Privacy Policy
Effective and last updated: July 25, 2026
We collect the data needed to operate Foundable, use scoped providers for core and enabled features, and do not sell personal information. On selected routes, selective session replay may record ordinary interface text and submitted chats as displayed; input fields, unsent drafts, media, and private regions stay protected. Optional advertising-platform measurement stays off until you explicitly opt in.
1. Who we are
Autono Labs, Inc., a Delaware corporation ("Autono Labs," "we," "us"), operates the Foundable service at foundable.com and related properties. ("Foundable" is the brand name of the Service; the legal entity is Autono Labs, Inc.) This Privacy Policy explains what personal information we collect when you use the Service, how we use and share it, and the choices you have. It applies to operators, account admins, and visitors to our website.
For Service customers in the European Economic Area (EEA), UK, or Switzerland, Autono Labs is the "controller" for personal information described here, except where we process Customer Content as a "processor" on your behalf. See our Data Processing Addendum for a non-binding review template and the execution process.
2. Personal information we collect
We collect the following categories of personal information:
- Account data: the email address and, when provided or used by a feature, your name, avatar, phone number, timezone, notification preferences, invitations, foundable memberships, role, and account timestamps. Source: you or your authentication provider.
- Customer Content: messages you send to Ted, files you upload, project plans, generated outputs, connected-service data, generated app source and backend data, and configuration you submit. Source: you, enabled product features, or third-party integrations you authorize.
- AI conversation analytics: chat inputs and outputs; tool names, status, and ordinary tool inputs and outputs; operator and thread identifiers; and account traits including your display name and email. Source: your account and use of the Service. Onboarding public-profile source URLs, headlines, and lookup inputs are omitted before transmission to Agnost Tech Inc.
- Public professional context: during onboarding, we may use the name on your account and a broad organization affiliation derived from your email domain when that domain is not recognized as a common personal-email provider. We use these details to search publicly accessible professional pages. Possible matches can include a page URL, title, and short public snippet describing a role, employer, industry, education, or professional experience. Source: public web pages returned by Exa Labs Inc. We may locally compare your email username, lowercased and with punctuation normalized, to the public profile handles Exa returns. We preserve distinguishing letters and numbers for this comparison. That username is not sent to Exa. We do not send your full email address to Exa or access your device contents, browser history, email inbox, contacts, or private accounts for this search.
- Integration credentials: OAuth access tokens, refresh tokens, and API keys for third-party services you connect (e.g. Linear, Notion, Slack, HubSpot). These are stored encrypted at rest with AES-256-GCM. Source: you (via OAuth or paste-in).
- Usage telemetry and selective session replay: pages visited, actions taken in the product, error logs, performance metrics, feature flags evaluated, and anonymous or identified session and account identifiers. On selected routes, replay records a reconstruction of page layout, navigation, clicks, pointer movement, scrolling, and other interactions so we can debug operational issues and improve product flows. Ordinary interface text outside designated private regions may be recorded. After you send a chat message, that submitted message and Ted's replies may be recorded as displayed. Input values, including text while it remains in the chat composer or another form, and unsent drafts remain masked; media and designated private regions are blocked; query strings, fragments, and variable path identifiers are stripped from recorded page and network URLs; and all request and response header and body contents are omitted. Because submitted chat may be recorded, do not put passwords, API keys, payment-card details, authentication codes, or special-category data in messages. Replay is not recorded on account, admin, authentication-callback, checkout, invitation, password-reset, or any other route that is not explicitly approved. Replay starts only for a signed-in operator after the server confirms acceptance of the current Privacy Policy, and is restricted to sessions geolocated to the United States; missing or other country hints fail closed. Global Privacy Control or Do Not Track keeps browser PostHog, including replay, off. Signed-in browser analytics is keyed to your operator ID and a bounded operator role; it does not add your email address to the PostHog person profile. Source: your device and use of the Service.
- First-party marketing attribution: when your visit to foundable.com arrives via a link carrying campaign tags (such as utm_source), for example from one of our own ads or a newsletter, we collect those tags, the landing page path, first-party PostHog session and device identifiers, and visit timestamps. If you have or later create an account, we may link those visits to your operator ID and our own billing records (for example, whether a subscription started). This first-party attribution is independent from the optional provider measurement below, and we do not send its PostHog attribution record to advertising platforms. Source: your device and use of the Service; our billing records.
- Optional advertising-platform measurement: only after you give an explicit, current opt-in, and only while Global Privacy Control and Do Not Track are absent, Foundable may send bounded server-side conversion measurement to the provider that sent the visit, including Google Ads measurement for YouTube campaigns. We do not place browser advertising pixels for Meta, Google Ads, TikTok, or X and do not share page visits through browser tags. Provider measurement may receive an applicable advertising click identifier (for Meta, a click identifier derived from fbclid and the first-party time when the ad landing was observed), conversion event name, event time, and provider-scoped pseudonymous stable event identifier used for safe retry and deduplication. Meta, TikTok, and X also receive the fixed event-source URL https://foundable.com/, without a path, query, or fragment; it does not reveal the page viewed. Our server payloads do not add the visitor's IP address, browser user agent, email, phone, actual page URL, referrer, or provider browser cookie. Payment value and currency are sent only for an actual successful payment event. A successful refund or payment reversal may be sent as a separately labeled refund event, never as a purchase and without a payment value. We never send idea text, private prompts, Customer Content, form contents, or full payment-method details through this measurement. Source: your device, your consent choice, the ad link, your use of the Service, and—only for an actual paid or refunded event—our billing records.
- Foundable Ads data: when you use Foundable Ads, campaign settings, destination URLs, approved ad creative, spend and delivery records, provider IDs, and limited conversion event metadata such as event name, event time, action source, event source URL, event ID, campaign/ad identifiers, and hashed or pseudonymous matching identifiers where configured. Raw email, phone, name, IP address, and user-agent fields are blocked before they reach Foundable Ads conversion delivery.
- Device and connection data: IP address, browser user-agent, operating system, referring URL, and approximate location derived from IP. Source: your device, captured by Vercel and AWS for the primary service, and by Cloudflare when a Turnstile, rendering, or managed-domain feature is used.
- Billing data (when applicable): name, email, billing address and country, tax information you provide, payment-method details such as card brand and last-four digits, transaction and invoice history, merchant-of-record route, and the original and local-presentment currencies and amounts. Full payment-method numbers are handled by Stripe or Link; we do not store them.
- Billing-consent records: the plan, price, renewal cadence, credit terms and policy versions you accepted; billing country and merchant-of-record route; Stripe Checkout and Price identifiers; acceptance time; and the IP address and browser user-agent used to record the acceptance. We keep this evidence to verify an authorized recurring purchase and resolve billing disputes.
- Communications: emails you send us, support tickets, and feedback you submit through the product.
We collect authentication and Integration credentials, which may be sensitive personal information. We use them only to provide, secure, and maintain the Service and do not use them to infer characteristics. Please do not submit health, biometric, precise-geolocation, government-ID, or other special-category content through the Service.
3. How we use personal information
We use personal information to:
- Provide, maintain, secure, debug, and improve the Service, including by reviewing selective replay to diagnose operational issues and understand where product flows break down.
- Process Customer Content through purpose-specific AI providers. Anthropic powers primary conversational and build reasoning; OpenAI and Cohere handle selected embedding, extraction, transcription, and reranking tasks; and fal.ai handles creative generation. Our provider registry lists the current providers and data categories.
- Analyze AI conversations and monitor product quality through Agnost Tech Inc., with onboarding public-profile source URLs, headlines, and lookup inputs omitted before transmission.
- Add a source-linked, tentative note to Ted's first onboarding welcome when a public professional profile is a likely match, while suppressing ambiguous or conflicting results. The unconfirmed profile is not provided to Ted's AI model or used to influence its questions.
- Authorize and execute calls to third-party Integrations you have connected.
- Draft, approve, deliver, measure, reconcile, pause, and secure Foundable Ads campaigns when you opt into that feature and approve spend.
- Measure our own marketing and advertising through independent first-party attribution: link campaign-tagged visits (for example, clicks on one of our ads) to signups and our own billing outcomes so we can tell which channels and ads work.
- With your explicit opt-in, send bounded server-side conversion measurement to Meta, Google Ads, TikTok, or X to attribute and deduplicate conversions, report campaign performance, and optimize ad delivery. This may include a separately labeled successful refund or payment-reversal event, which is never reported as a purchase. These providers do not receive idea text or private prompts.
- Keep platform-reported, first-party, and Stripe-reconciled attribution as separate views. We never sum or blend those views, and Stripe-reconciled records remain the source of truth for money.
- Authenticate you and protect against abuse, fraud, and unauthorized access.
- Process purchases and subscriptions, present local currency, calculate and remit applicable transaction taxes, deliver receipts, manage orders, and resolve payment support, refunds, and disputes.
- Send transactional messages (security alerts, billing receipts, important product changes). You can't opt out of these while you have an active account.
- Send product updates and announcements. This preference is enabled by default; you can opt out through the available preference or unsubscribe control.
- Comply with legal obligations and enforce our Terms.
- Conduct internal analytics and product research, on aggregated or de-identified data where practical.
4. Lawful bases (EEA / UK)
For users in the EEA, UK, and Switzerland, we rely on the following lawful bases under the GDPR Article 6:
- Performance of contract: to provide the Service you signed up for (account creation, processing your messages, calling Integrations, processing purchases and subscriptions, and delivering Foundable Ads campaigns you approve).
- Legitimate interest: to keep the Service secure, prevent abuse, debug errors and operational issues, use limited public professional context to explain a possible match during onboarding, conduct internal analytics, perform independent first-party measurement of our own marketing and advertising, and develop the product. We assess these against your rights and only proceed where the interest is not overridden.
- Consent: for optional server-side conversion measurement to Meta, Google Ads, TikTok, or X. Foundable does not load provider browser tags. No optional provider conversion is sent without an explicit, current grant. You can withdraw or change that choice at any time, and Global Privacy Control or Do Not Track forces the measurement off regardless of a saved grant. Other analytics uses rely on legitimate interests where permitted. The browser controls are described in our Cookie Notice.
- Legal obligation: to comply with applicable law (tax, accounting, lawful government requests).
5. How we share personal information
We share personal information only as needed to operate the Service, honor your instructions, and provide optional features you enable. Service providers that process data on our behalf may be subprocessors. The current provider, feature scope, data-category, location, and role table is at /subprocessors.
- Core infrastructure: Supabase stores account data and Customer Content in our primary us-west-1 project; AWS runs the API and workers in us-west-1; Vercel serves the UI; and Resend delivers transactional email.
- AI and research: Anthropic handles primary reasoning; OpenAI handles selected embeddings, extraction, and transcription; Cohere reranks selected text; Agnost receives feature-scoped conversation analytics; and Exa receives public-web research queries and requested public content. The registry page states each provider's scope and data handling.
- Build, creative, and growth: Daytona receives app source, build instructions, and build output; fal.ai receives creative prompts or media; AgentMail and LoopMessage process customer-directed communications; Zernio processes social publishing data; and Hunter processes contact-finding or verification inputs for enabled Grow features.
- Security and selected infrastructure: Sentry receives diagnostic events and performance traces; Cloudflare handles Turnstile, browser rendering, and DNS for applicable customer domains. Cloudflare is not the primary DNS or edge provider for foundable.com.
- Product analytics and internal operations: PostHog, Inc. acts as our processor for identified product analytics, feature flags, and selective session replay on selected routes; Better Stack receives endpoint or heartbeat availability, status, latency, and incident metadata; GitHub hosts Foundable source and CI; and feedback submitted to Foundable may be delivered to our internal Slack account.
For an eligible transaction labeled "Sold through Link," Sold through Link, LLC, a Stripe affiliate, acts as merchant of record. Stripe and Link use billing, payment, tax, device, fraud, transaction, and order information to charge and collect payment, convert currency, calculate and remit applicable transaction taxes, prevent fraud, send receipts, manage subscriptions and orders, and provide payment support, refunds, and dispute handling. For those merchant-of-record and Link functions, Stripe determines its own processing purposes and acts as an independent controller, not solely as our subprocessor. Stripe shares order information with us so we can deliver Foundable and manage our customer relationship. See the Link Privacy Center for its current practices and privacy controls.
We may also share personal information:
- With third-party Integrations you connect, when you instruct or authorize the Service to do so. Those providers generally act under their own terms for the connected service; their precise privacy role can depend on the activity.
- With advertising providers for Foundable Ads only when you opt into the feature and approve the campaign or conversion event use. For Meta campaigns, Meta Platforms, Inc. may receive limited campaign data and server-side conversion event data so it can deliver, measure, and reconcile the campaign under its own advertising terms and privacy policies.
- With Meta Platforms, Inc.; Google LLC for Google Ads, including YouTube campaign measurement; TikTok and its applicable advertising affiliate; and X Corp. for Foundable's own optional advertising measurement, but only after your explicit opt-in and only through bounded server-side conversion measurement. Depending on the provider and ad link, a recipient may receive an applicable advertising click identifier (for Meta, a click identifier derived from fbclid and the first-party time when the ad landing was observed), conversion event name, event time, provider-scoped pseudonymous stable event identifier, the fixed event-source URL https://foundable.com/ for Meta, TikTok, and X, and actual payment value/currency for a successful payment event. The fixed URL has no path, query, or fragment and does not reveal the page viewed. A successful refund or payment reversal may be sent as a distinct refund event without payment value and is never labeled as a purchase. Foundable's server payload does not add the visitor's IP address, browser user agent, email, phone, actual page URL, referrer, provider browser cookie, idea text, private prompts, or form contents. These providers process the information under their own advertising terms and privacy policies.
- With domain-registration recipients, including OpenSRS / Tucows, registries, ICANN, and escrow providers, when you register or administer a domain. Required registration and legal records may follow those recipients' own retention duties.
- With Pexels / Canva Germany when an enabled stock-photo rail sends a prompt-derived public-image search query.
- With professional advisors (lawyers, accountants, auditors) under confidentiality.
- With a successor entity in connection with a merger, acquisition, financing, or asset sale, subject to standard confidentiality.
- With law enforcement or regulators where legally required, after reviewing the request for validity.
We do not sell personal information. Outside operator-authorized Foundable Ads campaign delivery and measurement, and our own consent-gated advertising measurement described above, we do not share personal information with advertisers or data brokers. We do not use idea text, private prompts, or other Customer Content for "cross-context behavioral advertising."
6. International transfers
We are based in the United States. Provider processing can occur in the United States and other countries identified in our provider registry. Those countries may have data-protection laws different from the laws where you live.
Where required, provider agreements and a countersigned customer DPA can supply applicable Standard Contractual Clauses, the UK Addendum, or another recognized transfer safeguard. Our DPA page is available for review; contact us to execute the mechanism applicable to your account.
7. Data retention
We retain personal information for as long as needed to provide the Service and for the purposes described in this policy, then delete or anonymize it. Specifically:
- Account data: for the life of the account. When you delete your account, access is disabled immediately and a 30-day recovery window begins. You may email privacy@autono.sh during that window to request restoration. When the recovery window closes, permanent deletion begins for eligible operator data and solely owned foundables. Provider-held copies, financial records, and legally retained records follow their applicable provider or legal schedules. If another owner remains in a foundable, the foundable survives and your membership is removed.
- Customer Content: for the life of the relevant foundable and then through the deletion process above. Backup copies are not deleted record by record; they expire under provider-configured backup rotation. External providers and recipients may retain copies under their own documented schedules or legal obligations.
- Onboarding professional enrichment: Foundable keeps its temporary public-profile context in the active response system for no more than 30 minutes after collection. The record expires at that point, and an automated sweep deletes expired rows from the active database shortly afterward; backup copies expire under the Customer Content period above. If Ted cites a public source in your conversation, the citation and any source-derived context in that message follow the Customer Content retention period above. Separate cost and request-status records may remain after that point, but they do not contain the search query, source URL, snippet, or other result content.
- Integration credentials: kept only while the Integration is connected; deleted on disconnect.
- Server logs / telemetry: core AWS service logs are generally retained for 30 days; hosted-app and WAF logs for 14 days. Internal operational, activity, cost, audit, billing, and analytics records follow purpose-specific schedules based on their operational, trend-analysis, financial, and legal purpose. Provider telemetry follows the provider and project settings in our provider registry.
- Selective session replay: PostHog replay recordings are configured to expire after 30 days.
- Optional advertising measurement: withdrawing consent stops future server-side provider measurement sends. It does not retract data already sent. Meta, Google, TikTok, and X retain previously received measurement data under their own policies and account settings; applicable access, deletion, or objection rights may be exercised with us or the relevant provider.
- Billing-consent evidence: limited purchase, policy-acceptance, accounting, tax, fraud, dispute, and contract evidence is retained for as long as reasonably necessary for those purposes and applicable legal obligations. During deletion, direct identifiers and network metadata are reduced or removed where the implemented cleanup supports it; some pseudonymous transaction and policy-version evidence can remain after the live account is gone.
- Billing records: retained for accounting, tax, fraud, dispute, payment-support, and legal purposes for as long as reasonably necessary or required. Stripe and Link apply their own retention and deletion rules. A Link-side deletion request is separate from Foundable account deletion and does not remove records Foundable must or may independently retain for the purposes above.
- Anthropic-side retention: Anthropic's standard API retention is up to 30 days. Documented trust-and-safety and legal exceptions follow Anthropic's data-retention documentation for current details.
- Other provider retention: feature-specific provider schedules follow their service terms and account settings. The registry links to current provider materials.
8. Security
We use a layered set of safeguards described on our Security page. Highlights:
- Supabase protects its database volumes, object storage, and backups with provider-managed encryption at rest. Other providers apply the controls in their service and data-processing terms.
- OAuth tokens and API keys for Integrations are additionally encrypted with AES-256-GCM using a secret-managed key independent of the database.
- We use HTTPS with TLS to protect data in transit.
- Supabase Auth uses signed JWT access tokens and rotating refresh tokens. The browser auth client uses a refreshable SameSite=Lax cookie to support persistent sign-in; it is Secure on HTTPS. The Cookie Notice describes the configured lifetime.
- Protected operator-facing company routes authenticate the caller and validate current membership before returning or changing tenant data. Public, callback, internal, and admin routes use separate purpose-specific guards.
No system is perfectly secure. If we discover a security incident affecting your personal information, we notify affected individuals and regulators as required by applicable law. Under GDPR, a controller generally notifies the supervisory authority within 72 hours after becoming aware where the breach is likely to create risk, and notifies affected individuals without undue delay where it is likely to create high risk.
9. Your privacy rights
Subject to applicable law, you have the right to:
- Access the personal information we hold about you.
- Correct inaccurate personal information.
- Delete your personal information (the "right to erasure").
- Restrict or object to certain processing.
- Receive a portable copy of your personal information in a machine-readable format.
- Withdraw consent where we relied on it (this does not affect the lawfulness of past processing).
- Lodge a complaint with a supervisory authority.
Some account controls are available in the product:
- Edit your profile at Account > Profile.
- Owners and admins can export a JSON copy of each foundable at Account settings > Data & privacy > Export your data. For a broader account access request, contact privacy@autono.sh. Delete account is a separate control in the same settings area.
- Request deletion of a Link account and Sold through Link billing data through Link. Link deletion is separate from Foundable account deletion and may cancel active Sold through Link subscriptions. Our Data Deletion Instructions explain both paths.
- Disconnect any integration at Settings > Integrations.
- Change or withdraw your optional advertising-measurement choice at any time through the cookie choices on foundable.com. Withdrawal applies to future server-side provider sends and does not affect the lawfulness of processing performed while your consent was active.
For anything else, email privacy@autono.sh. We respond within the period required by applicable law, generally one month under GDPR and 45 days under CCPA, subject to permitted extensions. We may need to verify your identity before fulfilling a request.
10. California residents (CCPA)
California residents have the rights described in Section 9 plus, under the California Consumer Privacy Act (as amended by the CPRA):
- The right to know the specific pieces of personal information we have collected about you.
- The right to opt out of the "sale" or "sharing" of personal information. We do not sell personal information. Foundable Ads is opt-in; where campaign delivery or conversion measurement is treated as CCPA "sharing," you can avoid it by not using Foundable Ads or by asking us to disable that feature for your account. Foundable's own optional advertising-platform measurement is also off until you explicitly opt in, and you can withdraw that choice through the cookie choices on foundable.com.
- The right to limit our use and disclosure of "sensitive personal information" to the purposes the CPRA permits without separate consent. We use authentication and Integration credentials only for permitted operational and security purposes and do not use sensitive personal information to infer characteristics about you. You can submit a request to confirm or limit use where applicable.
- The right to non-discrimination for exercising any of these rights.
Browser PostHog analytics, including selective session replay, does not initialize when your browser sends Global Privacy Control or Do Not Track. Optional advertising-platform server-side conversion measurement is also forced off, and either signal overrides a saved consent grant. Because our independent first-party marketing attribution is derived from browser PostHog, those signals also exclude your visit from that attribution. The signals do not themselves disable an operator-enabled advertising workflow or all bounded server-side operational events; contact us to exercise any additional applicable opt-out right.
Categories of personal information collected, used, and disclosed in the last 12 months: see Section 2 (collected), Section 3 (used), and Section 5 (disclosed). We have not sold personal information. Limited Foundable Ads campaign and conversion event disclosures occur only when the operator opts into the feature and approves that use. Our own advertising-platform measurement disclosures occur only after the visitor gives explicit consent and only while that consent remains active and no Global Privacy Control or Do Not Track signal is present.
To exercise CCPA rights, email privacy@autono.sh. You may designate an authorized agent; we may require proof of authorization.
11. Cookies and tracking
We use cookies and similar technologies described in our Cookie Notice. Foundable Ads conversion measurement, when enabled for a campaign an operator approves, uses the server-side path described above. For our own advertising, we do not place browser advertising pixels or provider cookies. Optional provider conversion measurement uses only the consent-gated server path and is forced off under Global Privacy Control or Do Not Track. You can change the choice at any time. Our independent first-party PostHog attribution continues under its own controls and remains separate from provider-reported measurement and Stripe-reconciled billing truth.
12. Children
The Service is not directed at children under 16. We do not knowingly collect personal information from children under 16 (or, in jurisdictions where the threshold is higher, that higher age). If you believe a child has provided us personal information, contact privacy@autono.sh and we will delete it.
13. Automated decision-making
The Service is built around AI-generated output (see our AI Disclosure). The Service does not make solely automated decisions about individuals that produce legal or similarly significant effects. Foundable can carry out operational work within a scope, autonomy mode, budget, schedule, and connected accounts you enable, including a "Runs on its own" mode for supported motions. You can pause or disable those motions, but completed actions use the connected provider's available edit, recall, refund, or reversal controls.
14. Third-party services and links
Pages on our website or product may link to third-party sites or load third-party services (e.g. when you connect an Integration). Their privacy practices are governed by their own policies. We are not responsible for them.
15. Changes to this policy
We'll update this policy as the product evolves. The date at the top reflects the most recent revision. For material changes that affect existing customers, we'll give reasonable advance notice by email and/or a prominent in-product notice, plus any additional notice required by law. Subscription fee changes follow the 7-to-30-day notice described in the Terms where applicable.
16. Contact us
Privacy questions or requests: privacy@autono.sh
Postal mail:
Autono Labs, Inc.
Attn: Privacy (re: Foundable)
131 Continental Drive, Suite 305
Newark, DE 19713, USA
Paid availability depends on Checkout eligibility in the purchaser's country. EEA and UK organizations seeking a data-processing agreement should contact us; the public DPA is a review template and is not effective until countersigned.
Questions about this document? privacy@autono.sh
Postal: Autono Labs, Inc. (operator of Foundable), 131 Continental Drive, Suite 305, Newark, DE 19713, USA. See /legal for our full set of policies.