current storage inventory, providers and retention information.
Google AdSense and its certified CMP are not active by default. If activated after approval, Google's published Privacy & messaging flow will manage advertising consent, vendors, purposes and IAB TCF signals; the site's own analytics controls will not claim CMP certification or appear at the same time on monetized public pages.
You can change or withdraw an optional choice using “Privacy choices” in the page corner or “Privacy Choices” in the footer. In AdSense mode this opens Google's official revocation flow.
Service providers and transfers
Founder OS relies on infrastructure providers for hosting, database storage, authentication, transactional email, abuse protection and any explicitly requested AI or research function. These providers process only the information needed for their service under their applicable terms. A production operator must maintain the current provider list and applicable transfer safeguards as deployment configuration changes.
Retention and security
Public contact messages are scheduled for review or deletion after 180 days unless they must be retained longer to resolve the request or meet a legal obligation. Short-lived abuse-control records contain a keyed hash rather than a directly stored IP address. Account and workspace records are retained while the account is active and as needed for recovery, security, legal or operational obligations. Exact backup and security-log periods depend on the production infrastructure. Reasonable technical and organizational safeguards reduce risk, but no online service can promise absolute security.
Your controls
Authenticated users can review settings, export a machine-readable account package and readable report, revoke sessions and request eligible account closure. Depending on applicable law, you may also have rights to access, correct, delete, restrict or object to processing and to receive portable data. Identity verification may be required before acting on a request.
Changes to this notice
Material changes will be reflected on this page with an updated date. Advertising will not be activated merely by mentioning it here; the production configuration, consent controls and provider disclosure must all be ready first.
Last updated: 17 August 2026.