1. Scope and controller
Autono Labs, Inc., doing business as Foundable ("Foundable," "we," "us," or "our"), controls the personal information used to administer Foundable Creator Rewards (the "Program"). This Notice supplements Foundable's general Privacy Policy and applies to applicants, accepted Creators, post-acceptance social-account onboarding, Program submissions, product attribution, direct and Level-2 referral relationships, the 7-Day Perfect Run Challenge, weekly leaderboards, verification, licenses, payments, and appeals.
This Notice is presented at or before the Program application collects information. It is also available before post-acceptance social-account connection, Perfect Run enrollment, and public leaderboard opt-in. The Program is limited to natural persons age 18 or older who legally reside in the 50 United States or the District of Columbia.
2. Information we collect
- Application identity, eligibility, and acquisition information: signed-in verified Foundable email, legal or payout-verifiable name, server-derived display name, age-18-or-older and U.S./D.C. residency attestations, application status and decision, Foundable account and application IDs, and bounded source, UTM, placement, and direct-referral attribution. TikTok or Instagram profile information is not collected during the initial application under this version.
- Post-acceptance social-account onboarding: TikTok and Instagram handles, profile URLs, provider account IDs, authorization and connection records, account-control and created-after-acceptance attestations, exact attestation text and version, timestamps, the applicable Acceptance Timestamp, and provider ownership-verification results. Foundable may record a provider-supplied account-creation timestamp when reliably available. Provider ownership verification establishes control, not account age, unless the provider supplies reliable creation-time information.
- Program content and analytics: public post URLs, platform post IDs, original publication times, submitted content and samples, content fingerprints, native analytics screenshots or recordings, qualified-view counts, traffic-source evidence, review decisions, and clearance materials.
- Agreement and requirements evidence: the application-evidence or schema version; exact Program Terms, Rights Consent, Privacy Notice, and Program Requirements versions, URLs, and SHA-256 hashes; exact checkbox labels and acceptance text; separate acceptance and acknowledgment timestamps; application and account identities; source IP address; bounded browser user agent; account-onboarding attestation evidence; and durable receipt delivery.
- Product attribution: opaque Creator, product-link, and platform-source tokens; click, claim, and qualification timestamps; UTMs; attributed signup, account-verification, and first-build or first-project status; qualification and fraud-review decisions; and Creator-facing aggregate progress. Product-attribution records may link an eligible click to the resulting Foundable operator account for qualification, last-eligible-click attribution, and duplicate-prevention purposes.
- Referral relationships and commissions: opaque referral-link tokens; referral clicks and timestamps; referral source; the application-level attribution decision and lock timestamp; any correction required for a documented attribution error; direct referrer and, where active, one eligible Level-2 ancestor relationship; relationship and acceptance timestamps; covered paid-video counts and publication windows; completed view-tier reward used as the commission base; direct and Level-2 share amounts; per-video, per-relationship, monthly, and launch-season cap status; and qualification, hold, cap-exclusion, reversal, recovery, appeal, and fraud-review records.
- Perfect Run information: challenge enrollment and start time, creator-selected challenge timezone, locked seven-day dates, associated creative and publication records, provisional and finalized posting-day credits, individual 2,000-view milestones, completion status, Perfect Run badge, $25 or $50 bonus status, adjustments, appeals, and reversals. Foundable does not need precise geolocation for this purpose.
- Leaderboard information: weekly cohort assignment, program-wide leaderboard timezone, finalized qualified views, completed View Rewards, rank, paid-creative count, Perfect Run status, tie-break information, provisional and final status, weekly prize, score adjustments and appeals, public-display opt-in or opt-out, selected alias or handle, and opt-in change history.
- Payment, identity, and tax information: payment-provider IDs, recipient status, payment category, amount and currency, identity and residency status, tax-form status, payout and return events, accounting evidence, dependent reversals and recoveries, cap exclusions, and anti-duplicate-payment records. Full bank-account and card numbers are handled by payment providers and are not stored by Foundable.
- Device, security, integrity, and operational information: request timestamps, IP address, bounded user agent, service logs, audit events, and signals concerning duplicate participation, self-referral, circular chains, referral rings, artificial views, account farms, coordinated activity, manipulated attribution, challenge abuse, or score manipulation, together with reviewer, reason-code, prior-state, and new-state history.
- Communications: application and agreement receipts, acceptance or decline notices, support requests, information requests, appeals, decisions, license notices, challenge and leaderboard notices, and payment communications.
Sources include you, other Program applicants or Creators through referral activity, your public posts and platform analytics, your device, social-account and payment providers you authorize, Foundable's product and attribution systems, and public platform information needed to administer the Program.
Please do not provide passwords, MFA codes, recovery codes, unnecessary government identifiers, precise geolocation, biometric templates, health information, or other information the Program does not request.
3. Why we use information
Foundable uses Program information to:
- Receive, authenticate, verify, and review applications.
- Confirm age and geography eligibility and Program standing.
- Operate post-acceptance new-account onboarding, record the Creator's created-after-acceptance attestation, verify account control, and use provider-supplied creation timing only when reliably available.
- Provide the Creator portal, Program Requirements, assets, product-attribution links, referral links, and support.
- Validate URLs, publication times, cross-post groups, content eligibility, qualified organic views, signups, referrals, and exact measurement windows.
- Administer direct and Level-2 referral attribution, eligibility periods, dependent commissions, reversals, and caps.
- Operate the optional Perfect Run Challenge, daily credits, badge, and bonus.
- Assign weekly cohorts, calculate and finalize Verified Views and View Rewards, resolve ties, and administer weekly prizes.
- Display a Creator's selected alias or handle, rank, scores, badge, and winner status only after public-display opt-in.
- Detect and review duplicate, self-referred, circular, coordinated, automated, fabricated, or manipulated activity.
- Conduct human review, respond to appeals, and document decisions.
- Administer, track, and end organic and paid-media licenses.
- Make, reconcile, hold, deny, reverse, recover, and document payments and satisfy tax obligations.
- Send application, agreement, review, security, license, challenge, leaderboard, and payment communications.
- Secure, debug, audit, and improve the Program.
- Enforce the Program Agreement, protect legal rights, and comply with law.
Collection, use, disclosure, and retention are limited to what is reasonably necessary and proportionate for these disclosed purposes or a compatible purpose permitted by law.
5. Retention schedule
Foundable retains each category only for as long as reasonably necessary and proportionate for the purposes described in this Notice. The periods below are baseline recordkeeping periods or operational targets, not a promise that every copy is deleted on one exact day. Retention may continue while reasonably needed for an active application or participation, an unexpired license, payment, tax, or accounting, an appeal or support matter, security or fraud prevention, enforcement of the Program Agreement, establishing, exercising, or defending legal claims, a documented legal hold, or applicable law. When those purposes end, Foundable deletes, deidentifies, or restricts the information through its ordinary lifecycle.
| Information category | Retention period |
|---|---|
| Untouched application drafts with no agreement or operational evidence | Up to 30 days after creation. |
| Verified but declined or withdrawn application profile data | Generally at least 24 months after the final decision or appeal, and longer under the criteria above. |
| Minimal declined or withdrawn agreement and decision evidence | Generally at least 4 years after the final decision, and longer under the criteria above. |
| Accepted Creator profile and post-acceptance social-account information | During participation and generally at least 24 months after termination or last activity, and longer under the criteria above. |
| Social-provider credentials and live connection data | While connected and while needed to complete disconnect, cleanup, security, or provider reconciliation. |
| Account-control, created-after-acceptance attestations, and ownership evidence | Generally at least 4 years after the later of the last submission, final appeal, or Program termination; longer under the criteria above. |
| Raw analytics screenshots, recordings, and clearance files | Through final verification, appeal, and the applicable license, and generally at least 24 months afterward; longer under the criteria above. |
| Submitted content retained as an active marketing asset | Only during the applicable exact 12-month organic or exact 90-day paid-media term. |
| Nonpublic content copy, derived metrics, content fingerprint, eligibility, appeal, and license records | Generally at least 4 years after the later of the final decision, appeal, license expiration, or termination; longer under the criteria above. |
| Agreement and Program Requirements identities, acceptance text, timestamps, source IP address, and bounded browser user agent | Generally at least 4 years after the later of the last submission, latest license expiration, final appeal, or Program termination. Direct identifiers may be removed or pseudonymized earlier when no longer needed. |
| Product-attribution and referral click or session identifiers | Through attribution, qualification, payment, and appeal and generally at least 13 months after the click; longer for reconciliation, duplicate prevention, fraud, or disputes. |
| Referral relationships, eligibility windows, caps, commissions, reversals, and integrity records | Through qualification, payment, and appeal and generally at least 4 years after the later of relationship-window closure, final decision, or Program termination. |
| Perfect Run timezone, daily credits, badge, bonus, adjustment, and appeal records | Generally at least 4 years after the final challenge decision, appeal, or Program termination. |
| Weekly cohort, score, rank, tie-break, public-display choice history, prize decision, and adjustment records | Generally at least 4 years after the final weekly result, appeal, or Program termination. |
| Public leaderboard alias or handle, Verified Views, View Rewards, rank, badge, and winner or prize status | While opted in and while the applicable board is displayed. Foundable removes the information from controlled public display by the next scheduled weekly leaderboard refresh and no later than seven calendar days after opt-out. |
| Payment, tax, accounting, provider-reference, reversal, recovery, cap-exclusion, and anti-duplicate-payment records | At least 7 years after the calendar year of the final transaction, and longer when law, a dispute, or recovery requires. |
| Support and ordinary Program communications | Generally at least 3 years after closure. Payment, tax, or legal-dispute communications follow the applicable longer schedule. |
| Privacy-request records | At least 24 months after Foundable's response. |
| Core AWS service logs | Generally 30 days. |
| Hosted-application and web-application-firewall logs | Generally 14 days. |
| Deidentified and aggregated reporting | May be retained indefinitely when it cannot reasonably be linked to a person. |
Short-lived operational logs may contain an IP address or user agent for the shorter log periods above. The source IP address and bounded browser user agent retained as agreement evidence follow the agreement-evidence row.
Backups are not deleted record by record and expire under provider-configured rotation. Backup data is not used for ordinary operations. If restored for disaster recovery, applicable deletion or restriction instructions are reapplied.
A documented legal hold, tax duty, unresolved payment, security incident, fraud investigation, or dispute may extend retention for affected records until the purpose is resolved. Foundable will not publicly use content beyond its license merely because a private evidentiary copy remains.
6. Privacy rights and choices
Subject to applicable law, you may request access, correction, deletion, or a portable copy; object to or restrict certain processing; withdraw consent where processing relies on consent; and appeal a privacy decision.
The Perfect Run Challenge is voluntary. Public leaderboard identification is separately optional. You may change your public alias or opt out of future public display without losing Program eligibility, leaderboard scoring, or an earned reward. Opting out does not require deletion of nonpublic score, prize, tax, accounting, fraud, contract, or appeal records that Foundable may lawfully retain.
California residents may also request the categories and specific pieces of information collected, request correction or deletion, opt out of a legally defined sale or sharing, limit certain uses of sensitive personal information, use an authorized agent, and exercise rights without discriminatory treatment.
A deletion request does not require Foundable to delete information it must or may retain for payment, tax, security, fraud prevention, contract, license, dispute, legal compliance, or another statutory purpose. Account deletion does not revoke an active organic or paid-media license or invalidate lawful prior processing.
To submit a request, email privacy@foundable.com. Foundable may verify your identity and authority before acting. Where the California Consumer Privacy Act applies, Foundable ordinarily responds within 45 days, subject to permitted extensions.
7. Age limit
The Program is limited to people age 18 or older. Foundable does not knowingly accept minors. If Foundable learns that a minor submitted Program information, Foundable will reject the application and delete the information unless a minimal record must be retained for security or legal compliance.
A Creator must obtain any legally required parent or guardian release before submitting content featuring a recognizable minor.
8. Security and automated review
Foundable uses reasonable administrative, technical, and organizational safeguards appropriate to the nature of Program information. No storage or transmission system is perfectly secure.
Automated systems may calculate provisional views, payout tiers, referral and challenge progress, cap applications, weekly scores and ranks, and may flag duplicates, inconsistencies, or suspected artificial activity. Before an application, eligibility determination, final score or rank, weekly winner or prize, challenge bonus, referral commission, view-tier payment, or appeal decision becomes final, an authorized human reviews the output and other relevant information and has authority to change the result.
9. Changes to this Notice
Foundable may update this Notice prospectively and will identify the current version and effective date. Material changes affecting existing Creators receive reasonable notice. A material change to Program economics, Creator rights, license terms, referrals, challenge or leaderboard processing, or retention requires a new Program version and fresh acceptance before governing a new submission or other initiating event.
10. Contact
Privacy requests: privacy@foundable.com
Program support and appeals: support@foundable.com
Legal notices: legal@foundable.com
Postal address:
Autono Labs, Inc.
Attn: Privacy (Foundable Creator Rewards)
131 Continental Drive, Suite 305
Newark, DE 19713, USA