FoundName Start

Privacy policy

How FoundName handles data: no account, no cookies as long as you do not allow ads, and clearly named external check services.

Last updated: September 2026 · Deutsch

1. Controller

Silvio Lindstedt und Maik Gräfendorf, GbR
Pappelweg 27
39576 Stendal, Germany
E-mail: kontakt@silvio-und-maik.de

2. Principle: an account is optional

FoundName works without a user account, without a login and without a password. Without an account, no personal account data is collected; only if you buy Pro do we store your e-mail address (see section 7). If you want your projects and favorites on every device, you can create an account voluntarily (see 3.8).

3. Data processing during use

3.1 Run history (name generation)

When you start a run, we store in a database on our server: the random seed used, the number of names requested, optional theme/style words, timestamps and the generated names together with their check results (App Store, domains, Play Store). This enables the “History” feature, so you can look at an earlier run again without repeating the live checks. This data contains no information about you as a person. So that only your own runs appear in the history, your browser creates a random, non-personal identifier on your first visit (stored in localStorage, see 3.5), which is sent with every request; the history is filtered on the server by this identifier, so other visitors cannot see your runs and vice versa. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in the core function of the tool). For each identifier, only the last 50 runs or runs no older than 90 days are kept — older entries are deleted automatically.

3.2 IP address (abuse protection)

To protect against abuse (bot/spam protection), your IP address is processed briefly in a server-side rate limiter to limit the number of requests per period. It is not stored permanently and no profiling takes place. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in a working service protected against abuse).

3.3 Live availability check

For every generated name, an availability request is sent to external services: the iTunes Search API (Apple, USA) for the App Store check, public DNS resolvers and domain registries (RDAP) for the domain check, and a Play Store query (Google). Only the generated name is transmitted — no data that identifies you as a person. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in the core function of the tool). Where data is transferred to the USA (Apple, Google), this is based on appropriate safeguards under Art. 46 GDPR.

3.4 Optional AI idea extraction

If you enter a free-text description of your app idea in the input field, this text is sent to OpenAI, L.L.C. (USA) to derive fitting theme words from it. This feature is entirely optional and is only triggered when you enter a text yourself or select a style tag. Theme words that have already been recognised are cached anonymously in a word pool, so similar requests can be served later without another external call. Legal basis: Art. 6(1)(a) GDPR (your consent by actively entering the text or selecting a style tag). Where data is transferred to the USA, this is based on appropriate safeguards under Art. 46 GDPR.

AI logos (Pro). When you create a logo in a name's details, the name, the three brand colors of its palette, the chosen style tags and, if you enter them, your own logo idea and the description of your app idea are sent to OpenAI, L.L.C. (USA), which returns an image. Our server converts this image into a vector graphic and stores it together with the prompt it was made from (including your idea), your random history identifier (3.1) and a hash of your Pro key, so you find your logos again and the monthly allowance can be counted. Nothing is sent unless you start the creation yourself. Legal basis: Art. 6(1)(b) GDPR (providing the Pro feature you requested). Where data is transferred to the USA, this is based on appropriate safeguards under Art. 46 GDPR.

3.5 Local storage (localStorage)

For display settings (light/dark mode, language, sorting/filters, favorites) and the random history identifier from 3.1, only your browser’s localStorage is used. The identifier itself does not leave your browser — it is only sent along with requests to our server to assign your own history.

3.6 Name projects, notes, presets and API keys

If you create a name project, name a run, write a note, save a word list or style preset or create an API key, we store this information on the server together with the random identifier from 3.1, so that only your browser can retrieve it again. Of API keys we store only a cryptographic hash and the first characters for recognition, never the key itself. Please do not enter personal data in project briefs and notes. You can delete or revoke projects, presets and keys yourself at any time. Legal basis: Art. 6(1)(b) or (f) GDPR (providing the features you use).

3.7 Shared shortlists, votes and comments

If you share a shortlist, we create a public link that cannot be guessed, with a snapshot of the selected names. Anyone who opens the link can vote without signing in and leave a comment with an optional display name; for this we store the vote or comment text, the name given voluntarily, a timestamp and a random browser identifier (against multiple votes). Comments can be seen by anyone who knows the link and by the person who shared the shortlist. Shared shortlists are not listed publicly and are blocked for search engines (noindex). Legal basis: Art. 6(1)(a) GDPR (your voluntary input) and Art. 6(1)(f) GDPR (abuse protection).

3.8 Optional user account

You can create an account with your e-mail address and a password, or sign in with Google or GitHub. We then store your e-mail address, a cryptographic hash of your password (never the password itself), your display name if the provider supplies one, whether the address is confirmed, the time of your last login and, for Google/GitHub, the provider’s user ID. Everything this browser created before you signed in (projects, searches, favorites, brand profiles, presets, API keys) is assigned to your account, and a Pro license activated or bought while signed in is bound to it. To keep you signed in we set one technically necessary cookie (fn_session, HttpOnly, valid for 21 days after your last visit, no tracking); it holds a random session ID only. We send e-mails solely to confirm your address and to reset your password; the links in them work once and expire after 24 hours (confirmation) or one hour (reset).

If you sign in with Google or GitHub, your browser is forwarded to that provider, which tells us your confirmed e-mail address, your name and a user ID under its own privacy policy (Google, GitHub). We do not receive your provider password and no further data. You can delete your account yourself at any time under Settings → Account; this removes the account with all its projects, searches, favorites and profiles. A purchased Pro key keeps working on its own. Legal basis: Art. 6(1)(b) GDPR (providing the account you requested).

4. Hosting

This website is hosted by netcup GmbH, Karlsruhe, Germany. The host collects information that your browser transmits in server log files (IP address, time, page accessed). Legal basis: Art. 6(1)(f) GDPR (legitimate interest in providing the website).

Between your browser and the server sits the network of Cloudflare, Inc. (101 Townsend St., San Francisco, CA 94107, USA) as a reverse proxy and protection against attacks. All requests pass through Cloudflare, which processes your IP address and the technical data of the request to deliver the page and to fend off abuse. Cloudflare also forwards e-mails to addresses at foundname.app to our mailbox. A data processing agreement is in place with Cloudflare; transfers to the USA are based on the EU-US Data Privacy Framework, under which Cloudflare is certified, or on standard contractual clauses. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in secure and fast delivery). More information: cloudflare.com/privacypolicy.

5. Cookie-free web analytics (Matomo)

This website uses the self-hosted, cookie-free web analytics software Matomo (tracking address: matomo.silvio-und-maik.de) to create aggregated, anonymous usage statistics. No cookies are set and no information is stored on or read from your device; because tracking is cookie-free and IP-anonymised, no consent and therefore no cookie banner is required under § 25 TDDDG (German Telecommunications Digital Services Data Protection Act). Among other things, the anonymised IP address, browser and device type, screen resolution, language, region of origin, the referrer and the pages visited are recorded. There is no profiling, no cross-device tracking and no disclosure to third parties. Legal basis: Art. 6(1)(f) GDPR. You can object to this processing at any time (Art. 21 GDPR) — to do so, activate the opt-out option in the following box.

The opt-out box is loaded by Matomo. If it stays empty here (e.g. because of a script blocker), no tracking takes place, or you can set the objection directly at matomo.silvio-und-maik.de.

6. Advertising (Google AdSense) – only with consent

The tool is financed by ads from Google AdSense (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland). Ads are loaded only if you choose “Allow ads” in the notice on your first visit. Only then is the AdSense script loaded; cookies or similar technologies may be used and data such as your IP address and device information may be transmitted to Google, including to the USA (basis: EU-US Data Privacy Framework or standard contractual clauses under Art. 46 GDPR).

Visitors from the EEA, the United Kingdom and Switzerland are then shown Google’s own consent dialog certified under the IAB Transparency & Consent Framework (TCF) (Google’s “Privacy & messaging”). There you decide whether and for which purposes (e.g. personalised ads based on interest profiles, measuring ad performance) Google and its advertising partners may process your data. Without consent to personalisation you receive non-personalised or limited ads. Google stores your choice in a cookie on this domain; you can change or withdraw it at any time via the “Privacy and cookie settings” link shown by Google. More information: policies.google.com/technologies/ads.

The free offer is financed by these ads; the generator and the name check can therefore only be used if you allow ads. An ad-free alternative is a Pro key – with it, no ads are loaded. Without consent and without a Pro key, no ads are loaded either and no data is sent to Google; the information pages remain readable. Legal basis: Art. 6(1)(a) GDPR and § 25(1) TDDDG (your consent). Your decision is stored only in your browser’s localStorage. You can withdraw it at any time with effect for the future by choosing “Withdraw consent” in the settings or by deleting your browser’s site data; the generator and the name check are then locked until you consent again or use Pro.

So that the lock also applies on the server, the server issues a signed consent token after your consent. It is bound to the random identifier from 3.1, valid for 30 days and kept in your browser’s localStorage. It contains no data other than this identifier and is deleted when you withdraw consent. In addition, after your consent the page checks locally in the browser whether the ads are being prevented by an ad blocker; the result is neither transmitted nor stored. Legal basis: Art. 6(1)(b) and (f) GDPR (providing the ad-financed offer).

7. FoundName Pro and payment processing (Paddle)

You can buy Pro as 12-month access or with an amount of your choice for 3 months, each as a one-time payment without a subscription. The sale is handled by Paddle.com Market Limited (30 Old Bailey, London EC4M 7AU, United Kingdom) as reseller (“merchant of record”): Paddle is your contractual partner for the payment, issues the invoice and pays the VAT. This site opens the checkout in an embedded Paddle window; for this, a script from cdn.paddle.com is loaded when you buy. You enter your e-mail address, your country and your payment details directly with Paddle; we receive no card or account data. For the United Kingdom there is an adequacy decision of the EU Commission; transfers by Paddle to the USA are based on the EU-US Data Privacy Framework or on standard contractual clauses. From Paddle we receive the payment confirmation, a transaction and customer ID and your e-mail address. From this we store your Pro key (only as a hash and encrypted for the one-time display and e-mail delivery), the term, the Paddle IDs and your e-mail address, to which we send the key. You can find purchases and invoices in Paddle’s customer portal (Settings → “Purchases & invoices”). Storage period: We keep this order data (e-mail address, key hash and encrypted key, term and Paddle IDs) for the term of the licence and delete it 12 months after the licence expires or is revoked, unless we are subject to a statutory retention obligation. Invoices and payment records are kept by Paddle as the seller (merchant of record) in line with the statutory obligations that apply to Paddle. Legal basis: Art. 6(1)(b) GDPR (performance of a contract) and Art. 6(1)(c) GDPR for retention obligations under tax and commercial law. More information: paddle.com/legal/privacy.

8. Your rights

You have the right at any time to:

Contact for data protection requests: kontakt@silvio-und-maik.de

9. Changes

We reserve the right to amend this privacy policy to adapt it to changes in the law or in the service. You can always find the current version on this page.