Privacy Policy

Last updated October 10, 2026

This policy explains what WebflowX, operated by North Foundry (“we”), collects, why, and the choices you have. We do not sell your personal data.

1. What we collect

  • Account data: name, email, profile photo, title and bio; your sign-in method (password, Google or GitHub). Passwords are stored hashed, never in plain text.
  • Workspace content: messages, files, tasks, notes, documents, meeting records and transcripts, reactions, and workspace settings you or your teammates create.
  • Activity data: membership and role changes, audit log entries, notifications, and usage counts used to apply plan limits.
  • Newsletter: if you subscribe on our website, your email address, where you signed up, whether you confirmed, and the sign-up and unsubscribe times.
  • Technical data: basic logs such as IP address, device and browser type, used for security, rate limiting and troubleshooting.

2. How we use it

  • to send product updates and tips to people who subscribed and confirmed by email. Every email links to unsubscribe;
  • to provide and secure the Service, including real-time collaboration, search and notifications;
  • to send account emails such as verification codes and password resets;
  • to provide AI summaries and meeting transcripts you request;
  • to prevent abuse, enforce limits and fix problems.

3. Who sees your content

Your workspace’s owner and admins can access its content and the audit log. Members see what they have access to; locked channels are limited to the people added and to roles allowed to view them. Direct messages are visible only to the participants.

4. Service providers

We use trusted processors to run the Service. They handle data only on our instructions:

  • Convex — database, file storage and authentication backend;
  • Vercel — web hosting;
  • LiveKit — real-time audio and video for meetings;
  • Deepgram — live meeting transcription;
  • Groq — AI summaries and writing assistance;
  • Liveblocks — real-time document collaboration;
  • Resend — transactional and newsletter email;
  • Stripe — payments for paid plans;
  • Google, GitHub and Microsoft — if you choose to sign in with them.

The full list, with what each handles, is on the subprocessor page. Workspace data is stored in the United States; see Trust. Data may be processed in countries other than yours, with appropriate safeguards.

5. Retention

We keep your data while your account or workspace exists. Deleting a workspace removes its content; when you leave or are removed from a workspace, your channel messages and reactions stay in it under the name you had, marked as a former member: for 90 days on the Free plan, after which they are erased, and for as long as the workspace exists on paid plans, which keep full history. Your direct messages are removed when you leave. Backups and logs expire on their regular schedule. Meeting AI-usage records are kept for plan accounting.

6. Your rights and choices

You can edit your profile at any time and export your data from the Service (your own data from your profile menu; workspace owners and admins can export the workspace). Depending on where you live, you may also have the right to access, correct, delete or restrict the use of your personal data, or to object to it. To exercise a right we cannot satisfy in the app, email support@northfoundry.co.

7. Security

We use encryption in transit, role-based access, rate limiting and an audit log to protect your data. No system is perfectly secure, so use a strong, unique password and report anything suspicious to us.

8. Children

The Service is not directed to children under 13, and we do not knowingly collect their data.

9. Changes and contact

We will post updates here and, for material changes, notify you in the Service or by email. Contact: support@northfoundry.co. See also our Terms of Service.