Superfounder

Privacy

In effect from 5 October 2026

What this service stores, why it stores it, who can see it, and how to get it back or remove it. It describes the software as it actually runs today.

This service is operated by Superfounder. Questions about this document, or about your data, go to Josh@optivise.org.

What is collected

Your email address, because it is how you sign in. There is no password; signing in sends a link to that address.

A username, which you choose and which is shown publicly beside the founders you launch.

Anything you write: a founder's name, handle, tagline, mission, personality and context; a project's name, description, brief, type, status and any repository or deployment links you supply; and the build updates you post.

Images you upload as a founder's avatar or a project's cover. These are re-encoded on the server, which strips embedded metadata such as location, and stored in the database.

A record of actions taken on your founders and projects: created, status changed, details edited, update posted. This is the build log, and it is public.

Technical records needed to run the service: a session identifier in a cookie, a hash of each sign-in link, and counters used for rate limiting that are keyed on the requesting network address.

What is public

A founder is private while it is a draft. Launching it makes it public, permanently addressable at its handle, and visible to anyone, signed in or not.

Once a founder is launched, its projects are public from the moment they are created, including projects that are paused, failed or archived. That is the point of the product and it is not reversible for an individual project.

Your username appears on the founders you launch. Your email address does not, and is never returned by any public endpoint.

Public pages are intended to be indexed by search engines and shared. Assume anything you publish can be copied, cached or archived by third parties beyond this service's control.

Why it is stored

To operate the service: to sign you in, to show you your own drafts, to publish what you choose to publish, and to attribute it to you.

To keep the service usable: rate limiting exists so that a single sender cannot flood the sign-in mail or the creation endpoints.

There is no other purpose. Your data is not sold, and it is not used to build an advertising profile.

Who else sees it

An email provider sends the sign-in link. It necessarily receives your email address and the link itself in order to deliver it.

The hosting provider and the database provider process whatever the service stores, as part of running it.

Nothing else. There is no analytics service, no advertising network, no third-party tracking script, and no social embed on any page. The site loads no external scripts at all.

Automated processing

No text or image model is connected to this service. Nothing you write is sent to a model, used to train one, or processed by one, because there is no such integration in the running code.

If that ever changes, it will be stated on the page where it happens and this document will be updated before it does.

No decision about you is made automatically.

Payments and wallets

There are none. No payment is taken, no wallet is created or connected, no token exists, and nothing touches a blockchain. No financial information is collected because there is nothing to collect it for.

How long it is kept

Sign-in links expire twenty minutes after they are issued and can be used once. Expired and used ones are deleted automatically.

Sessions expire after thirty days, and expired sessions are deleted automatically.

Everything else is kept until you delete it. Deleting your account removes it, as described below.

Getting your data, and removing it

You can export everything associated with your account as JSON, at any time, from your account page. The export contains your profile, your founders, their projects, the updates and the activity log. It does not contain security internals such as session identifiers or sign-in token hashes.

You can delete your account from the same page. Deletion removes your account, your sessions, every founder you launched, every project belonging to them, every update and every log entry, and the images you uploaded. Public pages for that content stop existing: the URLs return a not-found response.

Deletion is immediate and cannot be undone, and it is asked for explicitly rather than inferred from a single click.

What deletion cannot reach is anything already copied elsewhere: a search engine's cache, an archive, or somebody's screenshot. Publishing is public, and that part is outside this service's control.

For anything not covered by those two buttons, contact Josh@optivise.org.

Security

Sign-in links are stored only as a hash, so reading the database does not yield a usable login. Sessions are long random identifiers held in an httpOnly cookie, marked Secure in production.

Every change to a founder or a project re-checks ownership on the server. The interface hiding a control is a convenience and is never what enforces it.

A draft answers as not-found rather than forbidden to anyone who does not own it, so the service does not confirm that somebody else's unpublished work exists.

No system is perfectly secure, and nothing here is a guarantee against a breach.

Changes

If this document changes materially, the date at the top changes with it. That date is set by hand when the wording changes rather than generated, so it means something.

Privacy · Superfounder