i idearoBack
Privacy

Privacy policy.

The boring bit that matters.

Last updated: September 9, 2026

1. Who is responsible?

The controller for personal data processed through Idearo is Artur Negru. Privacy requests: arturnegru@gmail.com.

2. What we collect

Depending on how you use Idearo, we may process your email address and authentication data; your profile information such as name, username, bio, skills, location and availability; projects, pitches and project settings you create; applications, memberships, messages, notes, tasks and calendar events you create or participate in; investment-interest records; and basic technical/security information needed to operate and protect the service.

3. Why we use it

We use personal data to provide accounts and project features, let builders discover and collaborate with projects, respond to requests, maintain security, prevent abuse, comply with legal obligations and improve the service where a valid lawful basis exists.

4. Public vs private

Projects marked active are designed for discovery. Information that you intentionally publish on a public project may be visible to other visitors. Team workspace content is restricted to the project owner and accepted members by database access controls. Account data is not sold.

5. Lawful basis

Depending on the activity, processing may be based on performance of a contract, compliance with a legal obligation, legitimate interests that are not overridden by your rights, or consent where consent is required. The applicable lawful basis is considered for each processing activity and may be updated as the service changes.

6. How long we keep data

We aim to keep personal data only for as long as necessary for the purpose for which it was collected, plus any period needed for legal, security or dispute-resolution requirements. Data is retained only for as long as reasonably necessary for the stated purpose, legal obligations, security and dispute handling.

7. Service providers

Idearo may use infrastructure and authentication providers such as Supabase and hosting providers to operate the service. Where they process data on our behalf, the appropriate contractual and transfer safeguards should be in place.

8. Your rights

Subject to the applicable rules and exceptions, you may request access, rectification, erasure, restriction, portability and object to certain processing. You may also withdraw consent where consent is the legal basis. Use arturnegru@gmail.com or the privacy controls.

9. Security

We use measures designed to protect confidentiality, integrity and availability, including row-level access controls, server-side authorization for sensitive actions, input constraints, secure authentication cookies, security headers and restricted server secrets. No internet service can promise perfect security.

10. Data breaches

We maintain an incident-response process for personal-data breaches. Where legally required, breaches are assessed and notified to the competent supervisory authority within the applicable deadline and affected people are informed where required.

11. Complaints

You may also complain to the Portuguese supervisory authority, the Comissão Nacional de Proteção de Dados (CNPD), where applicable.

12. Changes

We may update this policy when the service or legal requirements change. The current version will be published here with its update date.

See also Terms · Cookies · Security.