Foundable

Cookie & Tracking Notice

Effective and last updated: August 15, 2026

Foundable uses necessary storage, signed-in support functionality, first-party analytics, automatic session replay on every normal Foundable application page, and optional server-side advertising-platform conversion measurement. We do not place browser advertising pixels, and no optional provider conversion is sent until you explicitly opt in.

What this page covers

This Notice explains the cookies, local storage, session storage, and similar technologies (collectively, "cookies") used on foundable.com and within the Foundable product, and how you can control them. It supplements our Privacy Policy.

Strictly necessary (always on)

These keep the product working. You can't turn them off without breaking login and security.

  • Supabase auth session (e.g. sb-*-auth-token). Keeps you logged in. The browser auth client sets it for up to 400 days and refreshes that lifetime when it saves a refreshed session, with SameSite=Lax and Secure on HTTPS. The browser auth client reads this cookie to maintain and refresh your session.
  • Onboarding-finished flag (localStorage) — remembers that you've completed onboarding so we don't re-show the welcome banner.
  • Authentication confirmation state (cookie). This is a bounded, HttpOnly, Secure, SameSite=Strict value used during supported confirmation flows.
  • Investor-room access (cookie, when used). This is a seven-day HttpOnly, Secure, SameSite=Lax session for the protected investor-room route.

Functional (always on)

These remember your preferences and, when enabled, keep the signed-in human-support Messenger working. They don't track you across the web.

  • Theme preference (light / dark) — localStorage.
  • Advertising-measurement choice (localStorage, when you make a choice) — remembers your current opt-in or refusal and a random browser capability used only to update that choice. The raw capability remains in your browser and is sent only to Foundable's first-party consent endpoint when recording or updating the choice. That endpoint immediately derives its SHA-256 hash; durable server records and analytics receive only the hash. An opt-in expires after 180 days.
  • Ad-source handoff (sessionStorage, current tab only) — for up to 30 minutes, remembers the exact bounded campaign tags and applicable provider click identifier from an eligible public ad landing so a consent choice can be associated with the same provider. Re-reading the same landing does not extend that window. It never stores idea text, prompts, email, or arbitrary query parameters, and it does not itself send data to an advertising provider. GPC or DNT prevents this handoff from being stored or read.
  • Product state: may include the active foundable or thread, unsent chat drafts, navigation and policy handoffs, command-palette recents, dismissed prompts, builder state, layout choices, and recent-item preferences. Some keys include an operator or foundable identifier and remain until cleared or replaced.
  • Intercom Messenger identifier (intercom-id-[app_id], first-party cookie, when signed-in support is enabled): a unique Messenger identifier. Intercom's Product Privacy Notice lists a nine-month default duration. Foundable clears Intercom browser state during logout and detected session-loss flows.
  • Intercom Messenger session (intercom-session-[app_id], first-party cookie, when signed-in support is enabled): connects the current browser session to your prior support conversations. Intercom's default is one week; Foundable configures a one-hour Messenger session duration and clears it during logout and detected session-loss flows.
  • Intercom Messenger device identifier (intercom-device-id-[app_id], first-party cookie, when signed-in support is enabled): identifies a device that interacts with Messenger to help prevent abuse. Its default duration is 270 days and a successful Messenger ping can refresh it for another 270 days. Foundable clears Intercom browser state during logout and detected session-loss flows.
  • Intercom Messenger cached state (intercom.intercom-state-[app_id], first-party browser storage, when signed-in support is enabled): caches Messenger application and visitor data between page transitions. Intercom lists this storage as perpetual; Foundable clears it during logout and detected session-loss flows.

Foundable boots Messenger only after authenticating a signed-in operator. It is not booted for signed-out visitors or the public contact page, and Foundable does not use it for advertising, marketing, tours, standalone or proactive surveys, or proactive messages.

Analytics & error tracking

We use product and server-side telemetry to understand how the Service is used and to fix bugs. Server-side Foundable Ads conversion measurement, when you approve that feature for a campaign, is described in our Privacy Policy. We also use first-party PostHog data to measure our own marketing: when you arrive through a link carrying campaign tags (such as utm_source), the tags and first-party analytics identifiers help us understand which campaigns work. This first-party attribution is independent from the optional advertising-platform measurement described below. Global Privacy Control and Do Not Track apply only to that optional provider measurement; they do not disable first-party PostHog analytics or replay.

  • PostHog: product analytics, feature flags, and automatic session replay used to diagnose operational issues and improve product flows: how people move through public pages, Build, Grow, and Earn, and where they get stuck. Sets first-party analytics cookies served through our own domain. Campaign fields use a bounded allowlist, rendered text and element attributes are masked for analytics events, and URL query strings and fragments are removed before those events leave your browser. That analytics-event masking is separate from replay. Replay runs on every normal Foundable application page for anonymous visitors and authenticated operators in all countries and on supported mobile and desktop browsers. Short-lived authentication or redirect bridge documents and static or download assets are not application pages and are not recorded. Replay reconstructs page layout and interactions. Ordinary visible interface text, ordinary form values, unsent drafts, submitted chat messages, and Ted's replies may be recorded as displayed or entered. Passwords, one-time authentication codes, payment-card values, explicit secret or API-key fields, hidden input values, and file input values are masked or omitted. Recorded page and network URLs are sanitized to strip query strings, fragments, credentials, and variable path identifiers; all request and response header and body contents are omitted. Replay recordings expire after 30 days. Global Privacy Control and Do Not Track do not disable this first-party PostHog collection.
  • Sentry: error tracking. Captures stack traces, request URLs, and a session identifier; session replay is disabled. We redact authorization/cookie headers and a defined list of sensitive body keys (passwords, tokens, secrets, API keys) before events leave our server; stack-trace context can still incidentally include other Customer Content.
  • Better Stack: server-side uptime monitoring. Does not run code in your browser.

Optional advertising-platform measurement

We do not place Meta, Google Ads, TikTok, or X browser advertising pixels, and we do not share page visits with those providers through browser tags. Foundable may use bounded server-side conversion measurement only for the ad provider that sent the visit, including Google Ads measurement for YouTube campaigns. No provider conversion is sent from our server without an explicit, current opt-in on foundable.com. Refusing or withdrawing that choice prevents future provider sends. Global Privacy Control or Do Not Track forces all of this optional provider measurement off even if a grant was saved previously. Removing one of those browser signals does not turn measurement on; you must opt in again.

When enabled, Foundable sends only these categories:

  • Applicable advertising click identifiers captured from the ad link, when present: gclid, wbraid, and/or gbraid for Google Ads; fbclid together with the first-party time when the ad landing was observed is used to derive a Meta click identifier; ttclid is used for TikTok; or twclid is used for X. Meta, TikTok, and X also receive the fixed event-source URL https://foundable.com/, with no path, query, or fragment; it does not reveal which page the visitor viewed. Foundable does not add the visitor's IP address, browser user agent, email, phone, actual page URL, referrer, or provider browser cookie to these server conversion payloads.
  • A conversion event name, event time, and provider-scoped pseudonymous stable event identifier used for safe retry and deduplication. Event names can include a successful refund or payment reversal as a distinct refund event; it is never labeled as a purchase.
  • Payment value and currency only when Foundable sends an event for an actual successful payment. Signup, subscription-created, and refund events do not include payment value.

We do not send your idea text, private prompts, Customer Content, or full payment-method details through this advertising measurement. Advertising providers process the measurement data under their own privacy terms and may use their identifiers to attribute conversions, deduplicate events, report performance, and optimize ad delivery.

This provider measurement does not replace our independent first-party PostHog attribution. Granting, refusing, or withdrawing the provider measurement choice does not turn first-party PostHog attribution on or off. Global Privacy Control and Do Not Track apply to the optional provider measurement, not first-party PostHog analytics, replay, or attribution. We keep platform-reported, first-party, and Stripe-reconciled attribution as separate views and never sum or blend them. Stripe-reconciled records remain the source of truth for money.

Your choices

  • Browser settings: you can block or delete cookies in your browser. Blocking or deleting authentication cookies signs you out, prevents session persistence, and may stop protected product features from working.
  • Advertising measurement choice: you can use the cookie choices on foundable.com to grant or withdraw permission at any time. Withdrawal applies to future server-side provider sends; data already delivered to a provider remains subject to that provider's retention rules and your applicable privacy rights.
  • Do Not Track / Global Privacy Control — optional advertising-platform measurement is forced off, and either signal overrides any saved opt-in. These signals do not disable first-party PostHog analytics, replay, or attribution. Bounded server-side operational events and error monitoring can also still occur.
  • Account deletion — deletes or de-identifies account content after the grace period, while limited billing, consent, security, fraud-prevention, and legally required records may be retained as described in our Privacy Policy for the full retention schedule.

Updates

We'll update this Notice when we change the cookies we use. The date at the top reflects the most recent revision. For material additions (e.g. a new analytics or marketing tool), we'll provide notice and obtain a fresh explicit opt-in before new optional provider measurement begins.

Questions about this document? privacy@foundable.com

Postal: Autono Labs, Inc. (operator of Foundable), 131 Continental Drive, Suite 305, Newark, DE 19713, USA. See /legal for our full set of policies.

Continue to footer navigation