Privacy Policy

Last updated: January 1, 2025

1. Who We Are

Ideakly ("we", "us", "our") operates the Ideakly platform available at ideakly.com. This Privacy Policy explains how we collect, use, and protect your personal data when you use our service.

For questions: privacy@ideakly.com

2. Data We Collect

  • Account data: Email address, name (optional), authentication provider (email/Google)
  • Usage data: Business ideas you submit for analysis, generated reports, timestamps
  • Payment data: Payment status and plan (we do NOT store card numbers — processed by YooKassa/Prodamus)
  • Technical data: IP address (for rate limiting), browser type, device type
  • Cookie data: Session cookies, language preference, consent record

3. How We Use Your Data

  • Provide and improve the analysis service
  • Process payments and manage subscriptions
  • Send service-related emails (account confirmation, billing)
  • Enforce usage limits and prevent abuse
  • Improve AI model prompts and report quality (anonymized)

We do NOT sell your data to third parties or use it for advertising.

4. Legal Basis (GDPR)

  • Contract: Processing necessary to provide the service you requested
  • Consent: Marketing emails (you can withdraw at any time)
  • Legitimate interest: Fraud prevention, service security
  • Legal obligation: Accounting and tax compliance

5. Data Retention

  • Account data: kept while account is active + 90 days after deletion
  • Reports: kept while account is active; deleted on account deletion request
  • Payment records: kept 7 years (legal requirement)
  • IP logs (rate limiting): 24 hours

6. Third-Party Services

  • Supabase — database and authentication (EU/US data centers)
  • Groq — AI language model for report generation (US)
  • Tavily — web search for market data (US)
  • Vercel — hosting platform (US/EU)
  • YooKassa / Prodamus — payment processing (Russia)

7. Your Rights

Under GDPR and applicable laws, you have the right to:

  • Access your personal data
  • Correct inaccurate data
  • Delete your account and data ("right to be forgotten")
  • Export your data in machine-readable format
  • Object to processing or withdraw consent

To exercise any right: privacy@ideakly.com

8. Cookies

See our Cookie Policy for details.

9. Data Security

We use industry-standard security measures: encrypted connections (HTTPS/TLS), hashed passwords, row-level security in database, API key rotation. No system is 100% secure — we will notify you promptly of any breach affecting your data.

10. Children

Ideakly is not intended for users under 16. We do not knowingly collect data from minors.

11. Changes

We may update this policy. We will notify registered users by email for material changes. Continued use after the effective date constitutes acceptance.