Privacy Policy
idlepay turns your AI coding assistant's "thinking…" spinner into a single sponsored line and shares the revenue with you. This policy explains what we collect, why, and the choices you have. In short: we never read your code, files, or terminal — the extension only swaps the spinner verb.
1. Who we are
idlepay ("idlepay", "we", "us") operates the idlepay.co website, the earnings dashboard, and the idlepay editor extension (collectively, the "Service"). For any privacy question or request, contact us at support@idlepay.co.
This policy covers both people who earn with idlepay ("earners") and advertisers who buy spinner placements ("advertisers").
2. What we collect
Account information
When you sign in, we use Google sign-in. Google shares a limited profile with us: your name, email address, profile picture, and a stable account identifier. We store these to create your account, show your dashboard, and pay you.
Earnings & usage data (earners)
- An anonymous device identifier generated on your machine, used to attribute impressions to your account and to enforce anti-fraud limits.
- Sponsored-line events: counts of impressions (a sponsored line shown during a genuine AI wait-state) and clicks, with timestamps.
- An activity signal that confirms a coding session is genuinely active while an impression is credited. To generate this signal the extension checks the modification time of your local session file — it never reads its contents.
- Your earnings balance and payout history.
What the extension cannot see. It has no filesystem, workspace, terminal, or environment access. It is a status-bar item with a single allowed network origin and an anonymous device ID. It cannot read your code, prompts, files, keystrokes, or environment variables. These limits are declared in the extension's manifest, which you (or your security team) can inspect.
Advertiser information
If you run campaigns, we collect the account and campaign details you provide (business name, contact email, ad creative, bids, budgets) and process payments through our payment processor. Advertisers receive only aggregate performance statistics — never personal data about individual earners.
Payment data
Payments and payouts are handled by third-party processors (Stripe for advertiser billing and Whop for earner payouts). We do not store full card or bank-account numbers on our servers; those are held by the processor under their own terms and privacy policies.
Referral data
If you arrive through a referral link, we store the referral code in a first-touch cookie so we can credit the referrer. See Cookies below.
Technical & log data
Like most online services, our servers automatically record standard technical data — IP address, browser/user-agent, and request timestamps — for security, abuse prevention, and debugging.
3. How we use your data
- Provide the Service: run the extension, count impressions and clicks, calculate and display your earnings.
- Pay earners and bill advertisers.
- Prevent fraud and abuse (e.g. detecting inflated or manufactured impressions) and enforce per-account limits.
- Attribute referrals and calculate referral rewards.
- Communicate with you about your account, payouts, and material changes to the Service.
- Meet legal, tax, and accounting obligations.
We do not sell your personal data.
4. Cookies
- Authentication cookies — keep you signed in to the dashboard. Strictly necessary.
- Referral cookie — stores a referral code for up to 30 days so the correct referrer is credited. It contains no personal information.
- Analytics / advertising pixels — we may use privacy-conscious analytics or advertising pixels (for example, to measure how many visitors install the extension). Where required, we ask for your consent before loading them.
5. How we share data
We share data only with service providers that help us run idlepay, each acting on our instructions:
- Supabase — authentication and database.
- Stripe and Whop — payments and payouts.
- Hosting & infrastructure — website and API hosting (e.g. Vercel and AWS).
We may also disclose data if required by law, to protect our rights or users' safety, or in connection with a merger, acquisition, or sale of assets (in which case we will notify you).
6. Data retention
We keep account, earnings, and payout records for as long as your account is active and as long as needed to meet legal, tax, and accounting requirements. When you delete your account, we remove or anonymise personal data that we are not required to retain.
7. Your rights & choices
- Pause or uninstall anytime. Pause from the status bar, or uninstall the extension in one click — your editor is restored to its original state.
- Access, correction, deletion. Depending on where you live (including under the GDPR and CCPA), you may request a copy of your data, correct it, or ask us to delete it.
- Object or restrict certain processing, and withdraw consent for optional cookies at any time.
- Complain to your local data-protection authority.
To exercise any of these, email support@idlepay.co. We may need to verify your identity first.
8. Security
We use encryption in transit, restricted access, and reputable infrastructure providers to protect your data. No method of transmission or storage is perfectly secure, but we work to protect your information and to promptly address any issues.
9. International transfers
idlepay operates online and our providers may process data in countries other than yours. Where personal data is transferred internationally, we rely on appropriate safeguards (such as standard contractual clauses) as required by applicable law.
10. Children
idlepay is not directed to children. You must be at least 18 years old (or the age of majority where you live) to use the Service. We do not knowingly collect data from children.
11. Changes to this policy
We may update this policy from time to time. When we make material changes, we will update the "Last updated" date above and, where appropriate, notify you.
12. Contact
Questions or requests? Email support@idlepay.co.