Privacy Policy
HaveTheIdea is the name of this service. The person responsible for your personal data — the controller — is Tomas Bartunek, an Australian sole trader. This policy explains what we collect, why, and your rights under the Australian Privacy Act, the EU/EEA GDPR, the UK GDPR, the California Consumer Privacy Act (CCPA/CPRA) and comparable laws. We keep data collection to the minimum needed to run the Service. We do not sell your personal data and we do not use advertising or tracking cookies.
1. What we collect and why
| Data | Purpose | Legal basis (GDPR) | Retention |
|---|---|---|---|
| Email address | Sign-in (one-time codes), delivering your dossier, service emails | Contract (Art. 6(1)(b)) | Until account deletion |
| Business idea & wizard answers | Generating your dossier | Contract | Until you delete the draft/dossier or account |
| Generated dossiers | Providing your purchase | Contract | Until account deletion |
| Purchase records (amount, currency, Stripe IDs — never full card numbers) | Payment processing, accounting, fraud prevention | Contract + legal obligation (Art. 6(1)(c)) | As required by tax law (typically 5–10 years) |
| IP address, user agent, security logs | Security, rate limiting, fraud & abuse prevention | Legitimate interest (Art. 6(1)(f)) | 12 months |
| Cookies / localStorage | Session only — no advertising or analytics cookies | Strictly necessary | Session |
We do not knowingly collect special-category (sensitive) data. Please do not put third-party personal data or sensitive data into your idea description.
2. AI processing
To generate your dossier, the text you enter is sent from our servers to our AI model providers (currently DeepSeek; optionally Anthropic for higher tiers), which process it on our instructions to produce your dossier and return it to us. We do not use your content to train any model of our own, and we use these providers' API services rather than their consumer products. Their own terms also apply to that processing. Outputs may be inaccurate — see our Terms. Please do not submit other people's personal data.
3. Who we share with (processors)
We share only what is necessary, and only with providers acting on our instructions:
- Stripe — payment processing. We never receive or store your full card details.
- ChemiCloud — website and database hosting, and outgoing email, on servers in Sydney, Australia.
- DigitalOcean — the server that generates dossiers and renders PDFs, located in Singapore.
- AI model providers — as described in §2.
We never sell or rent personal data and we use no ad networks or cross-site tracking. We may disclose data if required by law, or to protect our rights or the safety of users.
4. International transfers
We are based in Australia and our servers are in Australia and Singapore, so your data is processed outside the EEA and the UK. Neither Australia nor Singapore is covered by a European Commission adequacy decision for this purpose. Where we process personal data of people in the EEA or the UK, we rely on the EU and UK Standard Contractual Clauses with our providers, together with technical safeguards including encryption in transit and encryption of secrets at rest.
5. Your rights — everyone
Depending on where you live, you may have the right to access, correct, delete, restrict or object to processing, data portability, and to withdraw consent. The easiest path is the in-app "Delete account" button, which removes your account, drafts and dossiers; records we must keep by law (e.g. purchase and tax records) are retained. To exercise any right, email info@havetheidea.com. We respond within the time required by applicable law (generally within 30 days).
Australia (Privacy Act)
You may ask for access to, or correction of, the personal information we hold about you. If you are not satisfied with how we handle a privacy complaint, you can contact the Office of the Australian Information Commissioner (oaic.gov.au).
EU / EEA & UK (GDPR / UK GDPR)
You have the rights above and the right to lodge a complaint with a supervisory authority. In the EEA that is the data protection authority of the country where you live or work; in the United Kingdom it is the Information Commissioner's Office (ico.org.uk). You can also always contact us first at info@havetheidea.com.
California (CCPA / CPRA)
California residents have the right to know, delete, correct, and to opt out of "sale" or "sharing" of personal information. We do not sell or share personal information as those terms are defined, and we do not use it for cross-context behavioural advertising. We will not discriminate against you for exercising your rights. Exercise them at info@havetheidea.com.
Other regions
If your local law (for example in Canada or Brazil) grants further rights, we honour them where they apply. Contact us and we'll help.
6. Security
API keys and secrets are encrypted at rest (AES-256-GCM), data is transmitted over TLS, sign-in is passwordless (one-time codes), and access is limited to the operator. No system is perfectly secure; we cannot guarantee absolute security.
7. Children
The Service is not directed at, and we do not knowingly collect data from, children under 16. If you believe a child has provided data, contact us and we will delete it.
8. Changes
We may update this policy; material changes will be announced by email or in the app. Continued use after the effective date means you accept the updated policy.
← Back to HaveTheIdea