Post your build ideas
Solo Era solo activities, solo maxxing, sidequests, challenge

Privacy

Effective 19 September 2026. Last updated 21 September 2026.

Who is responsible

The controller for this site is an independent developer based in Switzerland, reachable at gianmaurice@proton.me. The full name and postal address are on the imprint.

What is stored, and why

  • Post content: the name, idea, category and optional fields you type. Public by design, and permanent.
  • Salted hashes of your IP address, used for rate limiting and to allow one vote per voter. The raw address is never stored.
  • Idea Checker: not the text you paste. One row per check with its length, the time, a salted hash of your IP address, the number of tokens the call used, what it cost and whether it worked. See the Idea Checker.
  • Sponsor booking data: the details needed to place and pay for a slot — the placement itself, your email address, and the payment’s identifier at Stripe.
  • An admin audit log recording actions taken in the admin panel.

Buying a sponsor slot

The operator of this site is the seller of record for a sponsor slot, and Stripe processes the payment. Because of that, the Stripe checkout asks for a billing address — it is what the tax on the sale is worked out from. It is entered on Stripe’s own checkout page and held by Stripe. No tax or VAT number is asked for. This site never receives or stores your address or your card details — what reaches this database is your email address, what you booked, and Stripe’s id for the payment.

Why it is allowed — the legal basis for each purpose

Under the GDPR every purpose needs a basis. These are the ones relied on here, and nothing is processed for a purpose not on this list.

  • Running a sponsor booking — contract. Your email address, what you booked and the payment identifier are needed to perform the contract you entered into at checkout, and to answer you about it afterwards.
  • Tax and accounting records — legal obligation. Records of a sale have to be kept for as long as the law requires, and that outlives the booking itself.
  • Reading the text you paste into the Idea Checker — contract. It is the service you asked for, and it happens only when you press the button. The text goes to TypeSafe for that and for nothing else.
  • Rate limiting, spam and abuse prevention — legitimate interests. Salted IP hashes exist so one person cannot flood the board or vote a thousand times. The interest is keeping a public, account-free board usable; the impact is minimal because the raw address is never stored.
  • Analytics — legitimate interests. Knowing which pages are read, and publishing honest traffic figures a sponsor can check before paying. The interest is running and funding the site; the impact is minimal because the measurement is cookieless, aggregate, and carries no identifier that follows you between visits. That is also why there is no consent banner: there is nothing stored on your device to ask about.
  • Admin audit log — legitimate interests. Knowing what was changed in the admin panel, and by whom, so a removal or a refund can be accounted for.

Where the basis is legitimate interests you can object — see your rights.

How long it is kept

  • Posts are permanent by design, so the salted hash stored with a post is kept as long as the post exists. A post is removed on request when it is about a real, identifiable person.
  • Votes, and the voter hash attached to them, are kept as long as the vote exists.
  • Visit and page-view records — a salted visitor hash with the hour it was seen, and a per-day view count — are currently kept indefinitely. They are what the published figures are counted from. There is no automatic deletion of them today, and saying otherwise would be inventing a policy that is not implemented.
  • Click and prompt-copy records, including sponsor click counts, are kept indefinitely, for the same reason: the counts published on a sponsor card and on the stats page are counted from them.
  • Idea Checker records — length, time, a salted IP hash, token count, cost and outcome, never the text — are currently kept indefinitely. They are how the hourly and daily limits and the daily spending cap are counted, and how the cost of the feature is known. There is no automatic deletion of them today.
  • Sponsor booking data is kept as long as the booking record exists, and the record of the sale is kept for as long as tax and accounting law requires.
  • Unfinished checkouts — the details of a checkout that was opened but never paid — are deleted after 30 days.
  • Admin audit log: login-attempt rows are deleted after 90 days; records of real admin actions (a removal, a refund, an edit) are kept.
  • Emails sent about a booking are kept in the sending queue with the booking they belong to.

Who processes data for us

These are every third party this site sends data to. There is no advertising network, no data broker, and no one else.

  • Supabase — database and file storage, EU region.
  • Vercel — hosting.
  • Stripe — payment processing. The operator is the seller of record.
  • Resend — sending the emails about a sponsor booking.
  • Vemetric — analytics, EU-hosted.
  • TypeSafe AI, Inc. (United States) — reads the text you paste into the Idea Checker. What it does with it.

Data leaving Europe

Supabase stores this site’s database and files in an EU region, and Vemetric hosts its analytics in the EU. Four are different: Vercel, Stripe and Resend are US-headquartered, and processing or support access outside the EEA and Switzerland has to be assumed — a page is served by whichever region a request reaches, a payment is handled on Stripe’s own infrastructure, and an email passes through Resend’s, and the Idea Checker sends the text you paste to TypeSafe in the United States (below).

The safeguard relied on for the first three of those transfers is each provider’s data processing agreement incorporating the European Commission’s Standard Contractual Clauses, with the Swiss addendum recognised by the FDPIC where Swiss data protection law applies. If you want to see the agreement relied on for a particular provider, ask and you will be told which one and where to read it.

For TypeSafe the safeguard is its own data processing addendum, last updated 24 April 2026, which its customer agreement incorporates. It applies the European Commission’s standard contractual clauses (module 2, controller to processor) and the UK addendum, and names the Swiss Federal Data Protection and Information Commissioner as the competent authority for people in Switzerland.

Children

This site is for adults. Booking a sponsor slot requires you to be 18 or over. Nothing here is directed at children, no age is asked for on the post form and none is stored, and there is no knowing collection of data from a child. If you believe a child has posted something or that data about a child is held here, email gianmaurice@proton.me and it will be removed.

The Idea Checker

When you press the button on the Idea Checker, the text in the box is sent over an encrypted connection to TypeSafe AI, Inc., a US company, which reads it and sends back scores. This site does not store that text, does not put it in analytics and does not write it to a log. What it keeps is described under “What is stored” above: one row per check, without the text.

What TypeSafe’s own published documents say — its privacy policy, terms, data processing addendum, customer agreement and trust centre, read on 19 September 2026, with the privacy policy, terms, addendum and customer agreement checked again on 24 September 2026:

  • Where. The service is hosted in the United States. Its subprocessors are Amazon Web Services, which stores and processes customer information for live requests, and Modal, which processes prompts without storing them; both are in the USA. It publishes no EU or Swiss processing option.
  • Training. It says it will not train or fine-tune any model on what you send, and will not disclose it to anyone but its own service providers. Its customer agreement qualifies the training restriction: training on customer data requires the customer’s prior consent.
  • Its role. Under its data processing addendum TypeSafe is a processor acting on this site’s instructions, and the addendum is part of its customer agreement.
  • How long it keeps the text: not published. Its privacy policy says “as long as reasonably necessary”. Its customer agreement also permits ongoing processing to derive telemetry, monitor fraud and abuse, and comply with law. It gives no fixed deletion deadline. Zero data retention is described only as an option for enterprise customers, which this site has not set up. Assume the text may be kept for an unknown time.
  • Usage data. Its customer agreement lets it keep technical logs, hashes, summary statistics, classifications and metrics about how the service is used, to improve its services. Its documents do not say whether any of that can contain what you typed.

So: do not paste anything you would not want a US company to hold for an unknown time. That means personal details, secrets, and any idea you need to keep private. An idea you have not published may still be retained; the training restriction does not establish a deletion deadline.

Posts are public, on purpose

Everything published to the board — the name you type, the idea, the category and the optional fields — is public from the moment you press publish, visible to anyone, indexed by search engines, and readable through the site’s own pages and feeds. Appearing on the board does not make anything private, and there is no setting that makes a post visible to some people and not others.

Do not put anything in a post that you would not put on a public web page: not your address, not your phone number, not somebody else’s details. Posts are permanent for their authors and there is no self-service delete.

The one thing that always overrides permanence: a post about a real, identifiable person is removed on request, from that person, with no justification needed and no argument. Use the report page or email gianmaurice@proton.me.

Analytics

Traffic on this site is measured with Vemetric, and it is cookieless. Not a single cookie is set, and no identifier follows you from one visit to the next: to tell repeat views apart within a day, Vemetric derives a hash from a salt that rotates daily and is then unrecoverable. That is why there is no cookie banner on this site — there is nothing to ask you to accept.

What is kept in your browser is session storage only: a random number your tab uses to group its own page views into one visit, a marker noting that the post form has already been counted as started, and — if you open a sponsor checkout — the tier and week you picked, so that coming back without paying can be counted. All of it is per-tab, none of it identifies you, and all of it disappears the moment you close the tab. Nothing is written to disk and nothing survives the visit.

What it records is aggregate and about pages, not about people: which page was viewed, the referrer that led there, an approximate country, and the browser and device type. On top of that, the things this site is actually for are counted as events — an idea opened, liked, disliked or shared, a build prompt copied, a post started and published, and a sponsor checkout started, abandoned or completed. None of them carry your name, your email or your IP address.

Searches are recorded. When you search the board, the words you typed are sent as an analytics event together with how many results came back. This is genuinely useful — it shows what people come here looking for and do not find — but it is text you typed, so please treat the search box as public. It is capped at 64 characters, an empty search is never recorded, and the words are not linked to you or to anything else you do.

There is no cross-site tracking, no advertising network, no third-party pixel, no profile, and nothing is ever sold. Your browser does reach Supabase directly — that is this site’s own database and file storage, named above, and it is what makes the counters move and the sponsor icons appear. Analytics never load in the admin area. Vemetric’s servers are in the EU, and the numbers are published on the stats page rather than kept private.

Your rights

Under the Swiss FADP, and under the GDPR if you are in the EU or the UK, you can ask for:

  • Access — a copy of what is held about you, and what it is used for.
  • Correction of anything inaccurate.
  • Deletion, where there is no overriding reason to keep it. Records a law requires to be kept — a sale, for tax — are the usual exception, and you will be told if that is why.
  • Restriction of processing while something is being checked, and objection to anything relied on under legitimate interests, including analytics.
  • Portability of what you gave for a booking, in a machine-readable file.
  • Withdrawing consent, where consent was the basis. Nothing here currently relies on consent, which is why there is no banner to withdraw.

How to exercise them: email gianmaurice@proton.me, say which right you are exercising, and give enough for the data to be found — for a booking, the email address you paid with. There is one person here; you will get a human reply, and the aim is within 30 days. It costs nothing. You may be asked something to confirm the request is really yours, and no more than that.

You can also complain to a supervisory authority. In Switzerland that is the Federal Data Protection and Information Commissioner (FDPIC); in the EU it is the data protection authority of the country you live or work in, or where you think something went wrong; in the UK it is the Information Commissioner’s Office. You do not have to raise it here first, though it is usually faster.

An honest limit: most of what this site stores is a salted hash of an IP address, kept precisely so that nobody — including the operator — can work backwards from it to a person. That means an access or deletion request usually cannot be tied to those rows at all. For a sponsor booking, which does carry your email address, it can.

Supported by

0 of 100 slots · $1 / month Join →