← Back to home

Privacy Policy

Version 2.6.0 · Effective 2026-08-07

This document is shown in English. Use the NL button above for Dutch.

This Privacy Policy explains what personal data ideaboxd processes, why, on what legal basis, and what rights you have under the EU General Data Protection Regulation (GDPR). It is written to match how the app actually works. The data controller is Aurenix Creative Labs (eenmanszaak), the Netherlands - contact hello@aurenix-cl.com.

Implementation-accurate baseline, not legal advice. [square-bracket] passages are placeholders to be completed and verified before launch (see COMPLIANCE.md).

At a glance - processing summary

Data categoryPurposeLegal basisKey recipientsRetention
Account data (email, name, auth ids, consent record)Create & secure your account, provide the ServiceContract; legitimate interest (security)Supabase (processor)While your account exists
Your ideas & content (dump, reflections, plans, versions)Provide, sync, and back up your contentContractSupabase (processor)While your account exists; residual in backups until aged out
AI Refine input (idea text you submit on trigger)Generate draft answers you asked forContractGoogle Gemini (processor)Not stored beyond delivering the result
Payments & entitlements (ids, status, credits)Process purchases, prevent fraud, bookkeepingContract; legal obligationStripe; Apple; Google; RevenueCatTax records up to 7 years (NL)
Usage, logs, security (IP, device, timestamps)Security, abuse prevention, reliable operationLegitimate interest; legal obligationSupabase; Vercel (processors)Provider log cycle
Waitlist email, whether you asked for the beta, and page languageTell you when the iOS/Android apps launch; send a beta invite if you asked for oneConsentSupabase (processor)Until launch or unsubscribe
Product analytics (screen views, interactions, named events)Understand how the app is used and where people get stuckConsentPostHog (processor, EU)While consent stands; per PostHog retention
Website measurement, cookieless (page, referrer, country, device)See whether the site works and which pages people find usefulLegitimate interest (nothing stored on your device)PostHog (processor, EU)Per PostHog retention
Website analytics after you accept (cookie, interactions, session replay)Tell returning visitors from new ones and see how pages are usedConsentPostHog (processor, EU)While consent stands; per PostHog retention
Feedback you send us (message, your email, app context)Support and improving the ServiceContract; legitimate interestSupabase (processor)Deleted with your account
Abuse-prevention email hash (pseudonymised)Prevent free-tier abuse after deletionLegitimate interestInternal only12 months, then auto-deleted

1. Controller and contact

The controller is Aurenix Creative Labs (eenmanszaak), established in the Netherlands (The Hague; KvK 98214292). For any privacy question or to exercise your rights, email hello@aurenix-cl.com. We have not appointed a Data Protection Officer, as we are not required to [to be confirmed before launch].

2. Account data

When you create an account we process your email address, your display name (if you give one), your authentication identifiers, which sign-in method you used (email, Google, or Apple), your email-verification status, your language preference, the timestamps and versions of the Terms and Privacy Policy you accepted, and security-related events (such as sign-in attempts). Purpose: to create and secure your account and provide the Service. Legal basis: performance of our contract with you, and our legitimate interest in keeping the Service secure. Passwords for email sign-up are hashed by our authentication provider; we never see them in the clear. If you send us feedback from the settings screen, we store the message you wrote together with your account email address and basic context (app version, platform, and language) so we can understand the report and reply to you. Purpose: user support and improving the Service. Legal basis: performance of our contract and our legitimate interest in improving the Service. Feedback is deleted together with your account (section 11), and the address it is stored under is taken from your signed-in session, so it is always your own.

3. Guest data

If you use guest mode without an account, the ideas you write are stored only on your device and are not sent to us - there is no guest account, no cloud copy, and no server-side backup of guest content. Error monitoring (Sentry, section 9) stays switched off until you accept this Privacy Policy. Product analytics (PostHog, section 9) measure guest mode only in a strictly anonymous, cookieless way: screen views and feature events (for example that an idea was created - never its text) with nothing written to your device, no cookies or identifiers, no recordings, and your IP address discarded on arrival - the same pre-consent measurement our website uses. Legal basis: our legitimate interest in understanding whether the try-out works. Analytics that store identifiers on your device (section 10), interaction autocapture, and session replay still require an account and your acceptance of this policy, or your separate analytics-cookie consent given on our website. We run no advertising SDKs at all. Clearing your browser or app data deletes guest ideas permanently. If you later create or sign in to an account on that device, your guest ideas are adopted into the account and from then on are treated as account content (section 4), and the anonymous analytics session may be linked to your new account so we can see whether trying out led to signing up.

4. Your ideas and content

For account holders we process the content you create - ideas, the original note ("dump"), reflections, plan sections, versions, titles, and timestamps - and, when you use AI Refine, the parts of an idea you send to it (section 6). For accounts this content is synced to and stored in our database so it is available across your devices, and is included in routine backups. You can export your ideas (for example as Markdown, plain text, checklist, or a project brief) and you can delete individual ideas or your whole account (section 11). Because this is free-text you write yourself, it may incidentally contain sensitive information (for example about health, beliefs, or other people). Please do not enter special categories of personal data (for example data revealing health, religion, ethnicity, or sexual orientation) about yourself or others; the Service is not designed to handle such data and we ask you not to rely on it for that. [To be confirmed with counsel, or replaced with an explicit-consent flow if such use is intended.]

5. Payments and entitlements

When you buy something we process purchase and subscription identifiers, product identifiers, transaction and entitlement status, credit balances, and payment-related events. Your payment card details are handled by the payment provider or app store and do not reach our servers. On the web, payments are processed by Stripe; on mobile, by Apple’s App Store or Google Play via RevenueCat, which tells us only what we need to unlock the right plan and credits. Purpose: to process purchases, provide paid features, prevent payment fraud, and meet bookkeeping obligations. Legal basis: performance of our contract, and our legal obligation to keep financial records. Invoices/receipts come from the provider or store that took the payment.

6. AI Refine

AI Refine is optional and only runs when you trigger it; the first time you use it, we show an in-app notice explaining what is sent and ask you to confirm. When you do, we send the relevant parts of your idea (your original note, your reflections and plan sections, and the open questions being addressed) to our AI provider, Google, over the paid Gemini API, which returns short draft suggestions. Purpose: to help you think an idea through. Legal basis: performance of our contract (you asked for the draft). Data sent: only the idea text needed for that draft - not your email, account identifiers, or payment data. What Google does with it: under Google’s Gemini API terms for paid services, your input and the generated output are not used to train Google’s models; Google retains them only for a limited period to run the request and for safety and abuse monitoring, after which they are deleted. On our side we do not store your AI prompts or the model output beyond delivering the result to you and keeping a minimal, content-free record that a request happened (for credit accounting); the drafts you keep become ordinary idea content (section 4). Google acts as our processor and may process the request outside the EEA (for example in the United States) under an adequacy decision or Standard Contractual Clauses (section 13). We are finalising a formal data-processing agreement with Google covering these commitments before commercial launch. You can use the whole Service without ever using AI Refine.

7. Rewarded ads

ideaboxd includes a mechanism to earn a credit by watching a rewarded video, capped at a few per day. Today this is a placeholder that shows a short countdown - no third-party ad network is integrated, so we do not currently serve real ads, set advertising cookies, collect advertising identifiers, or track you across apps or sites. If and when we introduce real rewarded ads (for example via Google AdMob), we will update this policy first, explain what the ad provider processes, and ask for any consent the law requires; personalised advertising and cross-app tracking would only ever happen with your separate, explicit consent, and choosing to watch a rewarded ad would not by itself count as consent to tracking. You will always be able to use the Service after refusing non-essential tracking. [To be updated when an ad SDK is actually integrated.]

8. Waitlist and communications

If you join the pre-launch waitlist on our website we store the email address you submit, which form you used, the language of the page you used it on, and whether you ticked the box asking for the pre-launch beta, so we can let you know when the iOS and Android apps launch - in the language you were reading - and send you a beta invite if you asked for one. Legal basis: your consent. Ticking the beta box is optional; leaving it unticked still puts you on the waitlist. The store beta programmes themselves (Apple TestFlight and Google Play testing) are run by Apple and Google under their own terms and privacy policies, and joining one is a separate step you take with them. We do not add waitlist addresses to any other marketing without a separate valid basis, and we will honour an unsubscribe request sent to hello@aurenix-cl.com. We also send you service (transactional) emails you cannot opt out of while you have an account - for example email verification and password resets - sent through our authentication provider.

9. Usage, logs, and security

To keep the Service running and secure we and our infrastructure providers process technical data such as IP address, basic device/browser information, timestamps, and server and authentication logs, and we enforce rate limits and basic fraud/abuse checks. Purpose and legal basis: our legitimate interest in security, abuse prevention, and reliable operation, and where relevant our legal obligations. For account holders who have accepted this Privacy Policy, we also use an error-monitoring tool (Sentry, section 13) that collects technical crash and error reports - the error message, a stack trace, and basic device/app information - to help us find and fix bugs. It is switched off until you accept this policy, does not run in guest mode, and is configured not to record your IP address, your account identity, or your idea content, and not to capture screen recordings ("session replay"). For signed-in account holders who have accepted this Privacy Policy, we also use a product-analytics tool (PostHog, section 13) to understand how the app is actually used - which screens are opened, which features are used, and where people get stuck. It records screen views, app lifecycle events, a small set of named product events (for example that an idea was created or exported, or that feedback was sent), automatically captured interactions such as taps and clicks, and - in the web app - basic page-performance measurements such as how quickly a page renders and responds to input ("Core Web Vitals"), which describe the page rather than you. PostHog is configured to discard your IP address on arrival. That automatic capture is configured to record which element you interacted with and where it sits in the interface, but NOT the text inside it, and we never send your idea content, your email address, or your display name - you appear in PostHog under your account identifier and nothing else. Screen names use the route pattern (for example "/idea/[id]"), never the identifier of a specific idea. For users who have consented (a signed-in account that accepted this policy, or the analytics-cookie consent on our website), we also record a session replay of the app screen with ALL text and all input fields masked: the replay shows layout, navigation, and where the interface fails - never your idea content, which is replaced by placeholders before anything leaves your device. Without such consent, the app is measured only in the strictly anonymous, cookieless way described in section 3. Our purchase coordinator (RevenueCat, section 5) additionally reports subscription lifecycle events - for example that a trial started, converted, or was refunded, with product and price but never card details - into PostHog under your account identifier, so revenue can be understood next to usage. PostHog processes this data in the EU. Legal basis: your consent for identified analytics, autocapture, and session replay, which you can withdraw at any time (section 14) - withdrawing stops collection - and our legitimate interest for the anonymous, cookieless measurement described in section 3.

The website. Our public website - everything outside the app, such as this page and the pages describing the product - also uses PostHog, but on a different footing, because a visitor has no account to consent through. Before you answer the banner, and also if you decline it, measurement runs in a cookieless mode: nothing whatsoever is written to or read from your browser - no cookie, no local storage, no session storage - so there is no identifier attached to you, and you are not recognised from one page to the next or from one visit to the next. What we receive is what the request itself carries: the page you opened, the site or search engine that sent you, a coarse location (country/region), and basic device and browser information. PostHog discards your IP address on arrival, and no person profile is created. Because nothing is stored on or read from your device, this needs no consent; legal basis: our legitimate interest in knowing whether the site works and which pages people find useful. If you accept in the banner, PostHog additionally stores an analytics cookie and identifiers in your browser, and we switch on everything that needs your agreement to collect: a visitor profile, which lets us tell a returning visitor from a new one and remember which link or campaign first brought you; automatically captured interactions (which element you clicked and where it sits on the page, never the text inside it); clicks that did nothing, which is how we find a page that looks broken; page-performance and network-timing measurements; reports of JavaScript errors on the site, so we learn when something is failing; feature flags; and session replay - a recording of how the page was used, with every form input masked, so what you type is not part of the recording. Session replay is switched off entirely on the withdrawal form, whatever you accepted; in the app it runs only with the additional masking described above. Recording of browser console output is never switched on. Legal basis for all of that: your consent, which you can change at any time (section 10).

10. Cookies, local storage, and mobile identifiers

The app uses on-device storage strictly to run: your sign-in session, your language and theme choices, your consent record, and offline copies of your ideas. These are essential and are not used to track you. Our product-analytics tool (PostHog, section 9) additionally stores identifiers on your device - a device and session identifier that lets us join your actions into one visit. Those are non-essential: they are only set once you have an account and have accepted this policy, or once you have accepted analytics cookies on our website (the web app honours that same choice), and they are cleared when you sign out or withdraw that acceptance. Without them - guest mode before any consent - analytics run from memory only and store nothing on your device. We do not use advertising cookies or mobile advertising identifiers. If that changes (for example if we add rewarded ads), we will provide a clear consent tool with accept, reject, and change-your-mind options, and non-essential tracking will be off until you choose it.

On the website (outside the app), analytics store nothing in your browser unless you accept them in the consent banner. Declining, or simply never answering the banner, leaves your browser untouched by analytics - the site still works exactly the same. Accepting stores a PostHog analytics cookie and the related device and session identifiers. You can change that decision whenever you like: reopen the choice. Declining afterwards clears what was stored. Rejecting is exactly as easy as accepting, and we never treat "no answer" as a yes.

11. Retention and deletion

We keep your account and content while your account exists. When you delete your account, your profile, ideas, plans, and entitlements are removed from our live systems promptly; residual copies may remain briefly in encrypted backups and in logs until they age out on their normal cycle [exact backup-retention window to be confirmed with the hosting provider]. Payment and tax records are kept as long as the law requires (up to 7 years in the Netherlands). Waitlist entries are kept until launch or until you unsubscribe. To limit abuse of the free tier, we keep a one-way SHA-256 hash of your email address (never the address itself) for 12 months after deletion; see section 12. Deleting your account does not cancel an active app-store or Stripe subscription - cancel that separately.

12. Pseudonymised abuse-prevention identifier

When you delete your account we store a one-way SHA-256 hash of your email address for 12 months. This is a pseudonymised identifier, not anonymous data: it lets us recognise a returning email so the free-idea allowance cannot be farmed by repeatedly deleting and re-registering, without our keeping your actual address. Purpose and legal basis: our legitimate interest in preventing abuse of the free tier. It is stored so that only our backend can use it, is never turned back into your address, and is deleted automatically after 12 months. You can object to this processing by contacting us.

13. Providers, recipients, and international transfers

We share personal data only as needed to run the Service, with: Supabase (our database, authentication, backend functions, and the sender of our transactional emails such as verification and password-reset messages; processor; primary data region Frankfurt, EU); Google Gemini (AI Refine; processor; see section 6); Stripe (web payments; acts as an independent controller for payment and fraud purposes); Apple and Google (app-store purchases and, if you choose them, Sign in with Apple / Google; independent controllers and app marketplaces); RevenueCat (coordinates mobile store purchases, subscriptions, and entitlements on our behalf; processor); Vercel (website and web-app hosting/CDN; processor); Sentry (error and crash monitoring for account holders who have accepted this policy; processor; see section 9); and PostHog (product analytics for signed-in account holders who have accepted this policy; processor; PostHog EU Cloud, data region Frankfurt, EU; see section 9). We do not currently use any separate advertising or email-marketing provider; if we add one, we will update this policy and, where required, ask for consent (sections 7 and 10). Our primary database is hosted in the EU (Frankfurt), but some of these providers may process data outside the EEA (for example in the United States). Where they do, the transfer relies on an adequacy decision or on Standard Contractual Clauses with appropriate safeguards, and we keep a record of the mechanism used for each provider. A database region in the EU does not by itself prevent all access from outside the EEA. You can ask us for more detail about a specific provider or safeguard. We never sell your personal data.

14. Your rights

You have the right to access, rectify, erase, restrict, and port your data, and to object to processing based on our legitimate interests, including the abuse-prevention hash (section 12). Where we rely on consent (for example the waitlist), you can withdraw it at any time, as easily as you gave it, without affecting past processing. To exercise any right, use the in-app controls or email hello@aurenix-cl.com; we may need to verify your identity, will respond within the statutory period (normally one month), and will explain any case where the law lets us limit a right. You can also lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) or your local supervisory authority. We do not use your data for automated decisions producing legal or similarly significant effects.

15. Children

The Service is intended for people aged 16 and over and is not directed at children. We do not knowingly collect data from anyone under 16 without the involvement of a parent or guardian. If you believe a child has given us personal data, contact hello@aurenix-cl.com and we will delete it.

16. Security

We take reasonable technical and organisational measures to protect your data: traffic is encrypted in transit (TLS), each account’s rows are isolated by database row-level security so only your authenticated account can read them, passwords are hashed by our authentication provider, and sensitive server keys are never shipped in the app. No service can promise absolute security, and we do not disclose details that would help an attacker.

17. Changes and versions

We may update this policy; we will announce material changes in the app or by email, ask again for consent where the law requires it, and show a new effective date. Current version: 2.6.0. Effective: 2026-08-07. You can view the current policy any time at /app/legal/privacy and on this page, and request a copy of a prior version.