← Back to homePrivacy Policy
Last updated: June 20, 2026
1. Who we are
Founder Content Creator ("we", "our", "the Service") is an AI-assisted operating system for founder-led content creation, operated at foundercontentcreator.com. This policy explains what personal information we collect from you, why we collect it, and how you can access or delete it.
2. What we collect
- Account data from Clerk (email, name, avatar, sign-in timestamps) so we can identify you across sessions.
- Brand & workspace inputs you enter directly (brand name, niche, voice notes, ideas, scripts, uploaded images).
- Billing metadata from Stripe (customer ID, subscription status, invoice history — we never see your card number).
- Instagram Business data, if you connect your account: profile (username, account type, followers/follows count, avatar), your media (image URLs, captions, likes, comments count, timestamps), and insights (reach, impressions, engagement, profile views). We use a long-lived access token stored encrypted at rest.
- Canva data, if you connect Canva: OAuth tokens, template IDs you generate against, and the exported output URL.
- AI inputs & outputs: prompts you or the app send to Anthropic Claude, Google Gemini (image generation), or other LLMs, and the responses received. We keep these to power the tool and troubleshoot issues.
- Usage & error logs (route hit, timing, error stack traces) for reliability and abuse prevention.
3. What we do NOT collect
- We do not sell your personal data.
- We do not access your Instagram DMs beyond what you explicitly enable in-app.
- We do not share your data with advertisers.
- We do not train third-party foundation models on your private brand data.
4. How we use Instagram/Meta Platform data
When you connect Instagram, we use the Meta Graph API strictly to:
- Show your account status (username, avatar, follower count) inside the app.
- Read your media and insights to power the Analytics dashboard.
- Publish content on your behalf, either immediately or at a scheduled time you choose.
- Read and reply to comments (only when you initiate the action).
- Receive webhook notifications for events on your account (comments, mentions).
We store the minimum data needed: your access token, IG user ID, profile snapshot, and a rolling cache of insights (30-90 days) so charts load quickly. We refresh insight caches automatically and delete stale entries.
We comply with Meta's Platform Terms and Developer Policies. You can disconnect at any time from the Integrations tab, which revokes the token and purges Instagram data from our servers within 24 hours.
5. Third-party subprocessors
- Clerk — user authentication.
- Stripe — billing and payments.
- Anthropic (Claude) — LLM inference (Sonnet 4.5, Haiku 4.5). Requests are transient.
- Google Gemini (via Emergent proxy) — image generation (nano banana).
- Meta (Facebook/Instagram) — OAuth, publishing, insights.
- Canva — template autofill and export.
- MongoDB Atlas — primary database, encrypted at rest.
6. Data retention
- Account data: kept while your account is active. Deleted within 30 days of account deletion.
- Brand/workspace content: kept while your account is active.
- Instagram data: deleted within 24 hours of disconnecting or receiving a Meta data-deletion request.
- Error logs: kept for 90 days, then purged.
- Stripe invoice records: kept for 7 years as required by tax law.
7. Your rights
You can, at any time:
- Export your data by emailing privacy@foundercontentcreator.com.
- Delete your account from Settings → Delete Account (removes all workspace data within 30 days).
- Disconnect Instagram from Integrations → Instagram → Disconnect (purges IG data within 24 hours).
- Trigger Meta's data-deletion flow from your Instagram settings → Apps and Websites.
- Object to processing or request a copy of what we hold via the email above.
8. Security
We use TLS 1.2+ in transit, AES-256 at rest, and role-scoped MongoDB users. Access tokens are stored in a dedicated collection and never exposed to the frontend. Access to the production database is limited to authorized engineers and audit-logged.
9. Cookies
We use strictly-necessary cookies to keep you signed in (via Clerk). We do not use advertising cookies or third-party tracking pixels.
10. Children
The Service is not intended for anyone under 18. If we learn that a child has provided us data, we delete it.
11. Changes
We may update this policy. Material changes will be announced by email and in-app at least 30 days before they take effect.