FounderStory Studio

Privacy & data handling

This page is maintained by the FounderStory Studio team to explain what the product does with meeting content and personal data. It describes the product's actual controls — it is not a certification, an audit result, or legal advice.

What we store

  • Your account email and login records (email sign-in or Google sign-in).
  • Your profile context: name, role, company, links, audience note and the collaborators you add, plus your preferred AI model and privacy preferences.
  • Your public author profile if you create one: handle, display name, bio, avatar and links. This is visible to anyone on the internet.
  • Your Fireflies API key, used only to fetch your own transcripts.
  • Meetings from three input paths — synced from Fireflies, uploaded as files (TXT, MD, PDF, DOCX), or recorded in the browser — including audio you record, the resulting transcript, speaker labels and attendee email addresses.
  • The people, companies and products extracted from a meeting, and the web-research summaries and links gathered about them.
  • Brand presets and logos, templates, uploaded story images, generated articles and their version history.
  • Publishing and social records: published stories, comments, applause, bookmarks and follows.
  • A short log of your own privacy actions (exports and deletions) for your records.

Third parties involved

  • Fireflies — transcripts fetched with your own API key, only when you sync.
  • ElevenLabs — speech-to-text for meetings you record in the browser. The audio is sent for transcription and diarisation.
  • OpenRouter — analysis, rewriting and article generation, routed to the model you choose in Settings.
  • Tavily — web search for entity research, only while research is enabled.
  • Lovable Cloud — hosting, database, authentication, file storage and transactional email.

Shared provider keys are held server-side and are never exposed to the browser. Content sent to any provider is limited to what a given request needs.

Recording meetings

The in-browser recorder captures audio from your device until you stop it. Recordings in progress are cached locally in your browser so a tab crash or screen sleep does not lose them. Audio is uploaded for transcription, and you can delete the recording and its transcript at any time. Recording other people is your responsibility: obtain consent before you press record, in line with the law where the participants are.

Personal data about other people

Transcripts, recordings and research contain personal data about the people on your calls. You are the controller of that data; FounderStory Studio processes it on your instruction. Only record and analyse meetings you are entitled to, tell participants what you do with the recording, and publish articles about named individuals responsibly.

You can turn off web research on named individuals entirely in Settings → Privacy & your data. With it off, meetings are analysed from the transcript alone — no third-party searches on named individuals.

Publishing, sharing and social features

Nothing you write is public until you publish it. A published story is readable by anyone with the link and appears on your public author profile and in Discover, along with the applause, bookmark and comment counts it collects. Preview links are unlisted and can be revoked. Unpublishing removes a story from public view immediately.

Comments you leave on someone else's story, and the follows you make, are visible with your public profile name. Deleting your account removes them.

Agent and MCP access

You can connect an AI agent to your account over the Model Context Protocol. Access is granted by you through an explicit consent screen, is scoped to your own records under the same row-level security rules as the app, and can be revoked at any time. Agents can read and write your articles, brands and templates — treat a connection like giving out a key.

Retention

By default your content is kept until you delete it. You can set a transcript retention window of 7 to 365 days in Settings; once a meeting passes that window its raw transcript, recorded audio and attendee emails are wiped automatically, while your insights and articles remain. Deletions are immediate and permanent — there is no recovery window and no hidden archive copy. Articles you move to Trash stay recoverable until you purge them.

Your rights

Every right below is self-service in Settings → Privacy & your data, with no support ticket required.

  • Access & portability: download a complete JSON export of everything we hold, plus a list of your stored files.
  • Rectification: edit your profile and public author details, and correct any extracted person, company or product inline in the story workspace.
  • Erasure: delete a single category — transcripts, meetings and research, articles, images, brands, templates or your personal context — or erase your account and every file with it.
  • Objection & restriction: switch off web research, shorten the retention window, or opt out of product emails.

Email

Account and security emails — sign-in links, password recovery, email changes — are always sent, from our own verified sending domain. Product and tips emails are off by default and can be toggled in Settings at any time.

Security

Every table is protected by row-level security so records are readable only by the account that created them, apart from the fields a story you publish deliberately makes public. Uploaded files and recordings live in private buckets addressed by time-limited signed URLs. Shared AI, search and transcription keys are held server-side and are never exposed to the browser.

Contact

For privacy questions or a data request that the in-app tools do not cover, contact the app owner at the address published on their website.

Back to FounderStory StudioTerms of service