Idea Manager privacy

Updated on 5 October 2026, based on the inspected source implementation. Deployed app configuration has not been verified here.

Back to Idea Manager · Support guide

Account and stored data

Idea Manager uses Supabase authentication and database services for account access and stored ideas. The implementation sends account information, idea records, organisation relationships, feature preferences and key material needed by the service. Encryption does not make the account anonymous.

Content-encryption limits

With encryption unlocked, new idea titles and detailed thoughts, project names and tag names are encrypted in the client using AES-256-GCM before being sent to the database. RSA-OAEP wraps each content key. The stored private-key copy is encrypted using a password-derived key; recovery can add a separate encrypted wrapper. Existing legacy records may remain unencrypted until migrated.

Account details, record identifiers, timestamps, project/tag relationships, status and priority names and feature preferences are outside this content encryption. Feedback messages are not encrypted by the idea-content mechanism. Do not put private ideas, passwords or recovery material in feedback or support messages.

The unlocked private key and decrypted records are available in the running app session. The current web source keeps that key in memory and removes older local-storage key copies; a process restart requires unlocking again. Encryption depends on a trusted device, browser and delivered scripts. It does not protect against a compromised session or recipient copying content.

Browser storage and connections

The app can store an authentication session, appearance and view preferences, release notices and feature-discovery choices in browser storage. Its service worker caches application assets and runtime configuration. A cached interface is not an offline backup of account ideas; server reads and writes still require a connection.

Signing out clears the in-memory keys and attempts account/session cleanup and remote sign-out. Clearing browser data can remove local session and preferences; it does not itself delete server records or guarantee remote session revocation.

Sharing and external destinations

Optional sharing grants an eligible account access to a selected encrypted idea by wrapping its content key for that recipient. The service retains the sharing relationship and recipient key wrapper. Revoking access removes the grant but cannot erase copies already read or saved. Choose recipients carefully.

In-app feedback is sent to the account-backed service without idea-content encryption. Email support goes to the chosen mail service. If you choose the external Buy Me a Coffee support link, that service’s handling applies. None of these destinations receives an idea merely because you view this website product page.

Deployment and provider information

Operator identity, deployed app and migration configuration, providers and hosting logs, retention and deletion processes, international transfers and the data-rights contact process require owner confirmation. No retention period, deletion guarantee or blanket no-collection claim is established by this policy.

Contact Eternal Academy about Idea Manager privacy. Never include passwords, recovery codes or private idea content in a request.