Privacy Policy

Last updated: October 1, 2026

This policy explains how Co-Found ("we") handles your personal data when you use co-found.site. We follow the EU General Data Protection Regulation (GDPR). Contact: info@co-found.site.

What we collect

  • Account data: email address, name, and profile photo (also from Google if you sign in with Google).
  • Profile data: headline, bio, city, skills, interests, tech stack, portfolio, and reviews.
  • Activity: connection requests, chat messages, shared files, projects, and meetings.
  • Payment data: handled by Stripe. We only store subscription status, never your card number.
  • Technical data: last-seen time (for online status), plus IP address and technical logs used strictly to protect against abuse, spam and unauthorized account creation.

Why we use it

  • To run the service: showing your profile, matching, chat and projects (contract).
  • To keep members safe: AI-assisted spam detection on pitches, automated checks of uploaded images, and reviewing reports submitted by members — a reported message is shared with our team only for that review (legitimate interest).
  • To send account and notification emails, such as new pitches or missed messages (contract / legitimate interest).
  • To process payments for paid plans (contract) and meet accounting rules (legal obligation).

Who can see your data

Your public profile is visible to signed-in members. Anonymized previews (initials only, no contact details) may appear on public pages. Messages and files are only visible to the people in that chat or project team.

Service providers

We use trusted processors for hosting and database, email delivery, payments (Stripe), sign-in (Google), and AI text processing. They only process data on our behalf.

Retention

We keep your data while your account is active. You can delete your account yourself at any time from your profile settings; this takes effect immediately and removes your personal data, except what we must keep by law (for example accounting records).

Your rights

You can request access, correction, deletion, export, or restriction of your data, and object to processing. Email us and we will respond within 30 days. You may also complain to the Swedish Authority for Privacy Protection (IMY).

Cookies & storage

We only use essential storage to keep you signed in and remember your theme preference. We do not use advertising cookies.