Written from the actual database, not from a template. Every field listed below is a column that exists; every company listed is one that really receives something. If it is not here, we do not collect it.
Samir Messaoudi, a sole trader in the United States, is the data controller for IdeaNetWorth. Reach us through the contact form — choose “My personal data” and it comes straight to the person who can act on it.
We do not publish an email address anywhere on this site, which is why the form is the only route. It is monitored.
All of it, by category. Nothing is collected that is not on this list.
| Category | The actual fields |
|---|---|
| Account | Email address, password (stored only as a hash — we cannot read it), handle, display name, when you joined, when you were last seen. |
| Profile | Bio, website, and an avatar seed — a short string your initials and colour are generated from. There are no image uploads on this platform. |
| Plan and billing | Which plan you are on, when it renews, your credit balance, and a Stripe customer and subscription reference. No card details ever reach our servers. |
| What you do here | Ideas you submit or keep private, comments, likes and dislikes, shares, who you follow, which ideas you opened, your ratings and private notes, your scoring weights, and a record of each CSV or JSON export you take. |
| Email preferences | Whether you want the daily idea, the hour you chose, and your timezone. A row per day recording that it was sent, so you are never sent two. |
| Sessions | A hashed session token, its expiry, and the browser's user-agent string. |
| Sign-in attempts | Email address, IP address and whether it succeeded — kept briefly, to stop somebody guessing their way into your account. |
| Staff actions | An audit log of what staff did and to what. If a curator suspends an idea, that is recorded with their name against it. |
We do not collect your real name, address, phone number, date of birth or location. We do not buy data about you, and we do not run advertising or tracking pixels.
| What for | Basis |
|---|---|
| Running your account, showing you the library, taking payment | Contract — we cannot provide what you signed up for without it. |
| Sign-in attempt records, session handling, abuse and fraud prevention | Legitimate interests — keeping accounts from being broken into. |
| The daily email | Consent — off unless you switch it on, and one click to stop. |
| The audit log | Legitimate interests — being able to say who did what to the library. |
| Keeping records of payments | Legal obligation — tax and accounting rules. |
One cookie. No banner, because there is nothing to consent to.
ib_session — set when you sign in, cleared when you sign out. It holds a
random token and nothing about you. It is HttpOnly (JavaScript cannot read
it), Secure (HTTPS only) and SameSite=Lax (it is not sent from
other people's sites). It is strictly necessary to keep you signed in, which is the one
category of cookie that does not need consent.
We also keep your theme choice and your filter preferences in your browser's local storage. That never leaves your device and is not sent to us.
There are no advertising, analytics or tracking cookies. Our host, Vercel, may collect aggregate, cookieless performance measurements — page load timings with no identifier attached to them.
When you ask us to run the research on an idea, the text of that idea is sent to Anthropic, which generates the analysis and runs web searches for sources. That is the only time your content leaves us for an AI provider, and it only happens when you press the button.
Your email address, name and account are not sent with it. Anthropic does not train its models on data submitted through its business API.
If you would rather not send anything to a third party, use Copy a prompt instead — it gives you the same instructions to run wherever you like, and nothing leaves this site.
We do not sell personal data, and we do not share it for anybody else's marketing. These companies process it on our behalf, because the product cannot run without them:
| Who | What they get | What for |
|---|---|---|
| Vercel | Requests to the site, including your IP address | Hosting the site and its API |
| Railway | The database, so everything in section 2 | Running the Postgres database |
| Stripe | Your email address and card details, which you give them directly | Taking payment. They are the record of it, not us |
| Resend | Your email address and the message | Sending the daily email and anything about your account |
| Anthropic | The text of an idea, when you run the research on it | Generating the analysis — see section 5 |
We will also disclose data where the law requires it, or to establish or defend a legal claim.
International transfers. We are in the United States and so are most of these providers, so your data is processed there. Where you are in the UK or the EU, transfers rely on the providers' Standard Contractual Clauses or an adequacy decision.
Visible to anybody who can see your profile at /u/your-handle: your handle,
display name, bio, website, avatar, the ideas you have published, the ideas you have
shared, your follower counts and when you joined.
Visible to other signed-in members: your comments, and your name against them.
Never public: your email address, your credit balance, your private ideas, your notes and ratings, which ideas you opened, and anything you exported.
If you are in the UK or the EU, the GDPR gives you the rights below. We extend them to everybody, wherever you are, because running two standards is how mistakes happen.
Ask through the contact form, choosing “My personal data”. We answer within 30 days, and usually much sooner. There is no charge.
If you are unhappy with how we handle it, you can complain to your data protection authority — in the UK the ICO, in the EU the supervisory authority where you live.
HttpOnly, Secure and
SameSite=Lax, and every action that changes something checks where the
request came from.No system is perfectly secure. If there is a breach affecting your personal data, we will tell you and the relevant authority as the law requires.
This is not for under-18s, and we do not knowingly collect data about them. If you believe a child has an account, tell us through the contact form and we will remove it.
If this policy changes in a way that matters, we will email account holders before it takes effect. The version and date at the top always say which one applies.