Foundera (“we”, “us”) is a personal financial-planning and budgeting application. This policy explains what we collect, how we use it, and the choices you have. We designed Foundera to be private by default.
Using Foundera without an account
You can use Foundera entirely on your device without signing up. In that mode, your plans and budget data are stored only in your browser (local storage) and are never sent to our servers.
Because that data lives in your browser’s local database, it is stored unencrypted on your device by default — anyone with access to your computer, browser profile, or a disk backup could read it. For stronger protection you can enable App Lock (in the account menu): a passphrase that encrypts all on-device data at rest and locks the app. We also recommend turning on full-disk encryption, locking your device, and not using Foundera on a shared or public computer. On a shared device, each account keeps a separate local ledger and signing out switches to a fresh one.
What we collect when you create an account
To sync across devices, an optional account stores:
- Account information — your email address and authentication data (passwords are hashed by our auth provider; we never see them).
- Your content — the financial plan and budget information you choose to enter (incomes, expenses, account balances, goals, assumptions).
- Limited technical data — basic logs needed to operate the service and a security audit trail of sensitive actions (e.g. sign-in, account deletion). This trail does not store financial values.
We do not ask for or store your bank login credentials. Foundera is manual-entry-first; account linking is not offered today, and if it ever is, it will be strictly optional.
How your data is stored & protected
On your device: data you keep locally — everything in local-first use, and your budgeting ledger — is stored in your browser’s built-in database and is not encrypted at rest by default. You can turn on App Lock — a passphrase that encrypts all on-device data (plans and budget ledger) at rest (AES-GCM) and locks the app. Without it, protect your data with full-disk encryption and a device lock, and avoid shared or public computers.
In the cloud: data stored with our database provider (Supabase), on infrastructure located in the United States, is encrypted at rest and isolated per user with database row-level security, so one user can never access another’s data. The app is served over HTTPS with a strict content-security policy.
Error diagnostics
When Foundera hits an unexpected error, we send a diagnostic report so we can fix bugs and keep the service reliable. These reports contain only the shape of the error — its type, message, and code stack trace, the app screen you were on, and basic browser information. They are scrubbed on your device before they are sent: email addresses, dollar amounts and long numbers, and token-like strings are removed. No financial values, plan data, or account contents are included. Diagnostics are processed by our infrastructure provider (Supabase) and used only to operate and improve Foundera. If you use Foundera without an account, these scrubbed diagnostics are the only information ever sent to us.
Service providers
We rely on a small number of processors to run Foundera: Supabase (database & authentication), Vercel (application hosting), Stripe (payment processing for paid subscriptions — your card details go directly to Stripe and never touch our servers; we store only your plan tier and a Stripe customer reference), Plausible (privacy-first, cookieless visit analytics — no personal data, no cross-site tracking), Anthropic (AI assistant — processes the preset question you select and the plan summary sent with it; see “AI assistant” below), and Google Fonts (typography). We do not sell or rent your personal information to anyone.
AI assistant
If you use the AI assistant (a Pro feature), the preset question you select in the AI panel (questions come from a fixed menu — there is no free-form chat) and a summary of your plan and budget (the context needed to answer it) are sent to Anthropic, which acts as our processor to generate the response. Anthropic retains this data only as permitted by its API terms and does not use it to train its models. We never send your password, payment details, or anything you haven’t put in the app. The assistant’s answers are educational information, not financial advice — see the Terms of Service.
Your rights & choices
- Access & export — export any plan to a JSON file at any time from the app.
- Deletion — delete your account and all associated cloud data from the account menu; this is permanent.
- Correction — edit your data directly in the app at any time.
Depending on where you live, you may have additional rights (e.g. under GDPR or CCPA). Contact us to exercise them.
Data retention
We keep your account data until you delete it. When you delete your account, your plans, versions, and profile are removed.
Children
Foundera is not directed to anyone under 18, and we do not knowingly collect data from children.
Changes
We may update this policy as the product evolves; we’ll revise the “last updated” date and, for material changes, notify you in the app.
Questions about your data or these terms? Email support@founderafinancial.com.