Privacy Policy
Last updated: June 30, 2026
This Privacy Policy explains how LLC SaaS Evaluator(“Preflight”, “we”, “us”) collects, uses, and protects personal data when you use the Preflight service at https://www.ideaproof.net(the “Service”). It applies to visitors, registered users, and paying customers. For the purposes of the EU/UK GDPR, LLC SaaS Evaluator is the data controller for account data and the processor of the idea content you submit for evaluation.
1. Data we collect
- Account data: your email address and a securely hashed password, or, if you sign in with Google, your email and a Google account identifier.
- Evaluation content: the idea details you submit — title, description, optional target audience, target country and language, and any competitor URLs — and the generated report.
- Billing data: credit balance and transaction history. Card details are handled by our payment processor; we do not store full card numbers.
- Technical data: the IP address captured at registration (used to detect abuse of the free tier), and operational telemetry about evaluations (timings, model/provider call metadata, cost, and the related evaluation identifier).
- Cookies & local storage: a session cookie that keeps you signed in, and a local-storage value remembering your light/dark theme preference. See section 6.
2. How we use your data and our legal bases
- To provide the Service — run evaluations, store your reports, manage your account and credits (legal basis: performance of a contract).
- To prevent abuse and fraud — e.g. limiting multiple free accounts from the same IP (legal basis: legitimate interests).
- To operate and improve the Service — aggregate telemetry, reliability, and cost monitoring (legal basis: legitimate interests).
- To comply with the law — tax, accounting, and responding to lawful requests (legal basis: legal obligation).
3. Service providers and sub-processors
We share data with vetted providers only as needed to run the Service. They process data on our instructions under data-processing terms:
- Anthropic — AI analysis of your idea to generate the report.
- DataForSEO — search-volume, SERP, keyword, and domain metrics derived from your idea’s category and problem.
- Public data sources — Hacker News and Stack Exchange public APIs, and the Arctic Shift public Reddit archive, are queried for problem-validation signals using terms derived from your idea.
- Google — authentication, if you choose “Continue with Google”.
- Spaceship — infrastructure and transactional email.
A current list of sub-processors is available on request at inbox@ideaproof.net.
4. Your ideas and AI processing
Your submitted idea is processed only to generate your evaluation report. We do not publish or sell it, and we do not use it to train our own models. Third-party AI processing is governed by the provider’s API terms; we use the providers’ business/API tiers, which do not train foundation models on submitted inputs.
5. Data retention
We keep account and evaluation data for as long as your account is active. You can delete your account at any time (see section 7); on deletion we erase or irreversibly anonymise your personal data within 30 days, except where we must retain limited records (e.g. invoices) to meet legal obligations. The registration IP is retained for up to 12 months for abuse prevention.
6. Cookies and local storage
We use a strictly-necessary session cookie to keep you authenticated, and browser local storage to remember your theme. These are essential to the Service and are not used for advertising or cross-site tracking. For aggregate traffic measurement we use privacy-friendly, cookieless analytics (Umami): it sets no cookies, collects no personal data, and does no cross-site tracking or advertising — so no consent banner is required. If we introduce non-essential cookies, we will ask for your consent first.
7. Your rights
Depending on where you live (e.g. EU/UK GDPR, California CCPA), you may have the right to access, correct, delete, export, or restrict processing of your data, to object to processing, and to withdraw consent. To exercise these rights, contact inbox@ideaproof.net. You also have the right to complain to your local data-protection authority.
8. International transfers
Some providers process data outside your country (including the United States). Where required, such transfers are covered by appropriate safeguards such as the EU Standard Contractual Clauses.
9. Security
We protect your data with encryption in transit (HTTPS), hashed passwords, access controls, and scoped data access per user. No method of transmission or storage is completely secure, but we work to protect your information and to notify you of incidents where the law requires.
10. Children
The Service is not directed to children under 16, and we do not knowingly collect their data.
11. Changes
We may update this policy; material changes will be announced on this page and, where appropriate, by email. The “Last updated” date above reflects the current version.
12. Contact
Questions or requests: LLC SaaS Evaluator, inbox@ideaproof.net.