Privacy by design
Privacy Policy
Last updated 16 July 2026. This notice explains how IdeaClarify handles data across the public website, AI guidance, accounts, venture reports, purchases, and consulting requests.
Who is responsible
The data controller is KloudGentic B.V., operating IdeaClarify.com from Hilversum, The Netherlands (KVK 42034727). Privacy questions and rights requests can be sent to idea.clarify@kloudgentic.com. Full company details are on the Imprint.
Data we process
- Public Founder Guide: the question you submit, a Turnstile verification result, and a salted hash of the request IP for abuse prevention. IdeaClarify does not save the public question or answer to its database.
- Free verdict and venture workspace: your venture description, intake answers, generated reports, feedback, saved questions, and exports.
- Private Ask Studio: your question plus the original venture description and current reports required to answer it. Chat history is saved only when you select the save option.
- Account and communication: email address, authentication records, account settings, transactional emails, and optional marketing consent.
- Support requests: the email address, selected topic, description, workflow status, Turnstile verification result, and rate-limit metadata you submit through the support form. The ticket is stored in the IdeaClarify product database and an operator notification is delivered through Resend.
- Payments and consulting: purchase identifiers, product, price, tax/accounting records, and information you choose to include in a consulting request. Card data is handled by Stripe, not IdeaClarify.
- Security and reliability: rate-limit counters, timestamps, technical request metadata, and scrubbed error information. Request bodies are excluded from Sentry events.
- Consent-controlled browser analytics: anonymous page views through Umami and product events through PostHog only after you accept optional analytics, without venture descriptions, report text, search parameters, or chat questions.
Why we process it
We process data to provide the service you request, secure the platform, prevent abuse, deliver purchases and communications, meet accounting and legal obligations, and improve product reliability. Marketing email and optional browser analytics are based on consent and can be withdrawn. Security and narrowly scoped server-side operational metrics rely on legitimate interests, balanced against founder privacy. High-impact decisions remain yours: the product provides advisory analysis and does not make legal or similarly significant decisions about people.
AI processing and retention
The Founder Guide and venture reports use the commercial Anthropic API. Public Guide messages are not stored by IdeaClarify, but Anthropic’s current standard API terms state that API inputs and outputs are deleted from its backend within 30 days, subject to stated safety, legal, or separately agreed retention exceptions. IdeaClarify does not use founder content to train its own models and uses commercial API terms that exclude customer API content from model training.
Saved private Ask Studio history remains encrypted with the venture until you delete the venture or account. If saving is off, the answer remains only in the current browser page session. Account and venture deletion follows the product’s documented deletion workflow and completes within 30 days. Accounting records may be kept where law requires.
Unclaimed free analyses are deleted after 90 days. Resolved support tickets and completed data-rights records are deleted after 24 months; report-delivery metadata is deleted after 12 months; rate-limit records are pseudonymous and deleted after eight days. Export files and links expire after 24 hours. Open support or rights work can remain until it is completed. Accounting records may be retained for the period required by law, with the customer identity removed from the product account after erasure.
Processors and international transfers
The service uses Anthropic, Neon, Vercel, Inngest, Stripe, Resend, Cloudflare, PostHog, and Sentry for the limited purposes described on the confidentiality page. Some processors operate in the United States or globally. Appropriate contractual and transfer safeguards must be maintained with each processor where required.
Your choices and rights
- Use public articles without creating an account.
- Do not enter personal data, credentials, customer records, employee records, or unnecessary secrets in AI free-text fields.
- Keep Ask Studio history off, or save it intentionally to the venture.
- Export your account or venture data from the product.
- Request access, correction, deletion, restriction, portability, or object where GDPR provides those rights.
- Withdraw consent at any time without affecting earlier lawful processing.
- Accept, reject or revisit optional analytics through Cookie preferences.
- Complain to your competent EU data-protection authority.
We respond without undue delay and normally within one month. A complex request may take up to two additional months where GDPR permits, in which case we will explain the extension within the first month. Rights are not absolute: for example, limited accounting or legal-claims records may need to be retained. Verification is proportionate to the risk; for an account holder we normally use the existing account email or signed-in account rather than collecting a copy of an identity document.
Security and incident handling
IdeaClarify uses account-level tenancy checks, encrypted transport, application-layer encryption controls, server-only prompt and credential loading, output schemas, allow-listed recommendations, rate limits, anti-bot checks, and monitoring designed to exclude content. No online system can honestly promise to be “unhackable”; controls are reviewed and strengthened as threats and the product change.
Contact
Email idea.clarify@kloudgentic.com with “Privacy request” in the subject. We may need to verify account ownership before releasing or deleting account data.