Legal · v2026-09-01
Privacy Policy
Last updated: 1 September 2026
1. Data controller
The controller of personal data processed in connection with Idear.app (where Idear determines purposes and means) is FRANCISCO BARRUGUER GASCÓ, tax ID 53226439T, address AVDA. CAMÍ D'ONDA 16, 12530 BURRIANA, CASTELLÓN, ESPAÑA. Contact: estudio@pacobarruguer.com.
This Policy explains how we process personal data of platform users, marketing-site visitors and, where applicable, individuals whose data customers submit when using the Service.
Idear targets professionals and businesses in Spain and the EU. We apply Regulation (EU) 2016/679 (GDPR) and applicable Spanish data-protection law.
2. Dual role: controller and processor
For your account data (registration, your own billing, Service use, support), Idear generally acts as controller.
When you enter or invite data about your own clients, collaborators, or other third parties in boards, comments, reviews, forms, or review links, you are the controller of that data and Idear acts as processor, under your instructions via the Service and the applicable Data Processing Agreement (DPA).
If you are unsure which role applies in a specific case, contact estudio@pacobarruguer.com.
3. Categories of data we process
Account data: name, email, password (stored securely), language/UI preferences, session identifiers, and authentication data.
Fiscal and billing data: information needed to issue invoices and manage subscriptions (e.g. legal name, tax ID, billing address), processed together with the payment provider.
Board content and assets: images, renders, files, text, layers, and project metadata you or your guests upload or generate.
Comments, reviews, and collaboration: messages, pins, voice notes (if used), votes, or approval states linked to boards or client flows.
Forms and briefings: responses to forms created or linked from Idear. When forms are enabled, an external host (Tally) may be used technically; end users may not notice the provider.
AI tool inputs: prompts, images, or other inputs needed to generate outputs; sent to AI providers (processors) to deliver the feature.
Communications: transactional emails (e.g. verification, invites, security notices) via Resend; newsletter only with separate consent when offered.
Payments: payment data processed by Stripe (Idear does not store full card numbers).
Analytics and errors: usage events and metrics (PostHog; in production also Google Analytics 4 when active) and error reports (Sentry), with technical identifiers and, where applicable, related account data.
Infrastructure: data hosted in databases and object storage (Neon, Cloudflare R2) and application servers (Render), plus protections such as Cloudflare Turnstile when used.
4. Purposes and legal bases
Providing the Service and managing the account (performance of contract).
Billing, collections, and accounting/tax obligations (legal obligation and/or performance of contract).
Security, abuse prevention, and maintenance (legitimate interest and, where applicable, legal obligation).
Product improvement and usage analytics (legitimate interest and/or consent where law or cookie/analytics settings require it — NEEDS LEGAL REVIEW as to the exact consent regime in production).
Transactional communications needed for the Service (performance of contract). Newsletter or other marketing: only with prior consent, withdrawable at any time.
AI tools requested by the User (performance of contract / pre-contractual steps as applicable).
5. Retention
We keep data while the account is active and as needed to provide the Service.
After account or content deletion, we may keep residual copies for a limited time for technical (backups) or legal reasons.
Billing and tax data are retained for the periods required by applicable legal obligations. This Policy does not state a specific number of years; exact periods must be confirmed with counsel (NEEDS LEGAL REVIEW).
Security, analytics, and incident logs are kept as long as needed for the purposes described, under minimisation principles.
6. Recipients and processors (sub-processors)
We do not sell personal data. We share data with providers that help us run the Service, under appropriate contracts where they act as processors.
Verified sub-processors / providers in current operations (indicative list; may be updated):
• Render — application/API hosting.
• Neon — PostgreSQL database.
• Cloudflare — Pages (site), R2 (object storage), Turnstile (bot protection when enabled).
• Resend — transactional email.
• Stripe — payments and subscriptions.
• OpenAI — processing for AI tools.
• PostHog — product analytics (configured project; region to confirm — NEEDS LEGAL REVIEW).
• Sentry — error monitoring.
• Tally — form hosting when forms are enabled.
• Telegram (optional) — notifications if the User configures them (e.g. board alerts).
• fal.ai — possible/historical or optional AI provider when the related feature is enabled.
We may also disclose data to authorities when required by law.
7. International transfers
Some providers may process data outside the European Economic Area. Where that happens, we will apply appropriate safeguards (e.g. standard contractual clauses or other GDPR-recognised measures).
NEEDS LEGAL REVIEW: exact processing locations for each provider (including OpenAI, Stripe, PostHog, Sentry, Cloudflare, Render, Tally, fal.ai if applicable) and transfer documentation must be confirmed before definitive publication. We do not claim certifications that have not been verified.
8. Your rights
You may exercise rights of access, rectification, erasure, objection, restriction of processing, and portability under the GDPR by contacting estudio@pacobarruguer.com.
Where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing.
If Idear processes data as a processor for a customer (e.g. their clients’ data on a board), we may need to redirect your request to that customer controller.
You may also lodge a complaint with the Spanish Data Protection Agency (AEPD): https://www.aepd.es
9. Security
We apply reasonable technical and organisational measures (access control, encryption in transit, secure development practices, monitoring) suited to the nature of the Service. No system is 100% secure; please protect your credentials and set collaboration permissions carefully.
10. Minors
The Service is aimed at professionals and is not intended for individuals under 16 (or the applicable digital age of consent). We do not knowingly collect children’s data. If you believe a minor has provided data, contact estudio@pacobarruguer.com so we can delete it where appropriate.
11. Cookies and local storage
We use cookies and similar technologies needed for sessions and, in production, analytics tools. Details are in the Cookie Policy. Analytics may require a consent-regime review (NEEDS LEGAL REVIEW); this document does not claim a full complex CMP is in place.
12. AI-related processing
When you use AI tools, necessary content may be sent to OpenAI and, if enabled, other providers such as fal.ai. Those providers act as processors or sub-processors for that purpose. Do not use AI tools to submit sensitive personal data or other data you should not share unless you have a clear legal basis and need.
Generated outputs must be reviewed; they are not automatic professional advice.
13. Changes and contact
We may update this Policy. The current version is identified by date/version (e.g. 2026-09-01). For material changes we may request renewed acceptance or notify you by reasonable means.
Privacy / rights contact: estudio@pacobarruguer.com.