Privacy notice
Idea Builder uses an access-controlled workspace for each customer and minimizes identity, billing, and operational data.
Data the service is designed to process
- Verified sign-in identifiers, stored internally as an immutable user ID and one-way identity/email hashes.
- Customer-created cards, sources, decisions, tasks, notes, project history, and selected account preferences.
- Stripe customer, subscription, and event identifiers plus billing state; Idea Builder does not receive full card numbers.
- Idea Builder does not request, accept, or store customer API keys or other provider credentials.
- Content-minimized security and reliability metadata. Application logs exclude tokens, cookies, raw IP addresses, email addresses, board content, and tool arguments.
Purposes
Data is used to authenticate the customer, provide the workspace, enforce the selected plan, preserve project continuity, prevent abuse, diagnose failures, support export/deletion, and maintain audit evidence. If organization-managed share-safe routing is enabled, OpenAI processes only bounded packets that pass the service's disclosure gate.
Service providers
Cloudflare provides the application and durable storage boundary. Stripe provides hosted payment and billing management for paid plans. The customer's selected identity provider processes only the data required for sign-in. If organization-managed share-safe routing is enabled, OpenAI processes the bounded packet under OpenAI's applicable terms and privacy notice.
Retention and customer control
Project data remains until the customer deletes the account or a disclosed retention rule applies. Short-lived chat selection expires automatically. Export and account deletion are available in the authenticated app. Encrypted backups follow the published retention and deletion schedule.
Contact
Use the authenticated support path for privacy requests so the account and request can be verified without posting sensitive workspace content publicly.