Cofound is a software-as-a-service platform operated by LeapVision Technologies Inc. ("Cofound," "we," "us," or "our").
Privacy contact: privacy@buildwithcofound.com
Cofound is based in Canada. We are subject to Canada's federal Personal Information Protection and Electronic Documents Act (PIPEDA), which governs how private-sector organizations collect, use, and disclose personal information in the course of commercial activities.
This information is collected when you create an account.
We process payments through Paddle. We do not store your full card number, CVV, or any other raw payment credential. All billing data is handled under Paddle's PCI-DSS compliance.
All messages you send to your AI agents, and all responses the agents return to you. This history is stored for the life of your subscription so agents can maintain context across sessions and do effective work.
Important: Your conversation content -- including any prompts, instructions, and context you provide -- is sent to our third-party LLM providers for inference. This means our AI providers process your prompts in order to generate responses. See Section 4 for details.
All code, content, assets, configurations, and other files produced by your AI team and stored on the platform. This includes your product's source code, marketing copy, database schema files, and anything else your agents produce during sprints.
OAuth tokens, API keys, and other credentials you provide to connect third-party services (Gmail, GitHub, Notion, Google Sheets, etc.). These are stored encrypted at rest and are never returned to the browser in plaintext after initial setup. They are used only to make API calls on your behalf.
This information is collected automatically when you use the platform and is used for security, fraud prevention, and aggregate analytics.
| Purpose | Legal basis under PIPEDA |
|---|---|
| Operate and deliver the Cofound platform | Performance of contract |
| Authenticate your identity and secure your account | Legitimate interest / security |
| Process billing and manage your subscription | Performance of contract |
| Send transactional emails (sprint alerts, receipts, renewal notices) | Performance of contract |
| Allow your AI agents to maintain context across sessions | Performance of contract |
| Send your prompts to LLM providers to generate responses | Performance of contract (with consent) |
| Diagnose errors and improve platform reliability | Legitimate interest |
| Improve the platform using aggregate, anonymized usage data | Legitimate interest |
| Comply with legal obligations | Legal obligation |
We do not:
To operate Cofound, we share certain data with the following sub-processors. We have data processing agreements or equivalent contractual protections in place with each.
What they receive: Your conversation messages (prompts, context, instructions) and agent responses. LLM providers process these in real time to generate outputs. They do not receive your billing information or integration credentials.
Why: This data flow is inherent to how large language model inference works.
Data location: LLM providers may process data in the United States. If you are in Canada or elsewhere, your prompts are transferred to the provider's infrastructure for inference and the outputs are returned to Cofound.
What they receive: All application data stored in Cofound's database, including your account information, conversation history, project files, and usage data.
Why: Supabase provides our database and file storage.
Privacy policy: supabase.com/privacy
Data location: ca-central-1 (Montreal, Canada).
What they receive: Your account email address, password hash, and session tokens required for authentication.
Why: Clerk provides authentication and identity management.
Privacy policy: clerk.com/legal/privacy
Data location: United States.
What they receive: Your billing name, billing address, payment method information, and transaction records.
Why: Paddle processes all payments for Cofound subscriptions.
Privacy policy: paddle.com/legal/privacy
Data location: United States and EU.
What they receive: Your email address and the content of transactional emails we send you (sprint notifications, receipts, renewal notices).
Why: Resend delivers transactional email on our behalf.
Privacy policy: resend.com/legal/privacy-policy
Data location: United States.
What they receive: Web server logs including IP addresses and browser information from users of the Cofound platform.
Why: Vercel hosts the Cofound web application.
Privacy policy: vercel.com/legal/privacy-policy
Data location: Vercel uses edge nodes globally; origin data may be stored in US or EU.
What they receive: Aggregate, anonymized site usage data collected via GA4 on buildwithcofound.com (the marketing site only, not the platform).
Why: We use GA4 to understand how visitors find and use our marketing pages so we can improve them.
Privacy policy: policies.google.com/privacy
If we add a new sub-processor that will receive personal information, we will update this list and notify you by email at least thirty (30) days before the new processor begins processing your data.
| Data type | Retention period |
|---|---|
| Account information | Retained while subscription is active + 30 days after cancellation |
| Conversation history | Retained for life of subscription + 30 days after cancellation |
| Project files | Retained for life of subscription + 30 days after cancellation |
| Billing records | Retained for 7 years as required by Canadian tax law |
| Integration credentials | Deleted immediately upon disconnection or 30 days after account cancellation, whichever comes first |
| Usage logs (aggregate, anonymized) | Retained indefinitely |
| Device / browser logs | Retained for 90 days then deleted |
After the 30-day post-cancellation window, all personal data tied to your account is permanently and irreversibly deleted from our systems and from our sub-processors' systems (subject to their own deletion timelines).
We cannot recover deleted data. We strongly recommend you export your data before cancelling.
Under PIPEDA, you have the following rights regarding your personal information:
Right of access. You may request a copy of the personal information we hold about you. We will respond within 30 days.
Right to correct. You may request that we correct inaccurate or incomplete personal information.
Right to withdraw consent. Where we process data based on your consent, you may withdraw consent at any time. Note that withdrawing consent to necessary processing (such as sending your prompts to our LLM providers) means you will no longer be able to use the AI agent features.
Right to deletion. You may request deletion of your account and all associated personal information. We will process this within 30 days. Some data (billing records) will be retained as required by law.
Right to data portability. You may request an export of your data in a machine-readable format (JSON). This includes your conversation history, project files, and account information. You may also export your data at any time from your account settings without contacting us.
How to exercise your rights. Email privacy@buildwithcofound.com with your full name, the email address on your account, and a description of your request. We will verify your identity before processing the request.
Cofound is not currently targeted at users in the European Union. However, if you are in the EU and choose to use the platform, you have additional rights under the General Data Protection Regulation (GDPR):
Contact: privacy@buildwithcofound.com
Session cookie (authentication): Required for authentication. This cookie keeps you logged in and expires after 30 days or when you sign out.
Local storage (theme preference): We store your light/dark mode preference in your browser's localStorage. This is not a cookie and is not transmitted to our servers.
Analytics (marketing site only): buildwithcofound.com uses Google Analytics (GA4) for aggregate site usage analytics. GA4 uses cookies to distinguish visitors. You may opt out via Google's opt-out tool. The platform at app.buildwithcofound.com does not use advertising or analytics cookies.
No advertising cookies. We do not use third-party advertising cookies, tracking pixels, or retargeting technologies on the Cofound platform.
We implement the following security measures to protect your personal information:
Despite these measures, no system is perfectly secure. In the event of a data breach that affects your personal information and creates a real risk of significant harm, we will notify you and the relevant privacy authority as required by applicable law.
Cofound is not intended for users under the age of 18. We do not knowingly collect personal information from minors. If you believe a minor has created an account, please contact us at privacy@buildwithcofound.com and we will delete the account.
We may update this Privacy Policy from time to time. For material changes we will post the updated policy at buildwithcofound.com/privacy and send you an email notice to the address on your account at least thirty (30) days before the changes take effect.
For any privacy-related questions, to exercise your rights, or to file a privacy complaint:
Privacy contact: privacy@buildwithcofound.com
We aim to respond to all privacy requests within 30 days. If you are not satisfied with our response, you may escalate to:
Office of the Privacy Commissioner of Canada: priv.gc.ca