Privacy Policy
Effective date: 5 June 2026
1. Who we are
FounderReply(“we”, “our”, or “us”) operates the service available at https://founderreply.com. We build software that lets you connect your own social-media accounts and use an AI agent to draft and schedule posts and replies — subject to your explicit human approval before anything is published.
We are the data controller for the personal information described in this policy. Questions can be sent to privacy@founderreply.com.
2. Data we collect
We collect only the data necessary to operate the service:
Account identity
- Your email address — used for login and transactional notifications.
- A password hash (PBKDF2-SHA256 via Web Crypto, never the plaintext password) stored in our database.
- A session JWT (HS256, HttpOnly cookie named
sa_session, 30-day TTL) stored in your browser.
Connected social-platform identities
When you connect a social account via OAuth, we store — per connected account — the platform name, your platform user ID / handle, display name, and the granted permission scopes.
OAuth access tokens and refresh tokens
We store OAuth access tokens (and refresh tokens where the platform provides them) for each connected account. These tokens allow the service to act on your behalf. We currently support:
- Reddit — access token (+ refresh token); used to submit comments and retrieve mentions.
- Instagram — access token; used to publish posts and retrieve comments/DMs on your pages.
- Facebook — access token; used to publish posts and retrieve comments/DMs on your pages.
- LinkedIn — access token (+ refresh token); used to publish posts and retrieve reactions.
- X (Twitter) — access token + refresh token; used to post, reply, and retrieve mentions.
All OAuth tokens are encrypted at rest using AES-256-GCM (authenticated encryption) before being stored in the database. The encryption key is held separately from the database and is never stored in source code.
Content data
- Posts, drafts, and approval-queue items — AI-generated draft text, edited final text, and the decision (approve / reject / skip) you make on each.
- Scheduled publications — the post text, target platform/account, and scheduling metadata.
- Inbound mentions and DMs — content fetched from connected platform APIs (comments mentioning your accounts, direct messages to your pages/profiles).
Workspace configuration
- Workspace name and brand-voice description you enter.
- Per-workspace settings (e.g., X API credentials you supply for BYO-key access, stored encrypted).
Billing data
Subscription tier and credit balance are stored in our database. Payment card data is held exclusively by Stripe (see Sub-processors below) — we never see or store raw card numbers.
Technical logs
Standard server-side logs (request paths, HTTP status codes, error messages) retained for up to 30 days. We do not log request bodies containing personal data.
3. How we use your data
- Account authentication — verifying your identity on login using the stored password hash; maintaining your session via the JWT cookie.
- Social-platform operations — using your stored OAuth tokens to post content, retrieve mentions/DMs, and refresh tokens on your behalf, exclusively as instructed by your in-app actions (scheduling, approval decisions).
- AI drafting — your brand-voice description and recent mention/post context are sent to an AI model (see Sub-processors) to generate draft replies and posts. We do not use your content to train third-party AI models.
- Billing — processing subscription payments and credit purchases via Stripe.
- Transactional email — sending receipts, approval notifications, and account notices via Resend.
- Service improvement — aggregated, de-identified analytics on feature usage to guide product decisions. Individual content or token data is never shared with third parties for marketing purposes.
4. Social platform data — scope and limitations
Data retrieved from connected social accounts (mentions, DMs, post metadata) is used solely to power your approval queue and inbox within the service. We do not:
- Sell, share, or license platform data to third parties.
- Use platform data for advertising targeting or profiling.
- Retain platform data beyond your account lifetime (see Retention).
- Post to any platform without a confirmed human approval action.
Our use of data obtained via the Meta (Facebook/Instagram) APIs, the Reddit API, the LinkedIn API, and the X API is subject to each platform's developer policies. We comply with Meta's Platform Terms, Reddit's API Terms of Service, LinkedIn's API Terms of Use, and X's Developer Agreement.
5. Sub-processors
We use the following third-party services to operate FounderReply. Each receives only the minimum data required for its function.
| Processor | Purpose | Data shared |
|---|---|---|
| Supabase | Database (PostgreSQL) | All persistent user, workspace, token, and content data (encrypted tokens) |
| Cloudflare | Edge compute & CDN (Cloudflare Workers) | Request metadata; IP addresses (not logged) |
| Stripe | Payment processing | Email, workspace ID, subscription plan |
| Resend | Transactional email | Your email address, notification content |
| Google (Gemini API) | AI draft generation | Brand-voice text + mention/post context for drafting |
6. Data retention
- OAuth tokens — retained while the connected account remains active. Immediately and permanently deleted when you disconnect a platform account or delete your user account.
- Posts, drafts, and approval-queue items — retained for the life of your account. Deleted when you delete your account.
- Account and workspace data — retained while your account is active. Deleted on account deletion.
- Server logs — retained for up to 30 days, then auto-deleted.
- Billing records — retained as required by applicable accounting and tax law (typically 7 years), even after account deletion.
7. Security
- Token encryption at rest — all OAuth access and refresh tokens are encrypted with AES-256-GCM (authenticated encryption) before being written to the database. The encryption key is managed separately from the data.
- Password hashing — passwords are hashed with PBKDF2-SHA256 (100 000 iterations, random 128-bit salt) via the Web Crypto API. Plaintext passwords are never stored or logged.
- Session security — sessions use HS256-signed JWTs in an HttpOnly, Secure, SameSite=Lax cookie. The signing secret is never exposed to the browser.
- Transport security — all data is transmitted over TLS 1.2+.
- Access control — all database access uses a service-role key scoped to our backend; no direct client access to the database is permitted. Row-level security is enabled on all tables as defense-in-depth.
8. Your rights
Depending on your location, you may have the right to access, correct, or delete personal data we hold about you, object to or restrict certain processing, and data portability.
You can exercise most rights directly in the product:
- Disconnect a platform account — removes the associated OAuth tokens immediately.
- Delete your account — erases all your personal data, OAuth tokens, posts, workspaces, and workspace members. See Your Data & Deletion for step-by-step instructions, or go directly to Account Settings.
For requests you cannot fulfill in the product, or for GDPR/CCPA inquiries, email privacy@founderreply.com. We will respond within 30 days.
9. California residents (CCPA / CPRA)
This section applies to California residents and supplements the rest of this policy under the California Consumer Privacy Act, as amended by the CPRA.
Categories of personal information we collect
- Identifiers — email address, account ID, connected-platform user IDs and handles.
- Account credentials — a password hash and session token (never your plaintext password).
- Internet / network activity — server logs (request paths, status codes), and IP address (processed at the edge, not retained in logs).
- Commercial information — subscription tier, credit balance, and purchase history (card data is held by Stripe, not by us).
- User content — drafts, approval-queue decisions, scheduled posts, and inbound mentions/DMs you fetch from connected platforms.
- OAuth tokens — access and refresh tokens for connected accounts, encrypted at rest.
Purposes
We collect and use these categories for the purposes described in “How we use your data” above: to authenticate you, operate connected social accounts at your direction, generate AI drafts, process billing, send transactional email, and maintain and improve the service.
We do not sell or share your personal information
We do not sell your personal information, and we do not share it for cross-context behavioral advertising, as those terms are defined under the CCPA/CPRA. We have not sold or shared personal information in the preceding 12 months. We do not use or disclose sensitive personal information for any purpose other than providing the service you requested.
Your California rights
- Right to know — request the categories and specific pieces of personal information we have collected about you, the sources, the purposes, and any disclosures.
- Right to delete — request deletion of personal information we have collected from you, subject to legal exceptions.
- Right to correct — request correction of inaccurate personal information.
- Right to opt out — opt out of the sale or sharing of personal information. Because we do not sell or share personal information, no opt-out action is required.
- Right to non-discrimination — we will not discriminate against you for exercising any of these rights.
How to exercise your rights
You can delete your account and connected-account tokens directly from Account Settings. For know, delete, or correction requests you cannot complete in-product, email privacy@founderreply.com. We will verify your request against your account email and respond within 45 days. You may use an authorized agent to submit a request on your behalf.
10. Your privacy choices (U.S. state privacy rights)
This section applies to residents of U.S. states with comprehensive privacy laws (including, but not limited to, California, Colorado, Connecticut, Virginia, Texas, and Utah). It supplements the rest of this policy.
We do not sell or share your personal information
We do not sell your personal information and we do not share it for cross-context behavioral (targeted) advertising, as those terms are defined under U.S. state privacy laws. We have not done so in the preceding 12 months. Because no sale or sharing occurs, there is nothing to opt out of — and no opt-out toggle is required for the service as it operates today.
We honor the Global Privacy Control (GPC)
We recognize the Global Privacy Control browser signal as a valid opt-out of the sale or sharing of personal information. If your browser or extension sends a GPC signal, we treat you as having opted out. Today this is a forward-compatible safeguard: we set no advertising or third-party tracking cookies and engage in no sale or sharing, so there is no such processing to suppress. Should that ever change, a GPC signal will automatically be honored.
Your rights
Depending on your state of residence, you may have the right to:
- Access / know — confirm whether we process your personal information and obtain a copy of it.
- Delete — request deletion of personal information we collected from you, subject to legal exceptions.
- Correct — request correction of inaccurate personal information.
- Portability — obtain a copy of your personal information in a portable format.
- Opt out — opt out of the sale or sharing of personal information and of targeted advertising. As noted above, we do not sell, share, or use personal information for targeted advertising.
- Non-discrimination — we will not discriminate against you for exercising any of these rights.
How to exercise your rights
You can disconnect platform accounts and delete your account (and all associated personal data) directly from Account Settings. For access, delete, correct, or portability requests you cannot complete in-product, email privacy@founderreply.com. We verify requests against your account email and respond within the timeframe required by your state's law. You may use an authorized agent to submit a request on your behalf.
11. Cookies
We use a single first-party cookie:
sa_session— an HttpOnly session JWT. Strictly necessary for authentication; expires after 30 days of inactivity. No third-party tracking cookies are set.
12. Children
The service is not directed to children under 13. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us at privacy@founderreply.com and we will delete it promptly.
13. Changes to this policy
We will post changes to this page and update the effective date. For material changes we will notify you by email. Continued use of the service after the effective date constitutes acceptance of the updated policy.
14. Contact
For privacy questions, data-subject requests, or to report a data-related concern:
FounderReplyprivacy@founderreply.com
See also: Your Data & Deletion