Cookie & Tracking Notice
Effective and last updated: July 25, 2026
Foundable uses necessary storage, first-party analytics, selective session replay, and optional server-side advertising-platform conversion measurement. We do not place browser advertising pixels, and no optional provider conversion is sent until you explicitly opt in.
What this page covers
This Notice explains the cookies, local storage, session storage, and similar technologies (collectively, "cookies") used on foundable.com and within the Foundable product, and how you can control them. It supplements our Privacy Policy.
Strictly necessary (always on)
These keep the product working. You can't turn them off without breaking login and security.
- Supabase auth session (e.g.
sb-*-auth-token). Keeps you logged in. The browser auth client sets it for up to 400 days and refreshes that lifetime when it saves a refreshed session, with SameSite=Lax and Secure on HTTPS. The browser auth client reads this cookie to maintain and refresh your session. - Onboarding-finished flag (localStorage) — remembers that you've completed onboarding so we don't re-show the welcome banner.
- Authentication confirmation state (cookie). This is a bounded, HttpOnly, Secure, SameSite=Strict value used during supported confirmation flows.
- Investor-room access (cookie, when used). This is a seven-day HttpOnly, Secure, SameSite=Lax session for the protected investor-room route.
Functional (always on)
These remember your preferences within the product. They don't track you across the web.
- Theme preference (light / dark) — localStorage.
- Advertising-measurement choice (localStorage, when you make a choice) — remembers your current opt-in or refusal and a random browser capability used only to update that choice. The raw capability remains in your browser and is sent only to Foundable's first-party consent endpoint when recording or updating the choice. That endpoint immediately derives its SHA-256 hash; durable server records and analytics receive only the hash. An opt-in expires after 180 days.
- Ad-source handoff (sessionStorage, current tab only) — for up to 30 minutes, remembers the exact bounded campaign tags and applicable provider click identifier from an eligible public ad landing so a consent choice can be associated with the same provider. Re-reading the same landing does not extend that window. It never stores idea text, prompts, email, or arbitrary query parameters, and it does not itself send data to an advertising provider. GPC or DNT prevents this handoff from being stored or read.
- Product state: may include the active foundable or thread, unsent chat drafts, navigation and policy handoffs, command-palette recents, dismissed prompts, builder state, layout choices, and recent-item preferences. Some keys include an operator or foundable identifier and remain until cleared or replaced.
Analytics & error tracking
We use product and server-side telemetry to understand how the Service is used and to fix bugs. Server-side Foundable Ads conversion measurement, when you approve that feature for a campaign, is described in our Privacy Policy. We also use first-party PostHog data to measure our own marketing: when you arrive through a link carrying campaign tags (such as utm_source), the tags and first-party analytics identifiers help us understand which campaigns work. This first-party attribution is independent from the optional advertising-platform measurement described below. Browser PostHog does not initialize when Global Privacy Control or Do Not Track is present.
- PostHog: product analytics, feature flags, and selective session replay used to diagnose operational issues and improve product flows: how operators move through Build, Grow, and Earn, and where they get stuck. Sets first-party analytics cookies served through our own domain. Campaign fields use a bounded allowlist, rendered text and element attributes are masked for analytics events, and URL query strings and fragments are removed before those events leave your browser. That analytics-event masking is separate from replay. Replay is limited to selected routes and reconstructs page layout and interactions. Ordinary interface text outside designated private regions may be recorded; after you send a chat message, that submitted message and Ted's replies may be recorded as displayed. Input values, including text while it remains in the chat composer or another form, and unsent drafts remain masked; media and designated private regions are blocked; query strings, fragments, and variable path identifiers are stripped from recorded page and network URLs; and all request and response header and body contents are omitted. Account, admin, authentication-callback, checkout, invitation, password-reset, and all other unapproved routes are excluded. Replay starts only for a signed-in operator after the server confirms acceptance of the current Privacy Policy, and is restricted to sessions geolocated to the United States; missing or other country hints fail closed. Replay recordings expire after 30 days. Browser PostHog collection is disabled entirely when your browser sends a Global Privacy Control or Do Not Track signal.
- Sentry: error tracking. Captures stack traces, request URLs, and a session identifier; session replay is disabled. We redact authorization/cookie headers and a defined list of sensitive body keys (passwords, tokens, secrets, API keys) before events leave our server; stack-trace context can still incidentally include other Customer Content.
- Better Stack: server-side uptime monitoring. Does not run code in your browser.
Optional advertising-platform measurement
We do not place Meta, Google Ads, TikTok, or X browser advertising pixels, and we do not share page visits with those providers through browser tags. Foundable may use bounded server-side conversion measurement only for the ad provider that sent the visit, including Google Ads measurement for YouTube campaigns. No provider conversion is sent from our server without an explicit, current opt-in on foundable.com. Refusing or withdrawing that choice prevents future provider sends. Global Privacy Control or Do Not Track forces all of this optional provider measurement off even if a grant was saved previously. Removing one of those browser signals does not turn measurement on; you must opt in again.
When enabled, Foundable sends only these categories:
- Applicable advertising click identifiers captured from the ad link, when present: gclid, wbraid, and/or gbraid for Google Ads; fbclid together with the first-party time when the ad landing was observed is used to derive a Meta click identifier; ttclid is used for TikTok; or twclid is used for X. Meta, TikTok, and X also receive the fixed event-source URL https://foundable.com/, with no path, query, or fragment; it does not reveal which page the visitor viewed. Foundable does not add the visitor's IP address, browser user agent, email, phone, actual page URL, referrer, or provider browser cookie to these server conversion payloads.
- A conversion event name, event time, and provider-scoped pseudonymous stable event identifier used for safe retry and deduplication. Event names can include a successful refund or payment reversal as a distinct refund event; it is never labeled as a purchase.
- Payment value and currency only when Foundable sends an event for an actual successful payment. Signup, subscription-created, and refund events do not include payment value.
We do not send your idea text, private prompts, Customer Content, or full payment-method details through this advertising measurement. Advertising providers process the measurement data under their own privacy terms and may use their identifiers to attribute conversions, deduplicate events, report performance, and optimize ad delivery.
This provider measurement does not replace our independent first-party PostHog attribution. Granting, refusing, or withdrawing the provider measurement choice does not turn first-party PostHog attribution on or off; PostHog follows its own controls, including the Global Privacy Control and Do Not Track exclusion above. We keep platform-reported, first-party, and Stripe-reconciled attribution as separate views and never sum or blend them. Stripe-reconciled records remain the source of truth for money.
Your choices
- Browser settings: you can block or delete cookies in your browser. Blocking or deleting authentication cookies signs you out, prevents session persistence, and may stop protected product features from working.
- Advertising measurement choice: you can use the cookie choices on foundable.com to grant or withdraw permission at any time. Withdrawal applies to future server-side provider sends; data already delivered to a provider remains subject to that provider's retention rules and your applicable privacy rights.
- Do Not Track / Global Privacy Control — browser PostHog analytics, including replay, does not initialize when either signal is present. Optional advertising-platform measurement is also forced off, and the signal overrides any saved opt-in. Because our first-party marketing attribution is derived from browser PostHog, either signal also excludes your visit from that attribution. Bounded server-side operational events and error monitoring can still occur.
- Account deletion — deletes or de-identifies account content after the grace period, while limited billing, consent, security, fraud-prevention, and legally required records may be retained as described in our Privacy Policy for the full retention schedule.
Updates
We'll update this Notice when we change the cookies we use. The date at the top reflects the most recent revision. For material additions (e.g. a new analytics or marketing tool), we'll provide notice and obtain a fresh explicit opt-in before new optional provider measurement begins.
Questions about this document? privacy@foundable.com
Postal: Autono Labs, Inc. (operator of Foundable), 131 Continental Drive, Suite 305, Newark, DE 19713, USA. See /legal for our full set of policies.