Privacy Policy of Foundermatcha

Latest update: 19 August 2026

This Application collects some Personal Data from its Users. Users may be subject to different protection standards, and broader standards may therefore apply to some. Users can contact the Owner to learn more about such standards. This document contains a section dedicated to Users in the European Union and their privacy rights. This document can be printed for reference by using the print command in the browser's settings.

Privacy Commitment (TL;DR)

At Foundermatcha, we care deeply about your privacy. Any personal details you provide, such as your email address, phone number, CV, or LinkedIn profile, will be used solely for validation and matchmaking purposes. We never sell this information, and we do not share it with third parties. There is one thing this short version used to leave out, so we have added it here: if you are a developer, a description of your background — without your name, your photo, your links or your contact details — can be shown to a prospective founder who has not created an account yet, as part of matchmaking. What that description contains, and what it never contains, is set out in full under What people without an account can see about you below. Your data is otherwise handled securely, stored only as long as necessary, and used to improve your experience on the platform.

Owner and Data Controller

If you have questions or concerns about this Privacy Policy, please contact us at:

Foundermatcha Ltd
44 Shroton Street
NW1 6UG, London, UK
Email: hello@foundermatcha.com

Types of Data collected

Among the types of Personal Data that this Application collects, either directly or through third parties, there are: Usage Data; first name; last name; email address; username; city; device information; session statistics; browser information; and payment information.

Complete details on each type of Personal Data collected are provided in the dedicated sections of this privacy policy or by specific explanation texts displayed prior to the Data collection. Personal Data may be freely provided by the User, or, in case of Usage Data, collected automatically when using this Application. Unless specified otherwise, all Data requested by this Application is mandatory, and failure to provide this Data may make it impossible for this Application to provide its services. In cases where this Application specifically states that some Data is not mandatory, Users are free not to communicate this Data without consequences to the availability or the functioning of the Service. Users who are uncertain about which Personal Data is mandatory are welcome to contact the Owner. Any use of Cookies — or of other tracking tools — by this Application or by the owners of third-party services used by this Application serves the purpose of providing the Service required by the User, in addition to any other purposes described in the present document and in the Cookie Policy. Users are responsible for any third-party Personal Data obtained, published or shared through this Application.

Mode and place of processing the Data

Methods of processing

The Owner takes appropriate security measures to prevent unauthorised access, disclosure, modification, or unauthorised destruction of the Data. Data processing is carried out using computers and/or IT-enabled tools, following organisational procedures and modes strictly related to the purposes indicated. In addition to the Owner, in some cases, the Data may be accessible to certain types of persons in charge, involved with the operation of this Application (administration, sales, marketing, legal, system administration) or external parties (such as third-party technical service providers, mail carriers, hosting providers, IT companies, communications agencies) appointed, if necessary, as Data Processors by the Owner. The updated list of these parties may be requested from the Owner at any time.

Place

The Data is processed at the Owner's operating offices and in any other places where the parties involved in the processing are located.

Retention time

Personal Data shall be processed and stored for as long as required by the purpose for which they have been collected.

The purposes of processing

The Data concerning the User is collected to allow the Owner to provide its Service, comply with its legal obligations, respond to enforcement requests, protect its rights and interests (or those of its Users or third parties), detect any malicious or fraudulent activity, as well as the following: Analytics, Hosting and backend infrastructure, Registration and authentication, and Handling payments.

Detailed information on the processing of Personal Data

Analytics

The services contained in this section enable the Owner to monitor and analyse web traffic and can be used to keep track of User behaviour.

Google Analytics (Universal Analytics) (Google LLC)
Google Analytics is a web analysis service provided by Google LLC. Google utilises the Data collected to track and examine usage, to prepare reports on its activities, and share them with other Google services. Google may use the Data collected to contextualise and personalise the ads of its own advertising network.
Personal Data processed: Tracker; Usage Data.

Handling payments

Payments for subscriptions or in-app purchases are handled through RevenueCat. This payment service integrates with the app stores (Apple App Store and Google Play Store) to securely process transactions. Foundermatcha itself does not store or process raw credit card or banking information; all such information is handled directly by the app stores and RevenueCat.

Hosting and backend infrastructure

Firebase Cloud Firestore (Google LLC) — Personal Data processed: Usage Data; various types of Data as specified in the privacy policy of the service. Place of processing: United States.

Firebase Cloud Functions (Google LLC) — Personal Data processed: Usage Data; various types of Data as specified in the privacy policy of the service. Place of processing: United States.

Firebase Hosting (Google LLC) — Personal Data processed: various types of Data as specified in the privacy policy of the service. Place of processing: United States.

Registration and authentication

Firebase Authentication (Google LLC) — Personal Data processed: email address; first name; last name; username. Place of processing: United Kingdom.

Cookie Policy

This Website does not use Trackers. For future reference, this policy includes it.

Further Information for Users in the European Union

This section applies to all Users in the European Union, in accordance with the General Data Protection Regulation (the “GDPR”), and supersedes any other potentially divergent or conflicting information contained in the privacy policy for such users.

Legal basis of processing

The Owner may process Personal Data relating to Users if one of the following applies: Users have given their consent for one or more specific purposes; provision of Data is necessary for the performance of an agreement with the User; processing is necessary for compliance with a legal obligation; processing is related to a task carried out in the public interest; or processing is necessary for legitimate interests pursued by the Owner or a third party.

Further information about retention time

Personal Data collected for purposes related to the performance of a contract shall be retained until such contract has been entirely performed. Personal Data collected for the Owner's legitimate interests shall be retained as long as needed to fulfil such purposes. The Owner may be allowed to retain Personal Data for an extended period whenever the User has given consent, as long as such consent is not withdrawn. Once the retention period expires, Personal Data shall be deleted.

The rights of Users based on the GDPR

Users may exercise certain rights regarding their Data processed by the Owner, including the right to: withdraw consent at any time; object to the processing of their Data; access their Data; verify and seek rectification; restrict processing; have their Personal Data deleted; receive their Data in a portable format; and lodge a complaint with a data protection authority.

How to exercise these rights

Any requests to exercise User rights can be directed to the Owner through the contact details provided in this document. Such requests are free of charge and will be answered as early as possible and always within one month.

Guest sessions (trying Foundermatcha without an account)

You can try Foundermatcha by having a short spoken conversation with our AI assistant without creating an account. These are called guest sessions, and they work differently from the rest of this policy in ways worth setting out plainly.

What we collect. We use your microphone so you can speak rather than type. What you say is converted to text, and we keep that text, not the audio. From the transcript, our AI builds a structured profile of what you are building or looking for — the same kind of profile a signed-up user completes through a form. We also record basic technical information about the session, such as how long it lasted.

Automated processing. The profile built from your conversation is used by automated systems to assess who you might be matched with. No decision with a legal or similarly significant effect is made about you automatically, and you can ask us to review anything we have inferred.

No account, and no identity. A guest session is stored against an anonymous session identifier issued by your browser. We do not ask for, and do not receive, your name, email address, phone number, CV or LinkedIn profile during a guest session. If you later choose to give us your email address or create an account, that is a separate and clearly-labelled step.

Deletion after 30 days. If you do not create an account, your guest session — the transcript and the profile derived from it — is deleted automatically 30 days after it began. You do not need to ask. If you would like it removed sooner, contact us at the address in Owner and Data Controller above; because guest sessions carry no identifying details, please write from the same browser session or include the session identifier shown to you.

If you do create an account, your guest session becomes part of that account and the rest of this policy applies to it from that point.

What people without an account can see about you (developers)

If you are a developer on Foundermatcha, an anonymous visitor who has never given us an email address can be shown a description of you — not your name and not your face, but enough of your background to be a real description — and can then ask our AI questions about you and get answers. You were told you would be matched with founders. You were not told this. That is why this section exists, and we would rather set it out plainly than have you discover it.

Why it exists. Founders will not create an account to see an empty room. So we let a visitor talk to our AI without signing up, and at the end we show them one real developer from the network — described, not identified — as evidence that there is somebody here worth meeting. That developer might be you.

What they are shown. A card containing all of, and only, the following: a short role label written by our AI from your profile (for example, expert web builder); a seniority level, as a single word rather than a job title; your years of experience as a number; how close you are to them, expressed only as a relation and never as a place (one of same city, same timezone, same country, or elsewhere); your availability; the shape of your compensation posture, such as equity heavy, with no numbers and nothing you said about money in your own words; a few sentences on why you fit what they described; one quoted sentence our AI writes about something that stands out in your background; and, where our AI judges it useful, one further sentence addressed to the visitor about what to expect from working with someone like you. Please read the paragraph below about those sentences, which are the part of this we are least able to guarantee — it applies to all three of the free-text items just listed.

What is withheld. Not shown, at all, to anyone without an account: your name, first or last; your photo; any employer as a named field; your CV, your dossier and your reference notes; every link, including LinkedIn; every contact route; and your account identifier. Your account identifier in particular is never sent to a visitor's browser at any point in the guest flow, including after they sign up, so they cannot look you up directly even if they inspect what their browser received.

They can also talk to our AI about you. The visitor is not just shown a card. Our AI speaks the description aloud and then answers follow-up questions about you, live, during their conversation. It is given the same short, redacted description and nothing else — not your name, not your profile, not your CV — and it is instructed to answer only from that description, to invent nothing, never to give or guess a name, and to refer to you as they. Asked directly who you are, it declines and says that names and photos live in the app. So a visitor can learn more by asking than by reading; what it cannot do is exceed that description, because it was never given anything more. Plainly: an AI is describing you, in conversation, to a stranger, without your name attached. We have made it structurally unable to name you. We have not made it silent about you, because being able to talk about you is the point of the feature.

How often, and to whom. Only developers are shown this way; founders on the platform are not previewed to anonymous visitors. You are eligible only while your profile is complete and you are marked available for matching. Each visitor sees exactly one person and cannot page through the network or ask for someone else. There is currently no cap on how many visitors one developer can be shown to — selection is driven by how well the profiles fit, so a strong general profile can be shown to many visitors. We are not going to describe this as rare, because today it is not.

After they create an account. The visitor becomes an ordinary Foundermatcha user and the normal rules apply: at that point they see your first name and your photo. Your surname, your email, your LinkedIn, your dossier and your contact routes remain inside the app under the same rules as for every other user. Worth knowing: the person they end up matched with is re-derived through our full matching pipeline at that moment, and may not be you. Nothing we show a visitor before they sign up promises them a specific person.

What we cannot fully guarantee, and are telling you anyway. The sentences about why you fit, the quoted sentence about what stands out in your background, and the sentence about what to expect from working with you are all free text written by an AI from your profile. Every other field on the card is a specific value we select and coarsen; that text is not, and it is the weakest point in this system. We automatically remove any reason that uses your own first name, and that check is exact. We cannot reliably remove an employer name, a city, or the name of a colleague or client from that text, because we have no list to check them against — so a reason can mention where you worked, or where you are, even though the location field beside it has been coarsened to same city. We have seen this happen. Our mitigation is an instruction to the AI that writes those sentences: do not name employers, places or other people. It reduces how often this happens. It does not prevent it. That is a soft guarantee, not a boundary, and we would rather say so than let you assume otherwise.

What is kept, and for how long. The visitor's conversation is stored against an anonymous session identifier, not a person, and it contains our AI's spoken description of you in its own words, because that description was part of the conversation. The structured card itself is not stored there. We separately keep a server-side record linking that anonymous session to your account, so that reloading the page shows the visitor the same person rather than a new one each time; that record is never sent to their browser. If the visitor does not create an account, all of it — their transcript, their profile, and the record linking them to you — is deleted 30 days after their session. If they do create an account, their conversation becomes part of it and the ordinary retention terms in this policy apply from that point.

Your rights, and what objecting gets you today. You can ask us what we hold about you, ask us to correct it, ask us to delete it, and object to this particular use of it. Contact details are in Owner and Data Controller above, and requests are answered within one month. We are telling you the mechanics rather than implying more than exists: there is currently no per-developer switch that removes you from these previews while leaving your normal matching untouched. If you object, a person will read it and respond, and the lever available today is turning off your availability for matching — which also stops us matching you with founders in the ordinary way. If enough people want the narrow version, we will build it.

Additional information

The User's Personal Data may be used for legal purposes by the Owner in Court or in the stages leading to possible legal action. The Owner reserves the right to modify this Privacy Policy at any time by notifying its Users on this page. It is strongly recommended to check this page often.

Definitions and legal references

  • Personal Data (or Data) — Any information that directly, indirectly, or in connection with other information allows for the identification of a natural person.
  • Usage Data — Information collected automatically through this Application, which can include IP addresses, URI addresses, time of request, browser features, and other parameters about the device.
  • User — The individual using this Application, who, unless otherwise specified, coincides with the Data Subject.
  • Data Controller (or Owner) — The natural or legal person which determines the purposes and means of the processing of Personal Data.
  • Data Processor — The natural or legal person which processes Personal Data on behalf of the Controller.
  • This Application — The means by which the Personal Data of the User is collected and processed.
  • Service — The service provided by this Application as described in the relevant terms.
  • European Union (or EU) — All current member states of the European Union and the European Economic Area.

This privacy policy relates solely to this Application, unless otherwise stated within this document.

See also our Terms & Conditions