DocsReference
Limits, privacy & security
Hourly usage limits, what Idea Bucket sends to Google Gemini, who can read your ideas, what stays on your device and how to delete your data.
On this page
This page lists the limits Idea Bucket applies to every account, and explains where your ideas go: who can read them, what's sent to Google Gemini and when, what's kept on your device, and how to delete things for good.
Hourly limits
The AI features run on a shared Google Gemini allowance, so each account gets an hourly budget for them. Counts start over at the top of every hour (UTC). Everything else, like dropping, browsing, tagging, archiving and notes, has no hourly limit.
| Limit | What counts against it | Per hour |
|---|---|---|
| Search and indexing | Each idea you drop or edit (it gets indexed for search by meaning), each search you type, catch-up indexing when you open the app, and the same actions from a connected assistant (adding an idea, changing its text, searching) | 600 |
| Dictation | Each time you start the mic with Gemini transcription | 60 |
| Sparks | Each request for spark cards in Explore (one per Explore session) | 30 |
| Tag summaries | Each tag summary an assistant asks Gemini to write (only when there isn't an up-to-date one already) | 60 |
| AI notes | Each run of an automation that has Gemini write a note | 100 |
| Automations | Each automation run that gets as far as its action: tags, archive, calendar events, webhooks, AI notes and Grok Bot dispatches (and Grok Bot test sends) | 300 |
An AI note run counts against both AI notes and Automations. Runs that are skipped (the rule is off, or the idea is in the trash) and runs still waiting for your approval don't count.
What happens when you hit one
Nothing you type is lost. Here's what you'll see for each limit:
- Search and indexing, in the app. Your idea still saves, with the message Saved — hourly indexing limit reached, it will be indexed later. It's indexed automatically the next time you open the app after the hour rolls over. Searches still work, but match words only: Find shows Keyword only instead of Meaning + keywords.
- Search and indexing, from an assistant. The tool call fails with Hourly limit reached for search and indexing, try again later. When an assistant adds an idea and gets this message, that idea was not saved, so ask again after the top of the hour.
- Dictation. The mic keeps working with your browser's own speech recognition, and you'll see Dictation limit reached for this hour — using basic dictation. While it's listening, the composer shows Listening… (basic). If your browser has no speech recognition of its own, you'll see Dictation limit reached for this hour — try again later instead.
- Sparks. Explore works as usual, just without spark cards until the next hour. No message is shown.
- Tag summaries. The assistant still gets everything else about the tag (open ideas, the changelog, recent activity). The summary is left out, or the last one is returned marked as stale, with the note Hourly limit reached for tag summaries, try again later.
- AI notes and Automations. The run shows as failed in Recent runs on the Automations screen, with Hourly AI note limit reached or Hourly automation limit reached. It isn't retried by itself. Select Retry once the hour rolls over.
Other limits
| What | Limit |
|---|---|
| Idea length | 10,000 characters (the composer stops you there, and assistants get an error past it) |
| Note length | 20,000 characters per note |
| Access keys | 10 per account |
| Access key name | 60 characters |
| Search results | 20 per search in the app. Assistants get up to 50 (10 unless they ask for more) |
| Trash | Ideas stay for 30 days, then they're deleted for good |
| Saved on your device for offline use | Up to 500 of your newest ideas, plus the notes you've opened on that device |
Who can read your ideas
Only you. Every idea, note, tag, automation and connection belongs to your account. The database checks the signed-in account on every read and write (row-level security), so another account can't see or change your data, even by guessing an idea's ID.
Connected assistants work as you: they sign in through your account and get exactly the same view, never anyone else's ideas. They also can't see ideas in your trash.
What goes to Google Gemini
Idea Bucket uses Google's Gemini API for search by meaning, dictation, sparks and AI notes. The API key stays on Idea Bucket's servers and is never sent to your browser. Here's exactly what Gemini receives, and when:
| Feature | When | What's sent |
|---|---|---|
| Indexing for search | When you drop or edit an idea, or an assistant adds or rewrites one | The idea's text, without its tags. Notes aren't indexed. |
| Searching | When you search Find by words, or an assistant searches | Your search words (a #tag search doesn't use Gemini) |
| Dictation | While the mic is on and Gemini transcription is in use | The audio from your microphone, streamed straight from your device, plus your 200 most-used tag names so they're transcribed correctly |
| Sparks in Explore | Once per Explore session, when you're online | Up to 7 of the ideas shown in that session, each cut to 400 characters, with their tags |
| AI notes | When an automation with a Gemini note runs | Your instruction for the rule, the idea's full text and its tags |
| Tag summaries | When an assistant asks about a tag with more than 2 ideas and there's no up-to-date summary | The tag, up to 80 of its newest ideas (each cut to 400 characters) and up to 20 recent notes on them (each cut to 300 characters) |
Nothing else is sent to Gemini. Opening, browsing, tagging, archiving, filtering and Explore's own picks all run without it.
Google Calendar
Calendar automations need you to connect Google Calendar on the Automations screen. When you select Connect, Google asks you to allow:
- your email address (shown as Connected as you@example.com), and
- permission to create and edit events in your calendars (Google's
calendar.eventspermission). Idea Bucket only uses it to add the events your calendar rules describe.
Google gives Idea Bucket a long-lived token so rules can add events while you're away. It's stored on the server, and the app itself can't read it back. Select Disconnect on the Google Calendar card to delete that token. Events already created stay in your calendar.
AI assistants and access keys
When you connect Claude, ChatGPT, Gemini or Grok, you approve the connection on Idea Bucket's own screen, so the assistant never sees your password or sign-in link. You can see each connection in Profile → Connectors, and Disconnect cuts it off immediately.
Access keys (for apps that can't sign in, like Grok Bot) work the same way, as you. A key is shown once, when you create it. You'll see You won't see this key again. Idea Bucket keeps only a fingerprint of the key (a SHA-256 hash) plus its first few characters, so you can tell keys apart. If you lose a key, revoke it and create a new one.
Assistants can search and read your ideas, add ideas, change an idea's text and tags, archive and restore ideas, add notes, edit the notes they wrote, and send an idea to Grok Bot when you ask. They can't:
- move ideas to the trash or delete them,
- delete notes, or edit your notes or another assistant's,
- see the trash,
- change your automations, connectors, access keys or Google Calendar connection.
See Connectors for setup.
Secrets in automations
- Grok Bot key. The key you paste into a Grok Bot rule is saved where only the automation can read it. The editor then shows Key saved with a Replace link, and the key itself is never shown again.
- Webhook signing secret. Each webhook rule gets its own signing secret, generated by Idea Bucket. Unlike the Grok Bot key, it stays visible (and copyable) in the rule's editor, because you need it to verify signatures on your end.
Webhooks and Grok Bot send your idea to the address you set up. A webhook gets the idea's text, tags and dates. Grok Bot also gets its notes and your instructions. Only point them at services you trust.
What's stored on your device
To work offline and open quickly, the app keeps a copy of some of your data in the browser's storage on each device (IndexedDB):
- up to 500 of your newest ideas (active and archived), and the notes you've opened,
- counts (ideas, tags, trash), your automation rules and tag colors,
- the outbox: ideas you dropped while offline that haven't reached the server yet.
Your sign-in session is kept in the browser too, so you stay signed in.
When you select Sign out on the Profile screen, the saved copy is cleared from that device, except the outbox. Ideas that never synced stay on the device, and sync the next time the same account signs in there. If any are waiting, the app asks first: "1 idea hasn't synced yet. They'll stay on this device and sync next time you sign in."
Sign out only affects the device you're on. Your other devices and connected assistants stay signed in. Disconnect assistants separately in Profile → Connectors.
Deleting your data
- Delete an idea. Deleting an idea moves it to the Trash, notes and all. You can Restore it from there for 30 days. After that it's deleted for good automatically.
- Delete it now. In Trash, select Delete forever on an idea, or Empty trash for everything. Both ask first and can't be undone. The idea, its search index, its notes and its automation history are removed.
- Delete a note. Open the idea's notes and delete it there. Only you can delete notes.
- Revoke access. Disconnect assistants and revoke access keys in Profile → Connectors, and disconnect Google Calendar on the Automations screen.
Things that already left Idea Bucket aren't affected by deleting the idea: calendar events that were created, webhook deliveries and Grok Bot dispatches that were sent.