Kofounder

Privacy policy

Last updated October 5, 2026

Kofounder is operated by Molicule LLC, a Delaware limited liability company (“Kofounder”, “we”, “us”). This policy explains what we collect when you visit kofounder.ai, join the waitlist or use the product, why we collect it, who helps us process it, and what you can ask us to do with it.

In short: we collect what we need to run Kofounder, we don't sell your data or use it for advertising, we don't use your ideas to train AI models, and we'll delete your data if you ask.

1. What this policy covers

This policy covers kofounder.ai and the Kofounder product. It does not cover the apps you build with Kofounder. Those apps run in your own GitHub, Supabase and hosting accounts, and any data your app collects from its own users is yours to manage. You are responsible for your app's privacy notice and for handling your users' data lawfully.

2. What we collect

When you join the waitlist: your email address. We also record the page that referred you, campaign tags in the link you used (utm parameters) and your browser's user agent.

Your account: your name, email address and sign-in details. Passwords are handled by our authentication provider and are never visible to us.

Your projects: what you type into Kofounder (your idea, answers, chat messages and notes) and what it produces for you: research reports, plans, designs and code.

Connected accounts: if you connect GitHub or Supabase, we receive and store what's needed to work in those accounts on your behalf: your username or organisation, repository and project names, and access tokens. Tokens are only used on our servers and are never sent to your browser.

Usage and credits: a record of each AI request made for your account (the step, model, size and cost), used to run your free credits and control costs, and a record of errors you run into, so we can help when something goes wrong.

Collected automatically: your IP address, browser and device type, and server logs when you use the site, plus cookieless page analytics (see Cookies).

3. How we use it

  • To run Kofounder and do what you ask it to do.
  • To send you your invite from the waitlist, and account and service emails after that.
  • To run free credits and prevent abuse of the service.
  • To find and fix problems, keep the service secure and improve the product.
  • To meet legal obligations and enforce our terms.

4. AI processing

Kofounder uses Anthropic's Claude models. To research, plan, design and write code, we send the relevant parts of your project to Anthropic. During research, Kofounder also runs web searches through Anthropic based on your idea, so the search terms reflect what you're building.

We do not use your projects to train AI models. Anthropic processes this data under its commercial terms, which do not permit using it to train its models.

5. Who processes it

We use these service providers, each only for the purpose listed:

  • Supabase: database and authentication.
  • Vercel: hosting and cookieless page analytics.
  • Anthropic: AI models and web search.
  • Inngest: running long background jobs.
  • E2B: isolated sandboxes for checking generated code.
  • GitHub: only if you connect it, to create and update your repository.
  • Microsoft 365: our email.

We may also share information:

  • when the law requires it, or to protect the rights, safety or property of our users, the public or Kofounder;
  • with a buyer or successor if Kofounder is merged, acquired or sells its assets. This policy would continue to apply to your data, and we'd tell you before it became subject to a different policy.

We do not sell your personal information, and we do not share it for cross-context behavioural advertising.

6. Cookies

We use only the cookies needed to keep you signed in and to keep the site secure. Our page analytics are cookieless and don't identify you. We don't use advertising or cross-site tracking cookies, so there is nothing to opt out of.

7. How long we keep it

  • Waitlist: until you're invited and create an account, or until you ask us to remove you.
  • Account and projects: while your account is open. When you delete a project, its content is deleted.
  • When you delete your account: we delete your account and project data within 30 days. Copies in our providers' backups are overwritten on their normal schedule.
  • Usage, credit and error records: as long as needed to run credits, investigate problems and meet accounting and legal obligations. They don't include your project content.

8. Your rights and choices

You can ask us to tell you what personal information we hold about you, give you a copy, correct it, delete it, or stop or restrict how we use it, and you can withdraw consent where we rely on it. You can also disconnect GitHub or Supabase at any time.

Email privacy@kofounder.ai from the address on your account. We may need to confirm it's you before acting. We'll respond within 30 days, or sooner if your local law requires it. If we decline a request, you can ask us to reconsider by replying to our answer.

US residents: depending on your state, you have rights to know, access, correct, delete and get a copy of your personal information, and to opt out of its sale, sharing for targeted advertising, or profiling. We don't do any of those things. We won't treat you differently for using your rights.

EEA, UK and Swiss residents: you can also complain to your local data protection authority.

9. Legal bases (EEA, UK and Switzerland)

  • To provide the service you asked for (contract): your account, projects and connected accounts.
  • Our legitimate interests: security, fraud and abuse prevention, fixing problems and improving the product.
  • Consent: joining the waitlist. You can withdraw it any time.
  • Legal obligations: for example tax and accounting records.

10. International transfers

Kofounder is based in the United States and our providers store and process data mainly in the US. When we transfer personal data from the EEA, UK or Switzerland, we rely on our providers' standard contractual clauses or other approved safeguards.

11. Security

Data is encrypted in transit and stored with providers that encrypt it at rest. Access to each project is restricted to its owner at the database level, access tokens never reach the browser, and generated code runs only in isolated sandboxes. No system is perfectly secure. If a breach affects your personal data, we'll notify you as the law requires.

12. Children

Kofounder is for adults 18 and over. We don't knowingly collect data from anyone under 18. If we learn an account belongs to someone under 18, we'll close it and delete its data.

13. Changes to this policy

We'll update the date at the top when this policy changes. For material changes, we'll email account holders at least 30 days before they take effect.

14. Contact

Privacy questions and requests: privacy@kofounder.ai.