legal

Privacy Policy

Last updated August 4, 2026

Bloops are tiny apps that each do one job with a document or a piece of text you hand them. That means you trust us with real work — receipts, contracts, statements. This policy explains, plainly, what we collect, why, how it's protected, and the control you keep over it.

Overview

This Privacy Policy describes how Bloops (“Bloops”, “we”, “us”) handles information when you use our website and platform (the “Service”). It applies to visitors to our marketing site and to people who use Bloops through their organisation's workspace.

Where your organisation provides Bloops to you, that organisation controls its workspace and its data; we process that data on its behalf under our agreement with it. For content you submit to a bloop, your organisation is the controller and we are the processor.

Who we are

Bloops operates the Service. For any privacy question, or to exercise a right described below, contact us at privacy@bloops.studio. If you use Bloops through an employer or organisation, you may also want to contact that organisation's administrator.

What we collect

Information you give us

  • Account & identity — your email address and, via your organisation's single sign-on, your name and group memberships used to determine your role.
  • Content you submit to a bloop — the text, files, or connected documents you hand a bloop to work on, and the result it returns.
  • Communications — messages you send us for support or enquiries.

Information we collect automatically

  • Usage & job records — which bloops were run, when, their weight and cost, and success or failure — so we can bill accurately and show you your activity.
  • Device & log data — standard technical information such as IP address, browser type, and timestamps, used to operate and secure the Service.
  • Audit events — records of privileged and connector actions, kept so access is accountable.

How we use it

We use information only to run the Service you asked for:

  • To run the bloops you invoke and return their results.
  • To authenticate you, resolve your role, and keep your workspace isolated from others.
  • To meter usage and bill per finished job — and never to charge you for a job that failed.
  • To provide support, and to detect, prevent, and investigate abuse or security incidents.
  • To comply with our legal obligations.

We do not sell your personal information, and we do not use your content to build advertising profiles.

Your content & the bloop model

A bloop is deliberately narrow: it asks for exactly the one input it needs and returns one output. We handle the content you submit only to produce that output for you. Your content belongs to you (or your organisation). We claim no ownership of it, and we don't share it with other customers.

Results come back on a verification surface — extracted values carry a confidence and a link to their source — so you can check and correct a result before it leaves. Nothing you produce is shared publicly unless you explicitly choose to share it.

AI processing & training

Bloops use large language models to do their work. When you run a bloop, the input you provided (after redaction, where connectors are involved) is sent to the model provider solely to generate your result.

We do not use your content — your inputs or your outputs — to train models, ours or anyone else's. We contract with our model providers so that content processed for Bloops is not used to train their models either.

Connectors & sub-processors

If your organisation connects a source such as Google Drive, a bloop reads only what you pick, read-only, through a policy-gated picker, and at the narrowest scope that does the job. Connected content is redacted and audited before it reaches a model. We never write back to a connected source unless a specific, reviewed action app is set up to do so and you confirm it.

We use a small set of sub-processors to run the Service — cloud hosting, a database provider, a payments processor for billing, and the AI model provider that powers the bloops. Each is bound by contract to protect your data and to use it only to provide their service to us. A current list is available on request at privacy@bloops.studio.

Retention & deletion

We keep content and records only as long as needed to provide the Service, meet legal and accounting obligations, and honour your organisation's retention settings. Retention windows are enforced automatically.

When data is deleted — on request, or at the end of a retention window — we destroy the per-tenant encryption key that protects it. This “crypto-shred” makes the underlying ciphertext unrecoverable, rather than merely marking it as gone. To request deletion, contact your workspace administrator or privacy@bloops.studio.

How we protect it

  • Encryption — sensitive fields are encrypted at rest with AES-256-GCM under a per-tenant key, with a fresh random initialization vector per record and an authentication tag verified on read.
  • Isolation — every database read and write is scoped to a single tenant at one enforced choke point, so one workspace cannot reach another's data.
  • Least privilege — connector access is read-only, scoped to what you pick, and revocable; secrets and refresh tokens are never exposed to app code.
  • Encryption in transit — traffic to and from the Service is encrypted with TLS.

More detail lives on our Trust & security page. No system is perfectly secure, but security is designed into the platform rather than bolted on.

Your rights

Depending on where you live, you may have the right to access, correct, export, or delete your personal information, to object to or restrict certain processing, and to withdraw consent. To exercise a right, contact us at privacy@bloops.studio. If Bloops is provided through your organisation, we may direct your request to that organisation as the controller of the data, and we will support them in responding. You also have the right to complain to your local data protection authority.

International transfers

We may process and store information in countries other than your own. Where we transfer personal data across borders, we rely on appropriate safeguards — such as standard contractual clauses — to protect it.

Cookies

We use a small number of strictly necessary cookies to keep you signed in and to keep the Service secure. We don't use advertising or cross-site tracking cookies.

Changes to this policy

We may update this policy as the Service evolves. When we make a material change, we'll update the date above and, where appropriate, notify you. Continued use of the Service after a change means you accept the updated policy.

Contact

Questions about privacy? Email privacy@bloops.studio. For broader security questions, see our Trust & security page or write to trust@bloops.studio.

This document is provided for transparency and is not legal advice. Your organisation's agreement with Bloops governs where there is any conflict.