Privacy Policy
What ExitFounder collects, why, where it lives, who it is shared with and how to get it corrected or deleted.
1. Who we are
ExitFounder (https://www.exitfounder.io) is a database of internet businesses operated by the ExitFounder team. We are the data controller for the personal data described here. Contact: hello@exitfounder.io. This policy covers the website, the founder dashboard, the public API, the MCP server, the Telegram bot and email we send.
2. Public business data
Company profiles are built from information companies publish themselves (their websites, public listings) and from metrics providers (Domain Rating by Ahrefs, traffic estimates, PageSpeed). Founder names, roles, photos and social handles are included only when they appear on the company's own site or public profiles, or when the founder adds them. We process this professional, publicly available information on the basis of legitimate interest (a directory of businesses). Section 9 explains how to correct or remove it.
3. Account data and sign-in providers
You can create an account with an email magic link or by signing in with Google, GitHub, X (Twitter) or LinkedIn. From a sign-in provider we receive only what the provider returns for basic sign-in: your email address, your display name, your profile picture URL and the provider's user ID (for X: also your handle). We do not request access to your contacts, files, posts, calendar or any other scope.
We use this data to create and secure your account, to show your name and picture on your founder page and comments, to link your X or LinkedIn profile to your founder page when you choose to connect it, and to email you about your account (claims, verification, comments) — never for advertising. We store it in our database; we do not sell it and we do not share it with third parties except the sub-processors in section 7.
Google user data: our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. You can revoke access at any time at myaccount.google.com/permissions and disconnect providers from /dashboard/account.
- Stored: email, name, picture URL, provider ID and handle, the fields you fill in (username, bio), and your actions on the site (claims, upvotes, comments, saved startups, notification preferences, time zone).
- Not stored: provider access tokens beyond what the auth system needs for the sign-in itself; passwords (we do not use them).
4. Connected metrics providers
If you connect a payment or analytics provider (Stripe, Paddle, Lemon Squeezy, Google Analytics) to verify metrics, the credentials are stored encrypted in a private vault and used only to read the aggregate numbers shown on your profile (for example monthly recurring revenue). Raw provider payloads are never displayed or exported. You can disconnect at any time from the dashboard, which deletes the credential.
5. Telegram alerts and email
If you subscribe to the Telegram bot we store your Telegram chat ID, the account link (if you link one) and your alert preferences, and we send you the alerts you asked for. /stop pauses them; unlinking in Settings removes the link. Transactional email (magic links, claim decisions, comment notifications) is sent through Resend. You can turn optional notifications off in Settings.
6. Cookies and analytics
We use a first-party session cookie to keep you signed in and privacy-friendly, cookie-less analytics to count page views. We do not run advertising trackers or cross-site tracking. Details in the Cookie Policy.
7. Where data lives and sub-processors
The database is hosted on Supabase (PostgreSQL, EU/US regions) and the site on Vercel. Sub-processors, each used only for the purpose stated: Supabase (database, authentication), Vercel (hosting), Stripe (payments — we never see card numbers), Resend (email), Telegram (bot alerts), OpenAI (extraction of public website text; no account data is sent), Ahrefs, Google PageSpeed and our traffic-estimate provider (public metrics about websites, no personal data).
8. Sharing
Public profile content, upvote counts and comments are public by design and are available through the API, Markdown twins and to AI assistants with attribution. Account data (email, provider IDs, preferences) is never public and never sold. We share data with sub-processors only to run the service, and with authorities when legally required.
9. Your rights
You can export or delete your account from the dashboard, or email hello@exitfounder.io; deletion removes account data within 30 days (backups included). Founders can correct any field on a claimed profile. If you are named on a profile and want your name removed, email us from an address on the company domain or from the connected social account; we act within 7 days. EU/UK residents have the rights under GDPR/UK GDPR (access, rectification, erasure, restriction, portability, objection) and may complain to their supervisory authority; California residents have the corresponding CCPA rights. We do not discriminate for exercising them.
10. Retention
Account data is kept while the account exists and for 30 days after deletion in backups. Connected-provider credentials are deleted immediately on disconnect. Public business profiles are kept while the business exists publicly; removed profiles are deleted from the public schema and from feeds within 7 days. Server logs are kept for 30 days.
11. Children and security
The service is for people running or researching businesses and is not directed at children under 16; we delete accounts we learn belong to them. Data is encrypted in transit (TLS) and at rest; secrets live in a vault separate from the public database; access is limited to the people operating the service.
12. Changes and contact
We update this policy when the service changes; the date at the top is the last revision and material changes are emailed to account holders. Questions and requests: hello@exitfounder.io.