Privacy Policy
Effective September 28, 2026
This Privacy Policy explains what information Velofound ("we," "us") collects, how we use it, and the choices you have. By using Velofound, you agree to the practices described here.
1. Information we collect
We collect:
- Account information — your email address, used for passwordless sign-in (we don't store a password).
- Business information you provide — anything you enter about your business (descriptions, goals, pricing, hiring plans, and similar) so the Service can generate content for you.
- Financial information you enter or import — revenue and orders, costs, and your cash-on-hand balance, used for the money tools, runway, and reporting. If you connect a bank through Plaid (section 5), this also includes the balances and transactions of the accounts you choose to connect.
- Content you upload — documents or files you add to your project.
- Information about other people that you bring in — contacts and leads you research or import, customers who order through your generated site, and the email your business receives. See section 6 — this is the part of the Service where you are handling someone else's personal information through us.
- Usage data — basic technical data like device/browser type and how you interact with the Service, to keep it running and improve it.
2. How we use your information
We use your information to:
- Provide and operate the Service, including generating your Outputs;
- Maintain your account and remember your projects and settings;
- Communicate with you about your account or the Service;
- Improve and troubleshoot the Service.
3. AI processing
To generate Outputs, the business information you enter is sent to third-party AI providers for processing — Anthropic for text and planning, and OpenAI and Replicate for generated images, voiceover audio, and video. We don't sell this information, and we only send what's needed to produce the Output you asked for.
4. Where your data is stored, and how we protect it
Your account data, business information, and uploaded files are stored with Supabase, our database and storage provider, and the app runs on Vercel. The controls we use include:
- Encryption in transit (HTTPS) between you and the Service, and on to our providers;
- Per-account authentication, so a request has to be signed in as you to act as you;
- Row-level security policies on database tables, which are how we scope rows to the account that owns them;
- Server-side keys that stay on the server — never shipped to the browser — and are used for the specific jobs that need more access than a signed-in user has.
These are measures, not a guarantee. We can't promise that no bug, misconfiguration, or gap in how these controls are applied will ever expose data, and we'd rather say that plainly than imply a level of protection we can't verify for you. If we find out your data was exposed, we'll tell you.
One specific thing worth knowing: documents you upload go to private storage that needs a signed, expiring link to read. But generated media — logos, images, and video for your site and marketing — is stored in a public bucket, because your site has to be able to embed it on a plain URL. Anyone holding one of those URLs can open the file without signing in.
4a. Cookies and similar technologies
Essential — always on. Your sign-in session (Supabase auth cookies), your language choice, which project you have open, and your cookie choice itself. Without these the app doesn't work.
Analytics — Vercel Web Analytics records page views by path, referrer, UTM tag and device type. It doesn't use cookies or identify you across sites.
Advertising measurement — the Meta pixel tells us whether an ad on Facebook or Instagram brought you here, so we know which ads work. It sets Meta's cookies and sends Meta the pages you view on velofound.com and events like starting a project. Meta's use of that data is governed by its own privacy policy.
Your choice. If you are in the EU, UK or Switzerland, analytics and advertising measurement stay off until you accept them. Everywhere else they are on unless you choose “Essentials only”. Change your mind any time with the Cookie settings link in the footer. Neither runs on the websites we publish for your business — those pages carry only what you put on them.
5. Third-party service providers
Operating Velofound means handing parts of the job to other companies. Here is the full list, what each one receives, and why:
- Supabase — our database, authentication, and file storage. Holds your account, your projects, and everything you upload.
- Vercel — hosts and serves the app. Receives request data such as IP address and browser type.
- Anthropic — receives the business information needed to generate text Outputs, plans, and analysis.
- OpenAI — receives image prompts and script text to generate images, logo concepts, and voiceover audio.
- Replicate — receives video prompts to generate short marketing video clips.
- Stripe — payments. Handles your subscription to us, and (through Stripe Connect) payments your own customers make to your business. Card details go to Stripe directly; we never see or store them.
- Plaid — bank connections. If you choose to connect a bank account, you do so through Plaid Link, which shows you Plaid's own consent screen. Plaid then shares your account balances and transactions with us so we can show you your cash, burn, and runway. We request only the balance and transactions products, never your bank login (Plaid holds that, not us), and we do not sell or share this data with anyone else. You can disconnect a bank at any time from the Money page, which removes the connection at Plaid and deletes the bank data we hold. Plaid's use of your information is governed by the Plaid End User Privacy Policy.
- Resend — email delivery. Sends your sign-in links and account email, email your business sends, and receives email sent to your business address.
- Hunter.io — contact lookup for outreach. Receives the company domains and names you research so it can return business contact details.
- Google — Places API receives your local-business search terms to return real nearby businesses as leads; Google Fonts serves typefaces on generated sites, which means it sees your site visitors' requests.
- Meta — advertising. If you connect an ad account, receives the campaign, audience, and creative data needed to create and read campaigns.
- X (Twitter) — social posting. If you connect an X account, receives the posts and media you publish through us.
- Pexels — stock photography. Receives image search terms.
- Calendly — booking. If you add a scheduler, Calendly's script loads on your booking page and handles what visitors enter to book with you.
Some of these only come into play if you switch the feature on or connect the account. We don't sell your personal information to third parties, and we don't use your data to train AI models beyond what these providers do to deliver the Service itself.
6. Two flows we want to be explicit about
First Look goes to a person. When you send a project through First Look, you are asking a human being to read it, and that is exactly what happens. We take a snapshot of your project at that moment — including settled revenue, whether your costs are imported, your cash-on-hand and the runway computed from it, visitor and paying-customer counts — and email it, along with your free-text note, your name, and your email address, to our reviewers. It is a real email to a real inbox, sent so they can reply to you directly. Only send what you're comfortable having a person read.
Your business inbox stores the email itself. Each project can have its own address on our sending domain. When someone writes to it, we don't just log that a message arrived — we store its contents: the sender's name and email address, the subject, and the full message body and any attachments, so you can read and answer it from your dashboard. That means personal information about your customers and leads, written by them, sits in our database. You're the one who decides to use that address and who to hand it out to.
7. Deleting your account and your data
You can view and update your account information from your account settings at any time, and you can permanently delete your account from the same page.
Here's what deletion actually does. Deleting your account deletes your sign-in record, and almost every table in our database is tied to it in a way that cascades — so your projects, plans, documents records, metrics, inbox messages, and the rest of your rows go with it.
What it does not currently reach is files in storage. Uploaded documents, logos, and generated site and marketing assets are not covered by that cascade, so those files are left behind — and because generated media lives in a public bucket (see section 4), anything already published on a plain URL may remain reachable after your account is gone. If you want those files removed too, email us at hello@velofound.com and we'll delete them by hand. Backup copies may also persist briefly before being purged in the normal course of our data retention practices.
8. Your privacy rights
Velofound is available in many languages and we have users in the EU, the UK, and California, so these rights are worth stating plainly.
If you're in the EU or UK, you have the right to access the personal data we hold about you, to have it corrected, to have it deleted, to receive a copy in a portable form, to object to or ask us to restrict certain processing, and to withdraw consent where our processing relies on it. You can also complain to your local data protection authority. For your own account data we are the controller.
If you're in California, you have the right to know what personal information we collect and why, to request deletion or correction, and to opt out of the sale or sharing of personal information. We don't sell personal information. The Meta advertising pixel described in section 4a may count as “sharing” under California law; to opt out, choose “Essentials only” in Cookie settings (footer), which turns it off. We won't discriminate against you for exercising any of these rights.
About the data you upload concerning other people. For the contacts, leads, customers, and inbound email you bring into Velofound (section 6), the roles flip: you are the controller of that information and we act as your processor. We handle it to provide the Service to you, on your instructions. You're responsible for having a lawful basis for collecting and using it, and for answering requests from those people. If one of them contacts us directly, we'll point them to you and help you respond.
To make any of these requests, email hello@velofound.com. We may need to confirm you control the account's email address before we act, and we aim to respond within one month.
8a. Students and schools
When a college or university uses Velofound in a course, we act as a “school official” under the Family Educational Rights and Privacy Act (FERPA): we use student information only to provide the course tools the school asked for, under the school's direction, and never for anything else.
Specifically: we don't sell student information, share it with advertisers, or use it to build advertising profiles. The Meta advertising pixel described in section 4a never runs for students or instructors, or on any class page. We don't use student work to train AI models, and under their API terms our AI providers don't train on it either. Instructors see the work of students in their own course and nobody else's.
When a school's license ends, students keep their own account and work unless they delete it. A school can ask us to delete the accounts and records of its students at any time; we'll do it within 30 days and confirm in writing. We'll tell a school within 72 hours of learning of a breach affecting its students' information. We sign schools' data privacy agreements on request — email us at the address in section 11.
9. Children's privacy
Velofound is not directed at children under 16, and we don't knowingly collect information from them. If you believe a child has provided us information, contact us and we'll remove it.
10. Changes to this policy
We may update this Privacy Policy from time to time. If we make material changes, we'll make reasonable efforts to let you know. Continuing to use the Service after changes take effect means you accept the updated policy.
11. Contact
The data controller is Velofound, Inc. Questions about this policy or your data? Reach us at hello@velofound.com.