Tidbix Privacy Policy
Version 0.1 · Effective July 12, 2026 · This version is a working draft under review by counsel; material changes will be announced before they take effect.
Who we are
Tidbix LLC, a Texas limited liability company ("Tidbix," "we"), operates the Tidbix venture-building platform. For data-protection purposes we are the controller of the personal data described here. Contact: legal@tidbix.com.
What we collect
You give us:
- Account data — email address and password, or your Google sign-in identity.
- Profile data — name, headline, mission summary, and an optional profile photo. Your profile is private by default; showing it to other members is your choice.
- Founder work — your responses in the self-discovery tools (mission, Ikigai, values, Founder Energy Map, audience work), interview conversations with Tid, venture ideas and descriptions, sprint artifacts and evidence, mission briefs, and weekly next moves. This is the heart of the product and can include whatever you choose to write.
- Community content — posts, "looking for" listings, direct messages to other members, and reports you file.
- Newsletter signup — your email, if you subscribe.
Created while you use the Service:
- Progress and entitlement records — playbook completion, program and sprint status, gate outcomes, plan and billing status (including a Stripe customer reference — never your card number).
- Usage events — first-party records of actions like "completed a tool" or "generated a brief," stored in our own database and used to run the product (including free-plan run limits).
- Matching data — if you opt in to connecting, compatibility scores and a snapshot of matched members' public card info.
- AI outputs — drafts, analyses, scores, and reviews the AI Features generate from your inputs.
- Acceptance records — which version of the Terms and this policy you agreed to, and when.
Collected automatically:
- Analytics — we use PostHog to understand product usage (page views and feature-completion events). We do not link analytics to your identity — no name or email is sent to PostHog. Analytics uses cookies/local storage; see Cookies below.
- Cookies — sign-in session cookies (essential) and analytics cookies.
- Server logs — our hosting and infrastructure providers log requests (including IP addresses) to run and secure the Service; our application code does not separately record your IP.
What we do NOT collect: we do not ask for or want government IDs, health, biometric, precise-location, or other sensitive-category data. Free-text fields are for your venture work — please don't put sensitive personal information in them. We do not knowingly collect anything from anyone under 18.
Why we process it
| Purpose | Data | Lawful basis (EU/UK) |
|---|---|---|
| Provide the Service: accounts, founder work, playbooks, sprints, AI Features | Account, profile, founder work, progress | Contract |
| Payments, entitlements, receipts, fraud and audit records | Billing data via Stripe | Contract / legal obligation |
| Member features you opt into: directory, matching, messaging, publishing | Profile, matching data, content you share | Contract / consent (opt-in toggles) |
| Security, abuse prevention, rate limits | Usage events, logs | Legitimate interests |
| Product analytics | PostHog events | Consent where required |
| Newsletter and product updates | Consent; unsubscribe anytime | |
| Aggregated, de-identified insights (e.g., benchmark statistics) | Derived, non-identifying data | Legitimate interests (not personal data once anonymized) |
Who processes it — our providers
We share personal data only with processors who help us run the Service, under contracts that limit their use of it:
| Provider | Role | What they process |
|---|---|---|
| Supabase | Database, authentication, storage, functions | All service data |
| Stripe | Payments | Email, user reference, purchase data; your card details go directly to Stripe |
| OpenAI | AI processing for the AI Features | The text you submit to AI-assisted tools, and mission text for matching. Used only to return results — not to train models |
| PostHog | Product analytics (US-hosted) | Usage events, device data, analytics identifiers (not your name/email) |
| Optional sign-in | Your Google account identity | |
| Vercel | Web hosting | Request data including IP addresses in operational logs |
We never sell your personal data, and we do not share it with anyone for their own advertising or marketing. No targeted advertising runs on Tidbix.
What other people can see
- Nothing, by default. Profiles are private and matching is off until you opt in.
- Members-only: if you opt in — your profile card, matching, posts, and messages you send.
- Public, only if you publish: a mission brief or founder credential you choose to publish is visible to anyone on the internet (a credential includes your name). Publishing is opt-in and reversible, though search engines may cache pages after you unpublish. Profile photos are served from a public storage URL — use a photo you're comfortable being visible.
How long we keep it
| Data | Retention |
|---|---|
| Account, profile, founder work, community content, usage events | Until you delete your account — deletion cascades through all of it |
| Payment and audit records | Kept as required for tax, accounting, and fraud/audit purposes |
| Newsletter email | Until you unsubscribe or delete your account |
| Backups | Deleted data ages out of routine backups within a limited period |
| Analytics | Per our analytics retention settings |
Your rights
You can, at any time:
- Access and export your data (Profile → Privacy & Data → Export my data) — you get your founder work in a portable format.
- Correct your profile in-app.
- Delete your account and data (Profile → Privacy & Data → Delete account) — permanent, and stops future renewals.
- Unsubscribe from the newsletter in-app or via any newsletter email.
- Opt out / withdraw consent for member visibility, matching, and publishing via their toggles.
If you're in the EU/UK, these implement your GDPR rights (access, rectification, erasure, portability, restriction, objection), and you may also complain to your local supervisory authority. Residents of US states with privacy laws may have similar rights. We respond to requests at legal@tidbix.com within any legally required period. We don't discriminate against you for exercising rights.
International transfers
We are a US company and our providers process data in the United States. Where GDPR/UK GDPR applies, transfers rely on our processors' safeguards — EU Standard Contractual Clauses and/or the EU–US Data Privacy Framework where the provider is certified.
Anyone under 18
The Service is for adults 18+. We do not knowingly collect personal data from anyone under 18; if we learn we have, we delete the account and its data. Contact legal@tidbix.com if you believe a minor has an account.
Cookies and analytics
- Essential cookies — session cookies that keep you signed in. Always on.
- Analytics — PostHog cookies/local storage for product usage.
We don't use advertising cookies or cross-site trackers.
Changes
We'll post updates here with a new version number and effective date, and give notice of material changes (email or in-product) before they take effect. Changes to the "we never sell" or "no AI training" commitments would require your affirmative consent, not just notice.
Contact
Tidbix LLC · Tarrant County, Texas · legal@tidbix.com
Terms of Service · Subscription & Refunds · Acceptable Use · Copyright / DMCA · Accessibility