Privacy
What Foundry stores, and what it never sees
Draft. This text describes how Foundry works today. It has not yet been reviewed by a lawyer, and paid checkout with real money does not open until it has been.
Foundry stores the evidence you submit for a review, the result, the email address you give Stripe at checkout, and identifiers that link your payment and subscription to your reviews. It never receives your card details. Your evidence is not sent to an AI model and is not sold or used for advertising.
Who is responsible
Seller details not yet published. The legal entity that sells Foundry, its address and its contact details will be stated here before paid checkout with real money opens.
What Foundry stores
| Data | What exactly |
|---|---|
| Your evidence, as you classify it | For each evidence item: the behaviour type, how you acquired it, the source’s relationship to you, whether it is current, the date you collected it, and your own optional strength estimate. Also the decision risk you chose, falsifier dates, repair attempts, contradiction dates and your confirmations. |
| The text you write | The assumption, the falsifier statement, an alternative assumption if you give one, and one short note per evidence item. These are kept so you can recognise and re-read your review. If a note quotes or names a person, that is personal data you have chosen to give us; leave names out. |
| The result | The outcome, its reasons, the policy version and the evaluation time. |
| Your customer record | The email address you enter in Stripe Checkout and Stripe’s identifier for you as a customer. |
| Payment and subscription records | Stripe’s identifiers for your checkout and subscription, the product, the amount and currency, status, the current billing period end, whether a cancellation is scheduled, and the time of a failed payment if there was one. |
| Payment event log | A reduced record of each notification Stripe sends: its identifier, type, status and the identifiers it refers to. Names, addresses and tax IDs in those notifications are not kept. |
| Sign-in links | The email address a link was requested for, a one-way hash of the link’s token, and when it expires. The token itself is not stored. |
| Server logs | For each request: the route, the status, how long it took, and an error code. Not your evidence, text, email address or cookies. |
What Foundry never sees or stores
- Card numbers, bank details and other payment-method data. You enter them on Stripe’s pages, and they stay with Stripe.
- Your billing address and tax ID. Stripe collects them to calculate tax and issue invoices.
- Anything from your devices or accounts. Foundry has no access to your inbox, CRM, analytics or files.
What Stripe holds
Stripe is the payment processor and acts under its own privacy policy. It holds your payment method, billing details, tax information, invoices and receipts, and it sends receipts and manages the billing portal.
Who else processes data for Foundry
- Stripe — payments, tax calculation, invoices, the billing portal.
- Cloudflare — hosts this website and runs the Turnstile check on the pages where you start checkout or ask for a sign-in link. Turnstile processes technical information about your browser to tell people from automated traffic.
- Railway — hosts Foundry’s application server and database, currently in the United States.
- An email automation service operated for Foundry — sends the sign-in link email. It receives your email address and the link, and for a completed review only the outcome and identifiers, never your evidence or text.
Cookies and tracking
Foundry sets one cookie, __Host-foundry_session, after you pay or sign in. It keeps you signed in for up to 30 days, cannot be read by scripts, and is sent only to this site. It is strictly necessary to show you your own reviews. This site uses no analytics, advertising or cross-site tracking.
AI
The outcome of a review is produced by deterministic code. Your evidence is not sent to an AI model, and it is not used to train one.
How long it is kept
Your review history is kept so that it stays available to you. A fixed retention period has not been set yet; when one is, it will be stated here. A sign-in link stops working after 30 minutes or after one use. You can ask for your data to be deleted at any time.
Your requests
You can ask for a copy of your data, a correction, or deletion. If you are in the EU or the UK you also have the other rights data-protection law gives you, including complaining to your supervisory authority.
Privacy and deletion requests: a contact address will be published here before paid checkout with real money opens.