f3f3

f3 · legal

Privacy Policy

Last updated: July 25, 2026

DRAFT — NOT YET LEGAL TEXT. This document is a review draft. Every [OWNER: ...] marker is a decision the owner must make (with counsel) before launch. See docs/legal/README.md for the fill-in checklist.

1. Who we are

This Privacy Policy explains how [OWNER: legal entity name, e.g. "f3 Ventures, Inc."], registered in [OWNER: jurisdiction] ("f3", "we", "us"), collects and uses personal data when you use the f3 platform — the websites, Proof Pages, Proof Scores, the accountability agent, and related services (the "Service").

The data controller is [OWNER: legal entity name]. Contact: [OWNER: contact email] · [OWNER: company mailing address].

2. What we collect

Account data. Your email address, used to sign you in via magic link or password. Authentication is operated on Supabase infrastructure.

Profile and venture data you provide. Your name, username, role (founder / funder / friend), LinkedIn URL if you share it, and everything you add to your profile, venture, and Proof Page: interview answers, descriptions, commitments, documents, images, and other media.

Imported data. If you use the LinkedIn import, we process only the profile text you paste or the data-export file you upload yourself — we never connect to or scrape LinkedIn. The raw text is parsed in that one request and not stored; we keep only the proof candidates derived from it, and other people's names (connections, recommenders, endorsers) are dropped before anything is saved.

Content about you from other users. Other users may write testimonials or endorsements about you or your venture.

Usage and device data. Product analytics events (pages viewed, features used), collected via PostHog, and technical data such as browser type and approximate region. Error and crash reports, which can include technical context about your session, are collected via Sentry.

Cookies and similar technologies. We use cookies and local storage for sign-in sessions, role/lens preferences, and analytics. [OWNER: confirm final cookie list and whether a consent banner is required for your launch jurisdictions — see the README follow-up note.]

3. How we use your data

We do not sell your personal data, and we do not use your private content to train our own or third parties' foundation models.

4. AI processing

Parts of the Service send founder-provided content (for example interview answers, venture descriptions, or documents you submit) to third-party AI model providers — Anthropic (Claude) and Google (Gemini) — to generate summaries, diagnoses, drafts, and scores. These providers process the content to return a result to us; under our API terms with them, API content is not used to train their models. AI output can be inaccurate — review it before relying on it.

5. Public by design

Some surfaces of the Service are intentionally public and visible to anyone, including search engines and AI crawlers:

Content shown only in restricted lenses (for example funder-only views) is limited to signed-in users with that entitlement. Do not publish anything to a public surface you are not comfortable making public.

6. Who we share data with (processors)

We share personal data with service providers that process it on our behalf:

ProviderPurpose
SupabaseAuthentication, database, and application infrastructure
LoopsTransactional and account email delivery
PostHogProduct analytics
SentryError and crash reporting
Cloudflare R2File and media storage
Anthropic (Claude)AI processing of founder-provided content
Google (Gemini)AI processing of founder-provided content

We may also disclose data when required by law, to protect the Service and its users, or as part of a corporate transaction (merger, acquisition), in which case this policy continues to apply to your data.

7. International transfers

Our providers may process data in the United States and other countries. Where required, we rely on appropriate safeguards for cross-border transfers. [OWNER: confirm transfer mechanism (e.g. EU SCCs / UK IDTA / DPF reliance) with counsel based on the entity's jurisdiction and user base.]

8. Retention

We keep your data while your account is active. If you delete content or your account, we delete or anonymize the associated personal data within a reasonable period, except where we must keep it for legal, security, or dispute-resolution reasons, and except for routine encrypted backups that expire on a rolling schedule. Public content that others have re-shared outside the Service may persist there.

9. Your rights

Depending on where you live, you may have rights to access, correct, export, restrict, object to the processing of, or delete your personal data, and to withdraw consent where processing is based on consent. You can exercise these rights by emailing [OWNER: contact email]. You also have the right to complain to your local data-protection authority.

[OWNER: confirm which regimes apply at launch (GDPR/UK GDPR, CCPA/CPRA, etc.) and whether region-specific sections — e.g. a "California residents" notice or an EU representative — are required.]

10. Security

We use industry-standard measures to protect your data, including encryption in transit, access controls, and row-level security on our database. No system is perfectly secure; if we learn of a breach affecting your personal data, we will notify you and regulators as required by law.

11. Children

The Service is not directed to children and may not be used by anyone under 18. We do not knowingly collect data from children; if you believe a child has provided us data, contact [OWNER: contact email] and we will delete it.

12. Changes to this policy

We may update this policy from time to time. For material changes we will give notice (for example by email or an in-product notice) before they take effect. The "last updated" date at the top of the page shows the current version.

13. Contact

Privacy questions and rights requests: [OWNER: contact email] · [OWNER: company mailing address].