Privacy Policy
Effective
LightHouse Foundry ("Foundry", "we", "us") is operated by LightHouse Foundry, Inc., a Florida corporation at 4000 N Ocean Drive #402, Riviera Beach, FL 33404. This policy says what we collect, why, who sees it, how long we keep it, and how you get it back or get it deleted. We wrote it to be read, not skimmed. If anything here is unclear, write to privacy@lighthousefoundry.ai and a person will answer.
1. What Foundry is
Foundry is a coaching product for founders. You describe a business idea; the Coach, an AI, works through it with you and writes it up as a venture model; a separate Judge scores the work against evidence. Later stages build and host an application for that venture. Everything below follows from that: the data we hold is mostly the words you give the Coach and the record it writes for you.
2. What we collect, and where it comes from
If you join the waitlist before we open. We keep your e-mail address, the idea you typed if you chose to type one, the day you signed up, and — only if you chose to tell us — your name, your business and its website, what you have built, what you do, and how serious you said you are. We also keep the moment you accepted this notice. That is all, and every one of these is kept, deleted and exported under the same rules.
When you create an account. You sign in through one of these: Google, GitHub, LinkedIn, X, Facebook Login, or a link we e-mail you. From the provider we take only what identifies you: your name, your e-mail address, the provider's identifier for you, and a profile picture if the provider offers one. We ask for no write access to any of these accounts. Our GitHub app requests only read:user and user:email. If a provider does not give us a verified e-mail address, we ask you to confirm one before the account can be linked to anything.
What you tell the Coach. Every message you send the Coach, every answer you confirm or correct, and every file the Coach writes for you (the venture model, its history, briefs, score reports, the evidence you log) is stored as your venture's record. That record is yours; see section 7.
Code you import. If you point Foundry at an existing codebase, we read it to draft a starting venture model. We show you the pledge below before we read a byte, and you acknowledge it once per venture:
We read your code to lay out a starting venture model — a first draft of the business you have already built. Every line we infer is marked as a guess, for you to confirm or correct. Your code stays where it is; nothing is moved or changed.
We won't share your code with anyone. We won't copy it into our products. We won't compete with your idea.
When we rebuild your app on Foundry, we may use our own pre-built parts. Those parts stay ours, and we may use them for other founders. Your code is never one of them.
Billing. When you subscribe or buy credits, our payment processor (Stripe) handles your card. We never see or store your card number. We keep the record of what you bought, when, and for how much, and the receipts.
How you use the product. For each Coach turn we record when it happened, which venture it belonged to, how many credits it used, and technical measures of the AI work behind it (tokens, model, cost). We use this to meter your credits honestly, to refund turns that fail on our side, and to run the service. We also keep ordinary server logs: your IP address, browser, and the pages you load.
Cookies. We set only the cookies needed to keep you signed in and to remember which venture and stage you have open. We run no third-party analytics and set no advertising cookies.
3. How we use it
- To run the product: keep you signed in, hold your venture's record, generate the Coach's replies, score your work, meter credits, take payment, send receipts.
- To contact you about your account: a receipt, a security notice, an answer to something you asked.
- To send the one waitlist e-mail when Foundry opens (section 5).
- To improve the product using aggregate measures of how it is used. We do not read your venture's content to do this.
- To meet a legal duty when one applies to us.
We do not sell your information. We do not run advertising. We will not send you a newsletter or marketing sequence you did not ask for.
4. The AI behind the Coach, and where your words go
The Coach's replies are generated by third-party AI models. When you send the Coach a message, that message and the parts of your venture record it needs are sent to the model provider to produce the reply. Today that provider is Anthropic, reached through Vercel's AI Gateway. They process your content only to generate the response. Anthropic's commercial terms state that it may not train models on customer content, and it retains API inputs and outputs for up to 30 days for safety monitoring before deleting them.
The Coach also runs web searches on your behalf during intake and research steps; the search terms it sends are drawn from your conversation.
We will name any change of AI provider here before it takes effect.
5. Google user data
If you sign in with Google, we receive your name, e-mail address, Google account identifier, and profile picture. We use them only to create and identify your Foundry account and to show you who you are signed in as. We do not request access to your Gmail, Drive, Calendar, Contacts, or any other Google data. We do not share Google user data with anyone except the service providers in section 6 who host our product, and never for advertising. You can disconnect Google from your Foundry account at any time, and deleting your Foundry account deletes the Google data we hold.
6. Who else sees your data
Only the companies that run the product for us, each under a contract that limits them to that job:
| Provider | What they do for us | Where |
|---|---|---|
| Vercel | Hosts the application, runs the Coach's sandboxes, and routes AI requests | United States |
| Supabase | Stores accounts, venture records, and files | United States |
| Anthropic | Generates the Coach's and the Judge's responses (section 4) | United States |
| Stripe | Takes payment | United States |
| Resend | Sends transactional e-mail: sign-in links, receipts, the waitlist notice | United States |
| Google, GitHub, LinkedIn, X, Meta | Sign-in only, when you choose that provider | per provider |
Beyond that we share data only when the law requires it, to protect someone's safety, or if Foundry itself changes hands, in which case this policy travels with your data and you are told.
A few of us at LightHouse Foundry can see the waitlist and, when you ask for help, your account and venture record, because someone has to answer you. No one outside the company can.
7. Your venture is yours
The venture record Foundry writes for you belongs to you. You can export all of it at any time as a complete copy including its history, and you can download any file in it whenever you want, without asking us and without the rest of the product needing to be working. If you leave, hosting of anything we built for you ends with your subscription, and you take your source code and a copy of its database with you.
8. How long we keep things
Waitlist. If you never sign in, we delete your e-mail and your idea 90 days after the one e-mail we send when Foundry opens, and within a year of the day you signed up either way, whether or not we have opened by then. You do not have to wait for us to get out: write to privacy@lighthousefoundry.ai and we delete them, and the e-mail we send carries a link that does the same.
Account and venture data. For as long as your account is open. When you close it, or ask us to delete it, we delete your account and venture record within 30 days, except records we must keep for tax or legal reasons (payment records) and backups, which age out on their own schedule.
Usage logs. Server logs for 90 days. Credit and billing records for as long as tax law requires.
9. Your rights
Wherever you live, you can ask us to show you what we hold about you, correct it, export it, or delete it, and you can object to how we use it. If you are in the European Economic Area, the United Kingdom, or Switzerland, these are your rights under the GDPR and you may also complain to your data protection authority. If you are in California, you have the same rights under the CCPA, and we do not sell or share personal information for cross-context advertising. Write to privacy@lighthousefoundry.ai. We answer within 30 days and we do not treat you differently for asking.
10. Security
Data is encrypted in transit and at rest. Each founder's venture is isolated from every other founder's at the database level. Access inside the company is limited to the people who need it to run the service, and every access path a program uses is scoped to one venture at a time. No system is perfect; if a breach affects you we will tell you promptly and say what happened.
11. Where data lives
Our providers run in the United States. If you use Foundry from elsewhere, your data is transferred to and processed there. For transfers from the EEA, UK, and Switzerland we rely on the standard contractual clauses in our providers' agreements.
12. Age
Foundry is a business tool for adults. You must be 18 or older to use it. We do not knowingly collect data from anyone under 18; if we learn we have, we delete it.
13. Changes
If we change this policy in a way that affects you, we will say so in the product and by e-mail before it takes effect, and the date at the top will move. Earlier versions stay available on request.
14. Contact
privacy@lighthousefoundry.ai LightHouse Foundry, Inc., 4000 N Ocean Drive #402, Riviera Beach, FL 33404