Foundable

Cookie & Tracking Notice

Effective and last updated: August 31, 2026

Foundable uses necessary storage, signed-in support functionality, first-party PostHog analytics, and automatic session replay on every normal Foundable application page. Provider conversion delivery for Foundable's own advertising is currently off, so no provider sends occur. Operator-enabled Foundable Ads remains separate.

What this page covers

This Notice explains the cookies, local storage, session storage, and similar technologies (collectively, "cookies") used on foundable.com and within the Foundable product, and how you can control them. It supplements our Privacy Policy.

Strictly necessary (always on)

These keep the product working. You can't turn them off without breaking login and security.

  • Supabase auth session (e.g. sb-*-auth-token). Keeps you logged in. The browser auth client sets it for up to 400 days and refreshes that lifetime when it saves a refreshed session, with SameSite=Lax and Secure on HTTPS. The browser auth client reads this cookie to maintain and refresh your session.
  • Onboarding-finished flag (localStorage) — remembers that you've completed onboarding so we don't re-show the welcome banner.
  • Authentication confirmation state (cookie). This is a bounded, HttpOnly, Secure, SameSite=Strict value used during supported confirmation flows.
  • Investor-room access (cookie, when used). This is a seven-day HttpOnly, Secure, SameSite=Lax session for the protected investor-room route.

Functional (always on)

These remember your preferences and, when enabled, keep the signed-in human-support Messenger working. They don't track you across the web.

  • Theme preference (light / dark) — localStorage.
  • Product state: may include the active foundable or thread, unsent chat drafts, navigation and policy handoffs, command-palette recents, dismissed prompts, builder state, layout choices, and recent-item preferences. Some keys include an operator or foundable identifier and remain until cleared or replaced.
  • Intercom Messenger identifier (intercom-id-[app_id], first-party cookie, when signed-in support is enabled): a unique Messenger identifier. Intercom's Product Privacy Notice lists a nine-month default duration. Foundable clears Intercom browser state during logout and detected session-loss flows.
  • Intercom Messenger session (intercom-session-[app_id], first-party cookie, when signed-in support is enabled): connects the current browser session to your prior support conversations. Intercom's default is one week; Foundable configures a one-hour Messenger session duration and clears it during logout and detected session-loss flows.
  • Intercom Messenger device identifier (intercom-device-id-[app_id], first-party cookie, when signed-in support is enabled): identifies a device that interacts with Messenger to help prevent abuse. Its default duration is 270 days and a successful Messenger ping can refresh it for another 270 days. Foundable clears Intercom browser state during logout and detected session-loss flows.
  • Intercom Messenger cached state (intercom.intercom-state-[app_id], first-party browser storage, when signed-in support is enabled): caches Messenger application and visitor data between page transitions. Intercom lists this storage as perpetual; Foundable clears it during logout and detected session-loss flows.

Foundable boots Messenger only after authenticating a signed-in operator. It is not booted for signed-out visitors or the public contact page, and Foundable does not use it for advertising, marketing, tours, standalone or proactive surveys, or proactive messages.

Analytics & error tracking

We use product and server-side telemetry to understand how the Service is used and to fix bugs. We also use first-party PostHog data to measure our own marketing: when you arrive through a link carrying campaign tags (such as utm_source), the tags and first-party analytics identifiers help us understand which campaigns work. Operator-enabled Foundable Ads delivery and measurement, when you approve that feature for a campaign, is described in our Privacy Policy. That operator-directed product workflow is separate from Foundable's first-party PostHog analytics and replay. Global Privacy Control and Do Not Track do not disable that first-party collection. Global Privacy Control separately suppresses receipt-based acquisition and signup attribution; Do Not Track does not act as that provider-measurement control.

  • PostHog: product analytics, feature flags, and automatic session replay used to diagnose operational issues and improve product flows: how people move through public pages, Build, Grow, and Earn, and where they get stuck. Sets first-party analytics cookies served through our own domain. Campaign fields use a bounded allowlist, rendered text and element attributes are masked for analytics events, and URL query strings and fragments are removed before those events leave your browser. That analytics-event masking is separate from replay. Replay runs on every normal Foundable application page for anonymous visitors and authenticated operators in all countries and on supported mobile and desktop browsers. Short-lived authentication or redirect bridge documents and static or download assets are not application pages and are not recorded. Replay reconstructs page layout and interactions. Ordinary visible interface text, ordinary form values, unsent drafts, submitted chat messages, and Ted's replies may be recorded as displayed or entered. Passwords, one-time authentication codes, payment-card values, explicit secret or API-key fields, hidden input values, and file input values are masked or omitted. Recorded page and network URLs are sanitized to strip query strings, fragments, credentials, and variable path identifiers; all request and response header and body contents are omitted. Replay recordings expire after 30 days. Global Privacy Control and Do Not Track do not disable this first-party PostHog collection.
  • Sentry: error tracking. Captures stack traces, request URLs, and a session identifier; session replay is disabled. We redact authorization/cookie headers and a defined list of sensitive body keys (passwords, tokens, secrets, API keys) before events leave our server; stack-trace context can still incidentally include other Customer Content.
  • Better Stack: server-side uptime monitoring. Does not run code in your browser.

Foundable-owned provider measurement is off

We do not place browser advertising pixels for our own advertising or share page visits through provider browser tags. Server-side provider conversion delivery for Foundable's own advertising is currently off, so no provider sends occur while it is off. There is no visitor control for that inactive delivery path.

Global Privacy Control suppresses the separate receipt-based acquisition path. Events from the off period will not be backfilled if provider delivery is activated later.

This off state does not disable first-party PostHog analytics, replay, or attribution. It also does not disable operator-enabled Foundable Ads, which is a separate workflow directed by the operator for their own campaign.

Your choices

  • Browser settings: you can block or delete cookies in your browser. Blocking or deleting authentication cookies signs you out, prevents session persistence, and may stop protected product features from working.
  • Account deletion — deletes or de-identifies account content after the grace period, while limited billing, security, fraud-prevention, and legally required records may be retained as described in our Privacy Policy for the full retention schedule.

Updates

We'll update this Notice when we change the cookies we use. The date at the top reflects the most recent revision. For material additions, we'll provide any notice or choice required by applicable law.

Questions about this document? privacy@foundable.com

Postal: Autono Labs, Inc. (operator of Foundable), 131 Continental Drive, Suite 305, Newark, DE 19713, USA. See /legal for our full set of policies.

Continue to footer navigation