Foundable Creator Rewards

Creator Privacy & Retention Notice

This notice explains the Program information Foundable collects, why it is used, who receives it, how long it is retained, and the choices available to Creators.

1. Scope and controller

Autono Labs, Inc., doing business as Foundable ("Foundable," "we," "us," or "our"), controls the personal information used to administer Foundable Creator Rewards (the "Program"). This Notice supplements Foundable's general Privacy Policy and applies to applicants, accepted Creators, Program submissions, attribution, verification, rights, and payments.

This Notice is presented at or before the Program application collects information. The Program is limited to natural persons age 18 or older who legally reside in the 50 United States or the District of Columbia.

2. Information we collect

  • Application identity and contact information: legal or payout-verifiable name, display name, email, age-18-or-older attestation, U.S./D.C. residency attestation, application source, and optional source detail.
  • Social-account information: TikTok and Instagram handles, profile URLs, account-control attestations and evidence, platform account IDs, and bounded provider profile, authorization, and connection records.
  • Program content and analytics: public post URLs, platform post IDs, original publication times, submitted content and samples, content fingerprints, native analytics screenshots or recordings, qualified-view counts, traffic-source evidence, review decisions, and clearance materials.
  • Agreement evidence: exact Program Terms, Rights Consent, and Privacy Notice versions, URLs, and SHA-256 hashes; exact checkbox labels and consent text; separate acceptance timestamps; application and account identities; source IP address; bounded browser user agent; and durable receipt delivery.
  • Attribution and referral information: opaque Creator and link tokens, clicks, timestamps, platform source, UTMs, referral relationships, signup status, account-verification status, first-build or first-project status, qualification decisions, and aggregated progress.
  • Payment, identity, and tax information: payment-provider IDs, recipient status, payment amount and currency, identity and residency status, tax-form status, payout and return events, accounting evidence, and anti-duplicate-payment records. Full bank-account and card numbers are handled by payment providers and are not stored by Foundable.
  • Device, security, and operational information: request timestamps, IP address, bounded user agent, security and fraud signals, service logs, and audit events.
  • Communications: application and agreement receipts, acceptance or decline notices, support requests, information requests, appeals, decisions, license notices, and payment communications.

Sources include you, your public posts and platform analytics, your device, social-account and payment providers you authorize, Foundable's product and attribution systems, and public platform information needed to administer the Program.

Please do not provide passwords, MFA codes, recovery codes, unnecessary government identifiers, precise geolocation, biometric templates, health information, or other information the Program does not request.

3. Why we use information

Foundable uses Program information to:

  • Receive, authenticate, verify, and review applications.
  • Confirm age and geography eligibility, account control, and Program standing.
  • Provide the Creator portal, Program Requirements, assets, attribution links, referral links, and support.
  • Validate URLs, publication times, cross-post groups, content eligibility, qualified organic views, signups, referrals, and exact measurement windows.
  • Detect duplicate participation, artificial activity, abuse, account compromise, and fraud.
  • Conduct human review, respond to appeals, and document decisions.
  • Administer, track, and end organic and paid-media licenses.
  • Make, reconcile, reverse, recover, and document payments and satisfy tax obligations.
  • Send application, agreement, review, security, license, and payment communications.
  • Secure, debug, audit, and improve the Program.
  • Enforce the Program Agreement, protect legal rights, and comply with law.

Collection, use, disclosure, and retention are limited to what is reasonably necessary and proportionate for these disclosed purposes or a compatible purpose permitted by law.

4. How we disclose information

Foundable may disclose Program information:

  • To service providers supporting hosting, databases, authentication, email, analytics, security, social-account connectivity, content and metric verification, advertising delivery, and payment.
  • To TikTok, Instagram, and advertising platforms when needed to verify public content or exercise the exact organic or paid rights authorized by the Rights Consent.
  • To professional advisors, auditors, insurers, and accountants under appropriate duties of confidentiality.
  • To law enforcement, courts, regulators, or other parties where required or permitted by law after appropriate review.
  • To a successor in connection with a merger, financing, reorganization, acquisition, or sale of relevant assets, subject to appropriate safeguards.

Licensed content and identity elements embodied in it may be provided to social and advertising platforms solely for Foundable's authorized organic or paid uses. Creator dashboards show aggregate attribution status and do not reveal an attributed Foundable user's identity or private account information.

Sale and sharing. Foundable does not sell Creator personal information for money or use Program records for unrelated cross-context behavioral advertising. Foundable's general site analytics and advertising technologies remain governed by the Privacy Policy and Cookie Notice. If applicable law treats any covered processing as a "sale" or "sharing," the applicable opt-out rights and controls described in those policies remain available.

The current categories of infrastructure and service providers are described in Foundable's provider registry. Providers may process information in the United States and other locations described there, subject to applicable contractual and legal safeguards.

5. Retention schedule

Foundable retains each category only for as long as reasonably necessary and proportionate for the purposes described in this Notice. The periods below are baseline recordkeeping periods or operational targets, not a promise that every copy is deleted on one exact day. Retention may continue while reasonably needed for an active application or participation, an unexpired license, payment, tax, or accounting, an appeal or support matter, security or fraud prevention, enforcement of the Program Agreement, establishing, exercising, or defending legal claims, a documented legal hold, or applicable law. When those purposes end, Foundable deletes, deidentifies, or restricts the information through its ordinary lifecycle.

Creator Program retention periods
Information categoryRetention period
Untouched application drafts with no agreement or operational evidenceUp to 30 days after creation.
Verified but declined or withdrawn application profile dataGenerally at least 24 months after the final decision or appeal, and longer under the criteria above.
Minimal declined or withdrawn agreement and decision evidenceGenerally at least 4 years after the final decision, and longer under the criteria above.
Accepted Creator profile and social-account informationDuring participation and generally at least 24 months after termination or last activity, and longer under the criteria above.
Social-provider credentials and live connection dataWhile connected and while needed to complete disconnect, cleanup, security, or provider reconciliation.
Raw analytics screenshots, recordings, and clearance filesThrough final verification, appeal, and the applicable license, and generally at least 24 months afterward; longer under the criteria above.
Submitted content retained as an active marketing assetOnly during the applicable exact 12-month organic or exact 90-day paid-media term.
Nonpublic content copy, derived metrics, content fingerprint, eligibility, appeal, and license recordsGenerally at least 4 years after the later of the final decision, appeal, license expiration, or termination; longer under the criteria above.
Agreement document identities, exact acceptance labels, separate acceptance timestamps, source IP address, and bounded browser user agentGenerally at least 4 years after the later of the last submission, latest license expiration, final appeal, or Program termination. Direct identifiers may be removed or pseudonymized earlier when no longer needed.
Product-attribution and referral click or session identifiersThrough attribution, qualification, payment, and appeal and generally at least 13 months after the click; longer for reconciliation, duplicate prevention, fraud, or disputes.
Payment, tax, accounting, provider-reference, reversal, recovery, and anti-duplicate-payment recordsAt least 7 years after the calendar year of the final transaction, and longer when law, a dispute, or recovery requires.
Support and ordinary Program communicationsGenerally at least 3 years after closure. Payment, tax, or legal-dispute communications follow the applicable longer schedule.
Privacy-request recordsAt least 24 months after Foundable's response.
Core AWS service logsGenerally 30 days.
Hosted-application and web-application-firewall logsGenerally 14 days.
Deidentified and aggregated reportingMay be retained indefinitely when it cannot reasonably be linked to a person.

Short-lived operational logs may contain an IP address or user agent for the shorter log periods above. The source IP address and bounded browser user agent retained as agreement evidence follow that agreement-evidence row, including its earlier-minimization and extension criteria.

Backups are not deleted record by record and expire under provider-configured rotation. Backup data is not used for ordinary operations. If restored for disaster recovery, applicable deletion or restriction instructions are reapplied.

A documented legal hold, tax duty, unresolved payment, security incident, fraud investigation, or dispute may extend retention for affected records until the purpose is resolved. Foundable will not publicly use content beyond its license merely because a private evidentiary copy remains.

6. Privacy rights and choices

Subject to applicable law, you may request access, correction, deletion, or a portable copy; object to or restrict certain processing; withdraw consent where processing relies on consent; and appeal a privacy decision.

California residents may also request the categories and specific pieces of information collected, request correction or deletion, opt out of a legally defined sale or sharing, limit certain uses of sensitive personal information, use an authorized agent, and exercise rights without discriminatory treatment.

A deletion request does not require Foundable to delete information it must or may retain for payment, tax, security, fraud prevention, contract, license, dispute, legal compliance, or another statutory purpose. Account deletion does not revoke an active organic or paid-media license or invalidate lawful prior processing.

To submit a request, email privacy@foundable.com. Foundable may verify your identity and authority before acting. Where the California Consumer Privacy Act applies, Foundable ordinarily responds within 45 days, subject to permitted extensions.

7. Age limit

The Program is limited to people age 18 or older. Foundable does not knowingly accept minors. If Foundable learns that a minor submitted Program information, Foundable will reject the application and delete the information unless a minimal record must be retained for security or legal compliance.

A Creator must obtain any legally required parent or guardian release before submitting content featuring a recognizable minor.

8. Security and automated review

Foundable uses reasonable administrative, technical, and organizational safeguards appropriate to the nature of Program information. No storage or transmission system is perfectly secure.

Automated systems may flag possible duplicates, ineligible traffic, security threats, or inconsistencies for review. A human makes final application, eligibility, appeal, and payment decisions that materially affect a Creator.

9. Changes to this Notice

Foundable may update this Notice prospectively and will identify the current version and effective date. Material changes affecting existing Creators receive reasonable notice. A material change to Program economics, Creator rights, or license terms requires a new Program version and fresh acceptance before governing a new submission.

10. Contact

Privacy requests: privacy@foundable.com

Program support and appeals: support@foundable.com

Legal notices: legal@foundable.com

Postal address:
Autono Labs, Inc.
Attn: Privacy (Foundable Creator Rewards)
131 Continental Drive, Suite 305
Newark, DE 19713, USA