Legal

Privacy Policy

Effective August 8, 2026.

This Privacy Policy explains what personal data Dataset Foundry (registered in Ghana) collects, why, and what rights you have over it. It applies to everyone who uses the Service, regardless of where you're located.

1. What we collect

Account data: your email address, a hashed password (we never store your password in plain text), and your account creation/verification status.

Anti-abuse data: the IP address you register from, and a device/browser fingerprint computed at signup — used only to detect and correlate repeat signups attempting to bypass the free-tier allowance or rate limits.

Usage data: a log of your generation activity (rows generated, action type, timestamp) — this is what powers your own usage history and, for institutional accounts, an admin's visibility into their organization's pooled usage.

Payment data: when you buy rows or subscribe, Paystack processes your payment directly. We receive and store only transaction metadata (amount, reference, status, plan) — never your card number, CVV, or full Mobile Money details.

Generation configuration: the settings you use to generate a dataset (seed, row count, advanced-parameter overrides), so we can support regenerate/edit-reapply and so your dataset manifest is reproducible.

Institutional data: for institutional/enterprise accounts, we additionally hold seat membership, per-member usage logs, and invoice/PO records for that institution's billing admin to review.

We do not collect government ID numbers, biometric data, or any real individual's insurance/claims data as an input to our generation process — the datasets the Service produces are synthetic and don't describe any real person.

2. Cookies & tracking

Dataset Foundry does not use cookies or third-party analytics or advertising trackers. Your login session is kept in your browser's local storage, not a cookie, and is used solely to authenticate your own requests to our API.

3. Why we collect it, and our legal basis

  • To provide the Service you've asked for (contract performance): account data, generation configs, payment data.
  • To prevent abuse of the free-tier and rate-limit allowances (legitimate interest): IP address, device fingerprint.
  • To meet our own legal/accounting obligations: payment and invoice records.

4. Who we share it with

  • Paystack — processes all payments; see Paystack's own privacy policy for how they handle your payment details.
  • Our hosting and email-delivery providers — process data as needed to run the Service (e.g. sending your verification email); they don't use your data for their own purposes.

We do not sell personal data, and don't share it with advertisers.

5. How long we keep it

  • Account data: for as long as your account is active, plus a reasonable period afterward for legal/accounting purposes.
  • Generated dataset files: cached for 24 hours on the free tier, 30 days on Pro, then deleted — see the Methodology page for specifics. Your generation configuration (not the output file itself) is kept longer so you can regenerate it.
  • Usage logs: kept for as long as needed for security, billing accuracy, and dispute resolution.

6. Your rights

Wherever you're located, you can ask us to:

  • access the personal data we hold about you,
  • correct inaccurate data,
  • delete your account and associated personal data, subject to what we're required to retain for legal/accounting reasons,
  • export your data — your generated datasets are already yours to download directly.

If you're in Ghana, these rights are additionally guaranteed under the Data Protection Act, 2012 (Act 843). We aim to honor equivalent requests from users anywhere, even where not legally required to.

To exercise any of these, contact privacy@datasetfoundry.org.

7. International data transfers

Our hosting provider may process data outside Ghana. Where that happens, we rely on our provider's own security and contractual safeguards.

8. Children

The Service isn't directed at anyone under 18. If we learn a minor has created an account, we'll close it.

9. Security

Passwords are hashed, never stored in plain text. Payment details never touch our servers directly — Paystack's hosted checkout handles them. Access to institutional/audit data is restricted to that institution's own admins and to us for support purposes.

10. Changes to this policy

We'll post updates here with a new effective date, and email account holders about material changes.

11. Contact

privacy@datasetfoundry.org