Last updated August 25, 2026

Privacy Notice

This notice explains what Idea Vault collects, why it uses the data, what can become public, and what choices account holders have. It is a starting draft for this release. A qualified lawyer should review it for each jurisdiction before public launch.

1. Data we collect

2. Why we use it

We use this data to sign users in, protect project access, help define ideas, support collaboration, explain matches, keep project and agreement history, send account and project emails, answer messages, prevent abuse, run backups, fix failures, and improve Idea Vault.

3. The three disclosure layers

Sealed Core

Founder Idea Intake category selections, titles, rough descriptions, Founder Launch Interview answers, explicit unknowns, private working models and launch plans, legacy Founder Grounding Model responses, synthesis, assessments, Founder-only concept details, founder interview responses, private idea history, sealed files, and raw company financial records remain restricted to the Founder unless the product clearly says otherwise.

Verified Collaborator

Accepted collaborators receive the shared working context required for their role. They do not automatically receive the Sealed Core.

Public Teaser

Nothing is published automatically. A Founder creates a separate public record, reviews every field, confirms it is safe for the public internet, and chooses Publish. Unpublishing removes that record from Discover.

Member opportunity board

A Founder may publish a separate role brief to signed-in Idea Vault members. It contains only the project label, role title and summary, skills, time commitment, terms note, and location wording the Founder entered for that purpose. It does not automatically expose the Sealed Core, Founder identity, private project title, files, team, or economics. Expressing interest does not grant project access; a protected invitation remains a separate gate.

4. Sharing and service providers

Other project participants see only what their role and access level allow. The platform Owner can see counts, status, and contact or feedback messages, but not Sealed Core content. A deployment may send data to providers for hosting, file storage, email, AI processing, logs, or backups. The operator must list the actual providers and processing locations before launch.

5. AI features

When live AI is on, Founder Idea Intake may send the working title, category, rough description, previous Founder answers, and the current private working model to the configured provider so it can reassess the project stage, choose the next useful question, and decide when enough is known to act. Project Architect and Project Brain may also send the private project details needed to answer. Inside Idea Vault, these records stay in the Sealed Core and are not published or shared with Contributors.

Idea Vault sends live-AI requests with store: false; provider response storage is off for those requests. OpenAI may still keep abuse-monitoring logs for up to 30 days unless the operator has different approved data controls. Other providers may keep security, legal, or account records under their own terms. The interface says whether AI or the local backup wrote a result. For the adaptive Founder Launch Interview, the configured AI may receive the private title, category, rough description, previous Founder answers, and the current private working model so it can choose the next project-specific question and decide when enough is known to act. If AI is unavailable, a domain-specific local launch coach continues the intake. Founder statements remain the source record; the AI/local working model and launch plan are interpretation, and none of them become verified evidence merely because they appear in the intake.

6. Retention

Founder Idea Intake, account, and project data remains while the account or project is active and during backup retention periods. Contact messages and feedback remain until resolved and for the operator’s stated retention period. Security and audit records may remain longer to protect the service and document administrative actions.

7. Export and account closure

Signed-in users can download a JSON export from Account security & data. The export includes the member’s own Founder Idea Intake, weekly check-in, and opportunity-interest history and excludes passwords, session tokens, and security hashes.

Closing an account deletes unfinished Founder Idea Intakes. Projects you own become read-only historical records; Founder-only planning content is sealed, public listings are withdrawn, and your stored files enter a verified deletion queue. Your project access, sessions, tokens, and contact or feedback records end, and the account is anonymized. Shared records that other participants rely on—including accepted agreements, commitments, ownership, revenue obligations, material contributions, and integrity history—remain under “Former member” so the record stays accurate. Files uploaded by another participant remain with that project.

8. Security

Idea Vault uses salted password hashing, secure production cookies, email verification, rate limits, origin checks, session controls, restricted file access, verified backups, and security logs. No system is perfectly secure. Do not upload secrets the project does not need.

9. Your choices

10. Changes

We will date material changes here and, when appropriate, show them inside the product before they take effect. If you continue using Idea Vault after notice, the updated notice applies from its stated date.

11. Contact

Send privacy questions through the Idea Vault contact form and choose Support or Other.