← Back to home
Privacy Policy
Version 2.6.0 · Effective 2026-08-07
This document is shown in English. Use the NL button above for Dutch.
This Privacy Policy explains what personal data ideaboxd processes, why, on what legal basis, and what rights you have under the EU General Data Protection Regulation (GDPR). It is written to match how the app actually works. The data controller is Aurenix Creative Labs (eenmanszaak), the Netherlands - contact hello@aurenix-cl.com.
Implementation-accurate baseline, not legal advice. [square-bracket] passages are placeholders to be completed and verified before launch (see COMPLIANCE.md).
At a glance - processing summary
| Data category | Purpose | Legal basis | Key recipients | Retention |
| Account data (email, name, auth ids, consent record) | Create & secure your account, provide the Service | Contract; legitimate interest (security) | Supabase (processor) | While your account exists |
| Your ideas & content (dump, reflections, plans, versions) | Provide, sync, and back up your content | Contract | Supabase (processor) | While your account exists; residual in backups until aged out |
| AI Refine input (idea text you submit on trigger) | Generate draft answers you asked for | Contract | Google Gemini (processor) | Not stored beyond delivering the result |
| Payments & entitlements (ids, status, credits) | Process purchases, prevent fraud, bookkeeping | Contract; legal obligation | Stripe; Apple; Google; RevenueCat | Tax records up to 7 years (NL) |
| Usage, logs, security (IP, device, timestamps) | Security, abuse prevention, reliable operation | Legitimate interest; legal obligation | Supabase; Vercel (processors) | Provider log cycle |
| Waitlist email, whether you asked for the beta, and page language | Tell you when the iOS/Android apps launch; send a beta invite if you asked for one | Consent | Supabase (processor) | Until launch or unsubscribe |
| Product analytics (screen views, interactions, named events) | Understand how the app is used and where people get stuck | Consent | PostHog (processor, EU) | While consent stands; per PostHog retention |
| Website measurement, cookieless (page, referrer, country, device) | See whether the site works and which pages people find useful | Legitimate interest (nothing stored on your device) | PostHog (processor, EU) | Per PostHog retention |
| Website analytics after you accept (cookie, interactions, session replay) | Tell returning visitors from new ones and see how pages are used | Consent | PostHog (processor, EU) | While consent stands; per PostHog retention |
| Feedback you send us (message, your email, app context) | Support and improving the Service | Contract; legitimate interest | Supabase (processor) | Deleted with your account |
| Abuse-prevention email hash (pseudonymised) | Prevent free-tier abuse after deletion | Legitimate interest | Internal only | 12 months, then auto-deleted |
1. Controller and contact
The controller is Aurenix Creative Labs (eenmanszaak), established in the Netherlands (The Hague; KvK 98214292). For any privacy question or to exercise your rights, email hello@aurenix-cl.com. We have not appointed a Data Protection Officer, as we are not required to [to be confirmed before launch].
2. Account data
When you create an account we process your email address, your display name (if you give one), your authentication identifiers, which sign-in method you used (email, Google, or Apple), your email-verification status, your language preference, the timestamps and versions of the Terms and Privacy Policy you accepted, and security-related events (such as sign-in attempts). Purpose: to create and secure your account and provide the Service. Legal basis: performance of our contract with you, and our legitimate interest in keeping the Service secure. Passwords for email sign-up are hashed by our authentication provider; we never see them in the clear. If you send us feedback from the settings screen, we store the message you wrote together with your account email address and basic context (app version, platform, and language) so we can understand the report and reply to you. Purpose: user support and improving the Service. Legal basis: performance of our contract and our legitimate interest in improving the Service. Feedback is deleted together with your account (section 11), and the address it is stored under is taken from your signed-in session, so it is always your own.
3. Guest data
If you use guest mode without an account, the ideas you write are stored only on your device and are not sent to us - there is no guest account, no cloud copy, and no server-side backup of guest content. Error monitoring (Sentry, section 9) stays switched off until you accept this Privacy Policy. Product analytics (PostHog, section 9) measure guest mode only in a strictly anonymous, cookieless way: screen views and feature events (for example that an idea was created - never its text) with nothing written to your device, no cookies or identifiers, no recordings, and your IP address discarded on arrival - the same pre-consent measurement our website uses. Legal basis: our legitimate interest in understanding whether the try-out works. Analytics that store identifiers on your device (section 10), interaction autocapture, and session replay still require an account and your acceptance of this policy, or your separate analytics-cookie consent given on our website. We run no advertising SDKs at all. Clearing your browser or app data deletes guest ideas permanently. If you later create or sign in to an account on that device, your guest ideas are adopted into the account and from then on are treated as account content (section 4), and the anonymous analytics session may be linked to your new account so we can see whether trying out led to signing up.
4. Your ideas and content
For account holders we process the content you create - ideas, the original note ("dump"), reflections, plan sections, versions, titles, and timestamps - and, when you use AI Refine, the parts of an idea you send to it (section 6). For accounts this content is synced to and stored in our database so it is available across your devices, and is included in routine backups. You can export your ideas (for example as Markdown, plain text, checklist, or a project brief) and you can delete individual ideas or your whole account (section 11). Because this is free-text you write yourself, it may incidentally contain sensitive information (for example about health, beliefs, or other people). Please do not enter special categories of personal data (for example data revealing health, religion, ethnicity, or sexual orientation) about yourself or others; the Service is not designed to handle such data and we ask you not to rely on it for that. [To be confirmed with counsel, or replaced with an explicit-consent flow if such use is intended.]
5. Payments and entitlements
When you buy something we process purchase and subscription identifiers, product identifiers, transaction and entitlement status, credit balances, and payment-related events. Your payment card details are handled by the payment provider or app store and do not reach our servers. On the web, payments are processed by Stripe; on mobile, by Apple’s App Store or Google Play via RevenueCat, which tells us only what we need to unlock the right plan and credits. Purpose: to process purchases, provide paid features, prevent payment fraud, and meet bookkeeping obligations. Legal basis: performance of our contract, and our legal obligation to keep financial records. Invoices/receipts come from the provider or store that took the payment.
6. AI Refine
AI Refine is optional and only runs when you trigger it; the first time you use it, we show an in-app notice explaining what is sent and ask you to confirm. When you do, we send the relevant parts of your idea (your original note, your reflections and plan sections, and the open questions being addressed) to our AI provider, Google, over the paid Gemini API, which returns short draft suggestions. Purpose: to help you think an idea through. Legal basis: performance of our contract (you asked for the draft). Data sent: only the idea text needed for that draft - not your email, account identifiers, or payment data. What Google does with it: under Google’s Gemini API terms for paid services, your input and the generated output are not used to train Google’s models; Google retains them only for a limited period to run the request and for safety and abuse monitoring, after which they are deleted. On our side we do not store your AI prompts or the model output beyond delivering the result to you and keeping a minimal, content-free record that a request happened (for credit accounting); the drafts you keep become ordinary idea content (section 4). Google acts as our processor and may process the request outside the EEA (for example in the United States) under an adequacy decision or Standard Contractual Clauses (section 13). We are finalising a formal data-processing agreement with Google covering these commitments before commercial launch. You can use the whole Service without ever using AI Refine.
7. Rewarded ads
ideaboxd includes a mechanism to earn a credit by watching a rewarded video, capped at a few per day. Today this is a placeholder that shows a short countdown - no third-party ad network is integrated, so we do not currently serve real ads, set advertising cookies, collect advertising identifiers, or track you across apps or sites. If and when we introduce real rewarded ads (for example via Google AdMob), we will update this policy first, explain what the ad provider processes, and ask for any consent the law requires; personalised advertising and cross-app tracking would only ever happen with your separate, explicit consent, and choosing to watch a rewarded ad would not by itself count as consent to tracking. You will always be able to use the Service after refusing non-essential tracking. [To be updated when an ad SDK is actually integrated.]
8. Waitlist and communications
If you join the pre-launch waitlist on our website we store the email address you submit, which form you used, the language of the page you used it on, and whether you ticked the box asking for the pre-launch beta, so we can let you know when the iOS and Android apps launch - in the language you were reading - and send you a beta invite if you asked for one. Legal basis: your consent. Ticking the beta box is optional; leaving it unticked still puts you on the waitlist. The store beta programmes themselves (Apple TestFlight and Google Play testing) are run by Apple and Google under their own terms and privacy policies, and joining one is a separate step you take with them. We do not add waitlist addresses to any other marketing without a separate valid basis, and we will honour an unsubscribe request sent to hello@aurenix-cl.com. We also send you service (transactional) emails you cannot opt out of while you have an account - for example email verification and password resets - sent through our authentication provider.
9. Usage, logs, and security
To keep the Service running and secure we and our infrastructure providers process technical data such as IP address, basic device/browser information, timestamps, and server and authentication logs, and we enforce rate limits and basic fraud/abuse checks. Purpose and legal basis: our legitimate interest in security, abuse prevention, and reliable operation, and where relevant our legal obligations. For account holders who have accepted this Privacy Policy, we also use an error-monitoring tool (Sentry, section 13) that collects technical crash and error reports - the error message, a stack trace, and basic device/app information - to help us find and fix bugs. It is switched off until you accept this policy, does not run in guest mode, and is configured not to record your IP address, your account identity, or your idea content, and not to capture screen recordings ("session replay"). For signed-in account holders who have accepted this Privacy Policy, we also use a product-analytics tool (PostHog, section 13) to understand how the app is actually used - which screens are opened, which features are used, and where people get stuck. It records screen views, app lifecycle events, a small set of named product events (for example that an idea was created or exported, or that feedback was sent), automatically captured interactions such as taps and clicks, and - in the web app - basic page-performance measurements such as how quickly a page renders and responds to input ("Core Web Vitals"), which describe the page rather than you. PostHog is configured to discard your IP address on arrival. That automatic capture is configured to record which element you interacted with and where it sits in the interface, but NOT the text inside it, and we never send your idea content, your email address, or your display name - you appear in PostHog under your account identifier and nothing else. Screen names use the route pattern (for example "/idea/[id]"), never the identifier of a specific idea. For users who have consented (a signed-in account that accepted this policy, or the analytics-cookie consent on our website), we also record a session replay of the app screen with ALL text and all input fields masked: the replay shows layout, navigation, and where the interface fails - never your idea content, which is replaced by placeholders before anything leaves your device. Without such consent, the app is measured only in the strictly anonymous, cookieless way described in section 3. Our purchase coordinator (RevenueCat, section 5) additionally reports subscription lifecycle events - for example that a trial started, converted, or was refunded, with product and price but never card details - into PostHog under your account identifier, so revenue can be understood next to usage. PostHog processes this data in the EU. Legal basis: your consent for identified analytics, autocapture, and session replay, which you can withdraw at any time (section 14) - withdrawing stops collection - and our legitimate interest for the anonymous, cookieless measurement described in section 3.
The website. Our public website - everything outside the app, such as this page and the pages describing the product - also uses PostHog, but on a different footing, because a visitor has no account to consent through. Before you answer the banner, and also if you decline it, measurement runs in a cookieless mode: nothing whatsoever is written to or read from your browser - no cookie, no local storage, no session storage - so there is no identifier attached to you, and you are not recognised from one page to the next or from one visit to the next. What we receive is what the request itself carries: the page you opened, the site or search engine that sent you, a coarse location (country/region), and basic device and browser information. PostHog discards your IP address on arrival, and no person profile is created. Because nothing is stored on or read from your device, this needs no consent; legal basis: our legitimate interest in knowing whether the site works and which pages people find useful. If you accept in the banner, PostHog additionally stores an analytics cookie and identifiers in your browser, and we switch on everything that needs your agreement to collect: a visitor profile, which lets us tell a returning visitor from a new one and remember which link or campaign first brought you; automatically captured interactions (which element you clicked and where it sits on the page, never the text inside it); clicks that did nothing, which is how we find a page that looks broken; page-performance and network-timing measurements; reports of JavaScript errors on the site, so we learn when something is failing; feature flags; and session replay - a recording of how the page was used, with every form input masked, so what you type is not part of the recording. Session replay is switched off entirely on the withdrawal form, whatever you accepted; in the app it runs only with the additional masking described above. Recording of browser console output is never switched on. Legal basis for all of that: your consent, which you can change at any time (section 10).
10. Cookies, local storage, and mobile identifiers
The app uses on-device storage strictly to run: your sign-in session, your language and theme choices, your consent record, and offline copies of your ideas. These are essential and are not used to track you. Our product-analytics tool (PostHog, section 9) additionally stores identifiers on your device - a device and session identifier that lets us join your actions into one visit. Those are non-essential: they are only set once you have an account and have accepted this policy, or once you have accepted analytics cookies on our website (the web app honours that same choice), and they are cleared when you sign out or withdraw that acceptance. Without them - guest mode before any consent - analytics run from memory only and store nothing on your device. We do not use advertising cookies or mobile advertising identifiers. If that changes (for example if we add rewarded ads), we will provide a clear consent tool with accept, reject, and change-your-mind options, and non-essential tracking will be off until you choose it.
On the website (outside the app), analytics store nothing in your browser unless you accept them in the consent banner. Declining, or simply never answering the banner, leaves your browser untouched by analytics - the site still works exactly the same. Accepting stores a PostHog analytics cookie and the related device and session identifiers. You can change that decision whenever you like: reopen the choice. Declining afterwards clears what was stored. Rejecting is exactly as easy as accepting, and we never treat "no answer" as a yes.
11. Retention and deletion
We keep your account and content while your account exists. When you delete your account, your profile, ideas, plans, and entitlements are removed from our live systems promptly; residual copies may remain briefly in encrypted backups and in logs until they age out on their normal cycle [exact backup-retention window to be confirmed with the hosting provider]. Payment and tax records are kept as long as the law requires (up to 7 years in the Netherlands). Waitlist entries are kept until launch or until you unsubscribe. To limit abuse of the free tier, we keep a one-way SHA-256 hash of your email address (never the address itself) for 12 months after deletion; see section 12. Deleting your account does not cancel an active app-store or Stripe subscription - cancel that separately.
12. Pseudonymised abuse-prevention identifier
When you delete your account we store a one-way SHA-256 hash of your email address for 12 months. This is a pseudonymised identifier, not anonymous data: it lets us recognise a returning email so the free-idea allowance cannot be farmed by repeatedly deleting and re-registering, without our keeping your actual address. Purpose and legal basis: our legitimate interest in preventing abuse of the free tier. It is stored so that only our backend can use it, is never turned back into your address, and is deleted automatically after 12 months. You can object to this processing by contacting us.
13. Providers, recipients, and international transfers
We share personal data only as needed to run the Service, with: Supabase (our database, authentication, backend functions, and the sender of our transactional emails such as verification and password-reset messages; processor; primary data region Frankfurt, EU); Google Gemini (AI Refine; processor; see section 6); Stripe (web payments; acts as an independent controller for payment and fraud purposes); Apple and Google (app-store purchases and, if you choose them, Sign in with Apple / Google; independent controllers and app marketplaces); RevenueCat (coordinates mobile store purchases, subscriptions, and entitlements on our behalf; processor); Vercel (website and web-app hosting/CDN; processor); Sentry (error and crash monitoring for account holders who have accepted this policy; processor; see section 9); and PostHog (product analytics for signed-in account holders who have accepted this policy; processor; PostHog EU Cloud, data region Frankfurt, EU; see section 9). We do not currently use any separate advertising or email-marketing provider; if we add one, we will update this policy and, where required, ask for consent (sections 7 and 10). Our primary database is hosted in the EU (Frankfurt), but some of these providers may process data outside the EEA (for example in the United States). Where they do, the transfer relies on an adequacy decision or on Standard Contractual Clauses with appropriate safeguards, and we keep a record of the mechanism used for each provider. A database region in the EU does not by itself prevent all access from outside the EEA. You can ask us for more detail about a specific provider or safeguard. We never sell your personal data.
14. Your rights
You have the right to access, rectify, erase, restrict, and port your data, and to object to processing based on our legitimate interests, including the abuse-prevention hash (section 12). Where we rely on consent (for example the waitlist), you can withdraw it at any time, as easily as you gave it, without affecting past processing. To exercise any right, use the in-app controls or email hello@aurenix-cl.com; we may need to verify your identity, will respond within the statutory period (normally one month), and will explain any case where the law lets us limit a right. You can also lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) or your local supervisory authority. We do not use your data for automated decisions producing legal or similarly significant effects.
15. Children
The Service is intended for people aged 16 and over and is not directed at children. We do not knowingly collect data from anyone under 16 without the involvement of a parent or guardian. If you believe a child has given us personal data, contact hello@aurenix-cl.com and we will delete it.
16. Security
We take reasonable technical and organisational measures to protect your data: traffic is encrypted in transit (TLS), each account’s rows are isolated by database row-level security so only your authenticated account can read them, passwords are hashed by our authentication provider, and sensitive server keys are never shipped in the app. No service can promise absolute security, and we do not disclose details that would help an attacker.
17. Changes and versions
We may update this policy; we will announce material changes in the app or by email, ask again for consent where the law requires it, and show a new effective date. Current version: 2.6.0. Effective: 2026-08-07. You can view the current policy any time at /app/legal/privacy and on this page, and request a copy of a prior version.
← Terug naar home
Privacybeleid
Versie 2.6.0 · Van kracht 2026-08-07
Dit document wordt in het Nederlands getoond. Gebruik de EN-knop hierboven voor Engels.
Dit Privacybeleid legt uit welke persoonsgegevens ideaboxd verwerkt, waarom, op welke grondslag, en welke rechten je hebt onder de Algemene Verordening Gegevensbescherming (AVG). Het is geschreven om aan te sluiten op hoe de app echt werkt. De verwerkingsverantwoordelijke is Aurenix Creative Labs (eenmanszaak), Nederland - contact hello@aurenix-cl.com.
Implementatiegetrouwe basis, geen juridisch advies. Passages tussen [vierkante haken] zijn placeholders die vóór lancering moeten worden ingevuld en geverifieerd (zie COMPLIANCE.md).
In één oogopslag - verwerkingsoverzicht
| Gegevenscategorie | Doel | Grondslag | Belangrijkste ontvangers | Bewaartermijn |
| Accountgegevens (e-mail, naam, auth-ids, toestemmingsrecord) | Je account aanmaken & beveiligen, de Dienst leveren | Overeenkomst; gerechtvaardigd belang (beveiliging) | Supabase (verwerker) | Zolang je account bestaat |
| Je ideeën & content (dump, reflecties, plannen, versies) | Je content leveren, synchroniseren en back-uppen | Overeenkomst | Supabase (verwerker) | Zolang je account bestaat; restant in back-ups tot verlopen |
| AI Refine-invoer (ideetekst die je op verzoek stuurt) | Gevraagde conceptantwoorden genereren | Overeenkomst | Google Gemini (verwerker) | Niet bewaard na levering van het resultaat |
| Betalingen & rechten (ids, status, credits) | Aankopen verwerken, fraude voorkomen, boekhouding | Overeenkomst; wettelijke plicht | Stripe; Apple; Google; RevenueCat | Belastingadministratie tot 7 jaar (NL) |
| Gebruik, logs, beveiliging (IP, apparaat, tijdstippen) | Beveiliging, misbruikpreventie, betrouwbare werking | Gerechtvaardigd belang; wettelijke plicht | Supabase; Vercel (verwerkers) | Logcyclus van de provider |
| Wachtlijst-e-mail, of je de bèta wilde, en paginataal | Je laten weten wanneer de iOS/Android-apps lanceren; een bèta-uitnodiging sturen als je daarom vroeg | Toestemming | Supabase (verwerker) | Tot lancering of afmelding |
| Misbruikpreventie-hash (gepseudonimiseerd) | Misbruik van de gratis laag voorkomen na verwijdering | Gerechtvaardigd belang | Alleen intern | 12 maanden, daarna automatisch verwijderd |
1. Verantwoordelijke en contact
De verwerkingsverantwoordelijke is Aurenix Creative Labs (eenmanszaak), gevestigd in Nederland (The Hague; KvK 98214292). Voor privacyvragen of om je rechten uit te oefenen, mail hello@aurenix-cl.com. We hebben geen Functionaris Gegevensbescherming aangesteld, omdat dat niet verplicht is [vóór lancering te bevestigen].
2. Accountgegevens
Wanneer je een account aanmaakt verwerken we je e-mailadres, je weergavenaam (als je die opgeeft), je authenticatie-identifiers, welke inlogmethode je gebruikte (e-mail, Google of Apple), je e-mailverificatiestatus, je taalvoorkeur, de tijdstippen en versies van de Voorwaarden en het Privacybeleid die je accepteerde, en beveiligingsgerelateerde gebeurtenissen (zoals inlogpogingen). Doel: je account aanmaken en beveiligen en de Dienst leveren. Grondslag: uitvoering van onze overeenkomst met jou, en ons gerechtvaardigd belang bij het veilig houden van de Dienst. Wachtwoorden voor e-mailregistratie worden door onze authenticatieprovider gehasht; wij zien ze nooit leesbaar. Stuur je ons feedback via het instellingenscherm, dan slaan we het bericht dat je schreef op samen met het e-mailadres van je account en basiscontext (appversie, platform en taal), zodat we de melding kunnen begrijpen en je kunnen antwoorden. Doel: gebruikersondersteuning en het verbeteren van de Dienst. Grondslag: uitvoering van onze overeenkomst en ons gerechtvaardigd belang bij het verbeteren van de Dienst. Feedback wordt samen met je account verwijderd (artikel 11), en het adres waaronder die wordt opgeslagen komt uit je ingelogde sessie, dus het is altijd je eigen adres.
3. Gastgegevens
Gebruik je de gastmodus zonder account, dan worden de ideeën die je schrijft alleen op je apparaat bewaard en niet naar ons gestuurd - er is geen gastaccount, geen cloudkopie en geen server-side back-up van gastcontent. Foutmonitoring (Sentry, artikel 9) blijft uitgeschakeld totdat je dit Privacybeleid accepteert. Productanalytics (PostHog, artikel 9) meten de gastmodus uitsluitend strikt anoniem en cookieloos: schermweergaven en functiegebeurtenissen (bijvoorbeeld dat een idee is aangemaakt - nooit de tekst ervan) zonder dat er iets op je apparaat wordt geschreven, zonder cookies of identifiers, zonder opnames, en met je IP-adres dat bij binnenkomst wordt weggegooid - dezelfde meting van vóór toestemming die onze website gebruikt. Grondslag: ons gerechtvaardigd belang om te begrijpen of de try-out werkt. Analytics die identifiers op je apparaat opslaan (artikel 10), interactie-autocapture en session replay vereisen nog steeds een account en je acceptatie van dit beleid, of je aparte analytics-cookietoestemming op onze website. We draaien helemaal geen advertentie-SDK’s. Het wissen van je browser- of app-gegevens verwijdert gast-ideeën definitief. Maak je later op dat apparaat een account aan of log je in, dan worden je gast-ideeën in het account overgenomen en vanaf dan als accountcontent behandeld (artikel 4), en kan de anonieme analyticssessie aan je nieuwe account worden gekoppeld zodat we kunnen zien of uitproberen tot aanmelden leidde.
4. Je ideeën en content
Voor accounthouders verwerken we de content die je maakt - ideeën, de originele notitie ("dump"), reflecties, plansecties, versies, titels en tijdstippen - en, wanneer je AI Refine gebruikt, de delen van een idee die je daarheen stuurt (artikel 6). Voor accounts wordt deze content gesynchroniseerd naar en opgeslagen in onze database zodat die op al je apparaten beschikbaar is, en wordt die meegenomen in routineback-ups. Je kunt je ideeën exporteren (bijvoorbeeld als Markdown, platte tekst, checklist of projectbrief) en je kunt losse ideeën of je hele account verwijderen (artikel 11). Omdat dit vrije tekst is die je zelf schrijft, kan die onbedoeld gevoelige informatie bevatten (bijvoorbeeld over gezondheid, overtuigingen of andere mensen). Voer geen bijzondere categorieën persoonsgegevens in (bijvoorbeeld gegevens over gezondheid, religie, etniciteit of seksuele geaardheid) over jezelf of anderen; de Dienst is niet ontworpen om zulke gegevens te verwerken en we vragen je er niet op te vertrouwen. [Met een jurist te bevestigen, of te vervangen door een uitdrukkelijke-toestemmingsflow als zulk gebruik is beoogd.]
5. Betalingen en rechten
Wanneer je iets koopt verwerken we aankoop- en abonnement-identifiers, product-identifiers, transactie- en rechtenstatus, creditsaldi en betaalgerelateerde gebeurtenissen. Je kaartgegevens worden afgehandeld door de betaalprovider of appstore en bereiken onze servers niet. Op het web worden betalingen verwerkt door Stripe; op mobiel door de App Store van Apple of Google Play via RevenueCat, dat ons alleen vertelt wat nodig is om het juiste abonnement en de juiste credits te ontgrendelen. Doel: aankopen verwerken, betaalde functies leveren, betaalfraude voorkomen en boekhoudverplichtingen nakomen. Grondslag: uitvoering van onze overeenkomst en onze wettelijke plicht om financiële administratie te bewaren. Facturen/bonnen komen van de provider of winkel die de betaling afhandelde.
6. AI Refine
AI Refine is optioneel en werkt alleen wanneer jij hem start; de eerste keer dat je hem gebruikt tonen we een melding in de app die uitlegt wat er wordt verstuurd en vragen we je om te bevestigen. Doe je dat, dan sturen we de relevante delen van je idee (je originele notitie, je reflecties en plansecties, en de open vragen die worden aangepakt) via de betaalde Gemini API naar onze AI-provider Google, die korte conceptsuggesties teruggeeft. Doel: je helpen een idee te doordenken. Grondslag: uitvoering van onze overeenkomst (je vroeg om het concept). Wat er wordt verstuurd: alleen de ideetekst die voor dat concept nodig is - niet je e-mailadres, account-identifiers of betaalgegevens. Wat Google ermee doet: onder Googles Gemini API-voorwaarden voor betaalde diensten worden je invoer en de gegenereerde uitvoer niet gebruikt om Googles modellen te trainen; Google bewaart ze slechts een beperkte periode om het verzoek uit te voeren en voor veiligheids- en misbruikcontrole, waarna ze worden verwijderd. Aan onze kant bewaren we je AI-prompts of de modeluitvoer niet verder dan nodig om het resultaat aan je te leveren en een minimaal, inhoudsloos record dat een verzoek plaatsvond (voor creditadministratie); de concepten die je bewaart worden gewone ideeëncontent (artikel 4). Google treedt op als onze verwerker en kan het verzoek buiten de EER verwerken (bijvoorbeeld in de Verenigde Staten) onder een adequaatheidsbesluit of Standaardcontractbepalingen (artikel 13). We ronden vóór commerciële lancering een formele verwerkersovereenkomst met Google af die deze toezeggingen vastlegt. Je kunt de hele Dienst gebruiken zonder ooit AI Refine te gebruiken.
7. Beloningsadvertenties
ideaboxd bevat een mechanisme om een credit te verdienen door een beloningsvideo te bekijken, met een limiet van enkele per dag. Vandaag is dit een placeholder die een korte aftelteller toont - er is geen extern advertentienetwerk geïntegreerd, dus we tonen momenteel geen echte advertenties, plaatsen geen advertentiecookies, verzamelen geen advertentie-identifiers en volgen je niet over apps of sites. Als en wanneer we echte beloningsadvertenties invoeren (bijvoorbeeld via Google AdMob), werken we dit beleid eerst bij, leggen we uit wat de advertentieprovider verwerkt en vragen we de toestemming die de wet vereist; gepersonaliseerde advertenties en cross-app-tracking gebeuren alleen met je aparte, uitdrukkelijke toestemming, en het kiezen om een beloningsadvertentie te bekijken geldt op zichzelf niet als toestemming voor tracking. Je kunt de Dienst altijd gebruiken na het weigeren van niet-essentiële tracking. [Bij te werken wanneer een advertentie-SDK daadwerkelijk is geïntegreerd.]
8. Wachtlijst en communicatie
Meld je je aan voor de pre-launch-wachtlijst op onze website, dan bewaren we het e-mailadres dat je invult, welk formulier je gebruikte, de taal van de pagina waarop je dat deed, en of je het vakje voor de pre-launch-bèta aanvinkte, zodat we je kunnen laten weten wanneer de iOS- en Android-apps lanceren - in de taal die je las - en je een bèta-uitnodiging kunnen sturen als je daarom vroeg. Grondslag: je toestemming. Het bèta-vakje is optioneel; laat je het leeg, dan sta je nog steeds op de wachtlijst. De bètaprogramma's van de stores zelf (Apple TestFlight en Google Play-tests) worden door Apple en Google beheerd onder hun eigen voorwaarden en privacybeleid, en meedoen is een aparte stap die je bij hen zet. We voegen wachtlijstadressen niet toe aan andere marketing zonder een aparte geldige grondslag, en we honoreren een afmeldverzoek via hello@aurenix-cl.com. We sturen je ook service- (transactionele) e-mails waarvan je je niet kunt afmelden zolang je een account hebt - bijvoorbeeld e-mailverificatie en wachtwoordherstel - verzonden via onze authenticatieprovider.
9. Gebruik, logs en beveiliging
Om de Dienst draaiende en veilig te houden verwerken wij en onze infrastructuurproviders technische gegevens zoals IP-adres, basale apparaat-/browserinformatie, tijdstippen en server- en authenticatielogs, en handhaven we rate limits en basale fraude-/misbruikcontroles. Doel en grondslag: ons gerechtvaardigd belang bij beveiliging, misbruikpreventie en betrouwbare werking, en waar relevant onze wettelijke plichten. Voor accounthouders die dit Privacybeleid hebben geaccepteerd, gebruiken we ook een foutmonitoringtool (Sentry, artikel 13) die technische crash- en foutrapporten verzamelt - de foutmelding, een stacktrace en basale apparaat-/app-informatie - om bugs te vinden en op te lossen. De tool staat uit tot je dit beleid accepteert, draait niet in de gastmodus, en is zo ingesteld dat je IP-adres, je accountidentiteit en je idee-inhoud niet worden vastgelegd en dat er geen schermopnames ("session replay") worden gemaakt. Voor ingelogde accounthouders die dit Privacybeleid hebben geaccepteerd, gebruiken we ook een productanalyticstool (PostHog, artikel 13) om te begrijpen hoe de app daadwerkelijk wordt gebruikt - welke schermen worden geopend, welke functies worden gebruikt en waar mensen vastlopen. De tool registreert schermweergaven, app-levenscyclusgebeurtenissen, een kleine set benoemde productgebeurtenissen (bijvoorbeeld dat een idee is aangemaakt of geëxporteerd, of dat er feedback is verstuurd), automatisch vastgelegde interacties zoals tikken en klikken, en - in de webapp - basale pagina-prestatiemetingen zoals hoe snel een pagina rendert en op invoer reageert ("Core Web Vitals"), die de pagina beschrijven en niet jou. PostHog is zo ingesteld dat je IP-adres bij binnenkomst wordt weggegooid. Die automatische vastlegging is zo ingesteld dat wordt geregistreerd mét welk element je interacteerde en waar dat in de interface staat, maar NIET de tekst erin, en we sturen nooit je idee-inhoud, je e-mailadres of je weergavenaam mee - je verschijnt in PostHog uitsluitend onder je account-identifier. Schermnamen gebruiken het routepatroon (bijvoorbeeld "/idea/[id]"), nooit de identifier van een specifiek idee. Voor gebruikers die toestemming hebben gegeven (een ingelogd account dat dit beleid accepteerde, of de analytics-cookietoestemming op onze website) maken we ook een session replay van het app-scherm waarbij ALLE tekst en alle invoervelden gemaskeerd zijn: de replay toont lay-out, navigatie en waar de interface faalt - nooit je idee-inhoud, die door plaatshouders wordt vervangen voordat er iets je apparaat verlaat. Zonder zulke toestemming wordt de app uitsluitend op de strikt anonieme, cookieloze manier uit artikel 3 gemeten. Onze aankoopcoördinator (RevenueCat, artikel 5) rapporteert daarnaast levenscyclusgebeurtenissen van abonnementen - bijvoorbeeld dat een proefperiode startte, omzette of werd terugbetaald, met product en prijs maar nooit kaartgegevens - aan PostHog onder je account-identifier, zodat omzet naast gebruik begrepen kan worden. PostHog verwerkt deze gegevens in de EU. Grondslag: je toestemming voor geïdentificeerde analytics, autocapture en session replay, die je op elk moment kunt intrekken (artikel 14) - na intrekking stoppen we met verzamelen - en ons gerechtvaardigd belang voor de anonieme, cookieloze meting uit artikel 3.
De website. Onze publieke website - alles buiten de app, zoals deze pagina en de pagina's over het product - gebruikt PostHog ook, maar op een andere grondslag, omdat een bezoeker geen account heeft om toestemming via te geven. Voordat je de banner beantwoordt, en ook als je die weigert, draait de meting cookieloos: er wordt helemaal niets naar je browser geschreven of eruit gelezen - geen cookie, geen lokale opslag, geen sessieopslag - dus er is geen identifier aan jou gekoppeld en je wordt niet herkend van de ene pagina naar de andere of van het ene bezoek naar het volgende. Wat we ontvangen is wat het verzoek zelf meebrengt: de pagina die je opende, de site of zoekmachine die je stuurde, een grove locatie (land/regio) en basale apparaat- en browserinformatie. PostHog gooit je IP-adres bij binnenkomst weg en er wordt geen persoonsprofiel aangemaakt. Omdat er niets op je apparaat wordt opgeslagen of uitgelezen, is hiervoor geen toestemming nodig; grondslag: ons gerechtvaardigd belang om te weten of de site werkt en welke pagina's mensen nuttig vinden. Accepteer je in de banner, dan slaat PostHog daarnaast een analytics-cookie en identifiers in je browser op, en zetten we alles aan waarvoor je toestemming nodig is: een bezoekersprofiel, waarmee we een terugkerende bezoeker van een nieuwe kunnen onderscheiden en kunnen onthouden welke link of campagne je als eerste bracht; automatisch vastgelegde interacties (op welk element je klikte en waar dat op de pagina staat, nooit de tekst erin); klikken die niets deden, waarmee we een pagina vinden die kapot lijkt; pagina-prestatie- en netwerktimingmetingen; meldingen van JavaScript-fouten op de site, zodat we merken wanneer er iets misgaat; feature flags; en session replay - een opname van hoe de pagina is gebruikt, waarbij elk invoerveld gemaskeerd is, zodat wat je typt geen deel van de opname is. Session replay staat volledig uit op het herroepingsformulier, wat je ook hebt geaccepteerd; in de app draait die uitsluitend met de aanvullende maskering zoals hierboven beschreven. Het vastleggen van browser-consoleuitvoer zetten we nooit aan. Grondslag voor dat alles: je toestemming, die je op elk moment kunt wijzigen (artikel 10).
10. Cookies, lokale opslag en mobiele identifiers
De app gebruikt opslag op je apparaat strikt om te werken: je inlogsessie, je taal- en themakeuzes, je toestemmingsrecord en offline kopieën van je ideeën. Deze zijn essentieel en worden niet gebruikt om je te volgen. Onze productanalyticstool (PostHog, artikel 9) slaat daarnaast identifiers op je apparaat op - een apparaat- en sessie-identifier waarmee we je acties tot één bezoek kunnen samenvoegen. Die zijn niet-essentieel: ze worden pas gezet zodra je een account hebt en dit beleid hebt geaccepteerd, of zodra je op onze website analytics-cookies hebt geaccepteerd (de webapp volgt diezelfde keuze), en ze worden gewist wanneer je uitlogt of die acceptatie intrekt. Zonder die identifiers - gastmodus vóór enige toestemming - draaien analytics alleen vanuit het geheugen en slaan ze niets op je apparaat op. We gebruiken geen advertentiecookies of mobiele advertentie-identifiers. Verandert dat (bijvoorbeeld als we beloningsadvertenties toevoegen), dan bieden we een duidelijke toestemmingstool met accepteren, weigeren en van-gedachten-veranderen, en staat niet-essentiële tracking uit tot je ervoor kiest.
Op de website (buiten de app) slaan analytics niets in je browser op tenzij je ze in de toestemmingsbanner accepteert. Weigeren, of de banner gewoon nooit beantwoorden, laat je browser onaangeroerd door analytics - de site werkt precies hetzelfde. Accepteren zet een PostHog-analytics-cookie en de bijbehorende apparaat- en sessie-identifiers. Je kunt die keuze wijzigen wanneer je wilt: keuze opnieuw openen. Weiger je alsnog, dan wordt gewist wat er stond. Weigeren is precies zo makkelijk als accepteren, en we vatten "geen antwoord" nooit op als ja.
11. Bewaren en verwijderen
We bewaren je account en content zolang je account bestaat. Verwijder je je account, dan worden je profiel, ideeën, plannen en rechten direct uit onze actieve systemen verwijderd; restkopieën kunnen kort in versleutelde back-ups en logs blijven tot die in hun normale cyclus verlopen [exacte back-upbewaartermijn met de hostingprovider te bevestigen]. Betaal- en belastingadministratie bewaren we zolang de wet vereist (tot 7 jaar in Nederland). Wachtlijstvermeldingen bewaren we tot de lancering of tot je je afmeldt. Om misbruik van de gratis laag te beperken bewaren we na verwijdering 12 maanden een eenrichtings-SHA-256-hash van je e-mailadres (nooit het adres zelf); zie artikel 12. Je account verwijderen zegt een actief appstore- of Stripe-abonnement niet op - zeg dat apart op.
12. Gepseudonimiseerde misbruikpreventie-identifier
Wanneer je je account verwijdert bewaren we 12 maanden een eenrichtings-SHA-256-hash van je e-mailadres. Dit is een gepseudonimiseerde identifier, geen anonieme gegevens: hij laat ons een terugkerend e-mailadres herkennen zodat de gratis limiet niet kan worden gefarmd door herhaald verwijderen en opnieuw registreren, zonder dat we je echte adres bewaren. Doel en grondslag: ons gerechtvaardigd belang bij het voorkomen van misbruik van de gratis laag. Hij wordt zo opgeslagen dat alleen onze backend hem kan gebruiken, wordt nooit terug omgezet naar je adres en wordt na 12 maanden automatisch verwijderd. Je kunt tegen deze verwerking bezwaar maken door contact met ons op te nemen.
13. Providers, ontvangers en internationale doorgifte
We delen persoonsgegevens alleen voor zover nodig om de Dienst te laten werken, met: Supabase (onze database, authenticatie, backendfuncties en de verzender van onze transactionele e-mails zoals verificatie- en wachtwoordherstelberichten; verwerker; primaire dataregio Frankfurt, EU); Google Gemini (AI Refine; verwerker; zie artikel 6); Stripe (webbetalingen; treedt op als zelfstandig verwerkingsverantwoordelijke voor betaal- en fraudedoeleinden); Apple en Google (appstore-aankopen en, als je die kiest, Inloggen met Apple / Google; zelfstandige verwerkingsverantwoordelijken en app-marktplaatsen); RevenueCat (coördineert mobiele winkelaankopen, abonnementen en rechten namens ons; verwerker); Vercel (hosting/CDN voor website en web-app; verwerker); Sentry (fout- en crashmonitoring voor accounthouders die dit beleid hebben geaccepteerd; verwerker; zie artikel 9); en PostHog (productanalytics voor ingelogde accounthouders die dit beleid hebben geaccepteerd; verwerker; PostHog EU Cloud, dataregio Frankfurt, EU; zie artikel 9). We gebruiken momenteel geen aparte provider voor advertenties of e-mailmarketing; voegen we die toe, dan werken we dit beleid bij en vragen we waar vereist toestemming (artikelen 7 en 10). Onze primaire database staat in de EU (Frankfurt), maar sommige van deze providers kunnen gegevens buiten de EER verwerken (bijvoorbeeld in de Verenigde Staten). Waar dat gebeurt, berust de doorgifte op een adequaatheidsbesluit of op Standaardcontractbepalingen met passende waarborgen, en houden we per provider bij welk mechanisme wordt gebruikt. Een dataregio in de EU voorkomt op zichzelf niet alle toegang van buiten de EER. Je kunt ons om meer detail vragen over een specifieke provider of waarborg. We verkopen je persoonsgegevens nooit.
14. Je rechten
Je hebt het recht op inzage, rectificatie, verwijdering, beperking en overdraagbaarheid van je gegevens, en om bezwaar te maken tegen verwerking op basis van onze gerechtvaardigde belangen, inclusief de misbruikpreventie-hash (artikel 12). Waar we op toestemming steunen (bijvoorbeeld de wachtlijst) kun je die op elk moment intrekken, net zo eenvoudig als je die gaf, zonder gevolgen voor eerdere verwerking. Om een recht uit te oefenen, gebruik de bediening in de app of mail hello@aurenix-cl.com; we kunnen je identiteit moeten verifiëren, reageren binnen de wettelijke termijn (normaal één maand) en lichten elk geval toe waarin de wet ons een recht laat beperken. Je kunt ook een klacht indienen bij de Autoriteit Persoonsgegevens of je lokale toezichthouder. We gebruiken je gegevens niet voor geautomatiseerde besluiten met juridische of vergelijkbaar ingrijpende gevolgen.
15. Kinderen
De Dienst is bedoeld voor mensen van 16 jaar en ouder en is niet gericht op kinderen. We verzamelen niet bewust gegevens van iemand onder de 16 zonder betrokkenheid van een ouder of voogd. Denk je dat een kind ons persoonsgegevens heeft gegeven, neem dan contact op via hello@aurenix-cl.com en we verwijderen die.
16. Beveiliging
We nemen redelijke technische en organisatorische maatregelen om je gegevens te beschermen: verkeer is versleuteld tijdens verzending (TLS), de rijen van elk account zijn geïsoleerd met row-level security zodat alleen je geauthenticeerde account ze kan lezen, wachtwoorden worden door onze authenticatieprovider gehasht, en gevoelige serversleutels zitten nooit in de app. Geen enkele dienst kan absolute beveiliging beloven, en we onthullen geen details die een aanvaller zouden helpen.
17. Wijzigingen en versies
We kunnen dit beleid bijwerken; we kondigen wezenlijke wijzigingen aan in de app of per e-mail, vragen opnieuw om toestemming waar de wet dat vereist, en tonen een nieuwe ingangsdatum. Huidige versie: 2.6.0. Van kracht: 2026-08-07. Je kunt het actuele beleid altijd bekijken op /app/legal/privacy en op deze pagina, en een kopie van een eerdere versie opvragen.