Web App

Ownership, Access, and Continuity

FAQ on ownership, account access, portability, and continuity for existing managed workspaces.

Ownership, Access, and Continuity

For existing managed workspaces. The linked Terms, Privacy Policy, and Trust Center remain the sources for legal and security commitments.

1. Who owns my code, configurations, and other work? Does Cofounder retain any rights?

See License and Ownership in our current Terms of Service. That is the written ownership and license clause to review, including for investor or customer diligence. Account ownership, access, and the work needed to move a running service are separate operational questions covered below.

2. Who controls the accounts behind my workspace?

Resources provisioned under Cofounder's provider organizations are platform-managed. Connecting an account you already own does not by itself transfer that account to Cofounder.

ResourceStandard model
Managed GitHub repositoriesRepositories in a Cofounder-managed GitHub organization. Repository access is separate from ownership of the organization.
Managed Vercel projectsProjects in a Cofounder-managed Vercel team. Project access is separate from ownership of the team.
Managed SupabaseA project provisioned in a Cofounder-managed organization. An imported customer-owned project is a different arrangement.
Domains, registrar, DNSDepends on whether the domain was purchased or transferred through Cofounder, or connected from an outside registrar. Attaching a domain to a website does not establish registrar ownership.
Resend, Sentry, Google Cloud/OAuth, Lemon Squeezy, and other integrationsA provider's use by Cofounder itself does not establish that you have a separate account with that provider. Ownership and permissions depend on the account actually connected to your application. A service mentioned in a plan is not necessarily provisioned or active.

Use the managed-services guides, your connected integrations, and the Domains page to identify the applicable setup.

3. What direct access can I get, and can I use my own resources?

You can request access to your managed GitHub repositories. Repository access lets you work with and copy the code and Git history; GitHub administrator access is not included. Managed Vercel access requests are available from Settings > Advanced. An invitation must be accepted before it establishes access. Managed Supabase currently does not include a customer dashboard invitation.

Supported workspaces can import an existing GitHub repository or Supabase project. Follow the relevant guide; connecting one customer-owned resource does not transfer the rest of the managed stack.

4. Can Cofounder's systems or staff access my resources, including after launch?

Yes. Managed operations can require access to code and repository history, deployment configuration, database records, and credentials, including privileged database credentials. Encrypted credential storage does not mean the platform is unable to use the credential. Agents can use credentials made available to their execution environment. See Environment Files & Secrets.

Our staff access customer accounts only for support purposes. This access is limited to authorized internal administrators. Creating a support session requires a reason and records the administrator, target user, and session timing. This describes the support-session control; it is not a claim that every provider-console action, log read, or backup operation uses the same approval and audit mechanism.

Publishing your application does not itself revoke the access required to operate it. The Privacy Policy governs information use, sharing, and AI training.

5. How do I limit or revoke access?

For accounts you control, disconnect the integration in Cofounder and revoke its provider-side authorization when you want to end access. Remove unneeded repository/project grants and rotate credentials that should no longer work. For agent secret access, turn off Development environment for the relevant secret. Existing deployments or processes can retain previously supplied values until they are updated or restarted.

Managed infrastructure still needs platform access while Cofounder operates it. Complete a transfer or replacement of the relevant service before removing access it needs to run. Revoking a credential stops future use of that credential; it is separate from deleting previously stored data, logs, or backups.

6. Which privacy and security documents are available?

Our standard reference materials are the Terms of Service, Privacy Policy, and Trust Center.

We do not currently publish a standalone DPA, a complete subprocessor register and change-notification policy, a custom per-workspace data-flow inventory, or a managed-infrastructure SLA as part of the standard offering. The FAQ does not add those documents or commitments. Use the Trust Center for the security information and materials available there.

7. Who is responsible for vendor agreements, processing roles, and customer disclosures?

For Cofounder-managed services, Cofounder operates the managed provider resources. Customer-connected accounts remain under the customer's relationship with that provider. See Third Party Providers in the Terms of Service and Our Technology / Sharing Information in the Privacy Policy for the governing service and processing terms.

Whether your business needs a vendor DPA, a particular processing role, regional restrictions, international-transfer safeguards, or specific notices depends on your own use and agreements. These are not additional commitments supplied by this FAQ. For a Cofounder-managed service issue, contact our support team; for customer-owned accounts, use the provider's own support and notice channels as applicable. We do not supply a separate vendor-by-vendor contractual responsibility or international-transfer schedule through this FAQ. If a requirement is mandatory, identify that specific requirement before relying on the standard offering.

8. What can I take with me, and what is required to run independently?

Repository access lets you copy the code and Git history. Downloadable Library files and managed Vercel staging environment exports are also available. Downloading code alone does not move a database, its stored files, hosting accounts, or domain registration.

For an eligible configured marketing site, Settings > Advanced > Marketing site transfer provides a Vercel project transfer request. Transferring the product hosting, managed Supabase project/data, or domain registration must be resolved for the actual resources involved; the marketing transfer does not transfer the whole workspace.

Independent operation requires the corresponding provider accounts, data and files, deployment configuration, domain/DNS control, and replacement credentials. Once the destination works, revoke the old grants and rotate credentials. Confirm the available transfer/export method and any agreed assistance before cancelling or removing access.

9. What happens on cancellation, and what are the deletion, backup, and log-retention rules?

Subscription cancellation and company deletion are separate actions. See Billing, Credits and Payments and Termination in the current Terms of Service for service access, export, and deletion provisions.

A code download or credential revocation is not a deletion request. This FAQ does not add a separate backup/log-retention schedule or restoration guarantee. Any specific retention or recovery requirement needs an applicable published policy or an express agreement.

10. What support or additional contractual assurances are included?

For access, security, or offboarding questions, contact support. State the affected resource and the action you need. Support availability and obligations are governed by the Terms of Service; this FAQ does not promise a migration service, completion date, uptime SLA, or incident-notification deadline.

If your use requires the additional enterprise documents or contractual commitments described above, Cofounder's standard offering may not meet your needs. A public interest page, live pilot, or production launch does not add those commitments.