Last updated 17 September 2026
Privacy policy
What we collect, why, who can see it, and your choices.
In short
- Anyone can see a public profile, including Google, ChatGPT and Claude.
- You choose who can see each profile.
- We don't sell your data or show ads.
- You can ask us to fix or delete your data.
What we collect
Your account
- Email and password sign-in: your email address and a password. We store only a salted scrypt hash of the password, never the password itself.
- Google or GitHub sign-in: the provider's account ID, your verified email address, your display name and, for GitHub, your public profile URL. We use the provider's access token once to read these details and do not store it. We never see your Google or GitHub password.
What you publish
- Your profile: name, username, headline, bio, location, availability, what you are looking for, skills, experience, projects and links such as GitHub, LinkedIn or a portfolio.
- An optional profile photo. Your browser crops and resizes it before upload, and we remove embedded metadata such as GPS location. The photo is shown wherever your profile is visible, and you can change or remove it at any time.
- Organization pages and opportunity listings you create.
Technical data
- Cookies: a sign-in cookie (
foundaree-session, valid for 24 hours) and, while you sign in with Google or GitHub, a short-lived security cookie (10 minutes). Both are strictly necessary and cannot be read by page scripts. We use no analytics or advertising cookies. - Server logs: the address requested (which can include search terms), the response status and timing. Our hosting providers also process IP addresses to deliver and protect the service, and we use IP addresses briefly in memory to limit abusive request rates.
Connections and messages
Connection requests, messages and notifications are an early preview. They are currently kept only in your browser tab and are not sent to or stored on our servers.
How we use it
- To run your account and keep you signed in.
- To show your public profile, organizations and listings, and to make them searchable.
- To protect the service from abuse, fraud and security threats.
- To answer your requests and meet legal obligations.
We process account data to provide the service you asked for, and publish profile data because you chose to publish it. You can withdraw that choice by changing visibility or deleting the content.
Who can see your information
- Public profiles and listings are visible to everyone. They appear in our search, our sitemap and structured data, and our API and AI-assistant interfaces, so search engines and AI tools can index and quote them. Copies may remain in third-party caches for a while after you change them.
- Unlisted and private items are visible only to you when signed in. They never appear in search, sitemaps or AI-assistant results.
- Your email address and account details are never shown on your profile.
Service providers
We share data only with providers that help us run Foundaree:
- Vercel, which hosts the website.
- Railway, which hosts our API and database.
- Google and GitHub, only if you choose to sign in with them.
These providers may process data in countries other than yours. We don't sell personal data or share it for advertising. We may disclose data if the law requires it.
How long we keep it
We keep your account and content while your account exists. Sign-in sessions expire after 24 hours. When you ask us to delete your account, we delete your account, profile and sessions from our database, except where we must keep something to meet a legal obligation.
Your rights and choices
- Change your profile's visibility or edit its content at any time.
- Ask for a copy of your data, a correction, or deletion of your account.
- Withdraw consent by deleting content or making it private.
- Depending on where you live (for example under India's Digital Personal Data Protection Act, 2023, or the EU/UK GDPR), you may have further rights, including the right to complain to a data protection authority.
To make a request, email hello@foundaree.com. We may need to confirm that the account is yours before acting.
Security
We use HTTPS, hashed passwords and session tokens, HttpOnly cookies and rate limiting. No system is perfectly secure; see our security page for how to report a problem.
Children
Foundaree is for people aged 18 and over. We don't knowingly collect data from children.
Changes to this policy
If we make significant changes, we'll update the date above and, where appropriate, let you know before the changes take effect.
Contact
For any privacy question, email hello@foundaree.com.