FoundIn.ai

Legal

Privacy Policy

We're a small EU SaaS — this policy explains in plain language what data we hold, why, and how to get rid of it.

Last updated: 26 June 2026

1. Who we are (data controller)

FoundIn.ai is operated by Nexari B.V. (the "Controller", "we", "us"), a company registered in the Netherlands. References to "FoundIn.ai" in this policy mean Nexari B.V. acting as the controller for personal data processed through the foundin.ai website and product.

Contact for privacy matters: privacy@foundin.ai.

2. What we collect

We only collect what we need to deliver and improve the service:

  • Account data — email, name, hashed password (or Google OAuth subject), preferred language.
  • Business data you give us — the URL, prompts, competitors, and settings you save in the dashboard.
  • Usage data — pages viewed, features used, request logs, error traces. Tied to your account where you are signed in, anonymous otherwise.
  • Billing data — held by our payment processor Paddle (see sub-processors). We receive a customer reference, plan, transaction ID, and the country / VAT identifiers required for invoicing.
  • AI-engine outputs — text returned by ChatGPT, Gemini, Perplexity and Claude when we probe them on your behalf. We store these alongside your account so you can see your visibility over time.

3. Why we use it (legal bases)

  • Contract (Art. 6(1)(b) GDPR) — delivering the product, running probes, sending account emails.
  • Legitimate interest (Art. 6(1)(f)) — security logging, fraud prevention, product analytics from which we cannot identify you.
  • Consent (Art. 6(1)(a)) — non-essential cookies, marketing emails. Withdrawable at any time from the footer or your account.
  • Legal obligation (Art. 6(1)(c)) — keeping invoice records for the statutory retention period.

4. Who we share it with

We do not sell personal data. We share data only with the sub-processors listed at /legal/subprocessors, each bound by a Data Processing Agreement that mirrors the protections in this policy.

5. International transfers

Your data is processed primarily in the EU. Some sub-processors (e.g. AI engine APIs) process data in the United States. Where that happens we rely on the European Commission's Standard Contractual Clauses (SCCs) and, where applicable, the EU-US Data Privacy Framework.

6. How long we keep it

  • Account data — for as long as you have an account.
  • Soft-deleted accounts — purged 30 days after deletion (you can cancel the deletion during that window from your settings).
  • Probe history — rolling 24 months on paid plans, 90 days on free.
  • Invoices and tax records — 7 years (Dutch tax law).
  • Security logs — 90 days.

7. Your rights

You have the right to access, rectify, erase, restrict, port, and object to processing of your personal data. You can exercise each of these directly inside the app at Settings → Privacy (Export my data, Delete my account, Manage consent), or by emailing privacy@foundin.ai. We respond within 30 days.

You also have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) at autoriteitpersoonsgegevens.nl.

8. Security

Data is encrypted in transit (TLS 1.2+) and at rest. Access to production systems is restricted, logged, and protected by two-factor authentication. Read more on our Security page.

9. Cookies

See our Cookie Policy for the full table. You can change your choice anytime via the "Cookie preferences" link in the footer.

10. Changes to this policy

We'll notify you by email or in-app at least 14 days before material changes take effect. Older versions are kept in our changelog on request.

A quick word on cookies

FoundIn.ai uses essential cookies to keep you signed in. With your permission, we'd also use a few more to improve the product and see which features actually help.

Cookie Policy · Privacy