Privacy Policy
Last updated: July 13, 2026
1. Introduction
At FounderFlow, we build advanced AI tools to help startup founders distill massive email volume into high-level strategic intelligence. To deliver these features (like executive briefings and priority lead alerts), we must securely connect to your Gmail inbox. Your privacy, data security, and trust are our absolute top priorities.
Google API Services User Data Policy Compliance
FounderFlow's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy (opens in a new tab), including the Limited Use requirements.
Your Google data is processed strictly to generate your strategic briefings and prioritize your sales leads. We never sell your data or transfer it to advertisers, data brokers, or marketing platforms. Your email content is transferred to our AI sub-processors (OpenRouter, and the model providers it routes to) solely to produce your classifications, drafts, and briefings - under zero-data-retention terms and never for model training. It is also sent to integrations you explicitly connect, such as syncing a lead to your HubSpot CRM. See Section 4 for the full list.
OAuth Scopes Requested
2. Information We Collect
To deliver our intelligence dashboard, we collect the following data with your explicit OAuth consent:
- Google OAuth Credentials: Temporary access and refresh tokens to read your inbox messages.
- Email Headers & Metadata: Sender addresses, timestamps, and subject lines (used to filter out automated spam and categorize messages).
- Email Body Content: The text contents of your messages, used to extract lead and revenue insights. Bodies are encrypted at rest, and are sent to our AI sub-processors for classification and drafting as described in Section 4.
3. How We Process & Store Your Data
We believe in a secure, hyper-lean data pipeline built with your safety in mind:
- AES-256 Encryption: All OAuth tokens and sensitive email details are stored with military-grade AES-256 encryption at rest in our secure PostgreSQL database.
- 30-Day Garbage Collection Policy: Email bodies and raw messages are automatically and permanently purged from our servers 30 days after ingestion. We do not hoard your private communications.
- No AI Model Training: None of your private emails, business descriptions, or operational briefings are ever used to train public or commercial LLMs. Any processing handled via third-party AI endpoints (such as secure APIs) is conducted exclusively under zero-data-retention (ZDR) agreements to ensure your data is processed and immediately deleted without being stored for external optimization.
4. Sharing and Disclosure
We never sell or trade your email information, and we do not share Gmail API data with ad networks, data brokers, or marketing platforms under any circumstances. Beyond the service providers listed below, your data is only sent to third-party systems you explicitly authorize and link from your dashboard (for example, syncing a lead to your HubSpot account or creating an event on your Google Calendar).
To operate the service we rely on the sub-processors below. They process your data only on our instructions, only to deliver the features you asked for, and never for their own purposes:
FounderFlow strictly limits human access to your email data. Our engineers will only view email contents where required to resolve an isolation bug, debug an API connection error, or address an active security incident - and only with your explicit permission.
5. Security Standards
Our backend operates within secure private subnets, and all communication uses strict TLS/HTTPS protocols. Database access is strictly guarded with network firewalls, preventing root-access breaches.
6. Your Rights and Data Control
You maintain total, absolute ownership of your data. You can perform the following actions at any time directly from your dashboard settings:
- Disconnect your Google Account (instantly revoking all Google OAuth access tokens).
- Request the complete, permanent deletion of your entire user account and all historically ingested data.
7. Contact Us
If you have any questions about this Privacy Policy, your data handling, or our compliance with Google API standards, please reach out to our privacy officer at [email protected].