Founder Dashboard

Privacy Policy

Last updated 3 September 2026

This Privacy Policy explains what information Founder Dashboard (“the app”) collects, how it is used, where it is stored, who it is shared with, and the choices available. The app is built and operated by Akshay Maharaj (“the operator”, “I”) for his own use. Contact details are at the end.

1. What the app is

Founder Dashboard is a private, single-operator tool. It is not a product and is not offered to the public. Sign-in is restricted to the operator’s own Google accounts; no one else can use it. The app consolidates the connected account’s email, calendar and document activity into one workspace so meetings, correspondence and deals can be seen together.

2. Information collected

2.1 Account information. On sign-in with Google the app receives the account’s name, email address and profile picture, used to identify the operator’s account.

2.2 Google user data. When a Google account is connected, the app requests permission to access data in that account only. It never accesses data belonging to anyone who has not personally signed in and granted consent. The permissions (“scopes”) requested, and what each is used for:

  • Gmail — gmail.modify and gmail.compose. Read message threads so the dashboard can show recent correspondence with each contact, detect replies and scheduling requests, and create draft replies for review. The app does not send email except when the operator explicitly clicks send. It does not delete messages.
  • Google Calendar — calendar.readonly and calendar.events. Read upcoming meetings so the dashboard can show the schedule and prepare a brief for each meeting (attendees, related correspondence, related documents), and create calendar events when asked.
  • Google Drive — drive.readonly and drive.file. Locate documents related to a contact — proposals, agreements, meeting notes — by searching file names and contents, and create documents (such as meeting agendas) on request.
  • Identity — openid, userinfo.email, userinfo.profile. Confirm which Google account is connected and associate its data with the operator’s app account.

2.3 Information entered directly. Notes, contact details, deal values, tasks and similar records typed into the app.

2.4 Technical information. Standard server logs (request time, path, status code, approximate location derived from IP) generated by the hosting provider for security and debugging, retained by the provider for a limited period and not combined with Google data.

3. How information is used

  • Displaying the pipeline, contacts and tasks.
  • Showing the email correspondence and Drive documents associated with each contact.
  • Preparing meeting briefs from the calendar, correspondence and documents.
  • Generating summaries and suggested draft text, which are reviewed before use.
  • Detecting when a contact has replied or a follow-up is overdue.
  • Keeping the operator signed in and securing the account.

Google user data is not used for advertising, for building profiles for any third party, for market research, or for training generalised machine-learning models. It is not sold.

4. Where information is stored and how it is protected

  • Database. OAuth tokens and a working cache of derived data (message metadata and snippets, calendar entries, document titles and links, and briefs generated from them) are stored in a managed PostgreSQL database hosted by Neon, which encrypts data at rest.
  • Hosting. The application runs on Vercel. Connections between the browser, the app, Google and processors use TLS encryption in transit.
  • Credentials. Gmail, Calendar and Drive access and refresh tokens are held server-side only and are never sent to the browser. They are used solely to make requests to Google on the operator’s behalf.
  • Access. Only the operator can sign in. Sign-in attempts from any other Google account are refused, and a Gmail, Calendar or Drive connection is only accepted from the operator’s own accounts.

5. Retention and deletion

  • While connected. Google user data is retained for as long as the relevant service stays connected, so the dashboard can render without re-fetching everything on each load.
  • Disconnecting a service. Disconnecting Gmail, Calendar or Drive in Settings deletes the stored credentials for that service immediately; no further data is retrieved.
  • Deleting everything. All stored data (cached Google data, notes, tasks, the account) can be deleted on request to the contact below, completed within 30 days.
  • Revoking at Google. Access can also be revoked at any time from myaccount.google.com/permissions, which immediately stops all further retrieval.

6. Who information is shared with

Google user data is not sold and is not shared for advertising or any purpose unrelated to the features described here. To run the app, the following service providers process data only on the operator’s instructions:

  • Vercel — application hosting and server logs.
  • Neon — managed PostgreSQL database storage.
  • OpenAI — when the app is asked to summarise or draft something (for example, turning an email thread into a briefing note, or researching a contact), the relevant text is sent to OpenAI’s API to produce that output. OpenAI processes it under its API data terms and does not use API inputs to train its models.

Information may also be disclosed if required by law. Google user data is never transferred to a third party for that party’s own purposes.

7. Google API Services User Data Policy — Limited Use

Founder Dashboard’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In particular, Google user data is used only to provide and improve user-facing features of the app; it is not transferred except as necessary to provide those features, to comply with law, or as part of a merger or acquisition with prior notice; and no human reads it except with consent, for security purposes, to comply with law, or in aggregated, anonymised form.

8. Choices and rights

  • Each Google service can be connected or disconnected independently in Settings.
  • All access can be revoked from the Google Account permissions page.
  • A copy, correction or deletion of stored data can be requested by email.
  • Any additional rights under applicable local privacy law will be honoured.

9. Children

The app is a personal business tool and is not directed at, or used by, anyone under 18.

10. Changes to this policy

If how the app collects or uses Google user data changes, this page and the “last updated” date above will be updated before the change takes effect.

11. Contact

Akshay Maharaj · Toronto, Canada · akshay.yusuf@gmail.com

Privacy PolicyTerms of Service