Founder’s Bud
Legal

Privacy Policy

Last updated 25 August 2026

This page describes the product’s current data flows. It is not legal advice and is not a substitute for legal review. Before relying on it, complete the controller details, lawful-basis and international-transfer analysis, and retention schedule shown in brackets below with qualified counsel.

Who controls the data

Founder’s Bud is operated by [legal entity and postal address]. Privacy contact: [privacy contact] or hello@foundersbud.com.

What we collect

Account: your authentication email, password credentials held by Supabase Auth, and the public handle you choose.
Commitments: the test text, target number, date, timezone, optional label, witnesses you name, and the published outcome.
Billing: if subscriptions are enabled in the future, subscription status and Stripe customer references. Stripe, not us, collects and stores full card details.
Contact form: the message, optional reply email, and a shortened browser user-agent string.
Security and operations: session cookies, request and service logs, and an IP-derived rate-limit identifier used to prevent abuse. Authentication providers and hosting infrastructure may also process IP address and device/request metadata in their logs.

What’s public

Your handle, declarations (test, number, date and optional label), witness count, and outcomes are public on your page and in the public record. Your authentication email is never public. Witness and contact-form email addresses are never public.

How we use it

We use data to authenticate you; file, publish and automatically resolve commitments; send transactional and witness email; prevent abuse; operate subscriptions when enabled; answer contact-form messages; and diagnose reliability or security failures. We do not sell personal data or send marketing email.

The applicable legal bases and any regional disclosures remain subject to [legal review] before production reliance.

Processors and external services

Depending on which optional features are configured, we use:

Processor locations, contractual safeguards and international transfers require [legal review]. Each provider also retains data under its own terms and legal obligations.

Cookies

We use cookies needed to establish and refresh your Supabase session. We do not use advertising or third-party behavioural tracking cookies.

Retention and deletion

While your account exists, application records are kept to operate the public ledger and unsettled commitments. Account deletion is blocked while a commitment remains unsettled, because deletion cannot suppress an automatic outcome.

Once deletion is allowed, Settings permanently deletes the application user row and the commitments, outcomes, witnesses and subscription rows linked to it. Supabase Auth deletion also requires the configured server-side deletion integration; if that integration is unavailable, an inert authentication record may remain until the operator removes it. Contact-form submissions are not linked to an account and are not removed automatically; contact us to request access or deletion.

Operational logs, backups, and payment or accounting records may remain for security, recovery, reconciliation, fraud prevention, processor retention, or legal obligations. Founder’s Bud has not yet finalised a complete retention schedule. A reviewed schedule with concrete periods and backup-deletion handling is required before relying on this policy: [retention schedule and legal review].

Your rights

Depending on where you live, you may have rights to access, correct, restrict, export, object to processing, or delete personal data, and to complain to a regulator. Contact hello@foundersbud.com. These rights and the response process require [regional legal review].

Children

The Service is not intended for anyone under 18.

Changes

We’ll post changes here with an updated date. Contact: hello@foundersbud.com.


Terms of Service →

Privacy Policy — Founder's Bud