On this page 14 sections
The short version
- FOUND finds business buyers on LinkedIn and contacts them from our customers' own LinkedIn and email accounts.
- We never sell personal data, and we never use it for advertising.
- We never store your LinkedIn or mailbox password. It passes through our server once, straight to our connection provider; afterwards we hold only a reference to the connected account.
- Our app and database run on Amazon Web Services in Mumbai, India. Every company that handles data for us is listed below, with where it processes it.
- If a business using FOUND contacted you, our opt-out page is how you stop it, for every FOUND customer.
01Who we are, and who this covers
FOUND ("we", "us") makes an AI sales agent for businesses. This policy covers this website, the FOUND app at app.foundtofind.com, and the emails we send. For anything in it, write to hello@foundtofind.com. That address is also our privacy contact, our contact under India's Digital Personal Data Protection Act, 2023, and our grievance officer: we acknowledge within 48 hours and resolve within a month.
It covers three groups of people:
- Visitors to this website.
- Customers: people who sign in to FOUND, and the businesses they run it for.
- Prospects: people a FOUND customer finds or contacts through FOUND.
Who decides what happens to the data
- For your FOUND account, we are the controller (the "data fiduciary" under India's law).
- For the leads, messages and sequences in a customer's workspace, the customer is the controller. We process them on the customer's instructions, under our terms.
- We are also the controller of four things we keep across customers: a cache of verified work email addresses, a cache of company facts, a pool of company funding and hiring news, and opt-out requests.
02What we collect when you use FOUND
| What | Why | Legal basis | Kept |
|---|---|---|---|
| Your accountName, email address, Google account ID and profile picture, from Sign in with Google. There is no FOUND password. | To sign you in and to reach you about your account | Contract | While your account exists |
| Your workspaceYour website, what you sell, your ideal buyer, your goal, sender name, tone, deal size, booking link, and the agents, signals and sequences you set up | To run your agents and write in your voice | Contract | While your account exists |
| Your connected LinkedIn account and mailboxA reference to each connection, its status and country, the mailbox address and your sending settings. Never the password. | To find people and send from your own accounts | Contract | While your account exists |
| Conversations your agent startedMessages on LinkedIn and by email with the people your agent contacted | To show them in your inbox, stop a sequence when someone replies, and draft answers | Contract | While your account exists |
| ActivityWhat your agents did and when: searches, profile reads, invitations, messages, visits, credits used | To keep within your accounts' limits, show your dashboard and answer support questions | Contract; legitimate interests (keeping your accounts safe) | While your account exists |
| BillingPlan, status, renewal date, the subscription reference, credits bought and used. Your card stays with our payment provider. | To give you what you paid for, and keep tax records | Contract; legal obligation | As long as tax law requires |
| Integrations you addA webhook address and its signing secret, a Slack incoming-webhook link | To send events where you asked | Contract | Until you remove them |
| Emails you send us | To answer you | Legitimate interests | Until you ask us to delete them |
Your LinkedIn and mailbox passwords
You connect them on FOUND's own page. Your LinkedIn password, or your mailbox's app password, passes through our server once, straight to our connection provider, Unipile, and is never stored or logged. If LinkedIn asks for a verification code, it passes the same way. Afterwards we hold only a reference to the connected account.
What we read in your inbox
Unipile holds the connection to your LinkedIn account and your mailbox. FOUND reads only conversations with people your agent contacted: on LinkedIn, threads with your leads; in your mailbox, mail from an address your agent has already emailed. Everything else is ignored, not read and not stored. The notices Unipile sends us about new messages are logged with their IDs only, never their content, and that log is deleted after 14 days.
On this website
We don't collect anything about you here. There is no analytics, no ad pixel and no form that stores what you type. Cloudflare, which delivers the site, and Google Fonts, which serves its typefaces, see your IP address to do their jobs. The cookie policy lists everything that touches your browser.
03What we hold about people our customers contact
If a business using FOUND found or contacted you, this section is about you. The message came from that business, from its own LinkedIn account or mailbox. FOUND is the software it uses.
| What | Where it comes from |
|---|---|
| Name, headline, job title, company, location, LinkedIn profile address and member ID | LinkedIn, read through the customer's own connected account |
| The public activity that surfaced youA reaction or comment on a post, a post of your own, engagement with a competitor's page, a new job, your company hiring or raising money | LinkedIn; public funding news and job boards |
| Company factsSize, industry, website, and the technologies its website uses | LinkedIn; DataForSEO, which sees company domains only |
| A work email address, found and verified | Findymail, only when the customer's sequence has an email step or the customer asks for it |
| A fit score, and the reason you were included | Worked out by AI models from the facts above |
| Messages between you and the customerAnd whether you replied, opted out, or an email bounced | The customer's LinkedIn account and mailbox |
| Whether you opened an email | Only if the customer switched on open tracking for that mailbox. It is off by default. |
| Your details on a list the customer imported | The customer's own file, or list of LinkedIn addresses |
Profile visits
A customer's agent may view your LinkedIn profile from the customer's account, up to 100 visits a week per account, and LinkedIn may show you that visit under "Who viewed your profile".
Why, and on what basis
So a business can find and contact people likely to want what it sells. The legal basis is legitimate interests in business-to-business prospecting. We keep it fair: professional information only, only people who fit a business buyer, a slow pace, messages from the business's own named account, and a way to opt out in every email (FOUND refuses to send an email without one).
Never collected
Phone numbers, passwords, and private messages outside the conversation the agent started.
Shared between customers
We don't share one customer's leads with another. There are three exceptions, and they are the things we control ourselves: the cache of verified work emails (if another customer's lookup found your address in the last 30 days, the next lookup reuses it instead of paying for it again), the pool of company facts and funding and hiring news, and opt-out requests, which apply to every customer.
To stop it: reply "stop" to the message and that business stops at once. To stop every FOUND customer, or to get a copy of what we hold or have it deleted, use the opt-out page.
04How we use it
- To run the service: find people, check them against the customer's buyer, write and pace messages, handle replies, and show the results.
- To keep accounts safe: daily and weekly limits, a slow warm-up, and a pause when LinkedIn pushes back.
- To bill customers and support them.
- To tell customers about their account: a reply has landed, a thread was handed back, a payment went through. We send no marketing email unless you ask for it.
- To meet legal obligations, such as tax records and answering lawful requests.
We don't sell personal data, use it for advertising, or build profiles of website visitors.
05AI in FOUND
AI models do five jobs in FOUND. Each is named here, and each call goes through OpenRouter, which routes it to the model's provider.
- Reading your website. OpenAI's GPT-4o mini reads your site and drafts what you sell and who buys it; you edit the result. It also picks company names out of public funding news.
- Deciding who fits. TypeSafe's Jev model checks each person against your buyer and gives the reason. It also sorts replies (interested, later, not interested).
- Writing. Anthropic's Claude writes invitations and messages in your name, and drafts replies. A draft never sends itself.
- Answering. The agent that answers replies is off by default. Switched on for a thread, it replies in your name at a human pace, can offer your booking link, and hands the thread back when it meets something only you can answer.
- Ask. Findymail's company search turns one sentence into companies and a contact at each, and Jev checks each company against what you sell.
We don't train AI models on your data, or on prospects' data. No decision FOUND makes about a person has a legal or similarly significant effect on them: the fit score decides whom a business's agent writes to, and nothing else.
06Who else handles it
We never sell personal data. These are the companies that handle it for us, what each one sees, and where it processes it by its own published statement (read 24 September 2026).
| Company | What it does for us | What it sees | Where |
|---|---|---|---|
| Amazon Web ServicesUS company | Hosts the app, this website and the database; receives email sent to us | Everything FOUND stores; emails to hello@foundtofind.com | Mumbai, IndiaTokyo, Japan (email) |
| CloudflareUS company | DNS, delivery and security for the website and the app | Visitors' IP addresses and request details | Worldwide edgeUS and EU (logs) |
| UnipileFrance | The connection to your LinkedIn account and mailbox | The connected session, the LinkedIn inbox and mailbox it connects to, profiles read, messages sent | France only |
| FindymailEU company | Finds and verifies work emails; the company search behind Ask | Names, companies, domains, work emails | EU only |
| DataForSEOEstonia | Which technologies a company's website uses | Company domains only, no personal data | EU company |
| OpenRouterUS company | Routes every AI model call below | What each call contains: website text, profile details, messages, replies | United States |
| AnthropicClaude, via OpenRouter | Writes messages and drafts replies | Profile details, the conversation, your product facts | United States |
| OpenAIGPT-4o mini, via OpenRouter | Reads websites, drafts your buyer, and picks company names out of funding news | Website text, your buyer description, public news text | United States |
| TypeSafeJev, via OpenRouter | Checks fit and sorts replies | Profile details, your buyer, reply text | Not publishedWe reach it only through OpenRouter, in the United States. |
| ResendUS company | Sends FOUND's own emails to customers, such as "someone replied" | Your email address, and the notice, which can include the prospect's first name, company and the first lines of their reply | United States |
| Dodo PaymentsUS company, operating from India | Merchant of record: checkout, sales tax, invoices | Name, email, country, payment details (Dodo holds the card; we never see it) | WorldwideUnder standard contractual clauses, by its own policy. |
| GoogleUS company | Sign in with Google; the typefaces on this site and in the app | Your name, email, Google account ID and picture when you sign in; the IP address of anyone who loads a page | Google's global network |
Places you send data yourself
Slack alerts, webhooks and CSV exports go where you point them. Once data reaches your Slack, your systems or your files, it is yours, under the terms of the service receiving it.
Anyone else
- Legal requests. We hand over data only when the law requires it, and we tell the customer concerned unless the law forbids it.
- A sale of FOUND. If FOUND is sold or merged, data moves with it under this policy, and customers hear from us first.
- Our own access. Only FOUND's operator can reach the servers and the database, for support and security.
07Where it's processed
Our app and database run on Amazon Web Services in Mumbai, India. Email to hello@foundtofind.com arrives through Amazon's email service in Tokyo, Japan. Unipile, Findymail and DataForSEO process in the EU. OpenRouter, Anthropic, OpenAI, Resend, Cloudflare's logs and Google are in the United States. Dodo Payments uses processors worldwide.
If you live in the EU, the UK or Switzerland, your data goes to countries whose laws differ from yours. For each vendor, the transfer relies on what that vendor's data processing agreement offers: standard contractual clauses, or its certification under the EU-US Data Privacy Framework where it has one. If you're a customer there and need standard contractual clauses between your business and FOUND, write to us and we will sign them.
08How long we keep it
These are the rules our code runs, not targets.
| Data | Kept |
|---|---|
| Your account, workspace, leads, messages and sequences | While your account exists |
| Your account, once you ask us to delete it | Deleted within 30 days |
| Notices from our connection provider (IDs only, never content) | 14 days |
| A prospect's full profile snapshotThe name, headline and why they were considered stay while the customer's account exists | Cleared 30 days after its last refresh |
| Company facts | 60 days |
| Company funding and hiring news | 60 days |
| Events sent to your webhook or Slack | Content deleted once delivered; the record after 14 days |
| A "no email found" answer | Asked again after 30 days |
| Verified work emails in the shared lookup cacheReused for 30 days after a lookup | Until the person asks us to delete them |
| Website technology lookups (company domains, no personal data) | Looked up again after 90 days |
| Email open and unsubscribe links | While the customer's account exists |
| Billing records | As long as tax law requires |
| Opt-out requestsOnly the LinkedIn profile address, member ID and email | As long as the block must work |
| Your sign-in, in the app's browser storage | 30 days, or until you sign out |
When a subscription ends, nothing is deleted on its own. Your workspace stays as it was with your agents stopped, so you can come back, or sign in and export your leads, contacts and conversations as CSV. If you want it gone, email us from your account's address and we delete it within 30 days.
09Your rights
Wherever you live, you can ask us to:
- tell you what we hold about you, and give you a copy;
- correct it;
- delete it;
- stop using it to contact you;
- withdraw any consent you gave.
Customers can also export their leads, contacts and conversations as CSV from the app at any time. Asking costs you nothing. We acknowledge within 48 hours and answer within 30 days. For a copy, a deletion or a correction, we check the request comes from the email address in question before we act. In India, you can also nominate someone to use these rights for you if you die or can no longer act yourself.
If you are not happy with our answer, you can complain to:
- EU and EEA: the data protection authority where you live or work;
- UK: the Information Commissioner's Office;
- India: the Data Protection Board of India, once you have raised it with us;
- United States: your state's attorney general, and in California, the California Privacy Protection Agency.
10Keeping it safe
- Everything travels over HTTPS.
- Our servers accept traffic only through Cloudflare; a request that tries to reach them directly is refused.
- LinkedIn and mailbox passwords are never stored or logged.
- There is no FOUND password to leak: you sign in with Google.
- Only FOUND's operator can reach the servers and the database.
- Webhooks we send are signed, and Slack links are treated as secrets and never written to our logs.
If personal data is ever breached, we tell the customers affected and the authorities the law requires, including the Data Protection Board of India and each person affected under India's law, without undue delay.
12Children
FOUND is for businesses. It isn't meant for anyone under 18, and we don't knowingly collect data about children.
13Changes to this policy
The date at the top changes whenever this policy does. If a change is material, customers get an email at least 14 days before it takes effect. Before anything new starts handling your data, such as a new vendor, analytics or a new way to connect FOUND, this page changes first.
14Contact
FOUND, hello@foundtofind.com. Privacy questions, requests under any law, our contact under India's Digital Personal Data Protection Act and grievances all go to that address. We acknowledge within 48 hours and resolve within a month.
Also read