Privacy policy
Last updated .
[SQUARE BRACKET], confirm the sub-processor list matches what you actually use, and delete this box. Written for a small free tool operated inside the EU. Not legal advice.
Who is responsible
The data controller is [YOUR NAME OR COMPANY], [ADDRESS, CITY, COUNTRY]. For anything on this page, email [YOUR@EMAIL] and you'll get an answer from a person.
What we collect, and why
- The ideas you submit, and the analysis produced from them. Needed to give you the report and to show it to you again later. Legal basis: performance of the contract you enter by using the service.
- Your email address and a hashed password, if you create an account. Same basis.
- Basic technical data — IP address and request time — used only to enforce the daily limits and stop abuse. Legal basis: our legitimate interest in keeping a free service usable.
- Aggregate usage counts, for understanding how much the tool is used.
We do not collect payment details, because there is nothing to pay for. We don't sell anything to anyone, and there is no advertising.
Who else sees it
Two processors, both under contract:
- Supabase — hosts the database and handles logins. [Confirm your project's region.]
- [YOUR AI PROVIDER] — receives the text of your idea in order to produce the analysis. [Link their data policy and confirm whether they retain prompts.]
The site itself is served by Netlify. Where a provider processes data outside the EEA, that transfer relies on the European Commission's standard contractual clauses.
Public reports
Reports are private by default. If you press Publish, that one report becomes readable by anyone with the link, and search engines may index it. Analyses run without an account are public from the moment they are created — the page tells you so before you run one. Ask us and we'll unpublish or delete any report.
How long it is kept
- Ideas and reports: until you delete them, or until your account is deleted.
- Anonymous reports: [e.g. 12 months] from creation.
- Rate-limit records: [e.g. 30 days].
- Account records: deleted within 30 days of you asking.
Your rights
Under the GDPR you can ask for a copy of your data, correct it, delete it, restrict or object to how it's used, and take it elsewhere in a portable format. Email [YOUR@EMAIL] and we'll respond within one month. If you're not satisfied you can complain to your national data protection authority — in Greece that's the Hellenic Data Protection Authority.
Cookies and local storage
No advertising or tracking cookies. Your browser stores two things: your login session (so you stay logged in) and your light/dark preference. Both are strictly necessary or set by you, so there is no consent banner to click. [If you add analytics later, say which tool here — and if it sets cookies or profiles visitors, you will need a consent banner.]
Security
Traffic is encrypted in transit. Database access is restricted by row-level security policies, so one account cannot read another's reports. No system is perfect; if you find a problem, please email us rather than publishing it.
Children
This service isn't intended for people under [16]. We don't knowingly collect their data; tell us if you think we have and we'll delete it.