skip to main content

    privacy policy

    effective 1 September 2026last updated 25 August 2026
    This policy explains what Fundrd collects, why, who else sees it, and what you can demand from us. It is written for the Digital Personal Data Protection Act, 2023.

    the short version

    • We collect your account details, your resume, your Gmail send permission, and your outreach history - nothing beyond what the product needs.
    • We never read your inbox. The Gmail permission we request only lets us send the mail you compose.
    • Your resume goes to Anthropic's Claude to draft your emails, under terms that forbid training on it. It is never shared with a startup unless you attach it yourself.
    • We do not sell personal data. You can access, correct, or delete yours at any time.

    this summary is for orientation only - the full text below is what applies.

    01who we are

    Fundrd is a product operated from India. For personal data we handle about you, we are the Data Fiduciary under the Digital Personal Data Protection Act, 2023 (the “DPDP Act”), and the body corporate under the Information Technology Act, 2000 and the SPDI Rules, 2011.

    The DPDP Act is being brought into force in phases: the Rules were notified on 14 November 2025, with the substantive obligations applying from 13 May 2027. We are not waiting for that date - this policy describes how we already operate.

    02what we collect and why

    We collect only what the product needs to work. Each category below is used for the purpose stated next to it, and not for anything else.

    account details

    Your name and email address, and a securely hashed password. Used to create your account, sign you in, and contact you about the service. We never see your password in readable form.

    your resume

    The PDF or DOCX file you upload, and the text extracted from it - typically your work history, skills, education and contact details. Used to score how well each funded startup matches your background, and to give the AI enough context to draft outreach in your voice. The file is stored in a private bucket that is not publicly accessible, and it is sent to a startup only if you attach it to an email you choose to send.

    A resume can contain information that the SPDI Rules treat as sensitive. Please do not upload identity numbers, financial details, health information, or anything else you do not want stored - the product does not need them, and we do not ask for them.

    your gmail connection

    OAuth tokens that let us send mail from your account, and the address you connected. Used only to send the outreach you compose. See the Google section below for the specific commitments that apply.

    your outreach

    The subject, body and recipient of each message, its delivery status, and whether the tracking pixel in it was loaded. Used to show you your outreach history, to pace sending so your mailbox is not flagged as a spam source, and to tell you when a message was opened. Open tracking is an estimate - it is defeated by most modern mail clients.

    usage and technical data

    Log data such as IP address, browser type, pages viewed and timestamps, generated automatically when you use the service. Used to keep it secure, debug problems, and understand which features are worth building on.

    03how ai processes your data

    Fundrd sends your resume text and details of the startup you selected to Anthropic’s Claude models to produce a draft email and to explain why a startup matched you.

    • Your resume is sent for processing only when it is needed to produce a result for you.
    • We use the Anthropic API under terms that do not permit your inputs or outputs to be used to train their models.
    • AI output can be wrong or invent detail. Every draft is shown to you before anything is sent, and nothing is sent without your explicit action.

    04google user data

    When you connect Gmail, we request a single permission - gmail.send - which allows us to send mail as you. It does not allow us to read, search, or delete anything in your mailbox, and we do not.

    Fundrd’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, we do not use Google user data for advertising, we do not sell it, we do not transfer it except as needed to provide the service or as required by law, and we do not allow humans to read it except with your explicit consent, for security purposes, or where the law requires it.

    You can disconnect Gmail from settings at any time, or revoke access from your Google account permissions. Either way we delete the stored tokens and can no longer send on your behalf.

    05who we share data with

    We do not sell personal data and we do not share it for anyone else’s marketing. We use a small number of processors to run the service, each handling only what their job requires:

    • Supabase - database, authentication and private file storage for your account and resume.
    • Vercel - application hosting and request logs.
    • Anthropic - AI drafting and matching, as described above.
    • Google - sending the mail you compose, from your own account.
    • Apollo and Hunter - business contact discovery for founders. Your personal data is not sent to them.
    • Resend - our own transactional email to you, such as password resets and alerts.
    • Freemius, Inc. - as merchant of record, it takes your payment and holds your billing details. We never see or store your card number.

    We may also disclose data where the law requires it, or to establish or defend a legal claim. If Fundrd is ever acquired, personal data may transfer as part of that transaction, and we will tell you before it does.

    06where your data is stored

    Our infrastructure and the processors listed above operate outside India, so your data is transferred and stored abroad. The DPDP Act permits transfer to any country the Central Government has not restricted; no such restriction currently applies to the countries we use. We place contractual safeguards on every processor and require them to protect the data to a standard no lower than this policy. If the position changes, we will change our infrastructure or tell you.

    07how long we keep it

    • While your account is open - we keep your account details, resume and outreach history so the product works.
    • Resume - replaced when you upload a new one; the previous file is deleted.
    • Gmail tokens - deleted as soon as you disconnect or revoke access.
    • On account deletion - your account, profile, resume file and parsed text, tokens and outreach content are erased within 30 days.
    • What we must keep - records of payments and grievances, for as long as tax and consumer law require. These are kept separately and not used to build a profile of you.
    • Suppression list - if a founder asks us to remove their address, we keep a one-way fingerprint of it so it can never be surfaced again. That is the minimum needed to honour the request.

    08your rights

    Under the DPDP Act you have the following rights, and we will not charge you for exercising any of them:

    • Access - a summary of the personal data we hold about you and who we have shared it with.
    • Correction and completion - to have inaccurate or incomplete data corrected or updated.
    • Erasure - to have your data deleted, unless we are required by law to keep it.
    • Withdraw consent - as easily as you gave it. Withdrawing it stops future processing but does not undo what was lawful before.
    • Grievance redressal - to complain to us first, and then to the Data Protection Board of India.
    • Nominate - to name someone who can exercise these rights for you if you die or become incapacitated.

    Write to nishant@fundrd.ai or use the grievance form. We acknowledge within 48 hours and respond within 30 days. You are also expected to make your requests in good faith and not to file false or frivolous ones - the DPDP Act says so too.

    09how we protect it

    • Data is encrypted in transit (TLS) and at rest.
    • Resumes sit in a private storage bucket with no public URL; access is granted per request and expires.
    • Database access is constrained by row-level security so one user’s rows cannot be read by another.
    • Gmail tokens are stored server-side and never exposed to the browser.
    • Access to production data is limited to those who need it to operate the service.

    No system is perfectly secure. If a breach affects your personal data we will notify you and the Data Protection Board of India as the DPDP Act requires, and tell you plainly what happened and what to do.

    10cookies

    We use cookies that are strictly necessary: a session cookie to keep you signed in, and security cookies to protect the sign-in flow. We do not use advertising cookies and we do not run third-party tracking on the marketing site. Blocking the necessary cookies will stop you from being able to sign in.

    11children

    Fundrd is for adults looking for work and is not directed at children. We do not knowingly collect personal data from anyone under 18. If you believe a child has given us data, write to nishant@fundrd.ai and we will delete it.

    12contact and changes

    For anything in this policy, write to nishant@fundrd.ai. Our grievance officer is Nishant Upadhyay, Grievance Officer, at nishant@fundrd.ai.

    We will update this policy as the product and the law change. If a change materially affects how we handle your data, we will tell you by email or in the app before it takes effect, rather than quietly changing the date at the top.

    questions about this document? contact our grievance officer.