1. Overview
FoundChat is operated by Othmane Nejdi. We take security seriously and use technical, organizational, and operational safeguards to protect the FoundChat platform and customer data.
No internet service can be guaranteed to be completely secure, but we work to reduce risk, monitor abuse, and respond quickly to issues.
2. Infrastructure and Access Controls
We aim to protect FoundChat through measures such as:
- Role-based access to internal systems where available.
- Limited access to production data based on operational need.
- Use of reputable hosting, database, AI, analytics, and infrastructure providers.
- Monitoring for errors, abuse, suspicious activity, and service health.
- Regular updates to dependencies and platform components where practical.
3. Data Protection
Customer content may include websites, documents, knowledge base entries, uploaded files, prompts, settings, and conversation history. We use this information to provide and improve the service.
We apply reasonable safeguards to protect customer content from unauthorized access, loss, misuse, or disclosure. Customers are responsible for choosing what content they upload or connect and for avoiding unnecessary sensitive information.
4. Payments and Paddle
FoundChat payments are processed by Paddle, our Merchant of Record. Paddle handles checkout, payment processing, tax, invoices, subscriptions, cancellations, refunds, and payment-related security. FoundChat does not store full credit card numbers.
Paddle's buyer terms and privacy information are available at paddle.com/legal/buyer-terms and paddle.com/legal/privacy.
5. Customer Responsibilities
Customers are responsible for:
- Using strong, unique passwords and protecting account credentials.
- Restricting access to workspaces and integrations to trusted users.
- Reviewing AI agent responses before relying on them in sensitive workflows.
- Removing confidential, regulated, or unnecessary personal data from uploaded content where appropriate.
- Keeping their own websites, integrations, and embedded code secure.
6. AI and Model Providers
FoundChat may use third-party AI model providers and infrastructure services to generate responses and operate AI agents. We select providers with security practices appropriate for the service and use them to process prompts, retrieved knowledge, and conversation context as needed.
7. Incident Response
If we identify a security incident that affects customer data or service availability, we will investigate, take steps to contain and remediate the issue, and notify affected users where required by law or where appropriate.
8. Responsible Disclosure
If you believe you have found a security vulnerability in FoundChat, please contact us at [email protected]. Please include enough detail for us to reproduce and investigate the issue.
Do not access, modify, destroy, or exfiltrate data that does not belong to you. Do not disrupt the service or test against other users without permission.
9. Contact
Othmane Nejdi / FoundChat
Email: [email protected]