FoundRev.comBack to home

Last updated: May 12, 2026

Privacy Policy

Draft notice. This document is written in plain English for pilot customers. We recommend reviewing it with counsel before relying on it past your first ten installs.

1. The short version

We collect what we need to draft your weekly Klaviyo emails: your email address, your business name, OAuth tokens to your Klaviyo account, voice transcripts from the recording you make during setup, and the drafts we generate for you. We do not sell this data. We do not use it to train general-purpose AI models. You can request deletion at any time.

2. What we collect

  • Account data. Email address, business name, IP address, browser user agent, and the timestamps of your account actions.
  • Klaviyo OAuth tokens.Encrypted access and refresh tokens that let us read your account's campaigns, templates, lists, and image library, and push drafts to your Drafts folder. Tokens are encrypted at rest using AES-256-GCM with a master key we control.
  • Voice recordings. Short audio clips you record during onboarding. These are transcribed by OpenAI Whisper and the original audio is deleted immediately after transcription. We retain only the text transcript and a derived voice fingerprint.
  • Brand data from Klaviyo. Your last several sent campaigns, your sender name and email, your hosted image library, and the HTML of one of your best-performing templates.
  • Generated drafts. The email drafts FoundRev.com produces for you and any edits you make to them.
  • Billing data. Stripe handles payment information; we receive only the customer and subscription IDs and the last 4 digits of the card. We never see or store full card numbers.

3. How we use it

We use the data above only to operate FoundRev.com:

  • Drafting your weekly Klaviyo campaigns in your brand voice
  • Pushing those drafts into your Klaviyo Drafts folder
  • Sending you transactional emails (magic-link login, draft-ready notification)
  • Diagnosing errors and preventing abuse
  • Charging your subscription through Stripe

We do not sell your data. We do not use your voice transcripts or your Klaviyo content to train general-purpose AI models. We do send subsets of your data to the third-party processors listed below, who use it only to perform their part of the service.

4. Who else sees your data (sub-processors)

We rely on the following sub-processors. Each one sees only what they need to perform their role.

ProviderRoleWhat they see
AnthropicAI draftingPrompts containing your voice transcript and Klaviyo context. Anthropic does not train on our API traffic.
OpenAIVoice transcriptionVoice audio at the moment of transcription. Audio is discarded after we receive the text.
KlaviyoEmail platform we integrate withOAuth-scoped reads and writes to your own account. We share no data with Klaviyo beyond what their API needs to read or write your campaigns.
StripePaymentsYour email, billing details, and subscription state.
ResendTransactional email deliveryThe transactional emails we send to you (magic links, notifications) and your email address.
SupabaseDatabase and authenticationYour account record, encrypted Klaviyo tokens, voice transcripts, and generated drafts.
VercelWeb hostingHTTP request metadata (IP, user agent, request path) for the duration we serve you.
CloudflareBot detection at signupA bot-check token from your browser during sign-up.
UpstashRate limitingYour IP address and the endpoints you hit, kept long enough to enforce rate limits.

We pick processors that publish their own privacy commitments consistent with what we promise you. We don't use processors that train models on our customers' data.

5. How long we keep your data

  • Voice audio: deleted immediately after transcription (typically within seconds).
  • Voice transcript and fingerprint: kept for as long as your account is active, deleted within 30 days of cancellation.
  • Generated drafts: kept indefinitely while your account is active; you can delete individual drafts in the dashboard.
  • Klaviyo OAuth tokens: kept while your account is active. On cancellation we revoke and delete tokens within 30 days.
  • Billing records: retained for 7 years per US tax law.
  • Audit log: retained for 2 years for security and abuse investigation.

6. Your rights

Regardless of jurisdiction, you can email bryan@foundrev.com and ask us to:

  • Show you everything we hold about you
  • Correct anything that's wrong
  • Delete your account and all associated data
  • Export your data as JSON
  • Stop processing your data while we investigate a request

Customers in California (CCPA) and the European Economic Area (GDPR) have additional formal rights covered by those laws. We treat all customers to the GDPR/CCPA standard regardless of residence.

7. Security

We encrypt third-party credentials at rest using AES-256-GCM. All traffic to portal.foundrev.com is TLS-encrypted. We log privileged actions to an audit trail. We use Row-Level Security in our database so application bugs cannot leak cross-tenant data. We do not promise our security is unbreakable, only that it is considered and current.

8. Cookies

We use a small number of essential cookies (login session, anonymous onboarding session, bot-check token) and a single analytics cookie (PostHog) once analytics is enabled. We do not run advertising or cross-site tracking cookies.

9. Children

FoundRev.com is a B2B tool. We do not knowingly collect data from anyone under 18. If you believe a minor has somehow signed up, email us and we'll delete the account.

10. Changes to this policy

We may update this policy. Material changes will be emailed to the contact address on your account at least 14 days before they take effect.

11. Contact

Privacy questions or requests: bryan@foundrev.com.

FoundRev.com
TermsPrivacyRefunds© 2026