Founder Operating SystemOne surface for a solo founder from early signal to recurring revenue.
reviewed entrycheckout controlled

Privacy

Launch-baseline privacy disclosure

This in-app baseline matches the product behavior in the current codebase and deployment model. It is intentionally explicit about essential cookies and the absence of non-essential analytics by default.

What this baseline covers

This privacy page describes the current MicroSaaS Factory launch posture. It covers self-serve founder onboarding, Firebase authentication, Firestore persistence, Stripe billing, Resend onboarding email flows, GitHub or GCP integration data, session cookies, and the email-link localStorage helper used during Firebase email-link sign-in.

Account and workspace data

The application stores founder identity details such as name, email address, workspace name, invite/signup status, activation state, subscription status, and session metadata needed to let founders reopen their workspace.

Product and operating data

Workspace records can include product descriptions, validation leads, touchpoints, CRM tasks, spec content, build notes, launch gates, activity history, and integration health data.

Payments and transactional services

When billing is enabled, Stripe handles checkout and subscription events. Resend can be used for onboarding or test email delivery. The application stores only the billing and delivery data needed to track workspace status, not full card details.

Connected integrations

If you connect GitHub, Google Cloud, Stripe, or Resend to a product lane, the application stores encrypted credentials and operational metadata required to sync connection health, deployment status, billing summaries, and onboarding readiness.

Cookies and local storage

MicroSaaS Factory currently uses essential session cookies for founder or admin access and uses localStorage only for the Firebase email-link sign-in helper. Non-essential analytics, ad tracking, and marketing pixels are not enabled by default in this release.

Retention and access

Data remains in the configured backing store for the environment, which can be local JSON in development or Firestore in production. Access is limited by application authentication, runtime secrets, and the live rollout posture for self-serve, billing, and invite-assisted access.

Future updates

This is a launch-baseline privacy disclosure and can be revised as the production environment, analytics posture, or legal requirements evolve.