Privacy Policy

Last updated: June 8, 2026

What we collect

  • Account data: email address and password hash (via our auth provider) when you sign up.
  • Profile data: optional display name, avatar, and bio you choose to add.
  • Usage data: blueprints viewed, ideas read, saves, upvotes, Spark Lab prompts, and Library reading activity (book opened, last page viewed, AI search queries) — used only to enforce tier limits and improve the product.
  • Payment data: if you upgrade, Razorpay handles card and bank details directly; we only store the Razorpay order ID, payment ID, amount, currency, your purchased tier, and the date your access expires.
  • Contact messages: if you write to us through the Contact page, we store the name, email, subject, and message you submit so we can reply.
  • Newsletter data: email address and segment preferences (weekly / launches / main) when you subscribe.

What we do not collect

We do not track you across the web. We do not sell your data. We do not use third-party analytics that fingerprint devices.

How we use your data

  • To authenticate you and keep your session secure.
  • To deliver the content you paid for and enforce tier gates (e.g. the 3-page Library preview limit for free accounts).
  • To issue short-lived, signed Library view tokens that grant in-app reading without exposing the underlying PDF URL.
  • To send newsletters you explicitly opted into.
  • To surface relevant ideas and books (e.g., saved categories, search history).
  • To prevent abuse and spam via rate limiting.

Data storage & security

Your data is stored in our backend database with Row-Level Security (RLS) enabled. We use HTTPS everywhere. Passwords are hashed by our auth provider (bcrypt). Library PDFs are stored in private object storage and only served through signed, expiring URLs. We retain data only as long as your account is active or as required by law.

Cookies

We use a single session cookie to keep you logged in. No ad trackers. No cross-site cookies. You can clear cookies in your browser at any time.

Third parties

  • Razorpay — payment processing for tier purchases.
  • Brevo — newsletter and transactional email delivery (sender: newsletter@ideafordge.soy56.dev).
  • Lovable Cloud — authentication, database, and file storage hosting.
  • Lovable AI Gateway — powers Spark Lab blueprint generation and Library AI search; prompts and queries are sent to the gateway to return answers.
  • Google Drive (via Lovable Connector Gateway) — source storage for Library PDF books, fetched server-side and trimmed before being served to you.

Your rights

You can update your profile (display name, bio, avatar) from the Settings page. To export or delete your account data, send a request from the Contact page using the email on your account; we will action it within 30 days, removing your profile and anonymizing usage analytics. You can also unsubscribe from the newsletter at any time using the link in any newsletter email.

Changes

If we change this policy in a material way, we will email active users and update the date above.