← Back to home

Privacy Policy

Last updated: 24 September 2026 · Co-Founder AI

1. Data we collect — and why

  • Account information: email address, password hash, and display name. Used to create your account, sign you in, and identify your workspace. Google sign-in additionally stores the OAuth identity needed to recognise a returning Google account.
  • Company / workspace information: company name, description, industry, brand tone, and logo image. Used to personalise the workspace and agent outputs. You provide this during onboarding and can edit it on the Profile page.
  • Content you provide: chat messages, uploaded files and their descriptions. Used to answer your questions, retrieve relevant document passages, and generate requested outputs.
  • AI prompts, outputs and derived data: conversation history, session titles, chat memories, and document embeddings. Used to keep context across messages, retrieve relevant knowledge, and operate the agent pipeline.
  • Authentication and session data: a signed, httpOnly session cookie plus cached sign-in state in the browser. Used to keep you signed in securely without exposing the session token to JavaScript.
  • Connected integrations (only if you connect them): Google OAuth grant (account identifier, email, granted scopes, access and refresh tokens) shared by Gmail and Google Sheets connectors, and the Instagram long-lived token. Tokens are stored server-side, kept out of the browser, and used only to act on the connected account on your behalf.
  • Billing information: credit balance, order and payment identifiers, amounts, and payment status. Used to top up credits, verify payments server-side, and keep a payment history. Card details go directly to Razorpay Checkout — we never see or store them.
  • Technical and log information: IP-address-based rate limiting, error and application logs (which may include account identifiers such as email or company name), and aggregate usage / performance measurement on every visit. Used for security, abuse prevention, debugging, and reliability.

2. How we use data

  • Operate the product: authenticate you, resolve your workspace, run the agent pipeline, and stream answers.
  • Provide connected features you request, such as reading connected mail or sheets and publishing content you approve.
  • Process payments: create and verify Razorpay orders server-side, credit your balance, and record payment history.
  • Keep the service safe and reliable: rate limiting, fraud and abuse prevention, debugging, and aggregate performance analytics.
  • We do not sell your personal information. Prompts and retrieved context are sent to the AI, search, and execution providers needed to answer (such as OpenRouter-hosted models, Tavily, SerpAPI, and the e2b code sandbox) — that is processing on your behalf, not a sale.

3. Third-party processors

  • Supabase (authentication, database, file storage).
  • OpenRouter-hosted AI models (chat, embeddings, image generation).
  • Tavily and SerpAPI (web research when the agents need it).
  • e2b (isolated code execution for data analysis).
  • Razorpay (payments — receives order details; card details go directly to Razorpay).
  • Google (OAuth, Gmail and Sheets APIs — only when you connect them).
  • Meta / Instagram (OAuth and publishing — only when you connect it).
  • Vercel (hosting, plus analytics and performance measurement).
  • Google Analytics (page-view and usage measurement).

Each provider receives only what it needs for its function and is governed by its own privacy terms. While Google connectors are in Testing mode, reconnect may be required periodically and only allowlisted test users can connect.

4. Cookies and tracking

  • Essential sign-in and product storage is always on; the app cannot work without it.
  • Analytics (Vercel Analytics + Speed Insights + Google Analytics) load on every page for all visitors.
  • We use no advertising cookies and no Meta Pixel.

Details are in our Cookie Policy.

5. Retention and deletion

  • Chat sessions, messages, files, logos, and connections persist until you delete them.
  • You can delete a chat session, delete a file, or disconnect an integration at any time from the product; deleting a file removes it from storage and from retrieval.
  • Signing out clears the session cookie; sessions also expire automatically.
  • There is not yet a self-serve Delete Account button. For account export or full deletion, contact us (see below) and we will handle your request.
  • Backups and queued background work may retain copies briefly after deletion.

6. Security

  • Passwords are stored as Argon2 hashes — plaintext passwords are never stored.
  • Sign-in uses short-lived, single-use OAuth state, validated redirect targets, and per-IP rate limiting.
  • Payment secrets stay on the backend; payment verification runs server-side.
  • Connected OAuth tokens are kept server-side and stored encrypted at rest.
  • No system is perfectly secure — do not upload secrets, credentials, or data you lack rights to process.

7. International data transfers

We and our processors may store and process data in countries other than your own (for example where our hosting, database, AI, payment, or OAuth providers operate). Where required, we rely on appropriate safeguards for such transfers — requires legal review to confirm the transfer mechanism for each provider.

8. Your rights and how to request

  • You can access and correct your company profile from the Profile page, list and download files from Drive, review payment history from Billing, and disconnect integrations from Plugins at any time.
  • For access, correction, export, or deletion requests, contact us via the GitHub repository: https://github.com/karthik132007/Co_Founder.
  • We verify requests using your account email address before acting on them.

Owner note: no dedicated privacy email is configured yet. Set NEXT_PUBLIC_PRIVACY_EMAIL (recommended: privacy@get-cofounder.tech) to publish one here.

9. EU / EEA / UK information

If you are in the EU, EEA, or UK, you have the following rights (subject to applicable law and exceptions): right of access, right to rectification, right to erasure, right to data portability, right to restriction of processing, right to object, right to withdraw consent at any time (for processing based on consent, such as connected integrations you authorised), and the right to complain to your supervisory authority.

Our understood legal basis for major processing — requires legal review to confirm:

  • Account, workspace, content, and billing processing: performance of the service you requested (contract) — requires legal review.
  • Connected Google / Instagram integrations: consent you give when you authorise the connection (withdrawable by disconnecting) — requires legal review.
  • Analytics (Vercel + Google Analytics page-view and usage measurement): legitimate interests — requires legal review.
  • Security, fraud prevention, rate limiting, and debugging: legitimate interests — requires legal review.
  • Payment and tax records: legal obligations — requires legal review.

10. California privacy information

  • Depending on applicable law, California residents may have the right to know / access, delete, and correct personal information.
  • You may have the right to opt out of any sale or sharing of personal information. We do not sell personal information.
  • We will not discriminate against you for exercising your privacy rights.
  • To exercise these rights, use the contact method in section 8. We verify requests via your account email. An authorised agent may submit a request on your behalf with appropriate authorisation — requires legal review to confirm the agent-verification procedure.

This notice does not claim Co-Founder meets any specific California applicability threshold — requires legal/business review.

11. Changes to this policy

We may update this policy as the product evolves; material changes will be reflected in the Last updated date above. Continued use after changes constitutes acceptance.

Also see our Terms and Conditions and Cookie Policy.