Privacy Policy
Version 1.0 · Effective 8 August 2026
This Privacy Policy explains how TALLUM FOUNDRY SPÓŁKA Z OGRANICZONĄ ODPOWIEDZIALNOŚCIĄ processes personal data through ideadrive.ai and the IdeaDrive web application (together, "IdeaDrive").
1. Controller and contact details
The data controller is:
TALLUM FOUNDRY SPÓŁKA Z OGRANICZONĄ ODPOWIEDZIALNOŚCIĄ
Floriańska St. 6, Unit 02
03-707 Warsaw
- KRS: 0001252744
- NIP: 5214172327
- EU VAT: PL5214172327
- REGON: 54523141800000
- Email: info@tallumfoundry.com
No Data Protection Officer (DPO / IOD) has been appointed. Privacy requests should be sent to the email address above.
2. Scope and role of IdeaDrive
IdeaDrive is an AI-assisted SaaS product that helps users generate, structure, score and compare startup ideas. It uses information provided by a user, including a Startup Profile and idea-related inputs, to generate and evaluate possible business concepts.
IdeaDrive is intended as a decision-support tool. It does not make decisions that produce legal or similarly significant effects for users, and its outputs are not legal, tax, financial, medical or other professional advice.
3. Personal data we process
Data received during authentication
IdeaDrive supports Google OAuth, Twitter/X OAuth and email magic-link authentication through Supabase Auth. Depending on the method, provider and user settings, we may receive:
- provider account identifier;
- email address and email-confirmation status;
- display name, first name and last name, or a combined name where the provider does not return them separately;
- profile image or avatar;
- authentication provider and session metadata;
- login timestamps and security information.
IdeaDrive uses OAuth only to authenticate the user and create or link an account. We use the provider identifier, email, name and profile image or avatar for authentication and account setup. We do not use OAuth to access posts, contacts, followers, advertising profiles or other social-network content.
IdeaDrive does not receive or store a user's Google or Twitter/X password. Google sign-in uses the standard openid, email and basic-profile scopes required by Supabase Auth. X sign-in uses Supabase's X OAuth 2.0 provider with email access enabled and no additional application-requested permissions beyond authentication and basic user lookup. A magic-link user receives a one-time, time-limited authentication link through Resend; IdeaDrive does not create an application-owned password.
Account and profile data
We may process:
- display name, avatar, first and last name, email-confirmation state and notification preferences;
- professional background, experience and startup history;
- skills, preferred industries/domains and product types;
- available time, potential budget, goals, motivation and risk tolerance;
- account plan, token balance and token activity.
User content and AI data
We process content entered, saved or generated through IdeaDrive, including:
- startup ideas, descriptions, value propositions and target audiences;
- prompts, questionnaire answers, briefs, assumptions, URLs and related inputs;
- generated ideas, normalized content, scores, explanations, recommendations and other AI outputs;
- user edits, overrides, rankings, shortlist decisions and feedback.
Users should not submit health data, biometric or genetic data, political or religious beliefs, criminal-offence data, confidential third-party data, trade secrets they are not authorized to disclose, or other special-category or highly sensitive information.
Payment and transaction data
Stripe processes payment-card data through Stripe-hosted checkout. IdeaDrive does not receive or store full card numbers, card security codes or payment credentials. We may receive and retain:
- Stripe customer, checkout and transaction identifiers;
- purchase amount, currency, VAT/tax information and payment status;
- billing name, address and tax/VAT identifiers where provided;
- package, token allocation, refund, dispute and chargeback information;
- the immediate-performance consent text or version, timestamp, account and order or checkout identifier;
- invoices and accounting records.
Communications and support data
We process emails, support questions, legal/privacy requests, feedback, unsubscribe requests and related correspondence. Resend processes recipient information, message content, delivery metadata and email-event logs to send transactional, authentication and marketing messages.
Technical, usage and analytics data
We may collect:
- IP address, user agent, browser, device, operating system and approximate location derived from network information;
- page or screen views, clicks, feature events, session duration, referral and campaign information;
- authentication, scoring, generation, token and payment event logs;
- timestamps, error codes, diagnostic, security and fraud-prevention data;
- cookie-consent selections and identifiers stored through cookies or local storage.
Amplitude provides product analytics from a United States data center. Optional analytics technologies are used only after any consent required by applicable law. IdeaDrive does not use an advertising or conversion-tracking integration at launch.
4. How we obtain data
We obtain personal data:
- directly from users;
- from Google or Twitter/X when the user selects OAuth login;
- automatically from the user's browser, device and use of IdeaDrive;
- from Stripe in connection with checkout and payments;
- from service providers that help operate, secure, measure and communicate through IdeaDrive.
5. Purposes, legal bases and retention
| Purpose | Legal basis under GDPR | Retention baseline |
|---|---|---|
| Create and authenticate accounts; maintain sessions | Performance of a contract or steps requested before entering a contract; legitimate interests in account security | For the life of the account; expired Supabase sessions are cleaned up under provider/configuration rules |
| Provide the Startup Profile, idea workspace, scoring and AI features | Performance of a contract | Until account deletion or earlier user deletion where supported |
| Process token purchases, record immediate-performance requests and provide digital services | Performance of a contract; compliance with consumer-law obligations; establishment, exercise or defence of legal claims | Transactional and consent evidence for the applicable statutory limitation and mandatory record-keeping periods |
| Process payments, invoices, VAT and accounting | Performance of a contract and legal obligations | For the period required by Polish accounting and tax law |
| Security, abuse prevention, debugging and service reliability | Legitimate interests in protecting users, systems and legal rights | Technical, security, scoring and token audit logs: up to 12 months, unless longer retention is necessary for an incident, dispute or legal obligation |
| Vercel hosting and runtime diagnostics | Performance of a contract; legitimate interests in service delivery, security and debugging | Vercel Runtime Logs follow the active plan's standard window and are retained for no more than 30 days; no separate Vercel Log Drain is planned |
| Product analytics through Amplitude | Consent where required | User-level and event-level data: 12 months; aggregated or de-identified reports may remain available |
| Transactional and authentication email | Performance of a contract; legitimate interests in security and service communication | For as long as needed to deliver, document and troubleshoot the communication, subject to Resend's service retention |
| Marketing email | EEA recipients: consent. US recipients: legitimate interests in direct marketing, subject to CAN-SPAM and the recipient's right to opt out. Suppression records: legal obligations and legitimate interests in respecting opt-outs | Until consent is withdrawn or the user unsubscribes; a minimal suppression record may be kept to respect the opt-out |
| Support, feedback and legal/privacy requests | Performance of a contract, legitimate interests and legal obligations, depending on the request | For as long as needed to handle the request and establish, exercise or defend legal claims |
| Legal claims, fraud, chargebacks and authority requests | Legal obligation and legitimate interests | Until resolution and expiry of the applicable limitation period |
We do not retain identifiable personal data longer than reasonably necessary for the stated purpose, subject to mandatory legal obligations and provider-specific technical deletion cycles.
6. Account deletion and backups
When a user confirms account deletion, IdeaDrive deletes the account and associated active application data promptly; in normal operation this is intended to occur immediately. Exceptions apply to transaction, tax, fraud, dispute or other records that must be retained by law or are necessary to establish, exercise or defend legal claims.
Residual copies of deleted database data may remain in Supabase daily backups for up to 7 days, after which the relevant backup expires or is overwritten. Data separately retained by processors may follow their documented deletion cycles or mandatory legal requirements.
IdeaDrive does not provide a self-service pre-deletion export at launch. This does not limit statutory rights of access or portability. Where applicable, a user may request a copy of personal data or recovery of qualifying non-personal content by emailing info@tallumfoundry.com.
7. AI processing
IdeaDrive may send startup ideas, prompts, relevant Startup Profile context and generated or intermediate content to OpenAI and Anthropic APIs. We seek to exclude direct identifiers such as names and email addresses unless technically necessary.
- OpenAI states that API data is not used to train its models unless the customer explicitly opts in. Default abuse-monitoring logs may contain prompts and responses and may be kept for up to 30 days, subject to endpoint-specific storage and legal/security exceptions.
- Anthropic states that commercial API inputs and outputs are not used for model training unless the customer opts in and are deleted from its backend within 30 days by default, subject to agreed exceptions, usage-policy enforcement and law.
IdeaDrive does not authorize either provider to use IdeaDrive customer content for model training and will not opt in without updating this Policy and any required notices or consents.
EU AI Act transparency. Tallum Foundry acts as a deployer of third-party AI systems supplied by OpenAI and Anthropic. IdeaDrive informs users that they are using an AI-enabled service and that AI Outputs are machine-generated. AI-generated content is identified in the interface. IdeaDrive provides any disclosure required of a deployer by Article 50 of Regulation (EU) 2024/1689 (EU AI Act) and does not intentionally remove provider-supplied machine-readable markings from AI Outputs. Article 50 applies from 2 August 2026.
AI outputs may contain errors or omissions. They are reviewed and acted upon by the user and do not constitute automated decision-making with legal or similarly significant effects under Article 22 GDPR.
8. Recipients and processors
| Provider | Main role | Location / transfer context |
|---|---|---|
| Supabase | Authentication, PostgreSQL database, sessions and application storage | Project in us-east-1, Northern Virginia, United States |
| Vercel | Web hosting, global CDN / Edge Network, deployment, Vercel Functions and runtime diagnostics | Static files are distributed globally; Vercel Functions use the default iad1 region in Washington, D.C., United States; other global network processing may occur as needed to deliver the site |
| Google OAuth | Global, including the United States | |
| Twitter/X | Twitter/X OAuth | United States / global infrastructure |
| Stripe | Hosted checkout, payments, billing and fraud prevention | Applicable Stripe entity and global infrastructure |
| Resend / Plus Five Five, Inc. | Magic-link, transactional and marketing email delivery | United States |
| OpenAI | AI generation and analysis | United States and other configured service locations |
| Anthropic | AI generation and analysis | United States and other configured service locations |
| Amplitude | Product analytics | United States data center |
We may also disclose data to professional advisers, auditors, insurers, authorities or courts where necessary and legally permitted, or in connection with a merger, financing, reorganization or sale of the business subject to appropriate safeguards.
We do not sell personal data for money, share it for cross-context behavioural advertising or process it for targeted advertising. Users can record an opt-out through Do Not Sell or Share My Personal Information or a supported Global Privacy Control signal, as described in Section 15. That choice will apply before any such processing is introduced in the future.
9. International transfers
IdeaDrive is operated by a Polish company but uses providers and infrastructure in the United States. Where GDPR or equivalent transfer rules apply, transfers are supported as appropriate by provider Data Processing Addenda, the European Commission's 2021 Standard Contractual Clauses, participation in an applicable adequacy framework such as the EU-US Data Privacy Framework, or another lawful transfer mechanism.
The safeguards currently relied on for the principal providers are:
| Provider / transfer | Transfer safeguard |
|---|---|
| Supabase | The EU Standard Contractual Clauses incorporated into the Supabase DPA for the United States-hosted project and other restricted transfers |
| Vercel | The 2021 EU Standard Contractual Clauses incorporated into the Vercel DPA for EEA transfers not covered by an adequacy decision |
| Google OAuth | The EU-US Data Privacy Framework where applicable and Google's Standard Contractual Clauses for transfers not covered by an adequacy decision, as described in Google's data-transfer frameworks |
| Twitter/X OAuth | The European Commission's Standard Contractual Clauses for transfers to the United States and other non-adequate locations, as described by X |
| Stripe | The EU-US Data Privacy Framework where applicable, followed by the EEA Standard Contractual Clauses where required, under Stripe's Data Transfers Addendum |
| Resend | The EU-US Data Privacy Framework where applicable and the EU Standard Contractual Clauses incorporated into the Resend DPA |
| OpenAI | For EEA data, processing through OpenAI Ireland and transfers outside the EEA under an adequacy decision or agreements containing the EU Standard Contractual Clauses, under the OpenAI DPA |
| Anthropic | The Standard Contractual Clauses incorporated into Anthropic's DPA for commercial products and the Anthropic API, as described in the Anthropic Privacy Center |
| Amplitude | The 2021 EU Standard Contractual Clauses incorporated into the Amplitude DPA |
Where an adequacy mechanism no longer applies, we rely on an available contractual safeguard or suspend the affected transfer as required by law. Users may request information about the applicable safeguards by emailing info@tallumfoundry.com.
We review relevant providers and apply measures such as encryption in transit, restricted access, data minimization and avoidance of unnecessary direct identifiers in AI requests.
10. Cookies and tracking
For information about authentication cookies, Amplitude, Stripe and consent management, see the Cookie Policy. Users can change optional analytics preferences at any time through the Update cookie preferences control.
11. Security
We use technical and organizational measures appropriate to the nature and risk of the processing, including:
- HTTPS/TLS in transit and provider-supported encryption at rest;
- Supabase Row Level Security and account-level data isolation;
- server-side storage of provider credentials and secrets;
- role-based and least-privilege administrative access;
- managed OAuth and session controls;
- daily backups with a seven-day retention target;
- logging, monitoring, rate limits and cost/usage alerts;
- hosted Stripe checkout so IdeaDrive does not handle raw payment-card data.
No service can guarantee absolute security. Users should contact info@tallumfoundry.com if they suspect unauthorized account access or misuse.
If a personal-data breach occurs, we assess its nature, scope and risk and notify affected users, supervisory authorities or other regulators where and within the time required by applicable law.
12. Children
IdeaDrive accounts are available only to users aged 16 or older. Paid purchases are available only to users aged 18 or older. We do not knowingly collect personal data from children below the applicable threshold. If we learn that an ineligible child has created an account, we will delete the account and associated data, subject to legal requirements.
13. Special-category and third-party data
IdeaDrive does not request special-category personal data. Users must not include sensitive personal data or third-party information in prompts or ideas unless they have a lawful basis and authority to disclose it. A user who submits third-party data is responsible for the lawfulness and accuracy of that submission.
14. GDPR and EEA rights
Subject to applicable conditions and exceptions, users in the EEA may have the right to:
- receive information about processing;
- access personal data and obtain a copy;
- correct inaccurate or incomplete data;
- request deletion;
- restrict processing;
- object to processing based on legitimate interests or direct marketing;
- withdraw consent at any time;
- receive portable data in a structured, commonly used and machine-readable format;
- lodge a complaint with a supervisory authority;
- not be subject to solely automated decisions producing legal or similarly significant effects.
Requests can be sent to info@tallumfoundry.com. We may need to verify identity. GDPR requests are normally handled within one month, subject to lawful extensions.
Users may complain to the President of the Polish Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych) or their local EEA authority. Information is available at uodo.gov.pl.
15. United States privacy disclosures and rights
This section supplements the rest of this Policy for residents of California and other US states with comprehensive privacy laws. Rights and obligations apply only where the relevant law applies to IdeaDrive and may be subject to statutory thresholds and exceptions.
Categories of personal information
The table below describes categories of personal information that IdeaDrive has collected or expects to collect during the preceding 12 months. Retention periods are described in Sections 5 and 6.
| Category | Examples | Sources | Business or commercial purposes and recipient categories | Sold or shared |
|---|---|---|---|---|
| Identifiers and account data | Name, email address, provider and IdeaDrive account identifiers, IP address, cookie and device identifiers | User, Google, X, Supabase Auth, browser or device | Authentication, account administration, security, communications and analytics; disclosed to hosting, authentication, email and analytics providers as relevant | Not sold or shared for cross-context behavioural advertising |
| Customer-record and billing information | Billing name and address, tax or VAT identifiers, Stripe customer and transaction identifiers | User and Stripe | Checkout, payment, tax, accounting, fraud prevention and support; disclosed to Stripe, hosting providers and professional advisers as required | Not sold or shared for cross-context behavioural advertising |
| Commercial information | Purchases, token packages, token activity, refunds, disputes and chargebacks | User, IdeaDrive and Stripe | Supply of the digital service, account administration, accounting, fraud prevention and support | Not sold or shared for cross-context behavioural advertising |
| Internet or other electronic-network activity | Browser and device information, page and feature activity, session duration, referral and campaign data, diagnostics and logs | Browser, device, Vercel, Supabase and Amplitude | Service delivery, security, debugging and analytics | Not sold or shared for cross-context behavioural advertising |
| Approximate geolocation | Country, region or city inferred from IP address | Browser, device and service providers | Security, localization and analytics | Not sold or shared for cross-context behavioural advertising |
| Professional or employment-related information | Professional background, experience, startup history, skills and preferred industries | User | Startup Profile, idea generation, scoring and personalization; disclosed to Supabase and relevant AI providers to provide the Service | Not sold or shared for cross-context behavioural advertising |
| Inferences | Preferences, interests, scores, rankings and recommendations derived from profile information, User Content and product activity | IdeaDrive and its AI providers | Generate, structure, score and compare startup ideas and improve requested results | Not sold or shared for cross-context behavioural advertising |
| User Content and communications | Startup ideas, prompts, briefs, URLs, AI Outputs, support messages and privacy requests | User and IdeaDrive | Provide AI features, save requested content, respond to requests, secure the Service and comply with law; disclosed to Supabase, OpenAI, Anthropic, Resend and advisers as relevant | Not sold or shared for cross-context behavioural advertising |
IdeaDrive does not intentionally collect sensitive personal information for the purpose of inferring characteristics. Authentication and session credentials are used only to create, secure and maintain the account. Full payment-card credentials are handled by Stripe and do not reach IdeaDrive. Users should not submit sensitive information in User Content.
Do Not Sell or Share My Personal Information
IdeaDrive does not sell personal information for money, share it for cross-context behavioural advertising or process it for targeted advertising. IdeaDrive does not use an advertising integration at launch.
Users can record an opt-out through the Do Not Sell or Share My Personal Information page. The mechanism is available without creating or signing into an account and applies to sale, sharing and targeted advertising, including before any such processing is introduced in the future. We also recognize supported browser-based universal opt-out signals, including Global Privacy Control (GPC), as an opt-out for the browser or device from which the signal is sent. Users may also email info@tallumfoundry.com with the subject Do Not Sell or Share.
We process opt-out signals and requests as soon as reasonably feasible and no later than 15 business days where that deadline applies. After an opt-out, we do not ask the user to opt back in for at least 12 months where prohibited by law.
US state privacy rights
Depending on the user's state and applicable law, the user may have the right to:
- know whether we process personal information and obtain access to it;
- receive the categories and specific pieces of personal information collected, sources, purposes and recipient categories;
- correct inaccurate personal information;
- delete personal information, subject to statutory exceptions;
- receive a portable copy of personal information;
- opt out of sale, sharing, targeted advertising or qualifying profiling;
- limit the use or disclosure of sensitive personal information where applicable;
- appeal a refusal to act on a request; and
- exercise privacy rights without unlawful discrimination or retaliation.
Submit a request through the US Privacy Request form or by emailing info@tallumfoundry.com with the subject US Privacy Request. We may verify identity using information already associated with the account. Verification information is used only to process the request. An authorized agent may submit a request where permitted, subject to proof of authority and any permitted identity confirmation.
Where required, we confirm receipt within 10 business days and provide a substantive response within 45 calendar days. We may extend the response period once by up to an additional 45 days where permitted, after notifying the requester during the initial period and explaining the reason. Appeals are handled within the period required by the applicable state law, normally within 45 days.
16. Marketing communications and CAN-SPAM
For EEA recipients, IdeaDrive sends marketing email only with consent at launch. In the United States, IdeaDrive may send commercial email as permitted under the CAN-SPAM Act using an opt-out model.
Every marketing email sent through Resend must:
- use accurate sender and routing information and a subject line that is not deceptive;
- identify the message as an advertisement where required;
- include a clear unsubscribe mechanism; and
- include Tallum Foundry's valid physical postal address: Floriańska St. 6, Unit 02, 03-707 Warsaw.
The unsubscribe mechanism remains available for at least 30 days after the message is sent. We honour an opt-out within 10 business days, do not charge a fee, and do not require information beyond the email address or more than a reply email or a single web page. An opted-out address is retained on a suppression list and is not sold or transferred except to a provider used to honour the opt-out.
Users can unsubscribe using the link in a marketing email or by writing to info@tallumfoundry.com. Transactional, security, authentication and purchase-related messages may still be sent where necessary to provide the Service or protect an account.
17. Changes to this Policy
We may update this Policy as IdeaDrive, its providers or applicable law changes. The current version will be published on the website with a new effective date. Where a change materially affects registered users or requires renewed consent, we will provide an appropriate notice by email, in-product message or cookie banner.
18. Contact
Questions, privacy requests and complaints may be sent to: