← Back home

Privacy Policy

Last updated: 2026-05-03

Placeholder document. Replace with your final privacy policy reviewed by a lawyer before going live. Required under GDPR if you operate in the EU.

1. Data we collect

We collect the email address provided by Google when you sign in, and we keep a per-user record of your subscription tier, token balance, billing period, and Stripe customer/subscription IDs.

2. How we use it

Your data is used solely to operate the service: authenticate you, enforce token quotas, deliver subscription benefits, and process payments. We do not sell or rent personal data.

3. Third parties

  • Supabase — auth, database, hosting
  • Google — sign-in (OAuth)
  • Stripe — payment processing, billing

Each of these processors operates under its own privacy policy and data-processing agreement.

4. Cookies

We use cookies strictly necessary for authentication (Supabase session). No marketing or analytics cookies are set by default.

5. Retention

We retain account data for as long as your account is active, plus a reasonable period after deletion to satisfy legal, accounting, or reporting requirements.

6. Your rights

Under GDPR, you have the right to access, rectify, port, restrict, and delete your personal data, and to object to processing. Contact us at hello@blooplab.com to exercise these rights.

7. Contact

For any privacy-related question, write to hello@blooplab.com.