Privacy Policy

Effective Date: August 29, 2026

This Privacy Policy describes how RIKHATH LLC ("Founderr", "we", "us", or "our"), a Texas limited liability company, collects, uses, and shares your personal information in connection with the Founderr platform at founderr.io and related services (the "Service").

This policy states what we are permitted to do. Data Handling states what the software currently does — which store holds what, what our Agents can and cannot read, what a security scan keeps, and which retention and deletion steps are running today versus written but not yet scheduled. It is more specific and, in several places, narrower. Where the two differ in scope, this policy governs; where they differ on a matter of fact, the more specific page is the one we keep current.

1. Information We Collect

1.1 Information You Provide

  • Account information: name, email address, password (hashed), profile details, company name, role.
  • Billing information: payment method, billing address, transaction history. Payment card details are collected and stored by our payment processor (Stripe) and are not stored on our servers.
  • Communications: support requests, feedback, survey responses, and any content you send us.
  • AI inputs: prompts, instructions, files, and other content you submit to Agents.

1.2 Information We Collect Automatically

  • Usage data: pages viewed, features used, Agent interactions, timestamps, click events.
  • Device data: IP address, browser type, operating system, device identifiers, language settings, approximate location derived from IP.
  • Cookies and similar technologies: see our Cookie Policy.

1.3 Information from Third Parties

  • OAuth and integrations: if you connect third-party services (e.g., Google, GitHub, Slack, social media), we receive information from those services as authorized by you.
  • Payment processors: Stripe shares limited transaction information with us.
  • Analytics providers: aggregated usage information.

1.4 AI Outputs

We store AI Outputs generated for your Account so you can access them. AI Outputs may incorporate or reflect User Content you submitted.

2. How We Use Information

We use personal information to:

  • Provide, operate, and maintain the Service;
  • Authenticate users and secure Accounts;
  • Process payments and manage Subscriptions;
  • Enable Agent functionality, including transmission to AI providers (Section 3);
  • Communicate with you about the Service, updates, and support;
  • Send marketing communications where permitted (you may opt out at any time);
  • Detect and prevent fraud, abuse, and security incidents;
  • Comply with legal obligations and enforce our Terms;
  • Conduct analytics to improve the Service.

3. AI Processing and Third-Party AI Providers

3.1 The Service relies on third-party large language model providers, including but not limited to Anthropic, OpenAI, and Google. When you use Agents, your prompts, User Content, and related metadata may be transmitted to these providers for processing.

3.2 No model training on your data. We do not use your User Content, prompts, or AI Outputs to train our own models. Where AI providers offer no-training endpoints, we use those endpoints to ensure your inputs are not used by providers to train their models.

3.3 Each AI provider has its own data handling practices. Limited retention by providers may occur for safety, abuse-prevention, and legal-compliance purposes. See:

4. Legal Bases for Processing (EEA / UK Users)

If you are in the European Economic Area or the United Kingdom, we process your personal information on the following legal bases:

  • Contract: to provide the Service you request.
  • Legitimate interests: to secure, improve, and market the Service, balanced against your rights.
  • Consent: where required (e.g., marketing emails, certain cookies).
  • Legal obligation: where required by applicable law.

5. How We Share Information

We do not sell your personal information. We share information in these circumstances:

  • Service providers: hosting and databases (Google Cloud Platform — Cloud Run, Cloud SQL, Memorystore), content delivery and DDoS protection (Cloudflare), email delivery (Resend), analytics (Google Analytics), payment processing (Stripe), and AI providers (Section 3). These providers process data on our behalf under contractual confidentiality and security obligations.
  • Integrations you authorize: when you connect third-party services to your Account, we share data with those services as authorized.
  • Legal compliance: to comply with subpoenas, court orders, or applicable law; to enforce our Terms; to protect our rights, property, or safety, or that of users or the public.
  • Business transfers: in connection with a merger, acquisition, financing, reorganization, or sale of assets, your information may be transferred. We will notify you of any such transfer.
  • With your consent: for any other purpose with your express consent.

6. International Data Transfers

We are based in the United States, and our team operates internationally including from Pakistan. Your information may be processed in countries other than your own, including the United States. Where required, we use appropriate safeguards such as Standard Contractual Clauses (SCCs) approved by the European Commission and the UK ICO. You may request a copy of relevant safeguards at [email protected].

7. Data Retention

We retain personal information as long as your Account is active or as needed to provide the Service. Specific retention periods:

  • Account data: retained while your Account is active; deleted within 30 days of Account closure.
  • AI inputs and outputs: your conversations with your agents are retained for 12 months from the date each message is sent, then automatically deleted by a nightly job. You can also ask us to delete yours sooner by emailing [email protected]. Other agent-generated records (KPIs, expenses, briefs, scan findings) are retained while your Account is active.
  • Billing and tax records: retained for at least 7 years to comply with tax law.
  • Backup copies: may persist in encrypted backups for up to 90 days after deletion.
  • Anonymized or aggregated data: may be retained indefinitely.

8. Security

We implement administrative, technical, and physical safeguards to protect personal information, including encryption in transit (TLS), encryption at rest, role-based access controls, audit logging, and security monitoring. No system is fully secure; we cannot guarantee absolute security. Notify us immediately at [email protected] of any suspected breach.

For the specific controls behind this paragraph — how credentials in scan evidence are redacted, how tenant scoping is enforced at the tool layer, and which framework features we have disabled because we could not verify their scoping — see Data Handling.

9. Your Rights

9.1 General Rights

  • Access and portability: while signed in as the owner of your organization, visit /api/account/export to download your data immediately as structured JSON. It contains your apps, your agent conversations, your company wiki, your KPI and expense entries, your OKRs, your briefs, and your scan findings. Credentials for your connected accounts are deliberately excluded. If the file had to be shortened for size, it says so at the end, naming what was cut. If you are a member of an organization you do not own, email [email protected] and we will send you a copy of your data.
  • Correction: request correction of inaccurate or incomplete data.
  • Deletion: email [email protected] to close your Account. Closure takes effect when we confirm it, and we permanently delete your organization's data after a 30-day grace period, during which you can contact us to reverse it. Ask us and we will confirm in writing once the deletion has been carried out. Records we are required to keep — billing and tax records, and security audit logs — are retained as described above, unlinked from your Account. Closing your Account does not cancel an active subscription; cancel billing separately.
  • Objection / restriction: object to or restrict certain processing.
  • Withdraw consent: where we process based on consent.
  • Lodge a complaint: with your local data protection authority.

9.2 California Residents (CCPA / CPRA)

You have the right to:

  • Know what personal information we collect, use, disclose, and sell or share.
  • Request deletion of your personal information.
  • Correct inaccurate personal information.
  • Opt out of the sale or sharing of personal information. We do not sell personal information.
  • Limit the use of sensitive personal information.
  • Non-discrimination for exercising these rights.

To exercise rights, email [email protected]. We will verify your identity before responding. You may use an authorized agent.

9.3 EEA, UK, and Swiss Residents (GDPR / UK GDPR / FADP)

In addition to the General Rights above, you have the right to lodge a complaint with your supervisory authority. If you are in the EEA or UK, our representative for data-protection purposes can be contacted at [email protected].

To exercise any right, email [email protected]. We respond within 30 days (extendable by 60 days for complex requests).

10. Children's Privacy

The Service is not directed to children under 13 (or 16 in the EEA). We do not knowingly collect personal information from children. If we learn we have collected such information, we will delete it. Contact [email protected] if you believe a child has provided us information.

11. Cookies and Tracking

See our Cookie Policy for details on cookies and similar tracking technologies.

12. Do Not Track and Global Privacy Control

Our Service does not respond to "Do Not Track" browser signals. We respect Global Privacy Control (GPC) signals as opt-out signals where applicable under U.S. state privacy laws.

13. Marketing Communications

You may opt out of marketing emails at any time by clicking the unsubscribe link in any marketing email or by emailing [email protected]. Service-related communications (billing, security, terms updates) cannot be opted out of while your Account is active.

14. Automated Decision-Making

We do not use your personal information for automated decision-making that produces legal or similarly significant effects on you, except as necessary to enter into or perform our contract with you (such as fraud prevention checks).

15. Changes to This Policy

We may update this Privacy Policy. Material changes will be notified by email or prominent in-Service notice at least 30 days before taking effect. The "Effective Date" at the top will be updated. Continued use of the Service after changes take effect constitutes acceptance.

16. Contact

RIKHATH LLC
5900 Balcones Dr, Austin, TX 78731, USA
Email: [email protected]
Privacy lead: [email protected]