Legal

Privacy Policy

Last updated September 20, 2026

This Privacy Policy explains how The Idea Vault (“The Idea Vault”, “we”) processes personal information when you use IdeaVault at https://theideavault.online. It applies to founders with accounts, collaborators who sign an NDA through the Service, and visitors to the website.

1. Controller and contact

The Idea Vault is the controller of personal information described here. Privacy requests and questions: support@theideavault.online.

2. Information we collect

Account information: name, email address, password hash, authentication metadata and plan status.

Customer Content: everything you place in a Vault. We treat Vault contents as confidential and do not access them except as described in “Access by our personnel”.

Collaborator and NDA information: name, email address or phone number, role, typed or drawn signature image, IP address, user-agent string and the UTC timestamp of execution.

Billing information: plan, subscription status, billing period, and identifiers returned by Stripe. Full card numbers are handled by Stripe and are never received or stored by us.

Technical and usage information: log data, device and browser information, approximate location derived from IP address, error reports and feature-usage events.

Assistant interactions: the prompts you send to the in-app assistant and the responses generated, stored so your conversations persist.

3. How we use information

To provide, secure and maintain the Service; to authenticate you; to create and deliver invitations; to present, execute and preserve NDAs; to process payments and manage subscriptions; to provide support; to detect, investigate and prevent fraud, abuse and security incidents; to comply with legal obligations; and to improve reliability and performance.

We do not sell personal information, do not share it for cross-context behavioural advertising, and do not use Customer Content to train machine-learning models.

4. Legal bases (where GDPR or UK GDPR applies)

Performance of a contract: providing the Service and processing payments. Legitimate interests: securing the Service, preventing abuse, and improving it. Legal obligation: tax, accounting and lawful requests. Consent: optional communications and third-party tool connections you authorise, which you may withdraw at any time.

5. Service providers and disclosures

We share personal information with processors acting on our instructions under written agreements: Supabase (database, authentication and file storage hosting); Stripe (payment processing and subscription billing); Telnyx (delivery of invitation emails and SMS messages); Google (Gemini via the Lovable AI Gateway) (powering the in-app assistant); Composio (optional third-party tool connections you authorise).

We disclose information where required by valid legal process or to protect rights, safety and the integrity of the Service, and in connection with a merger, acquisition or asset sale, in which case this Policy continues to apply to the transferred information.

Prompts you send to the assistant are transmitted to the AI provider to generate a response. Content sent to third-party tools you connect leaves our control and is governed by that provider's terms.

6. Access by our personnel

Access to Customer Content by our personnel is restricted to the minimum necessary, permitted only to resolve a support request you raise, to investigate a security incident, or where legally compelled, and is logged.

7. International transfers

Information is processed in the United States and in other countries where our processors operate. Where required, transfers rely on Standard Contractual Clauses or another lawful transfer mechanism.

8. Retention

Account and Customer Content: retained while your account is active and deleted within 30 days of account closure or your deletion request.

NDA execution evidence: retained for 7 years so the parties can prove the agreement, even after a Vault is deleted.

Billing records: retained for 7 years as required by tax and accounting law. Backups: overwritten on a rolling cycle of up to 35 days.

9. Your rights

Subject to your location, you may request access, correction, deletion, a portable copy, restriction of or objection to processing, and withdrawal of consent. Residents of California may request disclosure of categories collected and may exercise these rights without discriminatory treatment.

Send requests to support@theideavault.online. We verify requests through the email address on the account and respond within the period required by applicable law. You may also lodge a complaint with your supervisory authority.

10. Security

We use encryption in transit, encrypted storage at rest by our hosting provider, row-level authorisation so a Vault is readable only by its owner and NDA-bound collaborators, hashed credentials, and least-privilege internal access. Report a suspected vulnerability or incident to support@theideavault.online.

11. Cookies and similar technologies

We use strictly necessary cookies and local storage for authentication, session continuity and security. We do not use advertising or cross-site tracking cookies. Blocking necessary cookies will prevent sign-in.

12. Children

The Service is not directed to children under 18 and we do not knowingly collect their personal information. If we learn we have, we delete it.

13. Changes and contact

We will post any update here and, for material changes, notify you in the Service or by email before it takes effect.

The Idea Vault — support@theideavault.online — https://theideavault.online. Version 1.0, effective September 20, 2026.

The Idea Vault · Version 1.0 · Effective September 20, 2026 · support@theideavault.online