Privacy Notice
This notice explains what Idea Vault collects, why it uses the data, what can become public, and what choices account holders have. It is a starting draft for this release. A qualified lawyer should review it for each jurisdiction before public launch.
Projects start private, but some shared records must remain accurate. A Founder must create and publish a separate Public Teaser before anything appears on Discover. After account closure, some shared agreement, work, ownership, and payment records remain under an anonymous “Former member” name so other participants keep an accurate record.
1. Data we collect
- Account and profile data: name, email, password verifier, role, capabilities, availability, preferences, portfolio links, and onboarding state.
- Project data: Founder Idea Intake category selections, titles, rough descriptions, adaptive Founder Launch Interview answers and explicit unknowns, private AI/local working models and launch plans, legacy Founder Grounding Model responses, assessments, interview responses, blueprints, assumptions, experiments, evidence, decisions, tasks, milestones, weekly check-ins, cited briefings, discussions, updates, files, contribution records, invitations, and activity history.
- Opportunity data: Founder-authored member-facing role briefs and Contributor expressions of interest, including the contribution note, availability note, shortlist state, and conversion to a protected invitation.
- Offers, company, and money records: offers, counteroffers, accepted terms, company details, ownership records, revenue obligations, and recorded payments.
- Contact and feedback data: the name, email, reason, message, rating, and page context you submit.
- Security and service data: privacy-hashed device and network signals, session timestamps, request IDs, rate-limit events, delivery status, backup status, and audit events. Raw passwords and session tokens are not stored in readable form.
2. Why we use it
We use this data to sign users in, protect project access, help define ideas, support collaboration, explain matches, keep project and agreement history, send account and project emails, answer messages, prevent abuse, run backups, fix failures, and improve Idea Vault.
3. The three disclosure layers
Sealed Core
Founder Idea Intake category selections, titles, rough descriptions, Founder Launch Interview answers, explicit unknowns, private working models and launch plans, legacy Founder Grounding Model responses, synthesis, assessments, Founder-only concept details, founder interview responses, private idea history, sealed files, and raw company financial records remain restricted to the Founder unless the product clearly says otherwise.
Verified Collaborator
Accepted collaborators receive the shared working context required for their role. They do not automatically receive the Sealed Core.
Public Teaser
Nothing is published automatically. A Founder creates a separate public record, reviews every field, confirms it is safe for the public internet, and chooses Publish. Unpublishing removes that record from Discover.
Member opportunity board
A Founder may publish a separate role brief to signed-in Idea Vault members. It contains only the project label, role title and summary, skills, time commitment, terms note, and location wording the Founder entered for that purpose. It does not automatically expose the Sealed Core, Founder identity, private project title, files, team, or economics. Expressing interest does not grant project access; a protected invitation remains a separate gate.
4. Sharing and service providers
Other project participants see only what their role and access level allow. The platform Owner can see counts, status, and contact or feedback messages, but not Sealed Core content. A deployment may send data to providers for hosting, file storage, email, AI processing, logs, or backups. The operator must list the actual providers and processing locations before launch.
5. AI features
When live AI is on, Founder Idea Intake may send the working title, category, rough description, previous Founder answers, and the current private working model to the configured provider so it can reassess the project stage, choose the next useful question, and decide when enough is known to act. Project Architect and Project Brain may also send the private project details needed to answer. Inside Idea Vault, these records stay in the Sealed Core and are not published or shared with Contributors.
Idea Vault sends live-AI requests with store: false; provider response storage is off for those requests. OpenAI may still keep abuse-monitoring logs for up to 30 days unless the operator has different approved data controls. Other providers may keep security, legal, or account records under their own terms. The interface says whether AI or the local backup wrote a result. For the adaptive Founder Launch Interview, the configured AI may receive the private title, category, rough description, previous Founder answers, and the current private working model so it can choose the next project-specific question and decide when enough is known to act. If AI is unavailable, a domain-specific local launch coach continues the intake. Founder statements remain the source record; the AI/local working model and launch plan are interpretation, and none of them become verified evidence merely because they appear in the intake.
6. Retention
Founder Idea Intake, account, and project data remains while the account or project is active and during backup retention periods. Contact messages and feedback remain until resolved and for the operator’s stated retention period. Security and audit records may remain longer to protect the service and document administrative actions.
7. Export and account closure
Signed-in users can download a JSON export from Account security & data. The export includes the member’s own Founder Idea Intake, weekly check-in, and opportunity-interest history and excludes passwords, session tokens, and security hashes.
Closing an account deletes unfinished Founder Idea Intakes. Projects you own become read-only historical records; Founder-only planning content is sealed, public listings are withdrawn, and your stored files enter a verified deletion queue. Your project access, sessions, tokens, and contact or feedback records end, and the account is anonymized. Shared records that other participants rely on—including accepted agreements, commitments, ownership, revenue obligations, material contributions, and integrity history—remain under “Former member” so the record stays accurate. Files uploaded by another participant remain with that project.
8. Security
Idea Vault uses salted password hashing, secure production cookies, email verification, rate limits, origin checks, session controls, restricted file access, verified backups, and security logs. No system is perfectly secure. Do not upload secrets the project does not need.
9. Your choices
- Update profile and matching visibility in your account.
- Unpublish a Public Teaser at any time if you own the project.
- Revoke other sessions, change your password, or export data from Account security.
- Close your account from Account security.
- Use the contact form for access, correction, or privacy questions that cannot be handled in the product.
10. Changes
We will date material changes here and, when appropriate, show them inside the product before they take effect. If you continue using Idea Vault after notice, the updated notice applies from its stated date.
11. Contact
Send privacy questions through the Idea Vault contact form and choose Support or Other.