Privacy policy
Last updated 2 July 2026
This policy explains how we handle personal data under the EU General Data Protection Regulation (GDPR). The data controller is the entity named in our imprint.
What we collect
We collect personal data only where there is a clear purpose:
- Email address — to send your roadmap, receipt, and essential service messages, and to unlock purchased roadmaps.
- Assessment answers — the structured answers you give in the FounderFit assessment, used to compute your Fit scores and personalise your roadmap. These contain no special-category data and we ask you not to enter any.
- Order details — what you purchased, the amount, and payment status (handled by our payment processor; we do not store full card numbers).
- MVP build application — your name, email, idea, target customer, desired core workflow, and any roadmap reference you submit so we can assess whether the project fits the advertised one-week scope. Please do not submit passwords, API keys, or sensitive personal data.
- Aggregate usage data — privacy-friendly, cookieless analytics that count page views without building a profile of you or tracking you across other sites.
Why we use it (legal bases)
- Performance of a contract (Art. 6(1)(b) GDPR) — to deliver the roadmap, account for your purchase, and take the steps you request before entering an MVP build agreement.
- Legitimate interests (Art. 6(1)(f) GDPR) — to keep the service secure and understand aggregate usage, balanced against your rights.
- Legal obligation (Art. 6(1)(c) GDPR) — to retain invoices and tax records for the period required by law.
- Consent (Art. 6(1)(a) GDPR) — where you opt in to non-essential messages; you can withdraw consent at any time.
Processors we rely on
We share data with a small set of vetted processors strictly to run the service. Each is bound by a data-processing agreement.
- Stripe — Payment processing for roadmap purchases. Privacy terms
- Resend — Transactional email delivery (receipts, roadmap links, and application confirmations). Privacy terms
- PostHog — Cookieless, aggregate website analytics — no cross-site tracking, nothing stored on your device. Privacy terms
- Supabase — Database and file storage for assessments, orders, generated roadmaps, and MVP build applications. Privacy terms
- Vercel — Application hosting and content delivery. Privacy terms
- OpenAI — AI synthesis of custom (ad-hoc) roadmaps from the idea and founder profile you submit. Privacy terms
- Anthropic — AI personalization of catalog roadmaps and pitch polish. Privacy terms
- Perplexity — AI research used to ground custom (ad-hoc) roadmaps. Privacy terms
- DataForSEO — Keyword search-demand estimates derived from idea-related terms. Privacy terms
We never sell your personal data and do not use it for third-party advertising.
AI processing
Generating a roadmap involves sending the idea text and profile answers you submit to the AI providers listed above (OpenAI, Anthropic, and Perplexity) so they can research and draft your roadmap, and to DataForSEO so it can estimate search demand for idea-related keywords. Each provider processes this data under its own privacy terms, linked above. We do not use this data for any purpose beyond generating your roadmap.
Submitting an MVP build application does not by itself send the application text to an AI provider. We use it to review the requested scope and reply to you.
Where your data is stored
We aim to store and process personal data within the European Union / European Economic Area. Where a processor transfers data outside the EEA, that transfer is covered by an adequacy decision or the European Commission's Standard Contractual Clauses with appropriate safeguards.
How long we keep it
We keep assessment data, MVP build applications, and account data only as long as needed to review your request, provide the service, and maintain your access to purchased roadmaps. Invoices and payment records are retained for the statutory period required by tax law. We delete or anonymise data once it is no longer needed.
Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you;
- rectify inaccurate data;
- erase your data (“right to be forgotten”);
- restrict or object to certain processing;
- receive your data in a portable format;
- withdraw consent at any time, without affecting prior processing.
To exercise any right, email support@fynd.lu. You also have the right to lodge a complaint with your local data protection supervisory authority.
Cookies & analytics
We use a cookieless, privacy-friendly analytics tool that does not set tracking cookies or build a personal profile. Referral attribution is disabled by default. If it is enabled after a documented privacy review, we will ask first and keep the choice optional.
- beginr_access — a strictly necessary, httpOnly access cookie used to keep a paid roadmap available after an emailed access link is opened.