Legal

Cookie Policy.

How IdeaDrive uses cookies and similar technologies, and how you can stay in control of them.

Version 1.3 · Effective September 19, 2026

Who we are

This Cookie Policy explains how TALLUM FOUNDRY SPÓŁKA Z OGRANICZONĄ ODPOWIEDZIALNOŚCIĄ ("Tallum Foundry", "we", "us" or "our") uses cookies and similar technologies on ideadrive.ai and the IdeaDrive web application (together, "IdeaDrive").

TALLUM FOUNDRY Sp. z o.o., Floriańska St. 6, Unit 02, 03-707 Warsaw, Poland.

1. What cookies and similar technologies are

Cookies are small files stored on a browser or device. Similar technologies include local storage, pixels, software development kits and device identifiers. They can keep a user signed in, remember preferences, measure product use and help prevent fraud.

2. How these technologies are used and how to opt out

Strictly necessary technologies are used because IdeaDrive cannot provide the requested account, authentication, security, checkout or waitlist functions without them.

Analytics technologies run by default, on the basis of our legitimate interests in understanding how IdeaDrive is used and improving it. IdeaDrive does not show a cookie banner. Blocking analytics does not limit access to IdeaDrive's content or account functionality.

A user can opt out of analytics at any time by:

IdeaDrive does not sell personal information, share it for cross-context behavioural advertising or use advertising technologies. Before introducing any of these, we will update this Policy and provide an opt-out, including recognition of browser-based universal opt-out signals such as Global Privacy Control (GPC).

A checkout request to begin providing a paid digital service before the Consumer's withdrawal period expires is unrelated to analytics. Evidence of that request is kept with the purchase record rather than in browser tracking storage.

3. Cookie and tracking inventory

The following inventory lists the cookies and similar technologies IdeaDrive uses. Names containing * represent deployment-specific identifiers or chunked variants. Any additional cookie or similar technology is classified and added to this Policy before it is enabled.

TechnologyProvider / partyCategoryPurposeMaximum lifetime
better-auth.session_token, served as __Secure-better-auth.session_token over HTTPSIdeaDrive (Better Auth), first-partyStrictly necessaryMaintains the authenticated session for Google OAuth and email magic-link usersUp to 30 days, extended while the account is in use
better-auth.session_data, served as __Secure-better-auth.session_data over HTTPSIdeaDrive (Better Auth), first-partyStrictly necessaryShort-lived signed copy of the session that avoids a database lookup on every request5 minutes
better-auth.state, served as __Secure-better-auth.state over HTTPSIdeaDrive (Better Auth), first-partyStrictly necessaryProtects the Google OAuth sign-in flow while it is in progress5 minutes; removed when sign-in completes
__Host-waitlist-csrfIdeaDrive website, first-partyStrictly necessaryProtects the waitlist form against forged submissions10 minutes; removed when the form is submitted
Cloudflare Turnstile challenge (script and challenge state served from challenges.cloudflare.com)Cloudflare, third-partyStrictly necessary (security)Tells people from automated traffic on the email sign-in formFor the duration of the challenge
AMP_*Amplitude, first-party analytics storageAnalyticsStores device, user and session identifiers and event sequencing metadataUp to 12 months
amplitude_cookie_test*Amplitude, first-partyAnalyticsTests whether the browser accepts cookiesRemoved after the test
_gaGoogle Analytics, first-party analytics cookie set on .ideadrive.ai and shared by the website and the applicationAnalyticsDistinguishes users for aggregated product and website analyticsUp to 2 years
_ga_<container-id>Google Analytics, first-party analytics cookie set on .ideadrive.aiAnalyticsPersists session state for the relevant GA4 propertyUp to 2 years
__stripe_midStripePayments and fraud prevention; necessary when checkout is requestedHelps Stripe prevent payment fraudUp to 1 year
__stripe_sidStripePayments; necessary when checkout is requestedMaintains a Stripe payment sessionAbout 30 minutes

Google may use its own cookies on its domains when a user chooses the Google OAuth sign-in flow. Stripe may use its own cookies on Stripe-hosted checkout pages. Those providers control their own cookies under their respective policies.

4. Cookie categories

Strictly necessary

These technologies support authentication, session continuity, form protection and security. They are not used for advertising by IdeaDrive and cannot be switched off where they are necessary to provide a feature requested by the user. Stripe payment and fraud-prevention technologies are used when a user requests checkout and are separately identified as payment technologies in the inventory above.

Analytics

Amplitude measures use of the application, and Google Analytics measures use of the website and the application. They record how users interact with IdeaDrive, including pages or screens visited, feature events, session information, device/browser information, approximate location, referral and campaign information, and technical performance. Amplitude is configured with a United States data center and a 12-month analytics retention period. The Google Analytics 4 property is configured with a maximum user-level and event-level retention period of 14 months; standard aggregated reports may remain available for longer under Google's documented retention behavior.

Amplitude and Google Analytics are used only for product and website analytics at launch. IdeaDrive does not use Google Ads, advertising personalization, remarketing or conversion-tracking integrations at launch.

Amplitude and Google Analytics start by default when a page loads. Google Analytics is loaded through Google Tag Manager with advertising storage, advertising user data and advertising personalization set to denied. Section 2 explains how to opt out.

Email tracking

Transactional and marketing emails are delivered through Resend. Where enabled, marketing emails may use pixels or redirect links to record delivery, opens or clicks. Marketing emails include an unsubscribe mechanism. A user may also request an opt-out at info@tallumfoundry.com.

5. Providers

7. Updates

We review this inventory after material changes to authentication, analytics, payments or email integrations, and before introducing any advertising technology. We may update this Policy by publishing a revised version and changing its effective date. If we introduce a consent banner, this Policy will describe it.

Data controller · TALLUM FOUNDRY Sp. z o.o. · KRS 0001252744 · NIP 5214172327 · Floriańska St. 6, Unit 02, 03-707 Warsaw, Poland.