This Privacy Policy explains what BlurBaby("BlurBaby," "we," "us") collects and what we do not. Our product is built so your photos and videos are protected on your own device.
1. The short version
- Face detection, covering, and export run on your device. We do not operate an upload path for your media.
- We do not receive, store, or train on your photos or videos.
- If you create an account or buy credits or a subscription, we store the minimum account and purchase records needed to deliver that service (identity, entitlements, payment provider references). Never your media.
2. Media processing (photos and videos)
When you use the BlurBaby editor in the browser or the mobile app, your file is loaded and processed locally. Face detection models and cover rendering run on-device. The protected copy is re-encoded from pixels so common embedded metadata (including location) from the original file is not carried into the export. The original file stays on your device unless you choose to delete or replace it yourself.
3. Information we may collect
3.1 When you use the site without an account
The marketing site and editor can be used without signing in. In that mode we do not create a BlurBaby user profile for you. Your browser may keep local preferences (for example a free-export counter) in localStorage on your device only.
3.2 When you sign in
If you create an account (email magic link / one-time code via our auth provider), we process the email address you provide and authentication session data so you can sign in across devices and keep your credits.
3.3 When you pay
Payments are handled by our payment processors. On the web that is Stripe. In the mobile apps that is Apple or Google together with RevenueCat, which tells our API that a store purchase succeeded so we can add credits or Unlimited to your account. We store entitlements and payment provider references against your account. We do not store full card numbers on BlurBaby servers.
3.4 Technical and security logs
Our hosting and API providers may process standard request metadata (such as IP address, user agent, and timestamps) for security, reliability, and abuse prevention. These logs are not used to inspect your media.
3.5 Product error reports
If the web or mobile app hits an unexpected error, it may send a short report to our API (error message, a truncated stack trace, and the screen or path where it happened). These reports do not include your photos, videos, or sign-in tokens. We use them only to fix bugs.
3.6 Feedback you send us
The Feedback form lets you send a short text note (a bug, an idea, or how the product is going). We store that text, an optional reply email, your platform (web, iOS, or Android), and the app version if you send one. If you are signed in we also attach your account id. We do not accept photo or video attachments — please do not paste images of anyone, especially children.
4. Cookies and similar technologies
We use only what is needed to run the product (for example maintaining a signed-in session). We do not use Google Analytics, advertising pixels, or cross-site trackers that build marketing profiles about you.
When product analytics are enabled for a build, we use PostHog on EU servers to count named funnel steps only (for example: opened the editor, exported a photo, saw the paywall, started checkout). Autocapture and session recording stay off. We never send your photos, videos, faces, filenames, or EXIF to analytics. You can ask us to delete associated analytics identifiers by emailing [email protected].
Hosting may still record the request logs described above for security and reliability.
5. How we use information
- Provide and improve the BlurBaby service
- Authenticate you and apply free allowances, credits, or subscriptions
- Process payments and prevent fraud or abuse
- Respond to support requests and feedback you send us
- Diagnose crashes from the error reports described above
- Comply with law where required
6. Sharing
We do not sell your personal information. We share data only with the processors that help us run the product, under their data processing terms (or equivalent contracts) that limit their use to providing those services, or when required by law. None of them receive your photos or videos, because those never leave your device:
- Supabase — accounts, authentication and the credit ledger
- Cloudflare — website hosting and the API, plus request logs used for security and reliability
- Stripe — payments on the web, including the billing details you give it directly
- Resend — delivery of sign-in and account emails
- RevenueCat — mobile in-app purchases. It receives the store transaction and your BlurBaby account id so we can grant what you bought. It does not receive your media.
- Apple and Google — purchases made inside the mobile apps
7. Retention
Media you open in BlurBaby is never retained on our servers, because it is never uploaded. Local editor data on your device is under your control. For the little we do store:
- Account and entitlements - kept while your account exists. Deleting your account removes them.
- Purchase and credit ledger records - kept for as long as tax, accounting, and chargeback rules require us to be able to show what was bought and granted, even after an account is deleted.
- Feedback you send - kept up to 12 months, then deleted. Sooner if you ask.
- Email signups - kept until you unsubscribe or ask us to remove you.
- Request logs and error reports - short-lived. Our hosting providers rotate them out within days to weeks.
- Free-allowance records - we keep a one-way hash of the email address that used a free allowance, so the free tier cannot be reset by deleting and recreating an account. The hash cannot be turned back into your address.
8. Security
We use HTTPS for the website and API, restrict access to production secrets, and design the product so media never needs to leave your device. No method of transmission or storage is perfectly secure; please keep your device and email account secure as well.
9. Children
BlurBaby is intended to help adults protect photos and videos of children before sharing. The service is directed at adults. If you believe we have collected personal information from a child in a way that is not allowed, contact us and we will delete it.
10. Your choices
- Use the editor without creating an account
- Sign out or request account deletion
- Send feedback through the in-app or web form (text only)
- Clear site data in your browser to remove local preferences
- Manage subscription billing through Stripe or the app store that sold it
11. Your rights over your data
If you are in the EU/EEA or the UK, the GDPR gives you the rights below, and we apply them to everyone rather than checking where you live:
- Access - ask what we hold about you and get a copy.
- Rectification - have inaccurate details corrected.
- Erasure - have your account and its data deleted. You can do this yourself: Settings in the mobile app, or your account page on the web. Purchase records we are legally required to keep are the one exception, and they are described in Retention above.
- Restriction and objection - ask us to pause a use of your data, or object to processing we base on legitimate interests.
- Portability - receive the data you gave us in a machine-readable form.
- Withdraw consent - where we relied on consent, take it back at any time. This does not affect what was already done.
Email [email protected] and we will answer within one month. There is no charge, and we will not ask you for more identifying information than we need to find your records.
You can also complain to a data-protection authority. Ours is the Croatian Personal Data Protection Agency (AZOP, azop.hr); you may instead go to the authority in the country where you live or work.
12. International users
We may process account and payment-related data in the United States or other countries where our providers operate. If you use BlurBaby from the EU/UK or similar jurisdictions, our legal bases include performing the contract (providing the service you request), legitimate interests (security and product improvement that do not override your rights), and consent where required.
13. Changes
We may update this policy as the product evolves. We will change the "Last updated" date above and, for material changes, provide additional notice when appropriate.
14. Who is responsible for your data
The data controller for the purposes described above is:
- DCQA Solutions d.o.o.
- Tadije Smiciklasa 1, 47000, Karlovac, Croatia
- Registration number: 05764408
Questions about privacy: [email protected] (or the support email listed on https://blurbaby.app).
See also our Terms of Service, Refund Policy, and Feedback.