Privacy
We collect almost nothing. Here is the almost.
Most privacy pages are long because the company is doing a lot. This one is short because we are not — and the parts that would normally be buried are the parts we put first.
Effective [◻ publish date] · Controller: GENIC FILM LLC, Los Angeles, California
1. This site does not track you
No analytics. No tracking pixels. No advertising tags. No third-party scripts, fonts, or embeds of any kind. We do not know how many people visited this page, where they came from, or how far they scrolled. We decided we would rather not know than build the machinery to find out.
We set no cookies of our own, and the site works with JavaScript disabled. [◻ VERIFY at publish] — the site is hosted on Cloudflare Pages, and Cloudflare may set a strictly-necessary security cookie (__cf_bm or similar) for bot protection. Confirm the actual behaviour on the live host at publish and state it here exactly, or remove this sentence if it turns out to set nothing.
When a paid campaign eventually runs, links to this site may carry UTM tags in the URL. Those are visible to you in your address bar, they are not stored in your browser, and they only tell us which channel a purchase came from — through the order record, not through you.
2. What we actually collect
Four things, each tied to something you chose to do:
| When | What we get | Why |
|---|---|---|
| You buyThrough Polar | Name, email, country, amount, and the order record. Never your card details — those go to Polar and its processors, and we cannot see them. | To deliver the files, send updates you are entitled to, and honour refunds. |
| You email ussupport@ or a reply | Your email address and whatever you write. | To answer you. Kept so we have the thread if you write again. |
| You apply to a cohortVia our intake form (a Notion form) | The answers you give: your role, company stage, which AI platform you use, and how to reach you. | To select the cohort and run the usability study. Optional field 13 is the only place you can opt in to hearing from us later — the default is nothing. |
| We email you coldSee section 4 | A business email address collected from public sources, plus the public company details around it. | To introduce the product once. Section 4 explains this in full, including how to end it permanently. |
That is the complete list. There is no account to create, no password to store, no profile we build about you.
3. What never reaches us
- Everything you put into the product. Your constitution, your decisions, your ledger, your company's facts — those live in your Claude or ChatGPT workspace and your own Notion. There is no sync, no telemetry, no phone-home. We could not read your records if we wanted to, and we have not built the ability to.
- Your payment details. Handled entirely by Polar.
- Anything we sell. We do not sell, rent, or trade personal information, and we never will. There is no advertising business here to feed.
4. If we emailed you and you never asked us to
We run cold outreach to businesses. Most companies hide this in a subclause; we would rather say it in a heading.
Where your address came from: a publicly published business contact — a company website, a chamber-of-commerce directory, or a similar public listing. We do not scrape LinkedIn or Reddit, we do not buy consumer lists, and we do not guess or pattern-generate addresses.
What you can do:
- Every message has a working one-click unsubscribe and our real postal address, as US law requires.
- Unsubscribing is permanent. Your address goes on a suppression list that survives every future campaign and every new list we build. We do not "re-engage" people who said no.
- Reply with "delete" instead and we erase the record entirely rather than suppressing it — tell us which you want.
We only send to US business addresses in English. Korea requires prior consent for commercial email, so we do not cold-email Korean addresses at all.
5. Who else touches the data
We use a small number of vendors, each for one job, each bound by its own agreement with us:
- Polar — checkout, receipts, and file delivery.
- Google Workspace — our email.
- Cloudflare — domains, DNS, and site hosting.
- Instantly — sending and managing the cold-outreach campaigns described in section 4.
- Notion — two jobs: it hosts the product template you duplicate (duplicating it does not tell us anything about you), and it runs our cohort intake form, whose responses land in our own private Notion workspace.
We add vendors reluctantly. If this list grows, this page changes on the same day.
6. How long we keep things
- Order records: as long as tax and accounting law requires (in California, generally seven years). We cannot delete these early, and neither can anyone else.
- Your email on the updates list: until you unsubscribe or ask us to delete it.
- Support threads: up to two years, then deleted.
- Cohort intake answers: for the cohort study and its report. Access is limited to the two founders, and nothing identifying you is published without your written permission.
- Suppression list: forever, by design — it is the only way "never contact me again" can actually mean never.
7. Your rights
Wherever you live, one email to support@secondfounder.io gets you: a copy of everything we hold on you, a correction, or deletion. No form, no identity-verification theatre beyond confirming you control the address. We aim to answer within 2 business days and will not take longer than 30.
If you are in the EU or UK, our lawful bases are contract (delivering what you bought), legitimate interest (B2B outreach and running the business), and consent where you gave it. You may object or withdraw consent at any time, and you may complain to your local data protection authority.
If you are in California, you have the right to know, delete, correct, and opt out of sale or sharing. There is nothing to opt out of, because we do not sell or share personal information, and we never discriminate against anyone for exercising a right.
8. Security, stated honestly
The data we hold is small and lives in mainstream vendor systems (Google, Polar, Cloudflare) protected by two-factor authentication. We do not run our own servers holding customer data, and we do not store anything sensitive — no card numbers, no passwords, no documents from your business.
We are two people. We are not going to claim a certification we do not have. The strongest security control here is that we collect very little in the first place. If a breach ever affected your data, we would tell you directly and put it in the public ledger, because a record that only shows good news is not a record.
9. Children
This is a product for people running companies. It is not directed at anyone under 16, and we do not knowingly collect their information.
10. Changes to this page
If what we collect changes, this page changes on the same day, and the change is dated in the public ledger. We will not quietly widen this policy and hope you do not re-read it.
11. Contact
GENIC FILM LLC, Los Angeles, California. Postal address for privacy notices: [◻ postal address]. Email: support@secondfounder.io.