f3 · legal
Privacy Policy
Last updated: July 25, 2026
DRAFT — NOT YET LEGAL TEXT. This document is a review draft. Every [OWNER: ...] marker is a decision the owner must make (with counsel) before launch. See docs/legal/README.md for the fill-in checklist.
1. Who we are
This Privacy Policy explains how [OWNER: legal entity name, e.g. "f3 Ventures, Inc."], registered in [OWNER: jurisdiction] ("f3", "we", "us"), collects and uses personal data when you use the f3 platform — the websites, Proof Pages, Proof Scores, the accountability agent, and related services (the "Service").
The data controller is [OWNER: legal entity name]. Contact: [OWNER: contact email] · [OWNER: company mailing address].
2. What we collect
Account data. Your email address, used to sign you in via magic link or password. Authentication is operated on Supabase infrastructure.
Profile and venture data you provide. Your name, username, role (founder / funder / friend), LinkedIn URL if you share it, and everything you add to your profile, venture, and Proof Page: interview answers, descriptions, commitments, documents, images, and other media.
Imported data. If you use the LinkedIn import, we process only the profile text you paste or the data-export file you upload yourself — we never connect to or scrape LinkedIn. The raw text is parsed in that one request and not stored; we keep only the proof candidates derived from it, and other people's names (connections, recommenders, endorsers) are dropped before anything is saved.
Content about you from other users. Other users may write testimonials or endorsements about you or your venture.
Usage and device data. Product analytics events (pages viewed, features used), collected via PostHog, and technical data such as browser type and approximate region. Error and crash reports, which can include technical context about your session, are collected via Sentry.
Cookies and similar technologies. We use cookies and local storage for sign-in sessions, role/lens preferences, and analytics. [OWNER: confirm final cookie list and whether a consent banner is required for your launch jurisdictions — see the README follow-up note.]
3. How we use your data
- To operate the Service: accounts, Proof Pages, Proof Scores, the accountability agent, and venture workspaces.
- To compute scores and generate AI-assisted content from material you provide (see section 4).
- To send transactional email — magic links, notifications, and product updates related to your account — via Loops.
- To understand product usage and fix problems (PostHog analytics, Sentry error tracking).
- To keep the Service safe: preventing fraud, abuse, and score manipulation.
- To comply with legal obligations.
We do not sell your personal data, and we do not use your private content to train our own or third parties' foundation models.
4. AI processing
Parts of the Service send founder-provided content (for example interview answers, venture descriptions, or documents you submit) to third-party AI model providers — Anthropic (Claude) and Google (Gemini) — to generate summaries, diagnoses, drafts, and scores. These providers process the content to return a result to us; under our API terms with them, API content is not used to train their models. AI output can be inaccurate — review it before relying on it.
5. Public by design
Some surfaces of the Service are intentionally public and visible to anyone, including search engines and AI crawlers:
- your venture's Proof Page (public lens) and its published content;
- your person identity card (name, username, aggregate score, roles);
- your Proof Score, where you have published it;
- testimonials and endorsements published to those surfaces.
Content shown only in restricted lenses (for example funder-only views) is limited to signed-in users with that entitlement. Do not publish anything to a public surface you are not comfortable making public.
6. Who we share data with (processors)
We share personal data with service providers that process it on our behalf:
| Provider | Purpose |
|---|---|
| Supabase | Authentication, database, and application infrastructure |
| Loops | Transactional and account email delivery |
| PostHog | Product analytics |
| Sentry | Error and crash reporting |
| Cloudflare R2 | File and media storage |
| Anthropic (Claude) | AI processing of founder-provided content |
| Google (Gemini) | AI processing of founder-provided content |
We may also disclose data when required by law, to protect the Service and its users, or as part of a corporate transaction (merger, acquisition), in which case this policy continues to apply to your data.
7. International transfers
Our providers may process data in the United States and other countries. Where required, we rely on appropriate safeguards for cross-border transfers. [OWNER: confirm transfer mechanism (e.g. EU SCCs / UK IDTA / DPF reliance) with counsel based on the entity's jurisdiction and user base.]
8. Retention
We keep your data while your account is active. If you delete content or your account, we delete or anonymize the associated personal data within a reasonable period, except where we must keep it for legal, security, or dispute-resolution reasons, and except for routine encrypted backups that expire on a rolling schedule. Public content that others have re-shared outside the Service may persist there.
9. Your rights
Depending on where you live, you may have rights to access, correct, export, restrict, object to the processing of, or delete your personal data, and to withdraw consent where processing is based on consent. You can exercise these rights by emailing [OWNER: contact email]. You also have the right to complain to your local data-protection authority.
[OWNER: confirm which regimes apply at launch (GDPR/UK GDPR, CCPA/CPRA, etc.) and whether region-specific sections — e.g. a "California residents" notice or an EU representative — are required.]
10. Security
We use industry-standard measures to protect your data, including encryption in transit, access controls, and row-level security on our database. No system is perfectly secure; if we learn of a breach affecting your personal data, we will notify you and regulators as required by law.
11. Children
The Service is not directed to children and may not be used by anyone under 18. We do not knowingly collect data from children; if you believe a child has provided us data, contact [OWNER: contact email] and we will delete it.
12. Changes to this policy
We may update this policy from time to time. For material changes we will give notice (for example by email or an in-product notice) before they take effect. The "last updated" date at the top of the page shows the current version.
13. Contact
Privacy questions and rights requests: [OWNER: contact email] · [OWNER: company mailing address].