legal
Privacy Policy
Last updated: August 25, 2026
This policy explains how Federated Unified Worker Network Inc collects, uses, shares, protects, and deletes information across the Spark iOS app and MyFounders AI service.
Scope and who we are
Federated Unified Worker Network Inc operates Spark, the MyFounders AI iOS application, website, and related services. This policy applies to the Spark mobile app and the MyFounders AI service at myfounders.ai.
You can contact us at hello@myfounders.ai about privacy, safety, account, AI memory, or deletion questions.
Information we collect
Account and identity information includes your email address, Sign in with Apple or other authentication identifiers, account and profile identifiers, display name, preferred language, authentication sessions, and account status.
Profile and user content includes information you submit to profiles, projects, Communities, Challenges, AI characters, updates, comments, check-ins, calendars, reports, blocks, messages, files, images, video, audio, links, and creator or membership settings.
AI information includes prompts, profile or project facts, saved memory, drafts, answers, and other content you intentionally send to an AI feature. AI output and your edits or approvals may also be stored.
Career and application information includes job preferences, saved or hidden jobs, application status, private career-foundation material, resumes, knowledge files, follow-up answers, and generated application documents that you choose to create or store.
Communications and safety information includes conversation participants, message and delivery metadata, reports, moderation decisions, content hashes, enforcement actions, and communications with support. Encrypted message content is treated as described below.
Technical information includes IP-derived information, request timestamps, page paths and referrers, browser or device type, app version and build, iOS version, device model, crash or error information, security events, push-notification tokens, and product analytics events.
Sources of information
We receive information directly from you; automatically from the app, website, browser, and device when you use Spark; from other members when they interact with you or report content; and from authentication, payment, hosting, analytics, email, safety, and other service providers.
Job listings and related employer information may come from public government sources, employer career sites, applicant-tracking-system feeds, and job-data providers. A public job listing is kept separate from your private job preferences, saved-job activity, and application materials.
Device permissions
Spark may request access to the camera, microphone, photo library, speech recognition, and notifications when you choose a feature that needs them. Camera, microphone, photos, and speech recognition are used to create, select, save, or caption content. Notification permission is used to deliver alerts you enable.
You can refuse or later change these permissions in iOS Settings. Some related features will not work without the applicable permission.
Cookies, browser storage, and website analytics
The website uses cookies and local browser storage for authentication, security, language and automatic-translation preferences, interface settings, and continuity between pages. Removing this storage or blocking required cookies may sign you out or reset those choices.
The website uses Vercel Web Analytics for aggregate page-view information such as page path, referrer, approximate location, browser, operating system, and device type. It is configured through Vercel's analytics integration and does not use third-party advertising cookies. We do not use website activity for cross-site behavioral advertising.
Public content and sharing with other members
Content you publish to a public profile, Project, AI character, Community, Challenge, update, comment, check-in, or other public area can be viewed, copied, shared, or interacted with by other people according to that feature's visibility settings.
Member-only and private content is shown to the people authorized for that area. Creators and moderators may receive information needed to manage memberships, posts, reports, and access.
Do not submit information about another person unless you have the right to do so. Removing content does not necessarily remove copies another person already saved or shared outside Spark.
Messages and encryption
Certain direct and group conversations use end-to-end encryption. For those conversations, Spark's server stores encrypted message envelopes, delivery information, conversation membership, and public device-key material, but is not designed to receive the plaintext message body or private encryption keys.
The first-party app may apply an on-device safety check before encrypting a message and send a short-lived hash-based moderation attestation. The attestation does not contain the plaintext message. Message metadata, reports, participant actions, public rooms, legacy messages, or conversations not identified as end-to-end encrypted may be processed by the service as needed to operate and protect them.
End-to-end encryption does not prevent recipients from saving, forwarding, reporting, or otherwise sharing content they receive.
AI, saved memory, and moderation
When you use an AI feature, content you submit may be sent to OpenAI or another identified AI provider to generate, classify, summarize, moderate, or transform content. Do not submit sensitive information that is not needed for the feature.
Saved memory means profile, Project, AI-character, account, and preference information retained so AI and account features can work later. AI suggestions do not become public merely because they were generated; publication depends on the action and visibility settings you choose.
Public and group user-generated text and media may be checked before publication for sexual, violent, hateful, threatening, self-harm, illegal, or other prohibited content. Spark may use local rules, OpenAI moderation, on-device Apple Sensitive Content Analysis when enabled by the device, server-side media review, and human review. Moderation records may contain a content hash, categories, scores, actor and subject identifiers, timestamps, and the decision rather than the full moderated text.
How we use information
We use information to create and secure accounts; operate profiles, discovery, chat, Communities, Challenges, Projects, AI characters, jobs and application tools, calendars, notifications, creator tools, support, and payments; personalize language and access; provide AI features; prevent abuse; moderate content; analyze reliability and product usage; comply with law; and enforce our Terms.
We do not sell personal information or use it for third-party cross-context behavioral advertising. Spark does not use Apple's advertising identifier for tracking.
Legal bases for processing
Where laws such as the GDPR or UK GDPR require a legal basis, we process information as needed to perform our contract with you and provide requested features; with consent for optional permissions or processing where consent is required; to comply with legal obligations; and for legitimate interests such as securing and improving Spark, preventing fraud and abuse, supporting users, enforcing rules, and protecting users and the public, provided those interests are not overridden by your rights.
You may withdraw consent for future processing where we rely on consent. Withdrawal does not affect processing that was lawful before withdrawal, and some features may no longer work. We do not use personal information to make solely automated decisions that produce legal or similarly significant effects about you.
Service providers and disclosures
We use service providers to operate Spark, including Supabase for authentication, database, realtime, and storage services; Vercel for hosting, server execution, operational logs, and website analytics; OpenAI for AI and moderation processing; PostHog for iOS product analytics; Stripe for payment processing, subscription management, and connected-account payouts; Cloudflare Stream for delivery of supported public video; Resend for verification, password-reset, security, and safety email; and Apple for Sign in with Apple, App Store services, device features, and push notifications.
PostHog analytics may use an app-generated anonymous identifier before sign-in and an account identifier after sign-in, together with event names, app/build information, iOS version, device model, locale, profile status, and aggregate feature counts. We do not intentionally include message bodies or uploaded media in analytics events.
Where a provider processes user data on our behalf, our agreements require it to use the data for services it provides to us and to protect the data consistently with applicable law and the protections described in this policy. Providers that act as independent controllers for some payment, App Store, or similar functions also process information under their own privacy policies.
We may disclose information when required by law; to protect users, the public, our rights, or the service; to investigate fraud or abuse; with your direction; or in connection with a merger, financing, acquisition, reorganization, or sale of assets subject to appropriate safeguards.
Payments
When payment features are offered, Stripe, Apple, or another provider identified in the transaction flow may collect payment credentials, billing information, transaction identifiers, subscription and promotion status, and fraud-prevention information. Spark receives transaction, promotion-code, and entitlement information needed to provide access, support creators, account for fees, prevent repeated promotional use, handle refunds, and maintain financial records. We do not receive or store full payment-card numbers entered into Stripe or Apple payment interfaces.
Retention, account deletion, and security
We retain information for as long as reasonably necessary to provide Spark, keep accounts secure, meet legal and financial obligations, resolve disputes, enforce agreements, and maintain safety records. Retention varies by data type. For example, transaction, fraud, moderation, report, and audit records may be retained longer than ordinary profile content when legally or operationally necessary.
You can delete your account from Account Settings on the website or initiate deletion in the iOS app. Account deletion removes the account, profile, and account-owned storage handled by the deletion process, subject to required financial, fraud, moderation, dispute, and legal records; limited backups; and messages or shared records that remain necessary for other participants, safety, or legal obligations. Retained shared records are separated from the deleted profile where supported. For Sign in with Apple accounts, Spark attempts to revoke Apple authorization during deletion and tells you if manual removal in Apple Account settings is required.
We use reasonable administrative, technical, and organizational safeguards, including access controls and encryption where appropriate, but no internet service can guarantee absolute security.
Your choices and privacy rights
You can edit many profile, private-memory, and creator fields; manage visibility and notification settings; leave Communities and conversations where supported; block members; delete content where available; and delete your account through website Account Settings or the app. You can also limit device permissions in iOS Settings and clear website cookies or browser storage through your browser.
You may request access, correction, deletion, or a copy of information associated with you by emailing hello@myfounders.ai. We may need to verify your identity, and legal, security, fraud-prevention, or other exceptions may apply.
Residents of California and other jurisdictions may have additional rights, including rights to know, access, correct, delete, obtain a portable copy, limit certain sensitive uses, opt out of sale or sharing where applicable, and receive equal service when exercising privacy rights. We do not currently sell personal information or share it for cross-context behavioral advertising.
Depending on where you live, you may also have rights to object to or restrict processing, withdraw consent, and appeal our response. EEA and UK residents may complain to their local data-protection authority. If we deny a request, you may reply to our response to ask us to reconsider where applicable law provides an appeal right.
International processing
Spark and its service providers may process information in the United States and other countries where they operate. Those locations may have different data-protection laws from your location.
Where applicable law requires a transfer mechanism, we use an applicable adequacy decision, contractual safeguards, or another lawful transfer mechanism. Contact us if you want more information about safeguards that apply to your information.
Children
Spark is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child submitted personal information, contact us so we can review and delete it where appropriate.
Changes and contact
We may update this Privacy Policy as Spark and applicable law change. The effective date above identifies the latest version. Material changes may also be communicated in the app or through another reasonable channel.
Questions or requests can be sent to hello@myfounders.ai.