DocsLegal
Privacy Policy
What Idea Bucket collects, why, who processes it, how long it's kept, and how to see, export, correct or delete your data.
On this page
Last updated: 5 October 2026
This policy explains what Idea Bucket ("we", "us") collects when you use ideabucket.app, the Mac app, the public demo, these docs and the connections you set up, why, who helps us process it, and the choices you have. For the short version, see Limits, privacy & security.
Idea Bucket is the controller of your personal data. Questions, requests and complaints go to privacy@ideabucket.app, and we answer within 30 days.
What we collect
| What | Examples | Why |
|---|---|---|
| Account details | Your email address, sign-in method (email link or Google), when you signed up and last signed in | To create and secure your account and sign you in |
| Your content | Ideas, notes, tags, tag colors, automations, shared tags and their members, invites you send | To store it and show it back to you: this is the service |
| Profile | Display name, profile picture or designed avatar | So teammates in shared tags can recognize you |
| Connections | Access-key fingerprints (never the key itself), assistants you approved, Google Calendar token, Jira site and token, Grok Bot key, webhook URLs and signing secrets | To run the integrations you set up |
| Usage counters | How many AI requests you made this hour or day | To apply plan limits fairly |
| Billing | Plan, status, renewal date, seats, and the payment provider's customer and subscription ids | To give you the plan you paid for |
| Analytics (only with consent) | Pages and features used, counts and kinds (never what you wrote), errors, masked session replays | To understand what's used and fix what breaks |
| Device storage | A copy of your newest ideas for offline use, your sign-in session, settings | So the app works offline and keeps you signed in |
We don't sell your data, use it for advertising, or train AI models on your ideas ourselves. See the next section for how Google handles what the AI features send.
AI processing with Google Gemini
Search by meaning, Ask, dictation, Explore sparks, AI notes, Jira write-ups and tag summaries use the Google Gemini API. When you use one of them, the relevant text (for example an idea's text to index it, your question and the ideas it gathered for Ask, or microphone audio while dictation is on) is sent to Google to produce the result. Exactly what each feature sends is listed under What goes to Google Gemini. Google processes this under the Gemini API terms; we don't let Google keep it to train its models on paid API usage, and we don't send your email address or account details with it.
Who processes your data
We use these service providers ("processors"). Each only gets what it needs for its job.
| Provider | Purpose | Location |
|---|---|---|
| Supabase | Database, sign-in, file storage (profile pictures), server functions | EU (Frankfurt, eu-central-1) |
| Google (Gemini API) | The AI features above | Google's global infrastructure |
| Cloudflare | Hosting the website, docs and demo; routing requests | Global network |
| PostHog | Product analytics and masked session replays, with your consent | EU |
| Resend | Sending shared-tag invite emails (address, your display name, the tag name) | Resend's infrastructure (USA or EU) |
| Lemon Squeezy or Paddle | Checkout, payments, invoices, sales tax, as merchant of record | See their privacy policies |
Only when you connect them: Google Calendar (events you create through rules), Atlassian Jira (issues written from your ideas, sent to your own *.atlassian.net site), Grok Bot / xAI (ideas you dispatch, with their notes and your instructions), your own webhook endpoints (an idea's text, tags and dates), and any AI assistant you connect over MCP (it reads and writes as you, within the limits in Connectors). Those services handle data under their own terms.
Shared tags
If you share a tag, or join one, members can read the ideas that carry that tag (yours and theirs), the notes on them and each member's display name and picture. They can't see your other ideas, your archive or trash, or your email address. Owners of email invites see the addresses they invited. Leaving or stopping sharing ends access immediately.
Analytics and cookies
Analytics run only after you choose Accept on the consent bar (or switch on Settings → Privacy → Share anonymous usage analytics). Until then, and if you choose Decline, the analytics script isn't loaded at all. If your browser sends Do Not Track or Global Privacy Control, we treat it as Decline and don't ask.
Your choice is stored in your browser's local storage and covers the site, the app, these docs and the demo on the same device. You can change it any time in Settings → Privacy. With consent, PostHog stores an identifier in local storage and a first-party cookie.
Separately, when your plan changes, the payment provider tells our server, which records the change (plan, monthly or yearly, seats) in our analytics against your account. This is needed to run billing and isn't affected by the consent choice.
We don't use advertising or third-party tracking cookies. The sign-in session and offline copy are strictly necessary local storage.
Legal bases (EU and UK)
- Contract: your account, your content, sync, sharing, integrations you set up and billing.
- Consent: analytics and session replays. You can withdraw it at any time.
- Legitimate interests: keeping the service secure, preventing abuse (rate limits), and fixing errors reported by the server.
- Legal obligation: keeping billing records where the law requires.
How long we keep it
- Your content stays until you delete it. Deleted ideas sit in Trash for 30 days, then are deleted for good.
- Your account: when you delete it (Settings → Account → Delete account), your ideas, notes, tags, automations, shared-tag memberships, connections, profile and picture are deleted. Data may remain in encrypted backups for a limited period before they're overwritten (up to 30 days).
- Usage counters are kept only for their time window.
- Analytics data is kept in PostHog for up to 12 months.
- Billing records are kept by the payment provider and by us for as long as tax and accounting law requires.
Things already sent to services you connected (calendar events, Jira issues, webhook deliveries, Grok Bot dispatches) stay with those services.
Your rights
You can:
- See and export your data: Settings → Account → Export my ideas downloads your ideas, notes and tags.
- Correct it: edit ideas, notes, tags and your display name in the app.
- Delete it: delete ideas, empty the trash, or delete your whole account in Settings → Account.
- Withdraw consent to analytics in Settings → Privacy.
- Object to processing based on legitimate interests, or ask us to restrict it.
If you're in the EU or UK you can also complain to your data protection authority. If you're in California, you have the right to know, delete and correct personal information, and not to be discriminated against for using these rights; we don't sell or share personal information for cross-context behavioral advertising.
To use any right we can't handle in the app, email privacy@ideabucket.app.
International transfers
Our main database is in the EU. Some providers (for example Google, Cloudflare and the payment provider) may process data outside your country. Where data leaves the EU or UK, we rely on the provider's adequacy decisions or Standard Contractual Clauses.
Security
All traffic is encrypted (HTTPS). The database checks the signed-in account on every read and write (row-level security), secrets for integrations are stored where only the server can read them, and access keys are kept only as fingerprints. No system is perfectly secure; if we learn of a breach that affects you, we'll tell you as the law requires.
Children
Idea Bucket isn't meant for children. You must be at least 16 to use it (or 13 where your country's law allows a lower age for consent to online services). If you believe a child has given us data, contact us and we'll delete it.
Changes
If we change this policy in a meaningful way, we'll update the date above and tell you in the app or by email before it takes effect.
Contact
Idea Bucket. Email privacy@ideabucket.app.
See also the Terms of Service.