Legal
Effective date: April 3, 2026
Privacy Policy
Last updated: April 3, 2026
1. Who We Are
XFoundry is operated by XFoundry ("we", "us", or "our"). We provide a SaaS idea discovery platform at xfoundry.dev that surfaces and scores business ideas from public online communities using AI.
For privacy inquiries, contact us at: [email protected]
2. Data We Collect
Account data
When you sign in via Google OAuth or magic link email, we collect your email address and a unique user identifier. We do not collect your name, phone number, or other personal details unless you provide them.
Usage data
We log which features you use (ideas saved, analyses run, pages visited) to operate and improve the service. This data is stored in our Supabase database and is tied to your account.
Payment data
Payments are processed by Stripe. We store your Stripe customer ID and subscription status, but we never see or store your card number, CVV, or full billing address — Stripe handles all payment data under their own Privacy Policy.
Telegram chat ID
If you connect Telegram notifications, we store your Telegram chat ID to deliver digest messages. We do not store message contents.
Data we do NOT collect
We do not collect IP addresses, device fingerprints, advertising identifiers, or any biometric data. We do not run analytics trackers (no Google Analytics, no Meta Pixel).
3. How We Use Your Data
We use the data we collect to:
- Authenticate you and maintain your session
- Deliver the service — idea feed, deep analysis, saved ideas, notifications
- Process payments and manage your subscription or credit balance
- Send transactional emails (digest notifications, billing receipts) if you opt in
- Detect and prevent abuse or fraudulent activity
We do not sell your data. We do not use your data for advertising or profiling.
4. Legal Basis for Processing (GDPR)
If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, our legal bases for processing your personal data are:
- Contract performance — processing necessary to provide the service you signed up for (Art. 6(1)(b) GDPR)
- Legitimate interests — fraud prevention, service security, and improving our product (Art. 6(1)(f) GDPR)
- Legal obligation — retaining transaction records as required by law (Art. 6(1)(c) GDPR)
- Consent — for optional email notification digests, which you can withdraw at any time
5. Third-Party Processors
We share data only with the following sub-processors, each bound by their own data processing agreements:
| Processor | Purpose | Location |
|---|---|---|
| Supabase | Auth, database (user accounts, ideas, analyses) | USA (AWS us-east-1) |
| Stripe | Payment processing, subscription management | USA / Global |
| Google OAuth | Sign-in authentication | USA / Global |
| Anthropic (Claude) | AI scoring and deep analysis of ideas | USA |
| Resend | Transactional email delivery | USA |
| Modal | Background jobs and notification delivery | USA |
| Telegram Bot API | Push notification delivery (opt-in) | Global |
| Vercel | Web hosting and edge delivery | USA / Global |
Where data is transferred outside the EEA, we rely on Standard Contractual Clauses (SCCs) or adequacy decisions as the transfer mechanism.
6. Data Retention
We retain your personal data for as long as your account is active. If you delete your account:
- Account and profile data is deleted within 30 days
- Payment records are retained for 7 years as required by financial regulations
- Anonymized usage statistics may be retained indefinitely
7. Your Rights
EEA / UK users (GDPR)
You have the right to: access your data, correct inaccurate data, delete your data ("right to be forgotten"), restrict or object to processing, data portability, and lodge a complaint with your local supervisory authority.
California users (CCPA / CPRA)
California residents have the right to: know what personal information we collect and how it's used, delete personal information (with certain exceptions), correct inaccurate personal information, opt out of the sale or sharing of personal information (we do not sell or share your data), and non-discrimination for exercising these rights.
To exercise any of these rights, email us at [email protected]. We will respond within 30 days (GDPR) or 45 days (CCPA).
8. Children's Privacy
XFoundry is not directed at children under 16 years of age. We do not knowingly collect personal information from children. If you believe we have inadvertently collected such information, please contact us immediately.
9. Security
We implement industry-standard security measures including TLS encryption in transit, row-level security in our database, and scoped API keys. However, no method of transmission over the internet is 100% secure, and we cannot guarantee absolute security.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify registered users by email for material changes. Continued use of the service after changes constitutes acceptance of the updated policy.
Terms of Service
Last updated: April 3, 2026
1. Acceptance
By creating an account or using XFoundry ("the Service"), you agree to these Terms of Service. If you do not agree, do not use the Service. These terms apply to all users globally, with additional provisions for EEA users where noted.
2. Description of Service
XFoundry is a SaaS idea discovery platform that aggregates publicly discussed business ideas from online communities, scores them using AI, and provides on-demand deep analysis reports. The Service is provided as-is for informational purposes only.
3. Accounts
- You must provide a valid email address to create an account
- You are responsible for maintaining the confidentiality of your account
- You must be at least 16 years old to use the Service
- One account per person — no shared accounts
4. Subscriptions and Credits
Free plan
Free users have access to the latest 100 ideas, with up to 10 saves and no notifications.
Pro subscription
Pro is available at €19/month or €157/year. Pro includes full idea history, unlimited saves, notifications, category watchlists, and 3 deep analysis reports per calendar month.
Credits
Additional deep analyses can be purchased as one-time credit packs. Credits do not expire. Credits are non-refundable once a deep analysis has been successfully generated.
Billing
Subscriptions renew automatically. You may cancel at any time from the Settings page; your Pro access continues until the end of the current billing period. We do not offer prorated refunds for partial subscription periods, except where required by applicable law (including EU consumer protection regulations).
EU right of withdrawal
EEA consumers have a 14-day right of withdrawal from the date of purchase, except where the digital service has already been fully performed with your prior consent. By running your first deep analysis or accessing Pro features immediately after subscribing, you acknowledge that performance has begun and waive the right of withdrawal for that service.
5. Acceptable Use
You agree not to:
- Use the Service for any unlawful purpose
- Scrape, crawl, or systematically download the Service's content
- Attempt to reverse-engineer, decompile, or extract the AI models or scoring logic
- Create multiple accounts to circumvent Free plan limits
- Resell or sublicense access to the Service without written permission
- Interfere with or disrupt the integrity or performance of the Service
6. Intellectual Property
The Service, including its design, code, AI models, and scoring methodology, is owned by XFoundry and protected by copyright and intellectual property laws. The community-sourced idea content is aggregated from public sources; we do not claim ownership over the underlying ideas.
Deep analysis reports generated for your account are for your personal or internal business use only and may not be redistributed commercially.
7. Disclaimers
The Service is provided "as is" without warranties of any kind. AI-generated scores and analysis reports are for informational purposes only and do not constitute business, legal, or financial advice. We make no guarantees about the accuracy, completeness, or fitness for a particular purpose of any content on the platform.
Market conditions change rapidly. An idea scored as "GO" today may become unviable tomorrow. Always conduct your own due diligence before making business or investment decisions.
8. Limitation of Liability
To the maximum extent permitted by applicable law, XFoundry shall not be liable for any indirect, incidental, special, consequential, or punitive damages, including loss of profits, data, or business opportunities, arising from your use of the Service.
Our total aggregate liability to you shall not exceed the amount you paid us in the 12 months preceding the claim.
Note: Some jurisdictions (including EU member states) do not allow the exclusion of certain implied warranties or limitations of liability for consumers. The above limitations apply only to the extent permitted by law in your jurisdiction.
9. Governing Law and Disputes
These Terms are governed by and construed in accordance with the laws of the jurisdiction in which XFoundry is incorporated, without regard to conflict of law principles.
For EU/EEA users: Nothing in these Terms affects your rights as a consumer under mandatory applicable EU or national law, including the right to bring proceedings in the courts of your country of residence. EU consumers may also use the EU Online Dispute Resolution platform at ec.europa.eu/consumers/odr.
For US users: Any disputes shall be resolved by binding arbitration under the AAA Commercial Arbitration Rules, except that either party may seek injunctive relief in court for IP infringement or misappropriation of confidential information.
10. Modifications and Termination
We reserve the right to modify these Terms at any time. Material changes will be communicated via email with at least 14 days notice. Continued use after the effective date constitutes acceptance.
We may suspend or terminate your account for violation of these Terms. Upon termination, your right to use the Service ceases immediately. Unused credits are non-refundable upon termination for cause.
Cookies We Use
We use only essential cookies — cookies that are strictly necessary for the Service to function. We do not use advertising cookies, tracking pixels, or analytics cookies.
| Cookie | Purpose | Duration |
|---|---|---|
| sb-* | Supabase authentication session — keeps you logged in | Session / 1 year |
| theme | Stores your light/dark mode preference (next-themes) | 1 year |
Because we use only strictly necessary cookies, we are not required to display a consent banner under the ePrivacy Directive or GDPR. No consent is needed for cookies that are essential to a service explicitly requested by the user.
You can disable cookies in your browser settings, but doing so will prevent you from staying logged in to XFoundry.
Questions about this policy? [email protected]
© 2026 XFoundry. All rights reserved.