Legal

Privacy policy

What data Foundry collects, why we process it, how Auto Reply and Meta messaging work, which subprocessors we use, and how you can request deletion.

Last updated 25 July 2026

We collect account, project, and messaging data to run Foundry and Auto Reply. We do not sell your project or conversation content. You can request access, correction, or deletion by emailing support or using Meta’s data-deletion flow when you connected Facebook.

Minimal collection

We collect what we need to authenticate you, store projects, run generation, publish sites, and power Auto Reply channels you connect.

No sale of project or message data

Your business ideas, generated artifacts, site content, and customer conversations are not sold to advertisers or data brokers.

Clear deletion paths

Email support to delete account data, disconnect channels in Auto Reply, or use Meta’s Apps and Websites deletion request for Facebook Login data.

Scope & controller

This policy describes how Foundry ("we", "us") processes personal data when you use tryfoundry.app, related APIs, published customer subdomains, and Auto Reply messaging channels (website chat, Facebook Messenger, WhatsApp, Telegram, and Viber).

Foundry is the data controller for Foundry account data, workspace/project data, and Meta Platform Data we receive when a business connects Facebook or WhatsApp through our app. When a business uses Auto Reply to message their customers, that business is the controller of the customer conversation content and Foundry processes it on their instructions to deliver the service.

For questions or privacy requests, email support@tryfoundry.app. For Meta Facebook Login data-deletion status, see /legal/data-deletion.

Data we collect

Account data

Handled by Clerk, our authentication provider.

  • Email address and authentication identifiers.
  • Profile name and avatar if you provide them.
  • Sign-in method metadata (e.g. OAuth provider).

Project & workspace data

Stored in Supabase Postgres for your projects.

  • Business ideas, chat messages, and notes you submit.
  • Generated artifacts: research, BrandDNA, websites, marketing assets.
  • Collaboration data: invites and member roles.
  • Deployment records and publish history.
  • Workspace memory notes you choose to store for AI context.

Auto Reply & messaging data

Collected only when you enable Auto Reply and connect channels.

  • Channel connection metadata: Page or bot IDs, display names, connection status.
  • Encrypted channel credentials (Page access tokens, bot tokens) stored server-side only.
  • Facebook Login user id associated with a Meta connection (for data-deletion mapping).
  • Conversation threads: customer display name/avatar when the channel provides them, platform-scoped customer ids (for example Messenger PSID), message text, delivery status, and optional lead phone/name if collected.
  • Inbound media metadata and files stored in a private project-scoped bucket (not used for AI vision in the current release).
  • Approved business facts and blocked topics you configure for replies.

Technical & usage data

Collected to secure and improve the service.

  • IP address, browser type, and device signals for fraud prevention.
  • Request logs and error reports.
  • Product analytics in aggregate form where enabled.
  • AI usage telemetry (feature key, token counts, status) for billing and reliability.

Meta Platform Data (Facebook & WhatsApp)

Required disclosures for Foundry’s Meta app used by Auto Reply.

Foundry operates one shared Meta app so businesses can connect Facebook Pages (Messenger) and, where enabled, WhatsApp Business accounts through Facebook Login for Business. We do not ask customer end-users to create a Foundry account to message a connected Page.

Meta data we process and why

DataSourcePurpose
Facebook user id of the person who authorises the connectionFacebook Login for Business / Graph APIMap and honour Meta data-deletion requests; secure the connection to the correct Foundry project
Page id, Page name, Page pictureGraph API after authorisationShow connection status and route inbound messages to the correct project
Page access token / WhatsApp access tokenGraph API after authorisationSubscribe webhooks, send replies, and keep the channel healthy — stored encrypted, never exposed to the browser
Messenger / WhatsApp message content, attachments, delivery eventsMeta webhooksPower Auto Reply, human inbox takeover, and delivery retries for the connected business
Page-scoped user id (PSID) or WhatsApp customer idMeta webhooksIdentify the conversation thread so replies reach the same person

How we use Meta data

We use Meta Platform Data only to provide Auto Reply for the business that connected the Page or WhatsApp number: receive messages, generate or send approved replies, show the inbox to authorised workspace members, and maintain the connection. We do not use Messenger or WhatsApp content to train foundation models, build advertising profiles, or sell lists of contacts.

  • Permissions requested are limited to what messaging setup needs (for example pages messaging and related Page metadata).
  • Webhook payloads are signature-verified. Raw provider errors and access tokens are never shown in the inbox UI.
  • Businesses can disconnect a Page or WhatsApp channel in Auto Reply; disconnecting stops new inbound processing for that channel.
  • End customers who messaged a business can ask that business to delete their thread, or email Foundry support with enough detail to locate the conversation.

How we use data

Purposes and legal bases (where GDPR applies)

PurposeExamplesLegal basis
Provide the serviceRun pipelines, store projects, authenticate sessions, publish sites, operate Auto ReplyContract performance
Messaging on behalf of businessesReceive/send channel messages, hand off to humans, store approved factsContract performance (with the business); business’s lawful basis toward their customers
Security & abuse preventionDetect fraud, enforce rate limits, verify webhooks, investigate incidentsLegitimate interests
Product improvementFix bugs, measure feature usage, develop new capabilitiesLegitimate interests
CommunicationsAccount notices, support replies, early-access updatesContract / consent where required
Legal complianceRespond to lawful and Meta Platform deletion requests, maintain required recordsLegal obligation / contract

AI processing

Your prompts, project context, and Auto Reply customer messages (plus approved facts) may be sent to Google Gemini / Vertex AI and other model providers to generate outputs. We configure providers for API use and do not authorise them to train on your data through our production integrations. Auto Reply answers are constrained to approved project facts where the product enforces that rule.

Sharing & subprocessors

We share data with service providers that help us operate Foundry. They process data on our instructions and under appropriate agreements. Channel providers (Meta, Telegram, Viber) also process messages according to their own terms when you or your customers use those networks.

ProviderRoleData processed
ClerkAuthenticationAccount identifiers, session data
SupabaseDatabase & private media storageProjects, artifacts, Auto Reply conversations, attachments
Google Gemini / Vertex AIAI generation & Auto Reply composePrompts, project context, customer message text and approved facts
ExaWeb researchResearch queries derived from your project
InngestWorkflow orchestrationJob metadata, step payloads including messaging jobs
VercelHosting & deploymentSite assets, deployment logs, request hosting
E2BSandbox validationGenerated code for compile checks
Meta (Facebook / WhatsApp)Messaging channelsPage/WhatsApp connection data, message webhooks, send API traffic
Telegram / ViberMessaging channelsBot tokens, message webhooks, send API traffic when connected

We may disclose data if required by law, to protect rights and safety, or in connection with a merger or acquisition with notice where practicable.

Retention

  • Account data is kept while your account is active and for a reasonable period after deletion to handle disputes and backups.
  • Project artifacts remain until you delete the project or your account, subject to backup retention windows.
  • Auto Reply conversations, facts, and channel credentials remain until you delete the project, disconnect the channel, delete your account, or we complete a validated deletion request.
  • Inbound media is stored in a private bucket and removed with the related conversation or project where practicable.
  • Security and audit logs may be retained longer where needed for incident response.
  • Published customer sites remain available until you unpublish or delete the project.

International transfers

Our subprocessors may process data in the United States and other countries. Where required, we rely on appropriate safeguards such as Standard Contractual Clauses or equivalent mechanisms.

Your rights & data deletion

Depending on your location, you may have the right to access, correct, delete, restrict, or port your personal data, and to object to certain processing. Meta Platform Terms also require us to honour deletion of Platform Data when requested.

  • Foundry account or project deletion: email support@tryfoundry.app from the email on your account and tell us what to delete.
  • Business owners: disconnect Facebook, WhatsApp, Telegram, or Viber in Auto Reply settings to stop channel processing; delete the project to remove related conversations and facts.
  • People who authorised Foundry via Facebook Login: remove the app under Facebook → Settings & privacy → Settings → Apps and websites, then use Send Request so Meta calls our data-deletion callback. Status: /legal/data-deletion.
  • People who only messaged a connected Page or WhatsApp number: contact the business you messaged, or email Foundry support with the Page/business name, approximate time, and any message details you can share so we can locate and delete the thread.
  • We respond within 30 days where GDPR or similar laws apply, often sooner.
  • You may lodge a complaint with your local supervisory authority.
  • California residents may have additional rights under CCPA/CPRA; we do not sell or share personal information for cross-context behavioural advertising.

Meta App Dashboard URLs

Privacy Policy URL: https://www.tryfoundry.app/legal/privacy — Data Deletion Request callback: https://www.tryfoundry.app/api/meta/data-deletion — Human-readable instructions: https://www.tryfoundry.app/legal/data-deletion

Children

Foundry is not directed at children under 16. We do not knowingly collect personal data from children. Contact us if you believe a child has provided data and we will delete it.

Changes to this policy

We update this policy when our practices or legal requirements change. Material updates will be posted on this page with a revised “Last updated” date.

Related policies

Review the other legal documents that apply to your use of Foundry.

Need help?

Questions about privacy policy? Contact support@tryfoundry.app. For account access, include the email on your Foundry account.

Get started with Foundry