Legal

Privacy Policy.

How Tallum Foundry Sp. z o.o. processes personal data through ideadrive.ai and the IdeaDrive web application — and the rights you have over it.

Version 1.2 · Effective September 19, 2026

1. Controller and contact details

The data controller is:

TALLUM FOUNDRY SPÓŁKA Z OGRANICZONĄ ODPOWIEDZIALNOŚCIĄ, Floriańska St. 6, Unit 02, 03-707 Warsaw, Poland.

No Data Protection Officer (DPO / IOD) has been appointed. Privacy requests should be sent to the email address above.

2. Scope and role of IdeaDrive

IdeaDrive is an AI-assisted SaaS product that helps users generate, structure, score and compare startup ideas. It uses information provided by a user, including a Startup Profile and idea-related inputs, to generate and evaluate possible business concepts.

IdeaDrive is intended as a decision-support tool. It does not make decisions that produce legal or similarly significant effects for users, and its outputs are not legal, tax, financial, medical or other professional advice.

3. Personal data we process

Data received during authentication

IdeaDrive supports Google OAuth and email magic-link authentication through an authentication service that we operate ourselves (Better Auth). Depending on the method, provider and user settings, we may receive:

  • provider account identifier
  • email address and email-confirmation status
  • display name, first name and last name, or a combined name where the provider does not return them separately
  • profile image or avatar
  • authentication provider and session metadata
  • login timestamps and security information

IdeaDrive uses OAuth only to authenticate the user and create or link an account. We use the provider identifier, email, name and profile image or avatar for authentication and account setup. We do not use OAuth to access posts, contacts, followers, advertising profiles or other social-network content.

IdeaDrive does not receive or store a user's Google password. Google sign-in uses the standard openid, email and basic-profile scopes. A magic-link user receives a one-time, time-limited authentication link through Resend; IdeaDrive does not create an application-owned password.

The email sign-in form is protected by Cloudflare Turnstile. To tell people from automated traffic, Cloudflare receives the IP address and browser and device signals of the person submitting the form.

Waitlist

When a visitor joins the waitlist on ideadrive.ai, we process the email address they submit in order to tell them when access is available. The address is stored in our database on Microsoft Azure.

Account and profile data

We may process:

  • display name, avatar, first and last name, email-confirmation state and notification preferences
  • professional background, experience and startup history
  • skills, preferred industries/domains and product types
  • available time, potential budget, goals, motivation and risk tolerance
  • account plan, credit balance and credit activity
  • the versions of the Terms and of this Policy that were published when the account was created, and the time they were accepted

User content and AI data

We process content entered, saved or generated through IdeaDrive, including:

  • startup ideas, descriptions, value propositions and target audiences
  • prompts, questionnaire answers, briefs, assumptions, URLs and related inputs
  • generated ideas, normalized content, scores, explanations, recommendations and other AI outputs
  • user edits, overrides, rankings, Roadmap decisions and feedback

Users should not submit health data, biometric or genetic data, political or religious beliefs, criminal-offence data, confidential third-party data, trade secrets they are not authorized to disclose, or other special-category or highly sensitive information.

Payment and transaction data

Stripe processes payment-card data through Stripe-hosted checkout. IdeaDrive does not receive or store full card numbers, card security codes or payment credentials. We may receive and retain:

  • Stripe customer, checkout and transaction identifiers
  • purchase amount, currency, VAT/tax information and payment status
  • billing name, address and tax/VAT identifiers where provided
  • plan or purchase, credit allocation, refund, dispute and chargeback information
  • the immediate-performance consent text or version, timestamp, account and order or checkout identifier
  • invoices and accounting records

Communications and support data

We process emails, support questions, legal/privacy requests, feedback, unsubscribe requests and related correspondence. Resend processes recipient information, message content, delivery metadata and email-event logs to send transactional, authentication and marketing messages.

Technical, usage and analytics data

We may collect:

  • IP address, user agent, browser, device, operating system and approximate location derived from network information
  • page or screen views, clicks, feature events, session duration, referral and campaign information
  • authentication, scoring, generation, credit and payment event logs
  • timestamps, error codes, diagnostic, security and fraud-prevention data
  • identifiers stored through cookies or local storage

Amplitude provides product analytics for the application from a United States data center, and Google Analytics measures use of the website and the application. Both run by default, on the basis of our legitimate interests in understanding and improving IdeaDrive; Section 10 explains how to object. IdeaDrive does not use an advertising or conversion-tracking integration at launch.

4. How we obtain data

We obtain personal data:

  • directly from users
  • from Google when the user selects OAuth login
  • automatically from the user's browser, device and use of IdeaDrive
  • from Stripe in connection with checkout and payments
  • from service providers that help operate, secure, measure and communicate through IdeaDrive

5. Purposes, legal bases and retention

PurposeLegal basis under GDPRRetention baseline
Create and authenticate accounts; maintain sessionsPerformance of a contract or steps requested before entering a contract; legitimate interests in account securityFor the life of the account; a session lasts up to 30 days, is extended while the account is in use and is then removed
Provide the Startup Profile, idea workspace, scoring and AI featuresPerformance of a contractUntil account deletion or earlier user deletion where supported
Process plan and credit purchases, record immediate-performance requests and provide digital servicesPerformance of a contract; compliance with consumer-law obligations; establishment, exercise or defence of legal claimsTransactional and consent evidence for the applicable statutory limitation and mandatory record-keeping periods
Process payments, invoices, VAT and accountingPerformance of a contract and legal obligationsFor the period required by Polish accounting and tax law
Waitlist: tell a visitor when access is availableConsent given by submitting the addressUntil access is granted or the person asks to be removed
Security, abuse prevention (including Cloudflare Turnstile on the email sign-in form), debugging and service reliabilityLegitimate interests in protecting users, systems and legal rightsTechnical, security, scoring and credit audit logs: up to 12 months, unless longer retention is necessary for an incident, dispute or legal obligation
Microsoft Azure hosting and runtime diagnosticsPerformance of a contract; legitimate interests in service delivery, security and debuggingApplication and platform logs in Azure Monitor (Log Analytics and Application Insights) are retained for 31 days
Product and website analytics through Amplitude and Google AnalyticsLegitimate interests in understanding how IdeaDrive is used and improving itAmplitude user-level and event-level data: 12 months. Google Analytics user-level and event-level data: 14 months. Aggregated or de-identified reports may remain available
Transactional and authentication emailPerformance of a contract; legitimate interests in security and service communicationFor as long as needed to deliver, document and troubleshoot the communication, subject to Resend's service retention
Marketing emailEEA recipients: consent. US recipients: legitimate interests in direct marketing, subject to CAN-SPAM and the recipient's right to opt out. Suppression records: legal obligations and legitimate interests in respecting opt-outsUntil consent is withdrawn or the user unsubscribes; a minimal suppression record may be kept to respect the opt-out
Support, feedback and legal/privacy requestsPerformance of a contract, legitimate interests and legal obligations, depending on the requestFor as long as needed to handle the request and establish, exercise or defend legal claims
Legal claims, fraud, chargebacks and authority requestsLegal obligation and legitimate interestsUntil resolution and expiry of the applicable limitation period. Where access to an account was closed because of a payment dispute, the account data is kept for as long as needed to defend the dispute

We do not retain identifiable personal data longer than reasonably necessary for the stated purpose, subject to mandatory legal obligations and provider-specific technical deletion cycles.

6. Account deletion and backups

When a user confirms account deletion, IdeaDrive deletes the account and associated active application data promptly; in normal operation this is intended to occur immediately. Exceptions apply to transaction, tax, fraud, dispute or other records that must be retained by law or are necessary to establish, exercise or defend legal claims.

After deletion we keep a one-way hash (SHA-256) of the account's email address, without the address itself, so that the same address cannot be registered again to obtain a new starting grant of credits. The hash is kept on the basis of our legitimate interests in preventing abuse, for as long as that protection is needed; a person can ask us to remove it by emailing info@tallumfoundry.com.

Residual copies of deleted database data may remain in the automated backups of Azure Database for PostgreSQL for up to 7 days, after which the relevant backup expires. The backups are kept in the same Azure region as the database. Data separately retained by processors may follow their documented deletion cycles or mandatory legal requirements.

IdeaDrive does not provide a self-service pre-deletion export at launch. This does not limit statutory rights of access or portability. Where applicable, a user may request a copy of personal data or recovery of qualifying non-personal content by emailing info@tallumfoundry.com.

7. AI processing

IdeaDrive may send startup ideas, prompts, relevant Startup Profile context and generated or intermediate content to OpenAI and Anthropic APIs. Where scoring uses web research, search queries derived from the idea are sent to Perplexity. These requests are routed through the Vercel AI Gateway. We seek to exclude direct identifiers such as names and email addresses unless technically necessary.

  • OpenAI states that API data is not used to train its models unless the customer explicitly opts in. Default abuse-monitoring logs may contain prompts and responses and may be kept for up to 30 days, subject to endpoint-specific storage and legal/security exceptions.
  • Anthropic states that commercial API inputs and outputs are not used for model training unless the customer opts in and are deleted from its backend within 30 days by default, subject to agreed exceptions, usage-policy enforcement and law.

IdeaDrive does not authorize any AI provider to use IdeaDrive customer content for model training and will not opt in without updating this Policy and any required notices or consents.

EU AI Act transparency. Tallum Foundry acts as a deployer of third-party AI systems supplied by OpenAI, Anthropic and Perplexity. IdeaDrive informs users that they are using an AI-enabled service and that AI Outputs are machine-generated. AI-generated content is identified in the interface. IdeaDrive provides any disclosure required of a deployer by Article 50 of Regulation (EU) 2024/1689 (EU AI Act) and does not intentionally remove provider-supplied machine-readable markings from AI Outputs. Article 50 applies from 2 August 2026.

AI outputs may contain errors or omissions. They are reviewed and acted upon by the user and do not constitute automated decision-making with legal or similarly significant effects under Article 22 GDPR.

8. Recipients and processors

ProviderMain roleLocation / transfer context
Microsoft Azure / Microsoft Ireland Operations LimitedHosting of the website, the application, database, sessions and background processing (Azure Container Apps, Azure Database for PostgreSQL, Azure Functions) and monitoringCentral US region, United States
VercelAI Gateway: routing of AI model and web-research requests to OpenAI, Anthropic and Perplexity; no hostingUnited States / global infrastructure
GoogleGoogle OAuth; Google Analytics and Google Tag ManagerGlobal, including the United States
CloudflareTurnstile bot protection on the email sign-in formUnited States / global infrastructure
StripeHosted checkout, payments, billing and fraud preventionApplicable Stripe entity and global infrastructure
Resend / Plus Five Five, Inc.Magic-link, transactional and marketing email deliveryUnited States
OpenAIAI generation and analysisUnited States and other configured service locations
AnthropicAI generation and analysisUnited States and other configured service locations
PerplexityWeb research used in scoringUnited States
AmplitudeProduct analyticsUnited States data center

We may also disclose data to professional advisers, auditors, insurers, authorities or courts where necessary and legally permitted, or in connection with a merger, financing, reorganization or sale of the business subject to appropriate safeguards.

We do not sell personal data for money, share it for cross-context behavioural advertising or process it for targeted advertising. If that ever changes, we will update this Policy and provide an opt-out before the processing begins, as described in Section 15.

9. International transfers

IdeaDrive is operated by a Polish company but uses providers and infrastructure in the United States. Where GDPR or equivalent transfer rules apply, transfers are supported as appropriate by provider Data Processing Addenda, the European Commission's 2021 Standard Contractual Clauses, participation in an applicable adequacy framework such as the EU-US Data Privacy Framework, or another lawful transfer mechanism.

The safeguards currently relied on for the principal providers are:

Provider / transferTransfer safeguard
Microsoft AzureContract with Microsoft Ireland Operations Limited; the EU-US Data Privacy Framework where applicable and the 2021 EU Standard Contractual Clauses incorporated into the Microsoft Products and Services DPA for the United States-hosted environment and other restricted transfers
VercelThe 2021 EU Standard Contractual Clauses incorporated into the Vercel DPA for EEA transfers not covered by an adequacy decision
Google (OAuth, Analytics, Tag Manager)The EU-US Data Privacy Framework where applicable and Google's Standard Contractual Clauses for transfers not covered by an adequacy decision, as described in Google's data-transfer frameworks
StripeThe EU-US Data Privacy Framework where applicable, followed by the EEA Standard Contractual Clauses where required, under Stripe's Data Transfers Addendum
ResendThe EU-US Data Privacy Framework where applicable and the EU Standard Contractual Clauses incorporated into the Resend DPA
OpenAIFor EEA data, processing through OpenAI Ireland and transfers outside the EEA under an adequacy decision or agreements containing the EU Standard Contractual Clauses, under the OpenAI DPA
AnthropicThe Standard Contractual Clauses incorporated into Anthropic's DPA for commercial products and the Anthropic API, as described in the Anthropic Privacy Center
PerplexityReached only through the Vercel AI Gateway, under the safeguards of the Vercel DPA above
CloudflareThe EU-US Data Privacy Framework where applicable and the EU Standard Contractual Clauses incorporated into the Cloudflare Customer DPA
AmplitudeThe 2021 EU Standard Contractual Clauses incorporated into the Amplitude DPA

Where an adequacy mechanism no longer applies, we rely on an available contractual safeguard or suspend the affected transfer as required by law. Users may request information about the applicable safeguards by emailing info@tallumfoundry.com.

We review relevant providers and apply measures such as encryption in transit, restricted access, data minimization and avoidance of unnecessary direct identifiers in AI requests.

10. Cookies and tracking

For information about authentication cookies, Amplitude, Google Analytics, Cloudflare Turnstile and Stripe, see the Cookie Policy.

Analytics runs by default and IdeaDrive does not show a cookie banner. A user can stop analytics cookies by blocking or deleting them in the browser, can use the Google Analytics Opt-out Browser Add-on, and can object to analytics processing by emailing info@tallumfoundry.com; we handle the objection under Section 14.

11. Security

We use technical and organizational measures appropriate to the nature and risk of the processing, including:

  • HTTPS/TLS in transit and encryption at rest on Microsoft Azure
  • server-side authorization of every request, so that each account can reach only its own data
  • server-side storage of provider credentials and secrets
  • role-based and least-privilege administrative access
  • managed OAuth and session controls
  • automated database backups retained for seven days
  • logging, monitoring, rate limits and cost/usage alerts
  • hosted Stripe checkout so IdeaDrive does not handle raw payment-card data

No service can guarantee absolute security. Users should contact info@tallumfoundry.com if they suspect unauthorized account access or misuse.

If a personal-data breach occurs, we assess its nature, scope and risk and notify affected users, supervisory authorities or other regulators where and within the time required by applicable law.

12. Children

IdeaDrive accounts are available only to users aged 16 or older. Paid purchases are available only to users aged 18 or older. We do not knowingly collect personal data from children below the applicable threshold. If we learn that an ineligible child has created an account, we will delete the account and associated data, subject to legal requirements.

13. Special-category and third-party data

IdeaDrive does not request special-category personal data. Users must not include sensitive personal data or third-party information in prompts or ideas unless they have a lawful basis and authority to disclose it. A user who submits third-party data is responsible for the lawfulness and accuracy of that submission.

14. GDPR and EEA rights

Subject to applicable conditions and exceptions, users in the EEA may have the right to:

  • receive information about processing
  • access personal data and obtain a copy
  • correct inaccurate or incomplete data
  • request deletion
  • restrict processing
  • object to processing based on legitimate interests or direct marketing
  • withdraw consent at any time
  • receive portable data in a structured, commonly used and machine-readable format
  • lodge a complaint with a supervisory authority
  • not be subject to solely automated decisions producing legal or similarly significant effects

Requests can be sent to info@tallumfoundry.com. We may need to verify identity. GDPR requests are normally handled within one month, subject to lawful extensions.

Users may complain to the President of the Polish Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych) or their local EEA authority. Information is available at uodo.gov.pl.

15. United States privacy disclosures and rights

This section supplements the rest of this Policy for residents of California and other US states with comprehensive privacy laws. Rights and obligations apply only where the relevant law applies to IdeaDrive and may be subject to statutory thresholds and exceptions.

Categories of personal information

The table below describes categories of personal information that IdeaDrive has collected or expects to collect during the preceding 12 months. Retention periods are described in Sections 5 and 6.

CategoryExamplesSourcesBusiness or commercial purposes and recipient categoriesSold or shared
Identifiers and account dataName, email address, provider and IdeaDrive account identifiers, IP address, cookie and device identifiersUser, Google, browser or deviceAuthentication, account administration, security, communications and analytics; disclosed to hosting, authentication, email and analytics providers as relevantNot sold or shared for cross-context behavioural advertising
Customer-record and billing informationBilling name and address, tax or VAT identifiers, Stripe customer and transaction identifiersUser and StripeCheckout, payment, tax, accounting, fraud prevention and support; disclosed to Stripe, hosting providers and professional advisers as requiredNot sold or shared for cross-context behavioural advertising
Commercial informationPurchases, plans, credit activity, refunds, disputes and chargebacksUser, IdeaDrive and StripeSupply of the digital service, account administration, accounting, fraud prevention and supportNot sold or shared for cross-context behavioural advertising
Internet or other electronic-network activityBrowser and device information, page and feature activity, session duration, referral and campaign data, diagnostics and logsBrowser, device, Microsoft Azure, Amplitude and Google AnalyticsService delivery, security, debugging and analyticsNot sold or shared for cross-context behavioural advertising
Approximate geolocationCountry, region or city inferred from IP addressBrowser, device and service providersSecurity, localization and analyticsNot sold or shared for cross-context behavioural advertising
Professional or employment-related informationProfessional background, experience, startup history, skills and preferred industriesUserStartup Profile, idea generation, scoring and personalization; disclosed to Microsoft Azure as hosting provider and relevant AI providers to provide the ServiceNot sold or shared for cross-context behavioural advertising
InferencesPreferences, interests, scores, rankings and recommendations derived from profile information, User Content and product activityIdeaDrive and its AI providersGenerate, structure, score and compare startup ideas and improve requested resultsNot sold or shared for cross-context behavioural advertising
User Content and communicationsStartup ideas, prompts, briefs, URLs, AI Outputs, support messages and privacy requestsUser and IdeaDriveProvide AI features, save requested content, respond to requests, secure the Service and comply with law; disclosed to Microsoft Azure, Vercel (AI Gateway), OpenAI, Anthropic, Perplexity, Resend and advisers as relevantNot sold or shared for cross-context behavioural advertising

IdeaDrive does not intentionally collect sensitive personal information for the purpose of inferring characteristics. Authentication and session credentials are used only to create, secure and maintain the account. Full payment-card credentials are handled by Stripe and do not reach IdeaDrive. Users should not submit sensitive information in User Content.

Do Not Sell or Share My Personal Information

IdeaDrive does not sell personal information for money, share it for cross-context behavioural advertising or process it for targeted advertising. IdeaDrive does not use an advertising integration at launch.

Because none of this processing takes place, there is nothing to opt out of today. Before introducing any sale, sharing or targeted advertising, we will update this Policy and provide an opt-out mechanism, including recognition of browser-based universal opt-out signals such as Global Privacy Control (GPC). Users may email info@tallumfoundry.com with the subject Do Not Sell or Share at any time, and we will record the request.

US state privacy rights

Depending on the user's state and applicable law, the user may have the right to:

  • know whether we process personal information and obtain access to it
  • receive the categories and specific pieces of personal information collected, sources, purposes and recipient categories
  • correct inaccurate personal information
  • delete personal information, subject to statutory exceptions
  • receive a portable copy of personal information
  • opt out of sale, sharing, targeted advertising or qualifying profiling
  • limit the use or disclosure of sensitive personal information where applicable
  • appeal a refusal to act on a request
  • exercise privacy rights without unlawful discrimination or retaliation

Submit a request by emailing info@tallumfoundry.com with the subject US Privacy Request. We may verify identity using information already associated with the account. Verification information is used only to process the request. An authorized agent may submit a request where permitted, subject to proof of authority and any permitted identity confirmation.

Where required, we confirm receipt within 10 business days and provide a substantive response within 45 calendar days. We may extend the response period once by up to an additional 45 days where permitted, after notifying the requester during the initial period and explaining the reason. Appeals are handled within the period required by the applicable state law, normally within 45 days.

16. Marketing communications and CAN-SPAM

For EEA recipients, IdeaDrive sends marketing email only with consent at launch. In the United States, IdeaDrive may send commercial email as permitted under the CAN-SPAM Act using an opt-out model.

Every marketing email sent through Resend must:

  • use accurate sender and routing information and a subject line that is not deceptive
  • identify the message as an advertisement where required
  • include a clear unsubscribe mechanism
  • include Tallum Foundry's valid physical postal address: Floriańska St. 6, Unit 02, 03-707 Warsaw, Poland

The unsubscribe mechanism remains available for at least 30 days after the message is sent. We honour an opt-out within 10 business days, do not charge a fee, and do not require information beyond the email address or more than a reply email or a single web page. An opted-out address is retained on a suppression list and is not sold or transferred except to a provider used to honour the opt-out.

Users can unsubscribe using the link in a marketing email or by writing to info@tallumfoundry.com. Transactional, security, authentication and purchase-related messages may still be sent where necessary to provide the Service or protect an account.

17. Changes to this Policy

We may update this Policy as IdeaDrive, its providers or applicable law changes. The current version will be published on the website with a new effective date. Where a change materially affects registered users or requires renewed consent, we will provide an appropriate notice by email or in-product message.

Data controller · TALLUM FOUNDRY Sp. z o.o. · KRS 0001252744 · NIP 5214172327 · Floriańska St. 6, Unit 02, 03-707 Warsaw, Poland.