Legal
Privacy Policy
Founder Voice Vault holds unpublished writing and internal material. This policy explains what the service collects, which providers may process it, and the controls available to you.
Last updated: 20 August 2026
1. Who operates the service
Founder Voice Vault is operated by [Legal name of the operator]. Questions or privacy requests can be sent to [privacy contact email].
2. Data we collect
Account and organization data: your name, email address, organization membership, role, invitations, plan, and subscription status. Stripe handles payment details; Founder Voice Vault does not store full card numbers.
Vault content: the identities you are authorized to represent, uploaded files, pasted text, extracted text, voice profiles, briefs, drafts, revisions, feedback, and source references.
Operational data: usage counts, generation audit records, request identifiers, processing status, and scrubbed error diagnostics. Error reporting is configured to exclude request bodies, cookies, source text, prompts, drafts, and email addresses.
3. How we use data
We use this data to authenticate users, isolate organizations, ingest and retrieve authorized source material, build editable voice profiles, generate and revise drafts, provide exports, enforce plan allowances, process billing, send team invitations, prevent abuse, and diagnose failures. We do not use one customer's vault to write for another customer or train a public model.
4. Service providers
We disclose only the data needed for providers to perform their part of the service:
- Vercel hosts the web application and server functions.
- Supabase provides authentication, Postgres databases, and private file storage.
- OpenAI may process active voice profiles, briefs, retrieved passages, embeddings, or audio transcription when the corresponding provider is configured.
- Mistral may process a scanned PDF through a short-lived signed URL when OCR is enabled and that file type is uploaded.
- Resend receives an invitee address, organization name, inviter name, and invitation link to deliver team invitations. It does not receive vault content.
- Stripe processes checkout, subscriptions, and portal activity. It does not receive vault content.
- Sentry may receive scrubbed error and performance diagnostics when configured. Session replay is disabled.
OCR and transcription providers receive content only when you use those media-processing paths. In local mock mode, no source content is sent to an AI provider.
5. Cookies and analytics
Founder Voice Vault uses required session cookies to sign you in and keep your account secure. The application does not currently use marketing analytics, advertising trackers, or non-essential tracking cookies. Stripe-hosted pages and other provider sites are governed by those providers' own cookie policies.
6. Isolation, security, and operator access
Customer records are scoped to an organization in both the application and database. Files are kept in a private storage bucket and accessed through short-lived signed URLs. The routine platform administrator console shows account and aggregate usage information; it does not expose source text, drafts, prompts, storage paths, or uploaded file bytes. Authorized infrastructure access may still be used when necessary to secure, maintain, or troubleshoot the service.
7. Export, retention, and deletion
Organization owners can export organization records as JSON. The export includes extracted source text and generated records, but not the original uploaded file bytes.
You can delete a source, a vault, or an organization. Organization deletion removes its stored files and customer records without a recovery period, so export first. Deleting a source does not remove quotations already preserved in an earlier draft's source references; delete the related draft or vault to remove that copy too.
Providers may retain limited billing, security, or delivery records under their own policies and legal obligations.
8. Children
Founder Voice Vault is a business service and is not directed to children. Do not create an account or submit personal data if you are under 18.
9. Changes and contact
We may update this policy as the service or its providers change. The date at the top identifies the current version. Contact [privacy contact email] with questions, requests, or complaints. Use of the service is also governed by the Terms.