Privacy Policy
What personal data Founderboard collects, why, on what legal basis, and what rights you have.
1. Controller
IntoApps Holding B.V., Tilburg, The Netherlands, is the controller for the personal data described here.
Privacy contact: privacy@founderboard.ai
We have not appointed a Data Protection Officer; we are not required to.
2. What we collect
You give us:
| Data | Where it comes from |
|---|---|
| Email address, password (hashed), name | Registration and sign-in |
| Profile photo | Optional upload |
| WhatsApp number | Optional, if you enable WhatsApp notifications |
| Venture data — company and project names, descriptions, industry, stage, team size, founder background, challenges | Onboarding and project settings |
| Working tool content — customer profiles, interview notes, outreach, competitor and market research, value proposition and other tool entries | The tools you use |
| Chat messages with AI board members | Your conversations |
| Dropboard items — notes, links, uploaded files | Quick capture |
| Meeting notes you capture | Founder meetings feature |
We generate:
- AI output — board member replies, board meeting summaries, audio briefings, news commentary, reports and readiness assessments;
- progress data — XP, level, streak, badges, activity and completion signals;
- usage and diagnostic data — AI model usage and token counts, error logs, request metadata.
We collect automatically:
- technical data needed to serve the site — IP address, browser and device type, timestamps — processed in server and security logs;
- with your consent only, analytics data via Google Analytics 4 (see the Cookie Policy).
We do not ask for special categories of personal data. Please do not put them into the tools or the chat.
3. Why we process it, and on what legal basis
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Creating and managing your account; authentication | Performance of a contract (6(1)(b)) |
| Providing the AI board, tools, meetings, reports and other features you use | Performance of a contract (6(1)(b)) |
| Sending service email — magic links, meeting notifications, message notifications | Performance of a contract (6(1)(b)) |
| Web push and WhatsApp notifications | Consent (6(1)(a)) — you enable them, and can turn them off |
| Analytics cookies | Consent (6(1)(a)) |
| Marketing email and product updates | Consent (6(1)(a)), or legitimate interest for existing users on closely related updates (6(1)(f)) |
| Security, abuse prevention, rate limiting, debugging | Legitimate interest (6(1)(f)) in keeping the service safe and working |
| Improving the product using aggregated and pseudonymised usage data | Legitimate interest (6(1)(f)) |
| Giving accelerator staff a read on enrolled ventures | Performance of a contract (6(1)(b)) with the program, and legitimate interest (6(1)(f)) of the program in running it |
| Meeting legal and accounting obligations | Legal obligation (6(1)(c)) |
Where we rely on consent you may withdraw it at any time, without affecting processing already carried out. Where we rely on legitimate interest you may object — see section 8.
4. AI processing
Your prompts, chat messages and the venture and tool content needed for context are sent to Google (Gemini API) to generate responses. Audio briefings additionally use ElevenLabs for speech synthesis.
- Content is sent to these providers only to produce the output you asked for.
- We use paid API tiers under terms that do not permit your content to be used to train the providers' models.
- We log AI requests and responses to our own self-hosted observability system (Langfuse) for debugging, quality and cost control. That system runs on our own infrastructure.
- AI output can be wrong. It is not professional advice, and no automated decision with legal or similarly significant effects is taken about you (GDPR Art. 22 does not apply).
5. Who we share it with
We do not sell personal data. We share it with the sub-processors needed to run the Service — the complete, current list, with what each one processes and where, is on the sub-processor page.
We also share data:
- with an accelerator or program, where your venture is enrolled in one, as described in section 6;
- with people you invite to your project, who can then see that project's content;
- with anyone holding a public share link you generate, limited to the venture overview snapshot — regenerating the link revokes the old one;
- with professional advisers, insurers, or authorities, where legally required;
- with an acquirer, in the event of a merger or sale, subject to this policy.
6. Accelerator and coach access
If your venture is enrolled in a program, that program's coaches and directors can see your board and tool content, progress metrics and activity signals, and AI-generated reports derived from them.
They cannot see your conversations with your AI board members. Chat content is excluded from every coach-facing surface and from every generated report, by design.
The program is a separate controller for what it does with the data it sees. Ask the program for its own privacy notice.
7. International transfers
Our infrastructure is hosted in the EU where the provider offers it. Some sub-processors — notably Google and ElevenLabs — may process data outside the EEA, including in the United States. For those transfers we rely on the European Commission's Standard Contractual Clauses, and where applicable the EU-US Data Privacy Framework, together with the providers' technical and organisational safeguards. You can ask us for a copy of the relevant safeguards at privacy@founderboard.ai.
8. Your rights
Under the GDPR you have the right to:
- access your personal data and get a copy;
- rectify inaccurate or incomplete data;
- erase your data ("right to be forgotten");
- restrict processing in certain circumstances;
- data portability — receive your data in a structured, machine-readable format;
- object to processing based on legitimate interest, and to direct marketing at any time;
- withdraw consent at any time.
You can exercise the most common ones yourself:
- Export — download a machine-readable copy of your account and venture data from your profile page.
- Delete — delete your account from your profile page.
- Cookies — change or withdraw your cookie consent from the "Cookie settings" link in the footer.
- Notifications — turn email, push and WhatsApp notifications on or off in your profile.
For anything else, email privacy@founderboard.ai. We respond within one month, and will tell you if we need longer (up to two further months) for a complex request. We may ask you to confirm your identity.
If you are unhappy with how we handled your request you can complain to the Autoriteit Persoonsgegevens (https://autoriteitpersoonsgegevens.nl) or to the supervisory authority where you live or work.
9. Retention
| Data | How long |
|---|---|
| Account data | While your account is active |
| Venture, tool and chat content | While your account is active, or until you delete the project |
| Deleted projects | Flagged deleted immediately and removed from all surfaces; purged from the database within 90 days |
| Deleted accounts | Identifiers are erased or anonymised immediately; residual records are purged within 90 days |
| Backups | Rolling backups are overwritten within 30 days |
| Server and security logs | Up to 12 months |
| AI observability traces | Up to 12 months |
| Analytics data | Up to 14 months (Google Analytics retention setting) |
| Invoices and accounting records | 7 years, as Dutch tax law requires |
What deleting your account does
Deleting your account signs you out everywhere, removes your sessions, push subscriptions and notification records, removes you from every project you are a member of, and erases or anonymises your identifiers — email, name, photo, WhatsApp number and password. Projects where you were the sole owner are deleted along with their content. Where you shared a project with other people, that project keeps running for them, and your past contributions to shared project content remain attributed to a deleted user rather than to you.
If you want a full purge of everything associated with you, including shared project content, email privacy@founderboard.ai and we will handle it manually.
10. Security
We protect data with encryption in transit (TLS), encryption at rest at our infrastructure providers, hashed passwords (bcrypt), least-privilege access for staff, and access controls that scope every request to your projects. No system is perfectly secure. If a breach is likely to result in a high risk to you, we will notify you and the supervisory authority as the GDPR requires.
11. Children
The Service is not intended for anyone under 18 and we do not knowingly collect their data. If you believe a child has given us personal data, contact privacy@founderboard.ai.
12. Changes
We may update this policy. Material changes will be announced in the product or by email. The version and effective date at the top of this page identify the current version.
13. Contact
IntoApps Holding B.V. Tilburg, The Netherlands privacy@founderboard.ai