Privacy policy
Last updated August 24, 2026
Who we are
Founder Brief (FndrBrief) is an independent product operated from the United Kingdom, and is the data controller for the information described here. For anything about your data — a question, a correction, a request to delete it — write to info@fndrbrief.com.
What we collect
Your email address (to sign you in and send your brief), and daily aggregate activity from the tools you connect: counts of merged pull requests, commits, deployments, the subject lines of your commits and open pull request titles, and counts of new rows in the one database table you choose.
If you subscribe, we also store the customer reference Stripe gives us and whether your plan is active — that is all our database holds about your payments. Your card details go straight to Stripe and never reach us: we cannot see them, store them, or charge your card outside the subscription you started. Stripe keeps its own record of your payments under its privacy policy.
What we never collect
The contents of your database rows. Your connected Supabase project is queried with counts, and with one exception: we read the timestamp of your most recent row in the single date column you map, so the brief can say how long it has been rather than only “no signups today”. That timestamp is used to work out a number of days and is not stored. No other column is ever read — we cannot see your users' names, emails, or any other row data. We do not read your source code. We do read the subject line of each commit — the one-line description you write, not the change itself — so the brief can say what you shipped rather than only how much.
How your credentials are stored
We ask for the least access each tool allows. GitHub is read-only and stores no credential at all — access is granted per-repository when you install our GitHub App, and short-lived tokens are issued as needed. Connecting it asks you to authorise us once: we use that only to confirm the installation is yours rather than someone else's, read nothing but the list of accounts you can install on, and discard the access immediately. Stripe accepts only restricted, read-only keys. When you connect Supabase we use the sign-in to fetch one project's key and then discard the account access itself, so we never hold standing access to your Supabase organisation.
The keys we do store are encrypted at rest with AES-256-GCM and are never sent to your browser. You can disconnect any integration at any time in Settings, which deletes the credential.
Diagnostics
When a brief fails to generate, our server logs record which account it was for, which step failed, and the technical error, so that it can be fixed. Those logs are held by our hosting provider for a short retention period and are used for nothing else. The failure alert we send ourselves is narrower still — a step name, a count, and an account identifier, never the error text and never anything drawn from your brief or your database.
Cookies and local storage
We set a session cookie to keep you signed in, and short-lived cookies during a connection flow to verify the request came from you. Both are marked HttpOnly and Secure, so they are unreadable to scripts and never sent over an unencrypted connection. Signing out clears them.
If you allow analytics and advertising, two third parties store an identifier in your browser: Mixpanel, in local storage, so it can tell that two events came from the same person; and Meta, in a cookie, so it can tell that someone who clicked one of our ads reached the site. Both are tracking, which is why we ask first rather than assuming, and neither loads at all until you say yes.
The Meta one does follow you to other websites — that is what an advertising pixel is, and we would rather say so than write around it. It reports three moments to Meta: that a public page was visited, that someone asked for a sign-in code, and that an account was created — so we can tell which ads bring founders here. It runs only on our signed-out pages, never once you are inside the product, so nothing about your account, your connected tools or your brief is part of it. Declining here stops it loading at all, and you can opt out of ad targeting more broadly in your Meta ad preferences.
Product analytics
If you allow it, we record three things in Mixpanel: that someone pressed the sign-up button on the homepage, that an account was created, and that a brief was generated. Each carries the day it was for and which button produced it, and nothing else. No page views, no other clicks, no scrolling, no session recordings, and never a word of what is in your brief or your connected accounts. Your IP address is not sent, so we do not know and cannot learn where you are reading from. The identifier tying those events together is your account id, so it disappears when your account does, and Mixpanel holds your email address so we can find your account if you write to us. Declining is a real answer we remember, not a delay before we ask again — and to change your mind either way, clear this site's data in your browser and the banner will ask again.
Third parties
We use Supabase (authentication and storage), Vercel (hosting), Resend (email delivery), OpenAI (to phrase your brief and answer questions), Stripe (payments), and — only with your consent — Mixpanel for the product counts described above and Meta for advertising measurement. Mixpanel and Meta process data in the United States. Only aggregate counts, commit subject lines and PR titles are sent to OpenAI — never your credentials, never your source code, never your users' data. We never sell your data, and nothing from inside your brief or your connected tools is ever used for advertising — the pixel sees only that someone visited a page anyone can visit, asked for a sign-in code, or created an account. Not who you are, and nothing you connect or generate.
How long we keep things
Your briefs, the daily figures behind them and your chat history are kept for as long as your account exists, so the archive stays readable and the brief can compare this week with last. We do not expire them on a timer; deleting your account deletes them.
Credentials are the exception, and they expire sooner. If your plan ends and a connected tool is paused, its stored key is deleted after 30 days — the settings stay so you can turn it back on, but the key itself goes, because holding access to a database we are no longer reading is access we have no use for. Reconnecting after that issues a new one.
Where your data is processed
We are based in London. Your data is stored in the European Union (Supabase, in Ireland), but some of the providers below process it in the United States — OpenAI when phrasing your brief, Vercel when serving these pages, Resend when sending your email, and Mixpanel if you allowed analytics. Those transfers rely on the standard data-protection terms each provider offers for exactly this purpose.
Your rights
You can see what we hold (your brief archive is all of it, readable in the app), correct it, export it, or have it erased — the last of those is the Delete account button in Settings, and it is immediate. You can withdraw analytics consent at any time, and object to how we use your data by writing to us. We will answer within a month.
If you think we have handled your data badly, please tell us first — but you also have the right to complain to the UK's Information Commissioner's Office at ico.org.uk, or to your own country's data protection authority.
Deletion
Delete your account yourself in Settings. It is immediate and permanent: all briefs, metrics, credentials, and chat history are removed, with no grace period and no way back. Disconnecting a single integration immediately deletes its stored credential. Two things sit outside our reach — the Founder Brief GitHub App stays installed on your repositories until you uninstall it in GitHub, and Supabase keeps its own record of the authorisation. Neither can reach anything once your account is gone.
Contact
Questions: write to info@fndrbrief.com.