Legal

Privacy Policy

Effective date: July 31, 2026 (v1.0)

This policy explains how fiund ("we," "us") collects, uses, shares, and protects personal information when you use fiund.com and the fiund contributor portal. Contact for anything in this policy: jaeden@fiund.com.

What we collect

  • Account information — name, email address, and a hashed password when you create a portal account.
  • Contributor information — your survey responses about your content library (formats, volume, languages, rights status) and records of submissions you make.
  • Payout information — payee name, country, tax residency status, and payout account details. Sensitive payout fields (bank account, routing, IBAN, PayPal address) are encrypted at the application layer with AES-256-GCM before storage; only a masked summary (for example the last four digits) is kept readable.
  • Agreement records — when you sign the Contributor Licensing Agreement we record the agreement version, your typed signature, timestamp, IP address, and browser user-agent, because that record protects both sides.
  • Usage data — basic technical logs (IP address, pages requested, timestamps) generated by our hosting infrastructure, and privacy-conscious site analytics.

We do not use advertising trackers, and we do not use email tracking pixels that report whether or when you open our emails.

How we use it

To operate the marketplace: running your account, evaluating and cataloging submissions, matching content with buyers, paying you, meeting tax and accounting obligations, securing the Service, and communicating with you about your account and deals. We do not sell personal information, and we do not use your personal information to train AI models. (Content you license through fiund is used as described in the Contributor Licensing Agreement you sign — that is the point of the marketplace — but that concerns your licensed media, not your personal account data.)

Legal bases (GDPR)

Where the GDPR or UK GDPR applies, we process personal information on the basis of: contract performance (account, submissions, payouts), legal obligation (tax, accounting), legitimate interests (security, service improvement), and consent where required. Where data is transferred out of the EEA/UK we rely on Standard Contractual Clauses.

Who we share it with

We share personal information only with the service providers that run the platform:

  • Supabase — database and authentication (US region);
  • Vercel — website and portal hosting;
  • Amazon Web Services — content storage (S3);
  • payout and tax providers — to send payments and collect required tax forms (W-9 / W-8BEN);
  • professional advisers, and authorities where the law requires it.

Buyers never receive your account credentials or payout details. Where deal documentation requires identifying you as licensor, that is governed by the licensing agreements you approve.

Retention

Account and submission records are kept while your account is active. Signed agreement records, deal documentation, and payment records are kept as long as required for legal, tax, and audit purposes (typically seven years). You can request deletion of everything else at any time.

Your rights

Everyone: you can access, correct, or delete your information, or close your account, by emailing jaeden@fiund.com. We respond within 30 days.

EEA/UK (GDPR): you additionally have the rights to restrict or object to processing, to data portability, to withdraw consent, and to lodge a complaint with your supervisory authority.

California (CCPA/CPRA) and other US states: you have the right to know what personal information we collect, use, and disclose; to correct it; to delete it; and to non-discrimination for exercising those rights. We do not sell or share personal information as those terms are defined in the CCPA/CPRA, and we have not done so in the preceding 12 months, so there is no need for a "Do Not Sell or Share" opt-out. We honor these rights for residents of all US states with comparable privacy laws.

Security

Transport encryption (TLS) everywhere, encryption at rest on our database and content storage, application-layer encryption for sensitive payout fields, row-level security isolating every contributor's records, and invite-only portal access. Details on the security page. No system is perfectly secure; if we learn of a breach affecting your personal information we will notify you as required by law.

Children

The Service is not directed to anyone under 18, and we do not knowingly collect personal information from them.

Changes

We will post any changes here with a new effective date, and notify portal users of material changes in the portal.