Privacy policy.
The boring bit that matters.
Last updated: September 9, 2026
1. Who is responsible?
The controller for personal data processed through Idearo is Artur Negru. Privacy requests: arturnegru@gmail.com.
2. What we collect
Depending on how you use Idearo, we may process your email address and authentication data; your profile information such as name, username, bio, skills, location and availability; projects, pitches and project settings you create; applications, memberships, messages, notes, tasks and calendar events you create or participate in; investment-interest records; and basic technical/security information needed to operate and protect the service.
3. Why we use it
We use personal data to provide accounts and project features, let builders discover and collaborate with projects, respond to requests, maintain security, prevent abuse, comply with legal obligations and improve the service where a valid lawful basis exists.
4. Public vs private
Projects marked active are designed for discovery. Information that you intentionally publish on a public project may be visible to other visitors. Team workspace content is restricted to the project owner and accepted members by database access controls. Account data is not sold.
5. Lawful basis
Depending on the activity, processing may be based on performance of a contract, compliance with a legal obligation, legitimate interests that are not overridden by your rights, or consent where consent is required. The applicable lawful basis is considered for each processing activity and may be updated as the service changes.
6. How long we keep data
We aim to keep personal data only for as long as necessary for the purpose for which it was collected, plus any period needed for legal, security or dispute-resolution requirements. Data is retained only for as long as reasonably necessary for the stated purpose, legal obligations, security and dispute handling.
7. Service providers
Idearo may use infrastructure and authentication providers such as Supabase and hosting providers to operate the service. Where they process data on our behalf, the appropriate contractual and transfer safeguards should be in place.
8. Your rights
Subject to the applicable rules and exceptions, you may request access, rectification, erasure, restriction, portability and object to certain processing. You may also withdraw consent where consent is the legal basis. Use arturnegru@gmail.com or the privacy controls.
9. Security
We use measures designed to protect confidentiality, integrity and availability, including row-level access controls, server-side authorization for sensitive actions, input constraints, secure authentication cookies, security headers and restricted server secrets. No internet service can promise perfect security.
10. Data breaches
We maintain an incident-response process for personal-data breaches. Where legally required, breaches are assessed and notified to the competent supervisory authority within the applicable deadline and affected people are informed where required.
11. Complaints
You may also complain to the Portuguese supervisory authority, the Comissão Nacional de Proteção de Dados (CNPD), where applicable.
12. Changes
We may update this policy when the service or legal requirements change. The current version will be published here with its update date.