Privacy Policy
Version 1.2 · Effective 19 September 2026
This Privacy Policy explains how TALLUM FOUNDRY SPÓŁKA Z OGRANICZONĄ ODPOWIEDZIALNOŚCIĄ processes personal data through ideadrive.ai and the IdeaDrive web application (together, "IdeaDrive").
1. Controller and contact details
The data controller is:
TALLUM FOUNDRY SPÓŁKA Z OGRANICZONĄ ODPOWIEDZIALNOŚCIĄ
Floriańska St. 6, Unit 02
03-707 Warsaw
- KRS: 0001252744
- NIP: 5214172327
- EU VAT: PL5214172327
- REGON: 54523141800000
- Email: info@tallumfoundry.com
No Data Protection Officer (DPO / IOD) has been appointed. Privacy requests should be sent to the email address above.
2. Scope and role of IdeaDrive
IdeaDrive is an AI-assisted SaaS product that helps users generate, structure, score and compare startup ideas. It uses information provided by a user, including a Startup Profile and idea-related inputs, to generate and evaluate possible business concepts.
IdeaDrive is intended as a decision-support tool. It does not make decisions that produce legal or similarly significant effects for users, and its outputs are not legal, tax, financial, medical or other professional advice.
3. Personal data we process
Data received during authentication
IdeaDrive supports Google OAuth and email magic-link authentication through an authentication service that we operate ourselves (Better Auth). Depending on the method, provider and user settings, we may receive:
- provider account identifier;
- email address and email-confirmation status;
- display name, first name and last name, or a combined name where the provider does not return them separately;
- profile image or avatar;
- authentication provider and session metadata;
- login timestamps and security information.
IdeaDrive uses OAuth only to authenticate the user and create or link an account. We use the provider identifier, email, name and profile image or avatar for authentication and account setup. We do not use OAuth to access posts, contacts, followers, advertising profiles or other social-network content.
IdeaDrive does not receive or store a user's Google password. Google sign-in uses the standard openid, email and basic-profile scopes. A magic-link user receives a one-time, time-limited authentication link through Resend; IdeaDrive does not create an application-owned password.
The email sign-in form is protected by Cloudflare Turnstile. To tell people from automated traffic, Cloudflare receives the IP address and browser and device signals of the person submitting the form.
Waitlist
When a visitor joins the waitlist on ideadrive.ai, we process the email address they submit in order to tell them when access is available. The address is stored in our database on Microsoft Azure.
Account and profile data
We may process:
- display name, avatar, first and last name, email-confirmation state and notification preferences;
- professional background, experience and startup history;
- skills, preferred industries/domains and product types;
- available time, potential budget, goals, motivation and risk tolerance;
- account plan, credit balance and credit activity;
- the versions of the Terms and of this Policy that were published when the account was created, and the time they were accepted.
User content and AI data
We process content entered, saved or generated through IdeaDrive, including:
- startup ideas, descriptions, value propositions and target audiences;
- prompts, questionnaire answers, briefs, assumptions, URLs and related inputs;
- generated ideas, normalized content, scores, explanations, recommendations and other AI outputs;
- user edits, overrides, rankings, Roadmap decisions and feedback.
Users should not submit health data, biometric or genetic data, political or religious beliefs, criminal-offence data, confidential third-party data, trade secrets they are not authorized to disclose, or other special-category or highly sensitive information.
Payment and transaction data
Stripe processes payment-card data through Stripe-hosted checkout. IdeaDrive does not receive or store full card numbers, card security codes or payment credentials. We may receive and retain:
- Stripe customer, checkout and transaction identifiers;
- purchase amount, currency, VAT/tax information and payment status;
- billing name, address and tax/VAT identifiers where provided;
- plan or purchase, credit allocation, refund, dispute and chargeback information;
- the immediate-performance consent text or version, timestamp, account and order or checkout identifier;
- invoices and accounting records.
Communications and support data
We process emails, support questions, legal/privacy requests, feedback, unsubscribe requests and related correspondence. Resend processes recipient information, message content, delivery metadata and email-event logs to send transactional, authentication and marketing messages.
Technical, usage and analytics data
We may collect:
- IP address, user agent, browser, device, operating system and approximate location derived from network information;
- page or screen views, clicks, feature events, session duration, referral and campaign information;
- authentication, scoring, generation, credit and payment event logs;
- timestamps, error codes, diagnostic, security and fraud-prevention data;
- identifiers stored through cookies or local storage.
Amplitude provides product analytics for the application from a United States data center, and Google Analytics measures use of the website and the application. Both run by default, on the basis of our legitimate interests in understanding and improving IdeaDrive; Section 10 explains how to object. IdeaDrive does not use an advertising or conversion-tracking integration at launch.
4. How we obtain data
We obtain personal data:
- directly from users;
- from Google when the user selects OAuth login;
- automatically from the user's browser, device and use of IdeaDrive;
- from Stripe in connection with checkout and payments;
- from service providers that help operate, secure, measure and communicate through IdeaDrive.
5. Purposes, legal bases and retention
| Purpose | Legal basis under GDPR | Retention baseline |
|---|---|---|
| Create and authenticate accounts; maintain sessions | Performance of a contract or steps requested before entering a contract; legitimate interests in account security | For the life of the account; a session lasts up to 30 days, is extended while the account is in use and is then removed |
| Provide the Startup Profile, idea workspace, scoring and AI features | Performance of a contract | Until account deletion or earlier user deletion where supported |
| Process plan and credit purchases, record immediate-performance requests and provide digital services | Performance of a contract; compliance with consumer-law obligations; establishment, exercise or defence of legal claims | Transactional and consent evidence for the applicable statutory limitation and mandatory record-keeping periods |
| Process payments, invoices, VAT and accounting | Performance of a contract and legal obligations | For the period required by Polish accounting and tax law |
| Waitlist: tell a visitor when access is available | Consent given by submitting the address | Until access is granted or the person asks to be removed |
| Security, abuse prevention (including Cloudflare Turnstile on the email sign-in form), debugging and service reliability | Legitimate interests in protecting users, systems and legal rights | Technical, security, scoring and credit audit logs: up to 12 months, unless longer retention is necessary for an incident, dispute or legal obligation |
| Microsoft Azure hosting and runtime diagnostics | Performance of a contract; legitimate interests in service delivery, security and debugging | Application and platform logs in Azure Monitor (Log Analytics and Application Insights) are retained for 31 days |
| Product and website analytics through Amplitude and Google Analytics | Legitimate interests in understanding how IdeaDrive is used and improving it | Amplitude user-level and event-level data: 12 months. Google Analytics user-level and event-level data: 14 months. Aggregated or de-identified reports may remain available |
| Transactional and authentication email | Performance of a contract; legitimate interests in security and service communication | For as long as needed to deliver, document and troubleshoot the communication, subject to Resend's service retention |
| Marketing email | EEA recipients: consent. US recipients: legitimate interests in direct marketing, subject to CAN-SPAM and the recipient's right to opt out. Suppression records: legal obligations and legitimate interests in respecting opt-outs | Until consent is withdrawn or the user unsubscribes; a minimal suppression record may be kept to respect the opt-out |
| Support, feedback and legal/privacy requests | Performance of a contract, legitimate interests and legal obligations, depending on the request | For as long as needed to handle the request and establish, exercise or defend legal claims |
| Legal claims, fraud, chargebacks and authority requests | Legal obligation and legitimate interests | Until resolution and expiry of the applicable limitation period. Where access to an account was closed because of a payment dispute, the account data is kept for as long as needed to defend the dispute |
We do not retain identifiable personal data longer than reasonably necessary for the stated purpose, subject to mandatory legal obligations and provider-specific technical deletion cycles.
6. Account deletion and backups
When a user confirms account deletion, IdeaDrive deletes the account and associated active application data promptly; in normal operation this is intended to occur immediately. Exceptions apply to transaction, tax, fraud, dispute or other records that must be retained by law or are necessary to establish, exercise or defend legal claims.
After deletion we keep a one-way hash (SHA-256) of the account's email address, without the address itself, so that the same address cannot be registered again to obtain a new starting grant of credits. The hash is kept on the basis of our legitimate interests in preventing abuse, for as long as that protection is needed; a person can ask us to remove it by emailing info@tallumfoundry.com.
Residual copies of deleted database data may remain in the automated backups of Azure Database for PostgreSQL for up to 7 days, after which the relevant backup expires. The backups are kept in the same Azure region as the database. Data separately retained by processors may follow their documented deletion cycles or mandatory legal requirements.
IdeaDrive does not provide a self-service pre-deletion export at launch. This does not limit statutory rights of access or portability. Where applicable, a user may request a copy of personal data or recovery of qualifying non-personal content by emailing info@tallumfoundry.com.
7. AI processing
IdeaDrive may send startup ideas, prompts, relevant Startup Profile context and generated or intermediate content to OpenAI and Anthropic APIs. Where scoring uses web research, search queries derived from the idea are sent to Perplexity. These requests are routed through the Vercel AI Gateway. We seek to exclude direct identifiers such as names and email addresses unless technically necessary.
- OpenAI states that API data is not used to train its models unless the customer explicitly opts in. Default abuse-monitoring logs may contain prompts and responses and may be kept for up to 30 days, subject to endpoint-specific storage and legal/security exceptions.
- Anthropic states that commercial API inputs and outputs are not used for model training unless the customer opts in and are deleted from its backend within 30 days by default, subject to agreed exceptions, usage-policy enforcement and law.
IdeaDrive does not authorize any AI provider to use IdeaDrive customer content for model training and will not opt in without updating this Policy and any required notices or consents.
EU AI Act transparency. Tallum Foundry acts as a deployer of third-party AI systems supplied by OpenAI, Anthropic and Perplexity. IdeaDrive informs users that they are using an AI-enabled service and that AI Outputs are machine-generated. AI-generated content is identified in the interface. IdeaDrive provides any disclosure required of a deployer by Article 50 of Regulation (EU) 2024/1689 (EU AI Act) and does not intentionally remove provider-supplied machine-readable markings from AI Outputs. Article 50 applies from 2 August 2026.
AI outputs may contain errors or omissions. They are reviewed and acted upon by the user and do not constitute automated decision-making with legal or similarly significant effects under Article 22 GDPR.
8. Recipients and processors
| Provider | Main role | Location / transfer context |
|---|---|---|
| Microsoft Azure / Microsoft Ireland Operations Limited | Hosting of the website, the application, database, sessions and background processing (Azure Container Apps, Azure Database for PostgreSQL, Azure Functions) and monitoring | Central US region, United States |
| Vercel | AI Gateway: routing of AI model and web-research requests to OpenAI, Anthropic and Perplexity; no hosting | United States / global infrastructure |
| Google OAuth; Google Analytics and Google Tag Manager | Global, including the United States | |
| Cloudflare | Turnstile bot protection on the email sign-in form | United States / global infrastructure |
| Stripe | Hosted checkout, payments, billing and fraud prevention | Applicable Stripe entity and global infrastructure |
| Resend / Plus Five Five, Inc. | Magic-link, transactional and marketing email delivery | United States |
| OpenAI | AI generation and analysis | United States and other configured service locations |
| Anthropic | AI generation and analysis | United States and other configured service locations |
| Perplexity | Web research used in scoring | United States |
| Amplitude | Product analytics | United States data center |
We may also disclose data to professional advisers, auditors, insurers, authorities or courts where necessary and legally permitted, or in connection with a merger, financing, reorganization or sale of the business subject to appropriate safeguards.
We do not sell personal data for money, share it for cross-context behavioural advertising or process it for targeted advertising. If that ever changes, we will update this Policy and provide an opt-out before the processing begins, as described in Section 15.
9. International transfers
IdeaDrive is operated by a Polish company but uses providers and infrastructure in the United States. Where GDPR or equivalent transfer rules apply, transfers are supported as appropriate by provider Data Processing Addenda, the European Commission's 2021 Standard Contractual Clauses, participation in an applicable adequacy framework such as the EU-US Data Privacy Framework, or another lawful transfer mechanism.
The safeguards currently relied on for the principal providers are:
| Provider / transfer | Transfer safeguard |
|---|---|
| Microsoft Azure | Contract with Microsoft Ireland Operations Limited; the EU-US Data Privacy Framework where applicable and the 2021 EU Standard Contractual Clauses incorporated into the Microsoft Products and Services DPA for the United States-hosted environment and other restricted transfers |
| Vercel | The 2021 EU Standard Contractual Clauses incorporated into the Vercel DPA for EEA transfers not covered by an adequacy decision |
| Google (OAuth, Analytics, Tag Manager) | The EU-US Data Privacy Framework where applicable and Google's Standard Contractual Clauses for transfers not covered by an adequacy decision, as described in Google's data-transfer frameworks |
| Stripe | The EU-US Data Privacy Framework where applicable, followed by the EEA Standard Contractual Clauses where required, under Stripe's Data Transfers Addendum |
| Resend | The EU-US Data Privacy Framework where applicable and the EU Standard Contractual Clauses incorporated into the Resend DPA |
| OpenAI | For EEA data, processing through OpenAI Ireland and transfers outside the EEA under an adequacy decision or agreements containing the EU Standard Contractual Clauses, under the OpenAI DPA |
| Anthropic | The Standard Contractual Clauses incorporated into Anthropic's DPA for commercial products and the Anthropic API, as described in the Anthropic Privacy Center |
| Perplexity | Reached only through the Vercel AI Gateway, under the safeguards of the Vercel DPA above |
| Cloudflare | The EU-US Data Privacy Framework where applicable and the EU Standard Contractual Clauses incorporated into the Cloudflare Customer DPA |
| Amplitude | The 2021 EU Standard Contractual Clauses incorporated into the Amplitude DPA |
Where an adequacy mechanism no longer applies, we rely on an available contractual safeguard or suspend the affected transfer as required by law. Users may request information about the applicable safeguards by emailing info@tallumfoundry.com.
We review relevant providers and apply measures such as encryption in transit, restricted access, data minimization and avoidance of unnecessary direct identifiers in AI requests.
10. Cookies and tracking
For information about authentication cookies, Amplitude, Google Analytics, Cloudflare Turnstile and Stripe, see the Cookie Policy.
Analytics runs by default and IdeaDrive does not show a cookie banner. A user can stop analytics cookies by blocking or deleting them in the browser, can use the Google Analytics Opt-out Browser Add-on, and can object to analytics processing by emailing info@tallumfoundry.com; we handle the objection under Section 14.
11. Security
We use technical and organizational measures appropriate to the nature and risk of the processing, including:
- HTTPS/TLS in transit and encryption at rest on Microsoft Azure;
- server-side authorization of every request, so that each account can reach only its own data;
- server-side storage of provider credentials and secrets;
- role-based and least-privilege administrative access;
- managed OAuth and session controls;
- automated database backups retained for seven days;
- logging, monitoring, rate limits and cost/usage alerts;
- hosted Stripe checkout so IdeaDrive does not handle raw payment-card data.
No service can guarantee absolute security. Users should contact info@tallumfoundry.com if they suspect unauthorized account access or misuse.
If a personal-data breach occurs, we assess its nature, scope and risk and notify affected users, supervisory authorities or other regulators where and within the time required by applicable law.
12. Children
IdeaDrive accounts are available only to users aged 16 or older. Paid purchases are available only to users aged 18 or older. We do not knowingly collect personal data from children below the applicable threshold. If we learn that an ineligible child has created an account, we will delete the account and associated data, subject to legal requirements.
13. Special-category and third-party data
IdeaDrive does not request special-category personal data. Users must not include sensitive personal data or third-party information in prompts or ideas unless they have a lawful basis and authority to disclose it. A user who submits third-party data is responsible for the lawfulness and accuracy of that submission.
14. GDPR and EEA rights
Subject to applicable conditions and exceptions, users in the EEA may have the right to:
- receive information about processing;
- access personal data and obtain a copy;
- correct inaccurate or incomplete data;
- request deletion;
- restrict processing;
- object to processing based on legitimate interests or direct marketing;
- withdraw consent at any time;
- receive portable data in a structured, commonly used and machine-readable format;
- lodge a complaint with a supervisory authority;
- not be subject to solely automated decisions producing legal or similarly significant effects.
Requests can be sent to info@tallumfoundry.com. We may need to verify identity. GDPR requests are normally handled within one month, subject to lawful extensions.
Users may complain to the President of the Polish Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych) or their local EEA authority. Information is available at uodo.gov.pl.
15. United States privacy disclosures and rights
This section supplements the rest of this Policy for residents of California and other US states with comprehensive privacy laws. Rights and obligations apply only where the relevant law applies to IdeaDrive and may be subject to statutory thresholds and exceptions.
Categories of personal information
The table below describes categories of personal information that IdeaDrive has collected or expects to collect during the preceding 12 months. Retention periods are described in Sections 5 and 6.
| Category | Examples | Sources | Business or commercial purposes and recipient categories | Sold or shared |
|---|---|---|---|---|
| Identifiers and account data | Name, email address, provider and IdeaDrive account identifiers, IP address, cookie and device identifiers | User, Google, browser or device | Authentication, account administration, security, communications and analytics; disclosed to hosting, authentication, email and analytics providers as relevant | Not sold or shared for cross-context behavioural advertising |
| Customer-record and billing information | Billing name and address, tax or VAT identifiers, Stripe customer and transaction identifiers | User and Stripe | Checkout, payment, tax, accounting, fraud prevention and support; disclosed to Stripe, hosting providers and professional advisers as required | Not sold or shared for cross-context behavioural advertising |
| Commercial information | Purchases, plans, credit activity, refunds, disputes and chargebacks | User, IdeaDrive and Stripe | Supply of the digital service, account administration, accounting, fraud prevention and support | Not sold or shared for cross-context behavioural advertising |
| Internet or other electronic-network activity | Browser and device information, page and feature activity, session duration, referral and campaign data, diagnostics and logs | Browser, device, Microsoft Azure, Amplitude and Google Analytics | Service delivery, security, debugging and analytics | Not sold or shared for cross-context behavioural advertising |
| Approximate geolocation | Country, region or city inferred from IP address | Browser, device and service providers | Security, localization and analytics | Not sold or shared for cross-context behavioural advertising |
| Professional or employment-related information | Professional background, experience, startup history, skills and preferred industries | User | Startup Profile, idea generation, scoring and personalization; disclosed to Microsoft Azure as hosting provider and relevant AI providers to provide the Service | Not sold or shared for cross-context behavioural advertising |
| Inferences | Preferences, interests, scores, rankings and recommendations derived from profile information, User Content and product activity | IdeaDrive and its AI providers | Generate, structure, score and compare startup ideas and improve requested results | Not sold or shared for cross-context behavioural advertising |
| User Content and communications | Startup ideas, prompts, briefs, URLs, AI Outputs, support messages and privacy requests | User and IdeaDrive | Provide AI features, save requested content, respond to requests, secure the Service and comply with law; disclosed to Microsoft Azure, Vercel (AI Gateway), OpenAI, Anthropic, Perplexity, Resend and advisers as relevant | Not sold or shared for cross-context behavioural advertising |
IdeaDrive does not intentionally collect sensitive personal information for the purpose of inferring characteristics. Authentication and session credentials are used only to create, secure and maintain the account. Full payment-card credentials are handled by Stripe and do not reach IdeaDrive. Users should not submit sensitive information in User Content.
Do Not Sell or Share My Personal Information
IdeaDrive does not sell personal information for money, share it for cross-context behavioural advertising or process it for targeted advertising. IdeaDrive does not use an advertising integration at launch.
Because none of this processing takes place, there is nothing to opt out of today. Before introducing any sale, sharing or targeted advertising, we will update this Policy and provide an opt-out mechanism, including recognition of browser-based universal opt-out signals such as Global Privacy Control (GPC). Users may email info@tallumfoundry.com with the subject Do Not Sell or Share at any time, and we will record the request.
US state privacy rights
Depending on the user's state and applicable law, the user may have the right to:
- know whether we process personal information and obtain access to it;
- receive the categories and specific pieces of personal information collected, sources, purposes and recipient categories;
- correct inaccurate personal information;
- delete personal information, subject to statutory exceptions;
- receive a portable copy of personal information;
- opt out of sale, sharing, targeted advertising or qualifying profiling;
- limit the use or disclosure of sensitive personal information where applicable;
- appeal a refusal to act on a request; and
- exercise privacy rights without unlawful discrimination or retaliation.
Submit a request by emailing info@tallumfoundry.com with the subject US Privacy Request. We may verify identity using information already associated with the account. Verification information is used only to process the request. An authorized agent may submit a request where permitted, subject to proof of authority and any permitted identity confirmation.
Where required, we confirm receipt within 10 business days and provide a substantive response within 45 calendar days. We may extend the response period once by up to an additional 45 days where permitted, after notifying the requester during the initial period and explaining the reason. Appeals are handled within the period required by the applicable state law, normally within 45 days.
16. Marketing communications and CAN-SPAM
For EEA recipients, IdeaDrive sends marketing email only with consent at launch. In the United States, IdeaDrive may send commercial email as permitted under the CAN-SPAM Act using an opt-out model.
Every marketing email sent through Resend must:
- use accurate sender and routing information and a subject line that is not deceptive;
- identify the message as an advertisement where required;
- include a clear unsubscribe mechanism; and
- include Tallum Foundry's valid physical postal address: Floriańska St. 6, Unit 02, 03-707 Warsaw.
The unsubscribe mechanism remains available for at least 30 days after the message is sent. We honour an opt-out within 10 business days, do not charge a fee, and do not require information beyond the email address or more than a reply email or a single web page. An opted-out address is retained on a suppression list and is not sold or transferred except to a provider used to honour the opt-out.
Users can unsubscribe using the link in a marketing email or by writing to info@tallumfoundry.com. Transactional, security, authentication and purchase-related messages may still be sent where necessary to provide the Service or protect an account.
17. Changes to this Policy
We may update this Policy as IdeaDrive, its providers or applicable law changes. The current version will be published on the website with a new effective date. Where a change materially affects registered users or requires renewed consent, we will provide an appropriate notice by email or in-product message.
18. Contact
Questions, privacy requests and complaints may be sent to: