Privacy

Privacy Policy

Effective date: . This policy explains what information FounderDex collects, why, how long we keep it and the choices you have. It covers the FounderDex apps for iPhone and Android, the website at founderdex.ai (including the map at founderdex.ai/map), the Ask FounderDex assistant and the FounderDex MCP server (together, "FounderDex").

1. The short version

2. Who we are

FounderDex is operated by FounderDex ("we", "us"). Postal address: Calle 92 #19C-17. We decide how and why the personal information described here is processed, so we are its controller. You can reach us at [email protected] or through the web forms on our support page.

3. Information we collect

3.1 When you sign in with Google

Sign in is optional. We use Better Auth, an open source sign in library that runs on our own servers, with Google as the only sign in provider. When you choose "Continue with Google", Google shares with us:

Google also gives us sign in tokens so we can confirm your identity, and we store them with your account. We only ask Google for basic profile and email access (the openid, email and profile scopes). We do not get access to your contacts, Gmail, Drive, Calendar or any other Google data. Our use of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements.

While you are signed in, we keep a session record with a session token, its expiry date, and the IP address and device user agent used to sign in. We use it to keep you signed in and to protect your account.

3.2 Your profile and photo

If you are signed in, the profile you fill in is saved to your account: display name, headline, company, city, up to 8 links (for example LinkedIn, X, a website, an email or a calendar link), up to 3 favorite founders, the topics you are interested in and whether you finished onboarding. It is stored in our database on Cloudflare D1.

You can add a profile photo. It is stored in Cloudflare R2 storage and can be viewed by anyone who has its link, for example when you share your pocketcard. Do not upload a photo you do not want others to see.

3.3 Pocketcard and wallet passes

Your pocketcard is a small builder profile you can add to Apple Wallet or Google Wallet. When you tap "Add to Apple Wallet" or "Save to Google Wallet", the app sends the details shown on your pocketcard (name, role, organization, city, focus and the QR code content) to our server, which signs the pass and returns it. We do not keep a copy. Apple Wallet passes are stored on your device by Apple. Google Wallet passes are stored by Google under Google's privacy policy. You can remove a pass from your wallet at any time.

3.4 Ask FounderDex

When you ask a question, we send the question and the filters you selected (for example a country, a city or a category) to an AI model that answers using only the FounderDex catalog and map. The model runs on Cloudflare Workers AI through a Cloudflare AI Gateway with request logging turned off, or on another OpenAI compatible model gateway if we configure one, in which case we will name it in section 8. We do not store your questions in our database and they are not linked to your account. To keep the service fast, the same question may be answered from a short lived cache for up to 1 hour. We do not use your questions to train AI models, and our providers do not either under our settings. Please do not include personal or sensitive information in your questions.

3.5 MCP server

The FounderDex MCP server at https://founderdex.ai/mcp lets AI assistants such as Claude, ChatGPT or Cursor read the public catalog and map. It is read only and needs no account or key. We do not receive your conversation with your assistant, only the tool calls it sends (for example a search for "fintech in Bogota"). Tool calls are not stored beyond the rate limit record described next.

3.6 Abuse prevention

To stop abuse and control costs, we limit how many questions, submissions, removal requests and MCP calls can come from one network per day or hour. For this we store a one way hash of your IP address, made with a secret salt, together with the type of request and the time. We cannot turn this hash back into your IP address, and we do not link it to your account.

3.7 Founder submissions and removal requests

If you submit a founder card for review, we collect what you enter in the form: name, company, title, LinkedIn, website, email, the collection and a photo, plus the IP hash described above. We use it to review the card and, if approved, publish it.

If you ask us to remove a founder card, we collect the card id or LinkedIn profile, your email and the reason you give. We use it to process and keep a record of the request. These forms are not linked to a FounderDex account.

3.8 Maps

The map shows tiles from a map provider, and your device requests those tiles directly: Apple Maps on iPhone, OpenStreetMap on Android and Esri (ArcGIS) on the website. Like any website, the provider receives your IP address and the area of the map you are viewing. FounderDex does not ask for or collect your location.

3.9 What we do not collect

We do not collect your precise location, contacts, SMS, call logs, camera or microphone data, advertising identifier or payment information. The apps and the website include no analytics, crash reporting or advertising SDKs. If the app asks for permission to show notifications, you can turn this off at any time in your device settings, and notifications send us no personal data.

4. What stays on your device

Some information is kept only on your phone and never sent to us:

Android may include the guest profile in your device backup if Android backup is on. Deleting the app, or using Delete account in the app, removes this data from your device.

5. Founder catalog and map sources

FounderDex shows cards about startup founders and a map of opportunities: fellowships, grants, scholarships, investors, accelerators, events, hackathons, startups and similar. Cards contain public professional information, such as name, company, role, public photo, city, the company's investors and funding stage. We collect it from public sources and from founders who submit their own card, and each card lists its source.

SourceWhat we useTerms
VCLense YCGlobe exportFounder names, titles, public photos, company, batch, industry, stage and location of Y Combinator companies, republished from public company pagesPublic data; FounderDex is not affiliated with VCLense or Y Combinator
Fund portfolio pagesCompany names, websites, status and headquarters listed by venture funds. Facts only: no photos, logos or descriptions are copied from fund sitesEach fund's published terms; sites whose terms forbid automated access are skipped
WikidataFounders, companies, headquarters and venture firmsCC0
Wikimedia CommonsFounder photos and investor logos, only under CC0, public domain, CC BY or CC BY-SA. The card shows the author and license, and cropped photos keep the same licensePer file license
Official program and event pages, public event calendars (Luma, MLH, Hack Club, confs.tech, developers.events) and the SEC Form ADV filesMap places: programs, events and investors with their dates, links and locationsEach source's terms; robots.txt is honored
OpenStreetMap (Nominatim) and the countries-states-cities databaseCoordinates of cities and addressesODbL 1.0
Founder submissionsCards that founders send us about themselves, after reviewSubmitted with consent

We do not scrape LinkedIn or Crunchbase. FounderDex is not affiliated with the founders, companies or investors shown. We process this public professional information because we have a legitimate interest in helping builders discover the people, programs and investors of the startup world, and we limit it to professional facts that were already made public. Founders can object at any time, as described next.

6. Removing a founder card

If you are a founder shown in FounderDex and want your card removed, you can:

All three create a request through POST /v1/founders/optout. We review it and remove the card, its photo and its detail page within 72 hours. Your name and LinkedIn profile stay on an internal exclusion list so the card is not added again by a later import. To correct a card instead of removing it, email us.

7. How we use information

We use information to:

We do not sell personal information, we do not share it for cross context behavioral advertising, and we do not use it to train AI models.

8. Service providers

We use a small number of providers who process data on our behalf and only for the purposes above:

We may disclose information if the law requires it, or to protect the rights, safety and property of our users or others. If FounderDex is ever transferred to a new owner, this policy will continue to apply to information collected under it.

9. Cookies

The website sets one cookie, and only if you sign in on the web (for example to delete your account at founderdex.ai/delete-account): a Better Auth session cookie that keeps you signed in. It is strictly necessary, it is not used for tracking, and it expires when your session ends or when you sign out. We use no analytics or advertising cookies, so there is no cookie banner. The apps use no cookies; they send the session token in a request header instead.

10. How long we keep information

Deleted photos may remain in Cloudflare edge caches for a short time after deletion, and in our providers' normal short term operational backups (for Cloudflare D1, up to 30 days) before they are overwritten.

11. Deleting your account and data

You can delete your account at any time:

Deleting your account permanently removes your account record, sign in tokens, sessions, profile and profile photos from our servers right away (through DELETE /v1/me). In the app it also clears the profile stored on your device.

Founder submissions and removal requests are not linked to your account. To delete them, email us from the address you used in the form. To also remove FounderDex's access from your Google Account, visit myaccount.google.com/connections and remove FounderDex.

12. Your rights

Depending on where you live (for example under the GDPR, the UK GDPR, the California Consumer Privacy Act or Colombia's Law 1581 of 2012), you may have the right to access, correct, delete or export your personal information, to object to or restrict some processing, and to withdraw consent. You can edit or delete most of your information directly in the app. For anything else, contact us and we will reply within 30 days. We will not treat you differently for using these rights. You may also complain to your local data protection authority (in Colombia, the Superintendencia de Industria y Comercio).

13. Security

All traffic between the apps, the website and our servers uses HTTPS. The apps keep your sign in token in secure storage on your device. Access to our infrastructure is limited to the people who run FounderDex. No system is perfectly secure, so please contact us if you notice anything unusual.

14. International transfers

Our providers run globally distributed infrastructure, so your information may be processed in countries other than your own, including the United States. When we transfer personal information from the European Economic Area, the United Kingdom, Colombia or other places with transfer rules, we rely on our providers' standard safeguards, such as the European Commission's Standard Contractual Clauses and the EU-U.S. Data Privacy Framework where the provider is certified.

15. Children

FounderDex is not directed to children under 13 (or under 16 where local law sets a higher age) and we do not knowingly collect their personal information. If you believe a child has given us personal information, contact us and we will delete it.

16. Changes to this policy

If we change this policy, we will update the effective date above and, for significant changes, tell you in the app or on the website before the change applies.

17. Contact

FounderDex
Calle 92 #19C-17
Email: [email protected]
Web: founderdex.ai/support (removal form) and founderdex.ai/delete-account (account deletion)