Legal

Privacy Policy

Effective: August 12, 2026 · Previous versions

The short version

1. Who we are

PostIdea (postidea.app) is operated by Syed Muhammad Sufyan, an individual proprietor based in Karachi, Pakistan ("we", "us", "our"). This policy explains what information we collect when you use PostIdea, why we collect it, and the choices you have. Questions or requests: support@postidea.app.

2. What we collect

Account data

Your email address, a hash of your password (if you register with one — we never store the password itself), your OAuth provider identifier and display name (if you sign in with Google or GitHub), and your role selection from onboarding. If you join the waiting list, we store the email address and role you submit so we can contact you about access.

Content you create

Your idea conversations, specifications, architecture documents, decisions, and statements of work. This is the substance of the product and is stored in our database for as long as your account and projects exist. Your conversation and specification content is sent to one of our AI providers to generate results (see Subprocessors).

Content you submit for verification

We do not store your source code. Verification runs entirely in memory: the file listing, file contents, and code diff you submit are processed to produce a report, and then discarded. What we keep is the report — verdicts, coverage scores, and SHA-256 fingerprints of the inputs and outputs — never the code itself. The optional AI audit (off by default) sends your code diff — never full file contents — to Groq for one-time advisory review; the prompt is not stored, only its fingerprint. The temporary cache that supports safe retries holds a copy of the report with all AI-generated advisory text removed, for at most one hour.

Technical data

Standard server logs (IP address, user agent, request identifiers), security event logs (for example, failed sign-in attempts, recorded with the email and IP involved), and short-lived security counters (sign-in failure counts, rate-limit state) that expire automatically within minutes. We use these to keep the service running and to detect abuse.

Founding member programme

If you join the Founding 100 programme, we create a founding member record. It holds the email address on your account, a sequential founder number, and whether your trial has been used. Everything below is additional to that, and all of it is optional.

Who can see this. Your founding member record is readable by Sufyan and by two people on the team who help run onboarding and support. Nobody else. Your founder number is not currently displayed publicly anywhere — there is no public founders list or profile page.

Founding member feedback

If you send feedback from the founding member page, we store what you wrote: an optional 1–5 rating, and three optional free-text answers — what confused you, what is missing, and what would stop you paying. Why: to decide what to build and fix next; the whole reason the programme is capped at 100 people is that feedback at that size can actually be read and acted on. Who: Sufyan and the same two people on the team who handle onboarding and support. How long: kept for 24 months from submission, or until you ask us to delete it. It is never sold, never shared with advertisers, and never used for anything other than improving the product.

Write only what you are comfortable storing. These are free-text boxes, so please do not paste passwords, API keys, or client information into them — we cannot filter what a text box receives.

Landing page visit counts

When the /founding page loads we increment a counter for that day and the campaign tag in the link you followed. This is a tally, not a record of you. We store no IP address, no browser fingerprint, no session identifier and no cookie against it — the table can answer “how many people arrived from this link today” and is structurally incapable of answering “who”. We use it to see which posts bring people in.

We do not sell this data, and we never share it with advertisers. It is not used for advertising, profiling, or any purpose other than running the founding programme and supporting you.

3. AI processing

PostIdea's generation features (idea refinement, specifications, architecture, statements of work, risk scoring, and the optional verification audit) are powered by large language models hosted by third-party providers. We currently use two:

Which stage runs on which provider can change as we tune output quality. Both providers are listed as subprocessors below, and both are contractually prohibited from using your inputs or outputs to train or fine-tune models.

Groq is bound by the Groq Services Agreement §4.2 (effective October 15, 2025) — see Groq's Services Agreement and Data Processing Addendum. Anthropic's Commercial Terms of Service state that Anthropic may not train models on customer content submitted through its commercial API — see Anthropic's Commercial Terms of Service, Data Processing Addendum, and Privacy Policy.

To be precise about the limits of that promise: "not used for training" does not mean "never accessed." A provider may access data as necessary to operate its service, monitor for abuse, and enforce its usage policy, and may retain inputs and outputs for a limited period for those purposes under the terms of its data processing addendum.

4. Subprocessors

We use a small number of service providers to run PostIdea:

Provider Purpose Location
Groq, Inc.AI inference (specification, architecture, SOW, risk scoring, and the optional verification audit)United States
Anthropic PBCAI inference (architecture council stage)United States
DigitalOcean, LLCApplication and database hostingIndia (Bangalore)
CreemMerchant of record — payment and subscription processing for paid plansUnited States / EU
Google LLC"Sign in with Google" authentication; web fonts on marketing pagesUnited States
GitHub, Inc."Sign in with GitHub" authentication; fetching file listings of public repositories you point us atUnited States
Resend, Inc.Transactional email — account verification codes, password-reset codes, account notices, and the founding member welcome emailUnited States
PostHog, Inc.Product analytics on the /founding page only — anonymous page-view, scroll, and button-click events before sign-upUnited States

When you buy a paid plan, payment is handled by Creem as merchant of record. Creem processes your checkout and payment details as an independent controller under its own privacy notice — we never receive or store your full card details.

We may substitute subprocessors with providers offering equivalent data protections and will update this list when we do. We also plan to add product analytics (for example, PostHog) and error monitoring (for example, Sentry); each will be added to this list and take effect only after this policy is updated to name it. We do not use either of them today.

PostIdea's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We access only your basic profile (email address and name) for authentication.

5. Retention

6. Cookies and third-party requests

We use only strictly necessary cookies: a session cookie that keeps you signed in (HttpOnly, so scripts cannot read it) and a CSRF-protection cookie. There are no advertising cookies and no ad-network tracking of any kind.

One analytics exception, and it is limited to a single page. The /founding landing page loads PostHog to measure how that page performs: it records that the page was viewed, which sections were scrolled to, and whether the “Claim your spot” button was clicked or led to checkout. Those events carry only the channel attribution described in section 2 — never your email, name, phone number, account id, or founder number. Nothing is measured after sign-up, and the rest of the site and the app load no analytics at all. If you block PostHog, the page and the checkout button work exactly the same.

Attribution values themselves are stored in your browser's sessionStorage for the duration of that browsing session. They are not cookies, they are not readable by other sites, and they are discarded when you close the tab.

One honest caveat: our marketing pages (including this one) load fonts and scripts from third-party CDNs (Google Fonts, Tailwind CDN). Your browser discloses your IP address to those services when it fetches these files. The app itself (/app) is stricter — it loads no third-party scripts at all, enforced by our Content Security Policy.

7. Your rights

You can access and correct your data in the app. You can copy or download your specifications and SOWs from the app directly; for a full export of your data, email us. You can delete your account and all associated data at any time from the app; deletion is immediate and cascading, with the single founding-member exception described in Retention. To have founding contact details and call notes erased, or for any other request — access, correction, deletion, portability, or objection — email support@postidea.app and we will respond within 30 days.

8. International transfers

We operate from Pakistan and use subprocessors in the locations listed above (primarily the United States). By using PostIdea you understand that your data is processed in those locations under the protections described in this policy and our subprocessors' agreements.

9. Children

PostIdea is not directed to children and requires users to be at least 18 years old. We do not knowingly collect data from anyone under 18; if we learn we have, we will delete it.

10. Security

We take specific, verifiable measures to protect your data — including HttpOnly session cookies, CSRF protection, brute-force lockouts, TLS everywhere, and a strict Content Security Policy. The full list, including what we don't yet claim, is on our Security page.

11. Changes to this policy

When we change this policy, we will update the effective date at the top and keep prior versions available at /legal/archive/. For material changes we will notify you in the app or by email before they take effect.

12. Contact

Privacy questions and requests: support@postidea.app. Security reports: security@postidea.app (see security.txt).