Privacy
Last updated: October 6, 2026
Foundmost helps businesses get found on Google and in AI answers. This page says what we collect, why, who helps us, and how to have it deleted.
Who we are
Foundmost is a brand of Roni Shmuel (רוני שמואל), a licensed sole trader (עוסק מורשה) registered in Israel, at 6 Sheshet HaYamim Street, Bat Yam, Israel (ששת הימים 6, בת ים).
Roni Shmuel is the controller of the personal data described on this page.
For anything on this page, write to privacy@foundmost.com. We reply within 30 days.
Where your data is
Our servers are in the United States (Virginia). We are based in Israel, so your data is transferred out of Israel to be stored and processed there, under written agreements with each company that helps us.
When you check a website
- We read the address you type and up to 10 public pages of that site, as any visitor could. We send at most 12 requests, one per second, and we respect the site's robots.txt. Our scanner identifies itself as FoundmostBot and links back to this site. It runs no JavaScript, and it reads no page that robots.txt asks it not to.
- We keep the report so its link keeps working. It holds what we found on the public pages: titles, descriptions, tags, short excerpts of up to 160 characters including the opening paragraphs of pages, and the business details published on the site: the name, the type of business, the town, and a phone number if one appears in the site's structured data. If you run the business on your own, some of that is personal information about you.
- Anyone with the report's link can open it. The link does not expire on its own. We keep the report until someone asks us to delete it.
- To stop abuse we keep a scrambled code made from your IP address and the date. We never store the address itself, and the code changes every day.
- We also count which steps of the check you reached, with a random visitor code. See "What we count".
When you leave your email
- We use it to send what you asked for: a copy of your report, a confirmation link, the result of the deeper check, or the confirmation of a reserved spot.
- We keep your email address and the site you asked about. If you asked for the deeper check, we also keep a scrambled copy of the confirmation link's code, so the link can be used once.
- To stop anyone from flooding an inbox, we send at most 3 copies of a report a day to one address, and we keep the same daily scrambled code of the sender's IP address.
- We do not send marketing email. If you ticked the box offering it, that records only that you would be willing to receive it. Nothing is sent. Before we send anything of the kind, we will add a one-click way to opt out, and we will update this page first.
When you have an account
- Your email, to sign you in with a link. We keep no password.
- The sites you add, what each monthly check measured, and the changes we suggested, made or undid, so you can see the history and undo a change.
- The business facts you give us (name, what you do, where, phone, hours), which we use to write for your site.
- Your Google review link, if you add it, and how many times you tapped the share button, so "Your tasks" can count your progress. We never send messages to your customers: you send them yourself.
- If you connect WordPress: a signed key that lets our plugin make the changes you allowed. We never see your WordPress password. The key is worked out on your site and on ours and is never sent over the internet; our copy is encrypted. Our plugin can read your published posts and pages, and can make seven kinds of change, listed in the terms. It can never delete anything, publish anything, change your settings, your theme, your users or your site's code, or run code we send it.
- Every change keeps a copy of what was there before, so it can be undone. That copy is kept both on your own site and on our servers, so the undo still works if the plugin is removed.
- If you joined from an invite: which invite, and when your free month ends.
- If you send an invite, the note you write about who it is for is stored with it, and we can see it.
If you are in a regulated profession
If your site belongs to a regulated profession (medical, dental, legal and others), we keep a record of every piece of text we published for you: the text itself, where it was published, when it went up, when it came down, and who approved it, with their licence number.
We keep that record for seven years, because your professional body can ask you for it. An Israeli lawyer, for example, must be able to produce three years of advertising records counted from the date each advertisement stopped running.
This record survives the deletion of your site and of your account, because its whole purpose is to outlive them. Everything else about your account goes.
What we count
We count steps such as "check started" or "report opened", with a random visitor code stored in a cookie on this site for one year, and the campaign you came from. These counts hold no name and no email, but the visitor code is an identifier that can be linked to the site you checked, so we treat it as personal information.
Every cookie and stored value we set, in full:
fm_vid: a random visitor code. One year. Set the first time you start a check. Used only to count steps, and to limit how many report copies one visitor can request.- Sign-in cookies, set by Supabase, our database and login provider. Needed to keep you signed in; without them you cannot use an account.
- A note in your browser's own storage remembering which screen you were last on, and a note that a screen was already counted this visit. Neither leaves your browser.
We use no advertising cookies and no tracking cookies. We run no analytics at all on the pages where you use the product. On our guides and comparison pages we use Vercel Web Analytics, which counts visits and where they came from without cookies.
We show no cookie banner, because nothing we set needs your permission. If that changes, this page changes first, and we will ask.
Who helps us
- Hosting and database: Vercel and Supabase (servers in the United States). Supabase also sends your sign-in link, through Resend.
- Email: Resend, which receives the address we are writing to and what the message says.
- Payments: Sold through Link, LLC (formerly Lemon Squeezy), which sells the plans as the merchant of record and handles tax. Your card details go to them, never to us. We receive the plan, its status and your email. From the notices they send us we keep only what runs your plan: the plan, its dates and status, and your email, for two years. We never see or store a card number. The charge appears on your statement as LEMSQZY, not as Foundmost.
- Page speed: Google's PageSpeed and Chrome UX Report services, which receive the address of the page being checked.
- AI answers and Google results, for the deeper check and for subscribers: the questions we write about the kind of business are sent to OpenAI (ChatGPT), Perplexity, Google (Gemini), Anthropic (Claude) and DataForSEO (Google results). Anthropic's Claude also reads the answers and writes content for your site.
None of those services ever receives your email address or anyone's IP address. The questions are written so that they never name your business.
What they do receive, when we write text for your site, is up to 4,000 characters of the page we are writing about, together with the business facts you gave us, including your phone number. If that page contains a customer's story, a staff member's name, or anything else about a person, that text goes too. Each provider keeps what it receives under its own standard terms.
The page text we send for writing goes to Anthropic (Claude) only, under its commercial terms. Anthropic may not train its models on it, and it deletes what it receives within 30 days. Something it flags for breaking its usage policy can be kept for up to 2 years.
We also keep the answers these services give us, word for word, so we can show you what changed month to month. Those answers sometimes name other businesses.
Access to your accounts. When you give us access to your website, Google Search Console, Google Analytics or Google Business Profile, we use it only to do the work your plan includes: we read your search and visit reports, and we make the changes on your pages and profile. We never ask for a password, and you can remove our access in those services at any time.
We do not sell your personal information, and we do not share it for advertising. We never have. The companies above process it for us, on our instructions, and for nothing else.
How long we keep it
Apart from payment notices, we do not delete anything automatically. Everything below is kept until you ask us to delete it or the law requires us to stop:
- Reports and the scans behind them.
- An email you left for a report copy, a reserved spot or a deeper check, and the deeper check's results.
- The step counts and the visitor code.
- Your account's data, for as long as you have the account. When you remove a site, everything we measured and wrote for it goes with it, except the free scan report, which keeps its own link, and the regulated-profession record described above.
- Payment notices from our merchant of record, for two years. The invoices themselves are kept by the merchant of record, as accounting law requires.
If you would rather we did not keep something, ask, and we will delete it.
Your rights, and how to use them
Wherever you are, you can ask us to:
- show you what we hold about you,
- correct anything that is wrong,
- delete your report, your email or your whole account,
- send you a copy of your account's data in a file you can read.
Write to privacy@foundmost.com from the address we hold, or from your account. We reply within 30 days. There is no charge, and asking changes nothing about how we treat you.
If you are in Israel, these are your rights of access and correction under the Privacy Protection Law, and you can complain to the Privacy Protection Authority.
If you are in California, we are not large enough to be a "business" under the California Consumer Privacy Act, but we will honour a request to know, delete or correct exactly as above. We neither sell nor share personal information.
If you are in the European Economic Area or the United Kingdom, write to us and we will tell you plainly whether we think that law applies to your situation, and act accordingly.
Changes to this page
We may update this page. If a change matters to you, we will email you before it applies.
Roni Shmuel, a licensed sole trader registered in Israel, 6 Sheshet HaYamim Street, Bat Yam, Israel. Foundmost is a brand of Roni Shmuel.