privacy policy
the short version
- We collect your account details, your resume, your Gmail send permission, and your outreach history - nothing beyond what the product needs.
- We never read your inbox. The Gmail permission we request only lets us send the mail you compose.
- Your resume goes to Anthropic's Claude to draft your emails, under terms that forbid training on it. It is never shared with a startup unless you attach it yourself.
- We do not sell personal data. You can access, correct, or delete yours at any time.
this summary is for orientation only - the full text below is what applies.
01who we are
Fundrd is a product operated from India. For personal data we handle about you, we are the Data Fiduciary under the Digital Personal Data Protection Act, 2023 (the “DPDP Act”), and the body corporate under the Information Technology Act, 2000 and the SPDI Rules, 2011.
The DPDP Act is being brought into force in phases: the Rules were notified on 14 November 2025, with the substantive obligations applying from 13 May 2027. We are not waiting for that date - this policy describes how we already operate.
02what we collect and why
We collect only what the product needs to work. Each category below is used for the purpose stated next to it, and not for anything else.
account details
Your name and email address, and a securely hashed password. Used to create your account, sign you in, and contact you about the service. We never see your password in readable form.
your resume
The PDF or DOCX file you upload, and the text extracted from it - typically your work history, skills, education and contact details. Used to score how well each funded startup matches your background, and to give the AI enough context to draft outreach in your voice. The file is stored in a private bucket that is not publicly accessible, and it is sent to a startup only if you attach it to an email you choose to send.
A resume can contain information that the SPDI Rules treat as sensitive. Please do not upload identity numbers, financial details, health information, or anything else you do not want stored - the product does not need them, and we do not ask for them.
your gmail connection
OAuth tokens that let us send mail from your account, and the address you connected. Used only to send the outreach you compose. See the Google section below for the specific commitments that apply.
your outreach
The subject, body and recipient of each message, its delivery status, and whether the tracking pixel in it was loaded. Used to show you your outreach history, to pace sending so your mailbox is not flagged as a spam source, and to tell you when a message was opened. Open tracking is an estimate - it is defeated by most modern mail clients.
usage and technical data
Log data such as IP address, browser type, pages viewed and timestamps, generated automatically when you use the service. Used to keep it secure, debug problems, and understand which features are worth building on.
03how ai processes your data
Fundrd sends your resume text and details of the startup you selected to Anthropic’s Claude models to produce a draft email and to explain why a startup matched you.
- Your resume is sent for processing only when it is needed to produce a result for you.
- We use the Anthropic API under terms that do not permit your inputs or outputs to be used to train their models.
- AI output can be wrong or invent detail. Every draft is shown to you before anything is sent, and nothing is sent without your explicit action.
04google user data
When you connect Gmail, we request a single permission - gmail.send - which allows us to send mail as you. It does not allow us to read, search, or delete anything in your mailbox, and we do not.
Fundrd’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, we do not use Google user data for advertising, we do not sell it, we do not transfer it except as needed to provide the service or as required by law, and we do not allow humans to read it except with your explicit consent, for security purposes, or where the law requires it.
You can disconnect Gmail from settings at any time, or revoke access from your Google account permissions. Either way we delete the stored tokens and can no longer send on your behalf.
06where your data is stored
Our infrastructure and the processors listed above operate outside India, so your data is transferred and stored abroad. The DPDP Act permits transfer to any country the Central Government has not restricted; no such restriction currently applies to the countries we use. We place contractual safeguards on every processor and require them to protect the data to a standard no lower than this policy. If the position changes, we will change our infrastructure or tell you.
07how long we keep it
- While your account is open - we keep your account details, resume and outreach history so the product works.
- Resume - replaced when you upload a new one; the previous file is deleted.
- Gmail tokens - deleted as soon as you disconnect or revoke access.
- On account deletion - your account, profile, resume file and parsed text, tokens and outreach content are erased within 30 days.
- What we must keep - records of payments and grievances, for as long as tax and consumer law require. These are kept separately and not used to build a profile of you.
- Suppression list - if a founder asks us to remove their address, we keep a one-way fingerprint of it so it can never be surfaced again. That is the minimum needed to honour the request.
08your rights
Under the DPDP Act you have the following rights, and we will not charge you for exercising any of them:
- Access - a summary of the personal data we hold about you and who we have shared it with.
- Correction and completion - to have inaccurate or incomplete data corrected or updated.
- Erasure - to have your data deleted, unless we are required by law to keep it.
- Withdraw consent - as easily as you gave it. Withdrawing it stops future processing but does not undo what was lawful before.
- Grievance redressal - to complain to us first, and then to the Data Protection Board of India.
- Nominate - to name someone who can exercise these rights for you if you die or become incapacitated.
Write to nishant@fundrd.ai or use the grievance form. We acknowledge within 48 hours and respond within 30 days. You are also expected to make your requests in good faith and not to file false or frivolous ones - the DPDP Act says so too.
09how we protect it
- Data is encrypted in transit (TLS) and at rest.
- Resumes sit in a private storage bucket with no public URL; access is granted per request and expires.
- Database access is constrained by row-level security so one user’s rows cannot be read by another.
- Gmail tokens are stored server-side and never exposed to the browser.
- Access to production data is limited to those who need it to operate the service.
No system is perfectly secure. If a breach affects your personal data we will notify you and the Data Protection Board of India as the DPDP Act requires, and tell you plainly what happened and what to do.
11children
Fundrd is for adults looking for work and is not directed at children. We do not knowingly collect personal data from anyone under 18. If you believe a child has given us data, write to nishant@fundrd.ai and we will delete it.
12contact and changes
For anything in this policy, write to nishant@fundrd.ai. Our grievance officer is Nishant Upadhyay, Grievance Officer, at nishant@fundrd.ai.
We will update this policy as the product and the law change. If a change materially affects how we handle your data, we will tell you by email or in the app before it takes effect, rather than quietly changing the date at the top.
questions about this document? contact our grievance officer.