← Legal
Build your board →
Legal/Privacy Policy

Privacy Policy

What personal data Founderboard collects, why, on what legal basis, and what rights you have.

Effective 19 August 2026Version 2026-08-19

1. Controller

IntoApps Holding B.V., Tilburg, The Netherlands, is the controller for the personal data described here.

Privacy contact: privacy@founderboard.ai

We have not appointed a Data Protection Officer; we are not required to.

2. What we collect

You give us:

DataWhere it comes from
Email address, password (hashed), nameRegistration and sign-in
Profile photoOptional upload
WhatsApp numberOptional, if you enable WhatsApp notifications
Venture data — company and project names, descriptions, industry, stage, team size, founder background, challengesOnboarding and project settings
Working tool content — customer profiles, interview notes, outreach, competitor and market research, value proposition and other tool entriesThe tools you use
Chat messages with AI board membersYour conversations
Dropboard items — notes, links, uploaded filesQuick capture
Meeting notes you captureFounder meetings feature

We generate:

  • AI output — board member replies, board meeting summaries, audio briefings, news commentary, reports and readiness assessments;
  • progress data — XP, level, streak, badges, activity and completion signals;
  • usage and diagnostic data — AI model usage and token counts, error logs, request metadata.

We collect automatically:

  • technical data needed to serve the site — IP address, browser and device type, timestamps — processed in server and security logs;
  • with your consent only, analytics data via Google Analytics 4 (see the Cookie Policy).

We do not ask for special categories of personal data. Please do not put them into the tools or the chat.

3. Why we process it, and on what legal basis

PurposeLegal basis (GDPR Art. 6)
Creating and managing your account; authenticationPerformance of a contract (6(1)(b))
Providing the AI board, tools, meetings, reports and other features you usePerformance of a contract (6(1)(b))
Sending service email — magic links, meeting notifications, message notificationsPerformance of a contract (6(1)(b))
Web push and WhatsApp notificationsConsent (6(1)(a)) — you enable them, and can turn them off
Analytics cookiesConsent (6(1)(a))
Marketing email and product updatesConsent (6(1)(a)), or legitimate interest for existing users on closely related updates (6(1)(f))
Security, abuse prevention, rate limiting, debuggingLegitimate interest (6(1)(f)) in keeping the service safe and working
Improving the product using aggregated and pseudonymised usage dataLegitimate interest (6(1)(f))
Giving accelerator staff a read on enrolled venturesPerformance of a contract (6(1)(b)) with the program, and legitimate interest (6(1)(f)) of the program in running it
Meeting legal and accounting obligationsLegal obligation (6(1)(c))

Where we rely on consent you may withdraw it at any time, without affecting processing already carried out. Where we rely on legitimate interest you may object — see section 8.

4. AI processing

Your prompts, chat messages and the venture and tool content needed for context are sent to Google (Gemini API) to generate responses. Audio briefings additionally use ElevenLabs for speech synthesis.

  • Content is sent to these providers only to produce the output you asked for.
  • We use paid API tiers under terms that do not permit your content to be used to train the providers' models.
  • We log AI requests and responses to our own self-hosted observability system (Langfuse) for debugging, quality and cost control. That system runs on our own infrastructure.
  • AI output can be wrong. It is not professional advice, and no automated decision with legal or similarly significant effects is taken about you (GDPR Art. 22 does not apply).

5. Who we share it with

We do not sell personal data. We share it with the sub-processors needed to run the Service — the complete, current list, with what each one processes and where, is on the sub-processor page.

We also share data:

  • with an accelerator or program, where your venture is enrolled in one, as described in section 6;
  • with people you invite to your project, who can then see that project's content;
  • with anyone holding a public share link you generate, limited to the venture overview snapshot — regenerating the link revokes the old one;
  • with professional advisers, insurers, or authorities, where legally required;
  • with an acquirer, in the event of a merger or sale, subject to this policy.

6. Accelerator and coach access

If your venture is enrolled in a program, that program's coaches and directors can see your board and tool content, progress metrics and activity signals, and AI-generated reports derived from them.

They cannot see your conversations with your AI board members. Chat content is excluded from every coach-facing surface and from every generated report, by design.

The program is a separate controller for what it does with the data it sees. Ask the program for its own privacy notice.

7. International transfers

Our infrastructure is hosted in the EU where the provider offers it. Some sub-processors — notably Google and ElevenLabs — may process data outside the EEA, including in the United States. For those transfers we rely on the European Commission's Standard Contractual Clauses, and where applicable the EU-US Data Privacy Framework, together with the providers' technical and organisational safeguards. You can ask us for a copy of the relevant safeguards at privacy@founderboard.ai.

8. Your rights

Under the GDPR you have the right to:

  • access your personal data and get a copy;
  • rectify inaccurate or incomplete data;
  • erase your data ("right to be forgotten");
  • restrict processing in certain circumstances;
  • data portability — receive your data in a structured, machine-readable format;
  • object to processing based on legitimate interest, and to direct marketing at any time;
  • withdraw consent at any time.

You can exercise the most common ones yourself:

  • Export — download a machine-readable copy of your account and venture data from your profile page.
  • Delete — delete your account from your profile page.
  • Cookies — change or withdraw your cookie consent from the "Cookie settings" link in the footer.
  • Notifications — turn email, push and WhatsApp notifications on or off in your profile.

For anything else, email privacy@founderboard.ai. We respond within one month, and will tell you if we need longer (up to two further months) for a complex request. We may ask you to confirm your identity.

If you are unhappy with how we handled your request you can complain to the Autoriteit Persoonsgegevens (https://autoriteitpersoonsgegevens.nl) or to the supervisory authority where you live or work.

9. Retention

DataHow long
Account dataWhile your account is active
Venture, tool and chat contentWhile your account is active, or until you delete the project
Deleted projectsFlagged deleted immediately and removed from all surfaces; purged from the database within 90 days
Deleted accountsIdentifiers are erased or anonymised immediately; residual records are purged within 90 days
BackupsRolling backups are overwritten within 30 days
Server and security logsUp to 12 months
AI observability tracesUp to 12 months
Analytics dataUp to 14 months (Google Analytics retention setting)
Invoices and accounting records7 years, as Dutch tax law requires

What deleting your account does

Deleting your account signs you out everywhere, removes your sessions, push subscriptions and notification records, removes you from every project you are a member of, and erases or anonymises your identifiers — email, name, photo, WhatsApp number and password. Projects where you were the sole owner are deleted along with their content. Where you shared a project with other people, that project keeps running for them, and your past contributions to shared project content remain attributed to a deleted user rather than to you.

If you want a full purge of everything associated with you, including shared project content, email privacy@founderboard.ai and we will handle it manually.

10. Security

We protect data with encryption in transit (TLS), encryption at rest at our infrastructure providers, hashed passwords (bcrypt), least-privilege access for staff, and access controls that scope every request to your projects. No system is perfectly secure. If a breach is likely to result in a high risk to you, we will notify you and the supervisory authority as the GDPR requires.

11. Children

The Service is not intended for anyone under 18 and we do not knowingly collect their data. If you believe a child has given us personal data, contact privacy@founderboard.ai.

12. Changes

We may update this policy. Material changes will be announced in the product or by email. The version and effective date at the top of this page identify the current version.

13. Contact

IntoApps Holding B.V. Tilburg, The Netherlands privacy@founderboard.ai

Build your new business — with an AI advisory board and the tools to do the work.

Beta · onboarding cohort 04

Menu

Why founderboardThe systemFeatures

Get started

Describe your ideaBuild your boardSign in

Company

For acceleratorsResourcesAbout

Legal

Terms of ServicePrivacy PolicyCookie PolicySub-processors
© 2026 FounderBoard · All rights reservedMade for founders