Cookie Policy
Version 1.3 · Effective 19 September 2026
This Cookie Policy explains how TALLUM FOUNDRY SPÓŁKA Z OGRANICZONĄ ODPOWIEDZIALNOŚCIĄ ("Tallum Foundry", "we", "us" or "our") uses cookies and similar technologies on ideadrive.ai and the IdeaDrive web application (together, "IdeaDrive").
Company details:
- registered address: Floriańska St. 6, Unit 02, 03-707 Warsaw;
- KRS: 0001252744;
- NIP / EU VAT: 5214172327 / PL5214172327;
- REGON: 54523141800000;
- contact: info@tallumfoundry.com.
1. What cookies and similar technologies are
Cookies are small files stored on a browser or device. Similar technologies include local storage, pixels, software development kits and device identifiers. They can keep a user signed in, remember preferences, measure product use and help prevent fraud.
2. How these technologies are used and how to opt out
Strictly necessary technologies are used because IdeaDrive cannot provide the requested account, authentication, security, checkout or waitlist functions without them.
Analytics technologies run by default, on the basis of our legitimate interests in understanding how IdeaDrive is used and improving it. IdeaDrive does not show a cookie banner. Blocking analytics does not limit access to IdeaDrive's content or account functionality.
A user can opt out of analytics at any time by:
- blocking or deleting analytics cookies in the browser, as described in Section 6;
- installing the Google Analytics Opt-out Browser Add-on;
- objecting by email to info@tallumfoundry.com; we handle the objection as described in the Privacy Policy.
IdeaDrive does not sell personal information, share it for cross-context behavioural advertising or use advertising technologies. Before introducing any of these, we will update this Policy and provide an opt-out, including recognition of browser-based universal opt-out signals such as Global Privacy Control (GPC).
A checkout request to begin providing a paid digital service before the Consumer's withdrawal period expires is unrelated to analytics. Evidence of that request is kept with the purchase record rather than in browser tracking storage.
3. Cookie and tracking inventory
The following inventory lists the cookies and similar technologies IdeaDrive uses. Names containing * represent deployment-specific identifiers or chunked variants. Any additional cookie or similar technology is classified and added to this Policy before it is enabled.
| Technology | Provider / party | Category | Purpose | Maximum lifetime |
|---|---|---|---|---|
better-auth.session_token, served as __Secure-better-auth.session_token over HTTPS | IdeaDrive (Better Auth), first-party | Strictly necessary | Maintains the authenticated session for Google OAuth and email magic-link users | Up to 30 days, extended while the account is in use |
better-auth.session_data, served as __Secure-better-auth.session_data over HTTPS | IdeaDrive (Better Auth), first-party | Strictly necessary | Short-lived signed copy of the session that avoids a database lookup on every request | 5 minutes |
better-auth.state, served as __Secure-better-auth.state over HTTPS | IdeaDrive (Better Auth), first-party | Strictly necessary | Protects the Google OAuth sign-in flow while it is in progress | 5 minutes; removed when sign-in completes |
__Host-waitlist-csrf | IdeaDrive website, first-party | Strictly necessary | Protects the waitlist form against forged submissions | 10 minutes; removed when the form is submitted |
Cloudflare Turnstile challenge (script and challenge state served from challenges.cloudflare.com) | Cloudflare, third-party | Strictly necessary (security) | Tells people from automated traffic on the email sign-in form | For the duration of the challenge |
AMP_* | Amplitude, first-party analytics storage | Analytics | Stores device, user and session identifiers and event sequencing metadata | Up to 12 months |
amplitude_cookie_test* | Amplitude, first-party | Analytics | Tests whether the browser accepts cookies | Removed after the test |
_ga | Google Analytics, first-party analytics cookie set on .ideadrive.ai and shared by the website and the application | Analytics | Distinguishes users for aggregated product and website analytics | Up to 2 years |
_ga_<container-id> | Google Analytics, first-party analytics cookie set on .ideadrive.ai | Analytics | Persists session state for the relevant GA4 property | Up to 2 years |
__stripe_mid | Stripe | Payments and fraud prevention; necessary when checkout is requested | Helps Stripe prevent payment fraud | Up to 1 year |
__stripe_sid | Stripe | Payments; necessary when checkout is requested | Maintains a Stripe payment session | About 30 minutes |
Google may use its own cookies on its domains when a user chooses the Google OAuth sign-in flow. Stripe may use its own cookies on Stripe-hosted checkout pages. Those providers control their own cookies under their respective policies.
4. Cookie categories
Strictly necessary
These technologies support authentication, session continuity, form protection and security. They are not used for advertising by IdeaDrive and cannot be switched off where they are necessary to provide a feature requested by the user. Stripe payment and fraud-prevention technologies are used when a user requests checkout and are separately identified as payment technologies in the inventory above.
Analytics
Amplitude measures use of the application, and Google Analytics measures use of the website and the application. They record how users interact with IdeaDrive, including pages or screens visited, feature events, session information, device/browser information, approximate location, referral and campaign information, and technical performance. Amplitude is configured with a United States data center and a 12-month analytics retention period. The Google Analytics 4 property is configured with a maximum user-level and event-level retention period of 14 months; standard aggregated reports may remain available for longer under Google's documented retention behavior.
Amplitude and Google Analytics are used only for product and website analytics at launch. IdeaDrive does not use Google Ads, advertising personalization, remarketing or conversion-tracking integrations at launch.
Amplitude and Google Analytics start by default when a page loads. Google Analytics is loaded through Google Tag Manager with advertising storage, advertising user data and advertising personalization set to denied. Section 2 explains how to opt out.
Email tracking
Transactional and marketing emails are delivered through Resend. Where enabled, marketing emails may use pixels or redirect links to record delivery, opens or clicks. Marketing emails include an unsubscribe mechanism. A user may also request an opt-out at info@tallumfoundry.com.
5. Providers
- Amplitude — product analytics. Privacy information and DPA
- Cloudflare — Turnstile bot protection on the email sign-in form. Privacy Policy and Customer DPA
- Google — Google OAuth, Google Tag Manager and Google Analytics product and website analytics. Privacy Policy, Google Analytics data safeguards and Google Ads Data Processing Terms
- Stripe — hosted checkout, payment processing and fraud prevention. Privacy Policy
- Resend / Plus Five Five, Inc. — transactional and marketing email delivery. Privacy Policy
6. Browser controls
Users can also delete or block cookies through browser settings. Blocking strictly necessary cookies may prevent authentication, checkout or other requested functionality.
7. Updates
We review this inventory after material changes to authentication, analytics, payments or email integrations, and before introducing any advertising technology. We may update this Policy by publishing a revised version and changing its effective date. If we introduce a consent banner, this Policy will describe it.
8. Contact
Questions or requests relating to cookies and tracking can be sent to info@tallumfoundry.com.