Privacy Policy
Last updated: February 2026
This Privacy Policy explains how Business Foundry ("we", "us", or "our") collects, uses, and protects your personal information when you use the Business Foundry platform ("the Service"). By using the Service, you agree to the practices described in this policy.
1. Information We Collect
Account information
When you create an account, we collect your email address and a hashed password. You may optionally provide your name.
Project and business data
The business ideas, validation data, step answers, and other content you enter into the Service are stored in your account ("Your Content"). This data is processed by AI models to provide analysis and scoring.
Usage data
We collect information about how you interact with the Service, including pages visited, features used, and actions taken. This is used to improve the Service and diagnose issues.
Payment information
If you subscribe to a paid plan, payment is processed by our third-party payment provider (Stripe). We do not store your full card details — only a billing reference provided by Stripe.
2. How We Use Your Information
We use the information we collect to:
- Provide, maintain, and improve the Service
- Generate AI analysis and scoring based on your project data
- Process payments and manage your subscription
- Send you transactional emails (account creation, password reset, subscription updates)
- Respond to support requests
- Detect and prevent fraud or abuse
We will not use your data for any purpose not described in this policy without your explicit consent.
3. AI Processing
Your project data is sent to AI service providers (currently Google's Gemini API) to generate analysis, auto-fill suggestions, and validation scores. This processing is governed by those providers' data processing agreements. Your data is processed solely to generate outputs for your account and is not used to train third-party AI models.
4. Data Sharing
We do not sell your personal data to third parties. We share data only with:
- Infrastructure providers — Firebase (Google Cloud) for database, authentication, and hosting
- AI providers — Google Gemini API for AI analysis (your project data only)
- Payment providers — Stripe for subscription billing
- Legal requirements — if required by law, court order, or to protect our rights
5. Data Retention
We retain your account data and project content for as long as your account is active. If you delete your account, we will permanently delete all associated data within 30 days, unless a longer retention period is required by law.
6. Your Rights
You have the right to:
- Access — request a copy of the personal data we hold about you
- Correction — request correction of inaccurate data
- Deletion — delete your account and all associated data at any time from your account settings
- Portability — request an export of your project data in a machine-readable format
- Objection — object to processing of your data in certain circumstances
To exercise these rights, email us at contact@businessfactory.ai.
7. Security
We use industry-standard measures to protect your data, including encrypted connections (HTTPS), authentication via Firebase Auth, and Firestore security rules that restrict data access to the account owner. No system is perfectly secure and we cannot guarantee absolute security.
8. Cookies
The Service uses essential cookies and browser local storage to maintain your session and remember your preferences. We do not use advertising or tracking cookies.
9. Children's Privacy
The Service is not intended for children under 18. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it.
10. International Transfers
Your data is processed and stored in Google Cloud infrastructure, which may involve transfers to data centres outside your country. Google Cloud provides appropriate safeguards for international data transfers in compliance with applicable privacy regulations.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email or by displaying a notice in the Service. Continued use of the Service after changes take effect constitutes acceptance of the revised policy.
12. Contact
If you have questions about this Privacy Policy or how we handle your data, please contact us at contact@businessfactory.ai.