Legal
Privacy Policy
- Effective
- August 31, 2026
- Updated
- August 31, 2026
This Privacy Policy (the "Policy") describes how Tech Above, LLC ("Tech Above," "we," "us," or "our") collects, uses, discloses, retains, and safeguards personal information in connection with the services identified in Section 1. By accessing or using those services, you acknowledge that you have read and understood this Policy.
1. Who we are and what this policy covers
Tech Above, LLC is a consulting firm located in Kansas City, Missouri, that also develops and publishes software. This Policy applies to:
- This website, techabove.earth.
- IdeaBucket, our application for capturing ideas and reminders, including its cloud synchronization and backup functionality.
- Our consulting services, comprising Linux systems design, security testing, and embedded systems consulting, together with the proposals, contracts, invoices, and correspondence arising from an engagement.
- Any other product or service we publish that links to this Policy.
For the purposes of this Policy, "personal information" means information that identifies, relates to, describes, or is reasonably capable of being associated with an identified or identifiable individual. Where applicable state law employs a different term, such as "personal data" under Virginia law or "covered information" under Nevada law, this Policy shall be construed to apply to that term.
Where we process data belonging to a client's systems in the course of a consulting engagement, including a security assessment, such processing is governed by the scope, confidentiality, and data handling terms of the applicable engagement agreement rather than by the product provisions of this Policy.
2. Our commitments
- We do not sell your personal information, and have not done so.
- We do not share personal information for cross context behavioral advertising, and we display no advertising in any product.
- We do not use your private content to train general purpose artificial intelligence models.
- Content you store in IdeaBucket remains private to you unless you elect to share it.
- We collect anonymous statistics concerning your use of the application, including the frequency with which the application is opened, the number of ideas retained in your bucket, and the manner in which you navigate the application. Such information is collected and aggregated through an analytics provider and will not be used to identify you or any content you have submitted to the application.
- You may request a copy of your information, request its correction, or request its deletion, and we will process such requests in accordance with applicable law.
These commitments are subject to change and may be updated at any time.
3. What information we collect
Information you provide to us
- Account information. Your email address, a display name where provided, a password hash or the identifier issued by your chosen sign in provider, and your language, time zone, and application settings.
- Your content. The material you store in IdeaBucket, including ideas, notes, reminders, titles, tags, lists, links, attachments, images, and audio recordings. This material is free form and may contain information you consider sensitive. All such material is treated as private.
- Subscription and billing information. Your subscription plan, renewal status, and billing history. Payment card numbers are transmitted directly to our payment processor and are not stored by us. We retain only the final four digits and the processor's token, which are sufficient to identify your subscription and insufficient to initiate a charge elsewhere.
- Support and correspondence. Information you submit in a support request, bug report, feedback form, or other correspondence, including attachments.
- Client engagement information. Where you engage our consulting services, the business contact details, scoping notes, engagement records, and deliverables relating to that engagement.
Information we collect automatically
- Device and application information, including device model, operating system version, application version, language, and display settings.
- Your Internet Protocol address and the approximate city or region level location derived from it. We do not collect precise geolocation.
- Synchronization and diagnostic data, including synchronization times and outcomes, crash reports, error logs, and performance measurements.
- Security signals, including sign in attempts, session tokens, and activity logs, retained to assist in cybersecurity and legal matters.
- Anonymous usage statistics as described in Section 2, collected and aggregated through our analytics provider.
With respect to this website, techabove.earth sets no cookies. The only information stored in your browser is your light or dark theme preference, retained in localStorage, which does not leave your device and which you may clear at any time. Where our analytics token is configured, the site loads Cloudflare Web Analytics, which is cookieless and does not fingerprint visitors or track them across sites. Where that token is not configured, the site issues no third party requests.
Within the application, IdeaBucket stores your session token and a local cache on your device, both of which are necessary for the application to function. The application incorporates the analytics component described in Section 2. It contains no advertising software development kit and no cross site tracking technology.
Information from other sources
- Sign in providers. Where you sign in through a third party, we receive the identifier and email address that provider furnishes to us and no other information concerning your account with that provider.
- Services you connect. Where you connect IdeaBucket to another service, we receive only that information which the permissions you have approved permit.
- Payment and application store providers. Apple, Google, and our payment processor furnish your subscription status and transaction history. They do not furnish your payment card details.
- Other users. A user who shares a bucket with you, or invites you to one, provides your email address in the process.
4. How we use information
We process personal information for the following purposes:
- to create, authenticate, and secure your account
- to store, synchronize, search, back up, and restore your content across your devices
- to process payment and maintain the billing records we are required to retain
- to respond to support requests, which may require access to an account with the account holder's permission
- to identify and remediate crashes, synchronization failures, and performance defects
- to understand in aggregate which features are used, in order to inform product development
- to detect and prevent fraud, abuse, credential stuffing, and unauthorized access
- to send service communications, including security alerts, billing notices, and notices of changes to this Policy. Such communications are not marketing and may not be declined while an account remains open
- to send marketing communications only where you have requested them, each of which will contain a functioning unsubscribe mechanism honored promptly as required by the CAN-SPAM Act
- to comply with legal obligations and respond to lawful legal process
- to establish, exercise, or defend legal claims
We may create aggregated or de-identified information. Where we do so, we will maintain such information in de-identified form and will not attempt to re-identify it, except as necessary to verify that the de-identification process is effective, consistent with the requirements of California law.
We do not use personal information to construct advertising profiles, and we do not engage in automated decision making that produces legal or similarly significant effects concerning you.
5. Cloud storage and synchronization
Where synchronization is enabled, your account information and content are transmitted to servers operated by us and by our contracted infrastructure providers, in order that your content may be made available across your devices, preserved in the event a device is lost or replaced, and restored from backup. We do not process information transmitted through the synchronization service for any purpose other than the provision of that service.
- Content is encrypted in transit using Transport Layer Security and encrypted at rest.
- Backups are encrypted and retained in accordance with the schedule in Section 8.
- Personnel access is restricted, logged, and limited to that which a specific task requires, such as reproducing a synchronization defect you have reported. We do not access your content for any other purpose.
- Our infrastructure is located in the United States, and we do not presently store customer content outside the United States.
Where IdeaBucket offers a local only mode, content retained in that mode remains on your device and is not received by us. Such content is transmitted only where you enable synchronization, export a backup, connect an integration, or submit it to us in a support request.
6. AI features and our position on model training
We do not use your private content to train general purpose artificial intelligence models, and our agreements prohibit our vendors from doing so.
Where we offer an optional artificial intelligence feature, such as the summarization of a note or the suggestion of tags, use of that feature transmits only the content necessary to fulfill your request, whether to our own systems or to a contracted provider. Our agreements with such providers prohibit them from training on your content or otherwise using it for their own purposes. Output generated by these features may be inaccurate or incomplete and should be reviewed before it is relied upon.
We will not use your content for model training unless we first describe the proposed use and obtain your express opt in consent. Consent will not be inferred from silence or from a revision to this Policy.
7. When we disclose information
We do not sell your personal information and we do not share it for cross context behavioral advertising. We disclose personal information only in the following circumstances:
- Service providers. Vendors providing hosting, storage, databases, authentication, payments, email delivery, analytics, crash reporting, and customer support. Such vendors act on our instructions under contract, may use the information solely to deliver the contracted service, and may not sell it or retain it for their own purposes. Under California law these vendors are service providers, and disclosures to them do not constitute sales.
- Users with whom you share content. Where you share a note or a bucket, the recipients may view it and, depending on the permission granted, may copy or export it. We are unable to retrieve a copy once it is in the possession of another user.
- Services you connect. The handling of information received by a service you connect is governed by that service's privacy policy rather than this Policy.
- Legal process. Courts, regulators, and law enforcement authorities, where we are legally required to comply. We review each request, object to requests that are overbroad or procedurally defective, and will notify you of a request concerning your information unless prohibited from doing so by court order or statute.
- Safety and enforcement. Where reasonably necessary to prevent imminent physical harm, fraud, or a security incident, or to enforce our terms.
- Professional advisers. Our attorneys, accountants, and auditors, each under a duty of confidentiality.
- Change of ownership. In connection with a merger, acquisition, reorganization, or dissolution, personal information may be transferred to the successor entity, which shall be required either to continue to honor this Policy or to provide notice and a choice before materially amending it.
- With your consent. To any other recipient at your direction.
8. How long we keep information
| Information | How long we keep it |
|---|---|
| Account details and your content | For as long as your account is open |
| Content you delete | Removed from the application immediately, purged from active systems within 30 days |
| A deleted account | Deleted or de-identified in active systems within 30 days of the request |
| Encrypted backups | Overwritten on a rolling cycle, so a deleted item is gone from backups within 90 days |
| Support correspondence | 2 years from the final message in the thread |
| Billing and tax records | 7 years, as required by applicable tax law |
| Security and access logs | 12 months, or longer where required for a specific investigation |
| Consulting engagement records | 7 years following conclusion of the engagement, or the period specified in the engagement agreement |
The following exceptions apply. We retain information for a longer period where it is subject to a legal hold or an unresolved dispute, and we retain aggregated or de-identified information indefinitely, as such information is no longer linked to you. Content you have shared with other users remains in their accounts following deletion of your copy.
9. Security and breach notification
We maintain administrative, technical, and organizational safeguards including Transport Layer Security for data in transit, encryption at rest, scoped access controls with logging, multi factor authentication on administrative accounts, dependency and vulnerability monitoring, and code review. Security testing forms part of our professional practice, and we hold our own systems to the standards we would advise a client to adopt.
No system of safeguards can guarantee absolute security. In the event of a breach affecting your personal information, we will investigate and contain the incident and will notify you and the applicable state attorneys general within the periods required by applicable breach notification law, including Missouri's, at RSMo 407.1500, and California's, at Civil Code 1798.82. Such notice will describe the nature of the incident, the categories of information involved, and the measures available to you.
10. Your privacy rights
The rights set out below arise under various state privacy laws and may not all be available to you as a matter of law. We extend each of them to all residents of the United States.
- Know and access. To confirm whether we process your personal information and to obtain a copy of it, together with the categories processed, the sources from which it was obtained, the purposes of processing, and the categories of third parties to whom it was disclosed.
- Correct. To have inaccurate personal information corrected.
- Delete. To have your personal information deleted, subject to the exceptions stated in Section 8.
- Portability. To obtain your content in a portable and machine readable format. The export function within IdeaBucket is the most direct means of exercising this right.
- Opt out of sale, targeted advertising, and profiling. We engage in none of these activities. The right nonetheless exists and may be exercised.
- Limit the use of sensitive personal information. California affords this right where a business uses sensitive personal information to infer characteristics concerning a consumer. We do not do so. The only sensitive personal information we hold consists of your credentials and such material as you elect to record in your own content, which we use solely to provide the service, a permitted purpose under Civil Code 1798.121(d).
- Opt out of marketing. To unsubscribe from marketing communications, whether through the mechanism contained in each message or by written request.
- Appeal. To appeal a decision declining a request, in accordance with Section 11.
- Non-discrimination. We will not deny service, charge a different price, or provide a different level of quality by reason of your exercise of a privacy right.
Global Privacy Control. We honor the Global Privacy Control and other recognized universal opt out mechanisms as a valid opt out request from the transmitting browser, as required by the laws of California, Colorado, Connecticut, and Texas. As we neither sell nor share personal information, no processing is disabled by such a signal.
California Shine the Light. Civil Code 1798.83 entitles California residents to request disclosure of personal information shared with third parties for those parties' own direct marketing purposes. We make no such disclosures.
Nevada. NRS 603A entitles Nevada residents to direct a business not to sell their covered information. We do not sell covered information. Requests may nonetheless be submitted to the address stated in Section 16.
11. How to make a privacy request
To submit a privacy request, write to [email protected] and identify the right you wish to exercise, being access, correction, deletion, portability, or opt out. Where you hold an account, the request should be sent from the email address associated with it. Account holders may also export their data and delete their account within the application's settings. As we operate exclusively online and maintain a direct relationship with you, an email address constitutes the designated method required by California law.
Requests are processed as follows:
- We will acknowledge receipt within 10 business days.
- We will verify your identity. For account holders, verification will ordinarily consist of correspondence from the address associated with the account and, where appropriate, authentication within the application. Further verification may be required for a deletion request, deletion being irreversible. Information submitted for verification is used solely for that purpose and is deleted thereafter.
- We will respond substantively within 45 days. Where a request is complex, we may extend that period by a further 45 days and will notify you of the extension before the initial period expires.
- Requests are processed without charge. Where requests are manifestly unfounded or repetitive, we may charge a reasonable fee or decline to act, and will state our reasons for doing so.
An authorized agent may submit a request on your behalf where permitted by applicable state law, upon provision of written authorization and information sufficient to verify the identity of both you and the agent.
Appeals. Where we decline to act on a request, you may appeal by replying to our decision or by writing to [email protected] with "Appeal" in the subject line. We will review the appeal and provide a written response within 60 days. Where an appeal is denied, our response will state the means by which you may submit a complaint to your state attorney general.
12. US state privacy disclosures
This section employs the statutory categories set out in the California Consumer Privacy Act, those categories being the most specific in United States law and the categories of other states mapping onto them.
| Category | Information collected | Sold or shared? |
|---|---|---|
| Identifiers | Name, email address, account ID, IP address, device identifiers | No |
| Customer records | Billing name and address, transaction history | No |
| Commercial information | Subscription plan, purchase history, support history | No |
| Internet or network activity | App and site usage, feature interactions, diagnostic and crash data | No |
| Geolocation | City or region level only, derived from your Internet Protocol address. Precise geolocation is not collected. | No |
| Audio, electronic, and visual information | Voice notes, images, and files you choose to save | No |
| Professional or employment information | Business contact and role information for consulting clients | No |
| Inferences | Limited to security signals and product settings. No advertising or behavioral profiles are constructed. | No |
| Sensitive personal information | Your account credentials, together with such sensitive material as you elect to record in your own content | No |
The foregoing categories are collected from you, from your devices, from services you connect, from other users who share content with you, and from our service providers. They are used and disclosed for the purposes described in Sections 4 and 7 and retained for the periods described in Section 8.
During the 12 months preceding the date stated at the top of this Policy, Tech Above, LLC has not sold personal information and has not shared personal information for cross context behavioral advertising, and has not knowingly done either with respect to any individual under 16 years of age. We do not use or disclose sensitive personal information for purposes other than those permitted by Civil Code 1798.121(d), and accordingly the right to limit the use of sensitive personal information does not apply.
This Policy is intended to satisfy the comprehensive privacy laws of California, Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Minnesota, Maryland, Tennessee, Indiana, Kentucky, and Rhode Island. Definitions and response periods vary among these statutes. Where the law of your state affords you greater rights than those described here, that law shall govern.
Health information. We are not a covered entity under the Health Insurance Portability and Accountability Act, and we do not collect consumer health data as that term is defined by Washington's My Health My Data Act. Health related information you elect to record within your own content constitutes your content, is treated as private, and is neither used for advertising nor sold.
13. Children's privacy
Our products are not directed to children. IdeaBucket and this website are intended for individuals 13 years of age or older, or such higher minimum age as applicable law may require. We do not knowingly collect personal information from a child under 13 years of age, as required by the Children's Online Privacy Protection Act (COPPA), and we do not sell or share the personal information of any individual under 16 years of age.
A parent or guardian who believes that a child has provided us with personal information may write to [email protected] and we will verify the report, delete the account and its associated content, and confirm the deletion.
14. Other companies' services
Our website and applications may link to or integrate with software operated by third parties. We do not control and are not responsible for the privacy practices of those parties. You should review their privacy policies before providing information to them or enabling an integration.
Disconnecting an integration terminates further access through that connection. It does not delete information previously received by the third party, which must be requested from that party directly.
15. Changes to this policy
We may update this Policy to reflect changes to our products, to the categories of vendor we engage, or to applicable law. The revised Policy will be posted on this page bearing a new "Updated" date.
Where a change materially affects your privacy, we will provide notice before the change takes effect, whether by email or within the application, and will obtain your consent where consent is required by law. We will not process information already collected for a materially different purpose without providing prior notice.
16. How to contact us
Privacy questions, requests, and complaints should be directed to:
- Tech Above, LLC
- Email: [email protected]
- Location: Kansas City, Missouri, United States
Correspondence unrelated to privacy should be directed to [email protected] instead.