TL;DR: Idea Eval v2 offers two access modes. Credit System: Minimal data collection (Chrome ID only) with secure Stripe payments. BYOK Mode: Zero data collection, API keys stored locally. We never sell your data.
Overview
Idea Eval v2 is a Chrome extension that evaluates startup ideas from tweets using AI perspectives. We offer two access models with different privacy implications.
Access Models
Credit System (Recommended)
Purchase credit packs for evaluations. We handle AI processing on secure backend infrastructure.
- Data Collected: Chrome ID (anonymous identifier), credit usage metrics
- Payment Processing: Handled by Stripe (we never see payment details)
- Benefits: No API key management, secure payments, instant setup
BYOK Mode (Bring Your Own Key)
Use your own AI provider API keys for unlimited evaluations.
- Data Collected: None
- API Keys: Stored locally on your device
- Benefits: Zero data collection, unlimited usage, full control
What Data We Collect
Credit System Data Collection
- Chrome ID: Anonymous identifier generated by your browser (not personally identifiable)
- Credit Usage: Number of credits used, evaluation type, timestamp
- Transaction Data: Processed by Stripe (we only store credit allocation, not payment details)
- No Personal Information: No email, name, or other personal data required
BYOK Mode Data Collection
- Zero Collection: No data is collected or transmitted to our servers
- Local Storage Only: All data remains on your device
How Your Data Is Used
Credit Management (Credit System Only)
- Chrome ID links your credits to your browser installation
- Usage metrics help us prevent abuse and manage system resources
- Transaction history enables customer support and refunds
- Data is never sold or shared with third parties
API Keys (BYOK Mode Only)
- Your API keys are stored locally using Chrome's secure storage API
- Keys never leave your device except when making direct API calls
- We cannot see, access, or retrieve your API keys
Tweet Content (Both Modes)
- Credit System: Tweet text is sent to our backend, then to AI providers for evaluation
- BYOK Mode: Tweet text is sent directly to your chosen AI provider
- Evaluations are displayed in real-time and not stored permanently
- Edited tweet content is temporarily stored locally for cross-tab synchronization
External Website Content
- When you grant permission, the extension can fetch content from links in tweets
- This content is included in AI evaluation requests for additional context
- Website content is not stored or cached
Data Storage
Data Type |
Storage Location |
Duration |
Who Can Access |
Chrome ID (Credit System) |
Our Secure Database |
Until account deletion |
Idea Eval only (encrypted) |
Credit Balance & Usage |
Our Secure Database |
Until account deletion |
Idea Eval only (encrypted) |
API Keys (BYOK Mode) |
Chrome Local Storage |
Until you remove them |
Only you |
Extension Settings |
Chrome Local Storage |
Until you change them |
Only you |
Edited Tweet Content |
Chrome Local Storage |
Session-based |
Only you |
Evaluation Results |
Not stored |
Display only |
Only you |
Third-Party Services
Idea Eval interacts with these third-party services based on your access mode:
Payment Processing
AI Providers
Infrastructure
Websites
- Twitter/X: The extension reads public tweet content that you can already see
- External Links: Only accessed if you grant optional permissions
Permissions Explained
Required Permissions
- activeTab: Allows the extension to work on the current Twitter/X tab when you interact with it
- storage: Saves your settings and cached credit information locally on your device
- identity: Generates anonymous Chrome ID for credit system (no personal information)
- tabs: Opens credit purchase pages in new tabs
- twitter.com & x.com: Allows the extension to add evaluation buttons to tweets
Optional Permissions
- All websites (https://*/*): Only requested if you want to fetch content from links in tweets. You can use the extension without granting this permission.
Data Security
Credit System Security
- Database Encryption: All data encrypted at rest in Neon Postgres
- HTTPS/TLS 1.3: All communications encrypted in transit
- PCI DSS Compliance: Stripe handles all payment processing securely
- Access Controls: Strict API authentication and rate limiting
- No Personal Data: Only anonymous Chrome IDs and usage metrics stored
BYOK System Security
- Local Storage: API keys stored using Chrome's secure storage APIs
- HTTPS Encryption: All API communications encrypted in transit
- No Server Storage: API keys never transmitted to our servers
- Code Isolation: Keys never exposed in extension logs or code
BYOK Security Considerations
BYOK Security Disclosure: API keys in BYOK mode are stored in Chrome's local storage without additional encryption. Credit System users don't need to worry about API key security.
BYOK Security Measures (For BYOK Users Only)
- Chrome Storage: Keys are stored in Chrome's local storage, which is sandboxed per extension
- HTTPS Only: All API communications are encrypted in transit
- No External Servers: Keys never pass through our servers
- Password Field: Keys are masked in the UI when entering
BYOK Security Limitations
- Plain Text Storage: API keys are not encrypted at rest in Chrome's storage
- Browser Access: Keys may be visible in browser developer tools during API calls
- Local Access: Anyone with access to your Chrome profile could potentially access stored keys
- No Key Rotation: The extension doesn't support automatic key rotation
BYOK Best Practices
- Use Dedicated API Keys: Create API keys specifically for this extension
- Set Usage Limits: Configure spending limits on your API keys
- Monitor Usage: Regularly check your API provider's dashboard for unusual activity
- Rotate Keys: Periodically generate new API keys and update them in the extension
- Secure Your Device: Use device encryption and strong passwords
- Private Browsing: Don't use the extension on shared or public computers
Your Rights
You have complete control over your data:
Credit System Users
- Access: View your credit balance and usage in the extension popup
- Delete: Request account deletion by contacting support
- Modify: Change your settings anytime
- Export: Request your data export (Chrome ID and usage history)
BYOK Users
- Access: View your stored settings in the extension popup
- Modify: Change your API keys and settings anytime
- Delete: Remove the extension to delete all local data
- Portability: Your API keys work anywhere, not just our extension
Children's Privacy
Idea Eval is not directed at children under 13. We don't knowingly collect information from children under 13.
Changes to This Policy
If we update this privacy policy, we'll update the "Last updated" date at the top. Continued use of the extension after changes constitutes acceptance of the updated policy.
Transparency
We believe in transparency about our privacy practices. This policy comprehensively outlines how we handle your data in both access modes. All backend services use industry-standard security practices.
Data Retention
Credit System
- Active Accounts: Data retained while extension is in use
- Inactive Accounts: Data deleted after 2 years of inactivity
- Account Deletion: All data permanently deleted within 30 days of request
BYOK Mode
- Local Data Only: No data retention on our servers
- Extension Removal: All data deleted when extension is uninstalled
Contact
For privacy questions or concerns:
Privacy Recommendation: Credit System offers the best privacy-to-convenience ratio with minimal data collection and no API key management. BYOK Mode provides zero data collection but requires API key security responsibility.