Privacy notice
What Foundanz collects, why, where it is kept and for how long. Questions to info@foundanz.com.
This website
The public pages set no cookies and load no analytics, advertising, fonts or scripts from anyone else. The hosting provider processes each request, including your IP address, in order to serve it.
Requesting access
The request form collects your name, work email, company, intended use and an optional note. Your IP address is stored only as a one-way hash, used to limit repeated requests. The request is emailed to the administrator and is used only to decide on and answer it. It creates no account and sets no cookie. Requests are deleted automatically 90 days after they are made.
Using the application
For invited users, the application keeps:
- your account: name, email, company if given, the sign-in methods you may use, your access period and when you last signed in;
- sign-in sessions, held in cookies on app.foundanz.com only, with the browser that started each one;
- the projects you create, which are private to your account;
- feedback you send: the message, the page you were on, the build, your browser and any screenshot you attach;
- errors you run into: where they happened and the technical detail, linked to your account.
An administrator can open a project read-only to answer a support question. Every such opening is recorded in an audit log.
Where data goes
- Vercel hosts this site and runs the application. Its functions run in Tokyo (hnd1).
- Supabase holds the database and file storage. Region: ap-northeast-1.
- Render runs the PDF renderer in Singapore. When a PDF report is produced, the report’s content is sent there to be laid out, and the PDF is sent back.
- Resend sends the application’s email: sign-in codes and links, account notices, and, to the administrator, feedback and access requests.
The Anthropic API is used for one administrator-only task: drafting a validation case from a worked example the administrator uploads. Nothing from your projects, account or feedback is sent to it.
How long it is kept
- A deleted project can be restored for 30 days and is then removed permanently by a scheduled job.
- Used and expired sign-in codes and links are removed after 7 days.
- Access requests are removed after 90 days.
- Account data is kept while the account exists. To have it removed, write to info@foundanz.com.