Privacy
Privacy Policy
Effective date: . This policy explains what information FounderDex collects, why, how long we keep it and the choices you have. It covers the FounderDex apps for iPhone and Android, the website at founderdex.ai (including the map at founderdex.ai/map), the Ask FounderDex assistant and the FounderDex MCP server (together, "FounderDex").
1. The short version
- You can use FounderDex without an account. As a guest, your profile stays on your device and nothing about you is sent to our servers.
- If you sign in with Google, we store your name, email address and Google profile picture link, plus the profile you choose to fill in, so you can use it on other devices.
- We do not sell your data, we do not show ads and we do not use analytics, crash reporting or advertising SDKs in the apps or on the website.
- We do not use your questions or your profile to train AI models.
- You can delete your account at any time in the app (Profile, gear icon, Delete account) or at founderdex.ai/delete-account.
- Founders shown on a card can have it removed. We act on removal requests within 72 hours.
2. Who we are
FounderDex is operated by FounderDex ("we", "us"). Postal address: Calle 92 #19C-17. We decide how and why the personal information described here is processed, so we are its controller. You can reach us at [email protected] or through the web forms on our support page.
3. Information we collect
3.1 When you sign in with Google
Sign in is optional. We use Better Auth, an open source sign in library that runs on our own servers, with Google as the only sign in provider. When you choose "Continue with Google", Google shares with us:
- your name,
- your email address and whether Google has verified it,
- the link to your Google profile picture,
- a unique Google account identifier.
Google also gives us sign in tokens so we can confirm your identity, and we store them with your account. We only ask Google for basic profile and email access (the openid, email and profile scopes). We do not get access to your contacts, Gmail, Drive, Calendar or any other Google data. Our use of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements.
While you are signed in, we keep a session record with a session token, its expiry date, and the IP address and device user agent used to sign in. We use it to keep you signed in and to protect your account.
3.2 Your profile and photo
If you are signed in, the profile you fill in is saved to your account: display name, headline, company, city, up to 8 links (for example LinkedIn, X, a website, an email or a calendar link), up to 3 favorite founders, the topics you are interested in and whether you finished onboarding. It is stored in our database on Cloudflare D1.
You can add a profile photo. It is stored in Cloudflare R2 storage and can be viewed by anyone who has its link, for example when you share your pocketcard. Do not upload a photo you do not want others to see.
3.3 Pocketcard and wallet passes
Your pocketcard is a small builder profile you can add to Apple Wallet or Google Wallet. When you tap "Add to Apple Wallet" or "Save to Google Wallet", the app sends the details shown on your pocketcard (name, role, organization, city, focus and the QR code content) to our server, which signs the pass and returns it. We do not keep a copy. Apple Wallet passes are stored on your device by Apple. Google Wallet passes are stored by Google under Google's privacy policy. You can remove a pass from your wallet at any time.
3.4 Ask FounderDex
When you ask a question, we send the question and the filters you selected (for example a country, a city or a category) to an AI model that answers using only the FounderDex catalog and map. The model runs on Cloudflare Workers AI through a Cloudflare AI Gateway with request logging turned off, or on another OpenAI compatible model gateway if we configure one, in which case we will name it in section 8. We do not store your questions in our database and they are not linked to your account. To keep the service fast, the same question may be answered from a short lived cache for up to 1 hour. We do not use your questions to train AI models, and our providers do not either under our settings. Please do not include personal or sensitive information in your questions.
3.5 MCP server
The FounderDex MCP server at https://founderdex.ai/mcp lets AI assistants such as Claude, ChatGPT or Cursor read the public catalog and map. It is read only and needs no account or key. We do not receive your conversation with your assistant, only the tool calls it sends (for example a search for "fintech in Bogota"). Tool calls are not stored beyond the rate limit record described next.
3.6 Abuse prevention
To stop abuse and control costs, we limit how many questions, submissions, removal requests and MCP calls can come from one network per day or hour. For this we store a one way hash of your IP address, made with a secret salt, together with the type of request and the time. We cannot turn this hash back into your IP address, and we do not link it to your account.
3.7 Founder submissions and removal requests
If you submit a founder card for review, we collect what you enter in the form: name, company, title, LinkedIn, website, email, the collection and a photo, plus the IP hash described above. We use it to review the card and, if approved, publish it.
If you ask us to remove a founder card, we collect the card id or LinkedIn profile, your email and the reason you give. We use it to process and keep a record of the request. These forms are not linked to a FounderDex account.
3.8 Maps
The map shows tiles from a map provider, and your device requests those tiles directly: Apple Maps on iPhone, OpenStreetMap on Android and Esri (ArcGIS) on the website. Like any website, the provider receives your IP address and the area of the map you are viewing. FounderDex does not ask for or collect your location.
3.9 What we do not collect
We do not collect your precise location, contacts, SMS, call logs, camera or microphone data, advertising identifier or payment information. The apps and the website include no analytics, crash reporting or advertising SDKs. If the app asks for permission to show notifications, you can turn this off at any time in your device settings, and notifications send us no personal data.
4. What stays on your device
Some information is kept only on your phone and never sent to us:
- If you use FounderDex as a guest, your profile, onboarding answers, favorite founders and interests.
- Your deck of founder cards and the app settings.
- Your sign in token, kept in the iPhone Keychain or in encrypted storage on Android.
Android may include the guest profile in your device backup if Android backup is on. Deleting the app, or using Delete account in the app, removes this data from your device.
5. Founder catalog and map sources
FounderDex shows cards about startup founders and a map of opportunities: fellowships, grants, scholarships, investors, accelerators, events, hackathons, startups and similar. Cards contain public professional information, such as name, company, role, public photo, city, the company's investors and funding stage. We collect it from public sources and from founders who submit their own card, and each card lists its source.
| Source | What we use | Terms |
|---|---|---|
| VCLense YCGlobe export | Founder names, titles, public photos, company, batch, industry, stage and location of Y Combinator companies, republished from public company pages | Public data; FounderDex is not affiliated with VCLense or Y Combinator |
| Fund portfolio pages | Company names, websites, status and headquarters listed by venture funds. Facts only: no photos, logos or descriptions are copied from fund sites | Each fund's published terms; sites whose terms forbid automated access are skipped |
| Wikidata | Founders, companies, headquarters and venture firms | CC0 |
| Wikimedia Commons | Founder photos and investor logos, only under CC0, public domain, CC BY or CC BY-SA. The card shows the author and license, and cropped photos keep the same license | Per file license |
| Official program and event pages, public event calendars (Luma, MLH, Hack Club, confs.tech, developers.events) and the SEC Form ADV files | Map places: programs, events and investors with their dates, links and locations | Each source's terms; robots.txt is honored |
| OpenStreetMap (Nominatim) and the countries-states-cities database | Coordinates of cities and addresses | ODbL 1.0 |
| Founder submissions | Cards that founders send us about themselves, after review | Submitted with consent |
We do not scrape LinkedIn or Crunchbase. FounderDex is not affiliated with the founders, companies or investors shown. We process this public professional information because we have a legitimate interest in helping builders discover the people, programs and investors of the startup world, and we limit it to professional facts that were already made public. Founders can object at any time, as described next.
6. Removing a founder card
If you are a founder shown in FounderDex and want your card removed, you can:
- tap "Remove this card" on the card in the app,
- use the removal form on our support page, or
- email [email protected] with the card or your LinkedIn profile.
All three create a request through POST /v1/founders/optout. We review it and remove the card, its photo and its detail page within 72 hours. Your name and LinkedIn profile stay on an internal exclusion list so the card is not added again by a later import. To correct a card instead of removing it, email us.
7. How we use information
We use information to:
- create and secure your account and keep you signed in (to provide the service you asked for),
- save your profile and show your pocketcard (to provide the service),
- answer your Ask FounderDex questions and MCP tool calls (to provide the service),
- review founder submissions and removal requests (with your consent, and to honor your rights),
- prevent abuse and keep the service running (our legitimate interest in a safe service),
- reply when you contact us.
We do not sell personal information, we do not share it for cross context behavioral advertising, and we do not use it to train AI models.
8. Service providers
We use a small number of providers who process data on our behalf and only for the purposes above:
- Cloudflare, Inc.: hosting (Pages and Functions), database (D1), file storage (R2), content delivery and AI inference (Workers AI and AI Gateway).
- Google LLC: Google sign in, and Google Wallet if you choose to save a pass.
- Apple Inc.: Apple Wallet passes and Apple Maps on iPhone.
- Map tile providers: OpenStreetMap on Android and Esri on the website, as described in section 3.8.
We may disclose information if the law requires it, or to protect the rights, safety and property of our users or others. If FounderDex is ever transferred to a new owner, this policy will continue to apply to information collected under it.
9. Cookies
The website sets one cookie, and only if you sign in on the web (for example to delete your account at founderdex.ai/delete-account): a Better Auth session cookie that keeps you signed in. It is strictly necessary, it is not used for tracking, and it expires when your session ends or when you sign out. We use no analytics or advertising cookies, so there is no cookie banner. The apps use no cookies; they send the session token in a request header instead.
10. How long we keep information
- Account, session and profile data, and your profile photo: until you delete your account. Sessions also expire on their own.
- Ask questions: not stored. Cached answers expire within 1 hour.
- Rate limit records (salted IP hashes): used for a rolling 24 hour window, and hourly MCP counters are pruned after 48 hours.
- Founder submissions: until reviewed. Approved submissions become part of the published card. Rejected submissions are kept no longer than 90 days, and you can ask us to delete them sooner.
- Removal requests: kept as a record so the removed card is not added again.
- Wallet passes: never stored by us.
Deleted photos may remain in Cloudflare edge caches for a short time after deletion, and in our providers' normal short term operational backups (for Cloudflare D1, up to 30 days) before they are overwritten.
11. Deleting your account and data
You can delete your account at any time:
- In the app: Profile, gear icon, Delete account, then Delete.
- On the web: at founderdex.ai/delete-account. Sign in with Google and confirm.
- By email: write to [email protected] from the Google email you signed in with.
Deleting your account permanently removes your account record, sign in tokens, sessions, profile and profile photos from our servers right away (through DELETE /v1/me). In the app it also clears the profile stored on your device.
Founder submissions and removal requests are not linked to your account. To delete them, email us from the address you used in the form. To also remove FounderDex's access from your Google Account, visit myaccount.google.com/connections and remove FounderDex.
12. Your rights
Depending on where you live (for example under the GDPR, the UK GDPR, the California Consumer Privacy Act or Colombia's Law 1581 of 2012), you may have the right to access, correct, delete or export your personal information, to object to or restrict some processing, and to withdraw consent. You can edit or delete most of your information directly in the app. For anything else, contact us and we will reply within 30 days. We will not treat you differently for using these rights. You may also complain to your local data protection authority (in Colombia, the Superintendencia de Industria y Comercio).
13. Security
All traffic between the apps, the website and our servers uses HTTPS. The apps keep your sign in token in secure storage on your device. Access to our infrastructure is limited to the people who run FounderDex. No system is perfectly secure, so please contact us if you notice anything unusual.
14. International transfers
Our providers run globally distributed infrastructure, so your information may be processed in countries other than your own, including the United States. When we transfer personal information from the European Economic Area, the United Kingdom, Colombia or other places with transfer rules, we rely on our providers' standard safeguards, such as the European Commission's Standard Contractual Clauses and the EU-U.S. Data Privacy Framework where the provider is certified.
15. Children
FounderDex is not directed to children under 13 (or under 16 where local law sets a higher age) and we do not knowingly collect their personal information. If you believe a child has given us personal information, contact us and we will delete it.
16. Changes to this policy
If we change this policy, we will update the effective date above and, for significant changes, tell you in the app or on the website before the change applies.
17. Contact
FounderDex
Calle 92 #19C-17
Email: [email protected]
Web: founderdex.ai/support (removal form) and founderdex.ai/delete-account (account deletion)