Privacy Policy
Last updated: August 28, 2026
Overview
Foundation ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, and safeguard your information when you use our product requirements and technical design platform.
Information We Collect
Account Information
When you create an account, we collect:
- Your name (provided via our authentication provider)
- Organization name (if applicable)
We use Clerk for authentication. Your authentication credentials are managed securely by Clerk and we do not store your password.
Usage Data
We collect browser product analytics and server-side usage events ONLY with your analytics consent — both are disabled until you opt in, and the choice applies to your whole account. When granted, product analytics are pseudonymous (tied to your user ID) and include page URLs and error descriptions in failure reports:
- Feature usage and interactions
- Performance metrics
- Error reports
Audit logs, billing records, and security logs are separate and unaffected by your analytics consent choice.
Content You Create
We store the PRDs, TDDs, and other documents you create within the platform. This content belongs to you and your organization.
How We Use Your Information
We use your information to:
- Provide and maintain the Foundation service
- Identify you within your organization
- Improve our product based on usage patterns
- Communicate important updates about the service
- Provide customer support
AI Features & Data Processing
Foundation uses AI to assist with document creation. Here's how we handle your data when using AI features:
Zero Data Retention (ZDR)
For Foundation-managed AI features, we route LLM requests through OpenRouter only to providers and models with Zero Data Retention. This means:
- Your prompts and document content are not used to train any models
- Your data is not stored by the AI provider after processing your request
- AI interactions are processed in real-time and not retained by the LLM provider
If your organization configures a Bring Your Own Key (BYOK) provider, its data handling is governed by that provider's terms and privacy policy.
What We Store
For our service to function, we do store:
- Your final documents (PRDs, TDDs) that you save
- Token usage metrics for billing purposes (counts only, not content)
What We Do Not Store
We do not store the content of prompts sent to AI providers. We retain prompt-template metadata (which template and version was used) and a one-way hash that correlates a generation to its prompt render; neither contains customer content. Generated content is stored when you save it as part of your documents, and temporary AI-task payloads are scrubbed on a 30/90-day retention cycle. We do not operationally log raw AI outputs.
- Draft content that you discard
AI Quality & Outcomes Analytics
Our AI Quality & Outcomes dashboard is metadata-only. Internal analytics retain limited user and document identifiers plus provenance to enforce tenant isolation and authorization, correlate lifecycle events, and produce aggregates. Analytics do not retain raw prompts; generated, document, or retrieved content; content-derived hashes or diffs; raw provider payloads; or raw failure messages.
This is currently a section-generation pilot for PRD and TDD preview workflows. Provider usage is shown when providers report it; incomplete or unavailable usage is identified as coverage rather than counted as zero. Other AI calls may contribute spend-only usage without fabricated lineage or outcomes.
We do not perform content analytics. Any future analytics use of content requires a separate, explicit opt-in.
Third-Party Services
We use the following third-party services:
- Clerk — Authentication and user management
- PostHog — Product analytics, only after you grant analytics consent (see Usage Data above)
- OpenRouter — Routes Foundation-managed LLM requests only to Zero Data Retention providers and models (see above)
- OpenAI — Embeddings only, with Zero Data Retention (see above)
- Stripe — Payment processing (we do not store your payment details)
- Render — Hosting and application infrastructure
- Resend — Transactional email delivery
- Better Stack — Operational logging and monitoring
- Customer-configured integrations (GitHub, Linear, Notion, and Bring Your Own Key AI providers) — connected at your discretion; their data handling is governed by each provider's terms and privacy policy
Each service has its own privacy policy governing how they handle data. We require appropriate data processing terms from our vendors.
Data Security
We implement industry-standard security measures to protect your data, including encryption in transit and at rest. However, no method of transmission over the Internet is 100% secure, and we cannot guarantee absolute security.
Data Retention
We retain your account information and content for as long as your account is active. When an organization owner deletes an organization, access is deactivated and a reactivation deadline is recorded. Permanent deletion of organization data is completed by our privacy team on request — contact about@foundationworks.io.
Your Rights
You have the right to:
- Access your personal data
- Correct inaccurate data
- Delete your account and associated data
- Export your documents
- Opt out of non-essential communications
Cookies
We use essential cookies to maintain your session and preferences. A functional localStorage entry stores your analytics consent choice. Analytics cookies load only after you grant consent.
You can control cookie preferences through your browser settings.
Children's Privacy
Foundation is not intended for use by children under 16. We do not knowingly collect personal information from children under 16.
Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new policy on this page and updating the "Last updated" date.
Contact Us
If you have questions about this Privacy Policy, our data practices, or wish to request deletion of your data, please contact us at about@foundationworks.io