1. Data we collect
Account data. Email address, display name, avatar and a hashed password when you register with email, or the identifier, name, email and avatar returned by Google or GitHub when you sign in with them. We never receive or store your Google or GitHub password.
Content you create. Prompts, uploaded reference images, the websites, apps, files, versions and messages you generate, projects you publish, items you list on the marketplace, and settings you choose.
Billing data. Your plan, credit balance and credit history, Whop membership and payment identifiers, and the amounts paid. Card numbers and bank details are entered directly with our payment processor Whop and never reach our servers.
Usage and technical data. IP address, browser and device information, pages and features used, AI runs (model, tokens, cost), timestamps and error logs, and referral or affiliate codes you arrived with.
2. Why we use it and the legal basis
To provide the Service (performance of a contract): creating your account, running AI agents on your prompts, storing and publishing your projects, granting plan credits and purchased credit packs, paying marketplace sellers and affiliates.
To keep the Service secure (legitimate interest): rate limiting, fraud and abuse detection, protecting accounts, verifying payment webhooks, auditing admin actions.
To improve and support the Service (legitimate interest): diagnosing errors, measuring which features are used, answering your support requests.
To comply with law (legal obligation): tax, accounting and payment regulations, responding to lawful requests.
We do not sell personal data and we do not use it for third-party advertising.
3. AI processing
When you run an agent, your prompt, the current project content and any reference images are sent to our AI model providers, Anthropic (Claude models) and OpenAI (GPT models), to generate the result. These providers process the data on our behalf under their API terms, which state that API inputs are not used to train their models. We do not send your email, password or billing data to AI providers. Please do not include passwords, secrets or other people’s sensitive personal data in prompts.
4. Who we share data with
We use a small number of service providers (processors) that only handle data under our instructions:
- Vercel (hosting and edge network, EU region), including error and access logs.
- Supabase (PostgreSQL database, hosted in the EU, London region).
- Whop (payment processing, subscriptions and payouts). Whop is an independent controller for the payment data you enter with them; see their privacy policy.
- Anthropic and OpenAI (AI model inference, United States).
- Google and GitHub (optional sign-in). They only receive that you are signing in to IDÆVIA Build.
Marketplace: when you buy an item, the seller sees an anonymised sale (amount and date), never your email. When you sell, buyers see your display name. Affiliates see counts and commission amounts, never the identity of referred users.
We may disclose data if required by law, to enforce our Terms, or to protect the rights and safety of users and the public. If IDÆVIA is involved in a merger or acquisition, data may be transferred as part of that transaction under the same protections.
5. International transfers
Our servers and database are in the European Union. AI providers and some sub-processors are in the United States. Where data leaves the EU/EEA we rely on the EU Standard Contractual Clauses and the providers’ certifications under the EU-US Data Privacy Framework.
6. Retention
- Account and project data: for as long as your account exists. When you delete your account we delete it within 30 days, except data we must keep for legal reasons.
- Billing records: 7 years, as required by accounting and tax law.
- Security and access logs: up to 12 months.
- Payment webhook events: 24 months, for dispute handling.
7. Your rights
Under the GDPR and equivalent laws you can ask us to access, correct, export or delete your personal data, restrict or object to certain processing, and withdraw consent where processing is based on it. You can update your name and avatar in Settings and delete your account by emailing us. To exercise any right, write to support@idaevia.app. We answer within 30 days. You also have the right to lodge a complaint with your local data protection authority.
8. Security
Passwords are stored as bcrypt hashes. Sessions use signed, HTTP-only, secure cookies. All traffic is encrypted with TLS (HTTPS) and HSTS. Generated websites are rendered in a sandboxed context, separate from the application. Payment webhooks are verified with HMAC signatures. Access to production systems is restricted to authorised staff. No system is perfectly secure; if we learn of a breach affecting you we will notify you and the authorities as required by law.
9. Cookies
We only use strictly necessary cookies. Details are in our Cookie Policy.
10. Children
The Service is not directed at children under 16 and we do not knowingly collect their data. If you believe a child has created an account, contact us and we will delete it.
11. Changes and contact
We may update this policy as the Service evolves. Material changes are announced in the app or by email before they take effect. Questions and requests: support@idaevia.app. Controller: IDÆVIA, operator of idaevia.app.