Privacy Policy

Last updated: June 7, 2025

1. Introduction

BlueprintHQ ("Company", "we", "us", or "our") is committed to protecting your privacy and personal data. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our platform and services (collectively, the "Service").

This Privacy Policy complies with the General Data Protection Regulation (GDPR) (EU) 2016/679 and other applicable data protection laws. By using the Service, you agree to the collection and use of information in accordance with this policy.

2. Data Controller

The data controller responsible for your personal data is:

BlueprintHQ
Email: privacy@blueprinthq.com

3. Information We Collect

3.1 Information You Provide Directly

  • Account Information: Name, email address, username, password (encrypted)
  • Profile Information: Location, profile picture, bio, preferences
  • User Content: Habits, goals, reflections, notes, and other content you create
  • Communications: Messages, feedback, and support requests you send us

3.2 Information Collected Automatically

  • Device Information: Device type, operating system, browser type, unique device identifiers
  • Usage Data: Pages visited, features used, time spent, click patterns
  • Log Data: IP address, access times, referring URLs, error logs
  • Cookies and Similar Technologies: Session cookies, preference cookies, analytics cookies

3.3 Information from Third Parties

  • Authentication Providers: If you sign in via Google, Apple, or other providers, we receive basic profile information
  • Analytics Services: Aggregated usage data from analytics providers

4. Legal Basis for Processing (GDPR Article 6)

We process your personal data based on the following legal grounds:

Contract Performance (Art. 6(1)(b))

Processing necessary to provide the Service, manage your account, and fulfill our contractual obligations to you.

Consent (Art. 6(1)(a))

For optional features, marketing communications, and non-essential cookies. You may withdraw consent at any time.

Legitimate Interests (Art. 6(1)(f))

For security, fraud prevention, service improvement, and analytics, where our interests do not override your rights.

Legal Obligation (Art. 6(1)(c))

When required to comply with applicable laws, regulations, or legal processes.

5. How We Use Your Information

We use your personal data for the following purposes:

  • Providing, operating, and maintaining the Service
  • Creating and managing your account
  • Personalizing your experience and providing recommendations
  • Processing transactions and sending related information
  • Sending administrative notifications, updates, and security alerts
  • Responding to your comments, questions, and support requests
  • Analyzing usage patterns to improve the Service
  • Detecting, preventing, and addressing technical issues and security threats
  • Complying with legal obligations and enforcing our Terms of Service
  • With your consent, sending marketing and promotional communications

6. Data Sharing and Disclosure

We do not sell your personal data. We may share your information only in the following circumstances:

6.1 Service Providers

We use third-party service providers to help operate our Service. These providers have access to your data only to perform specific tasks on our behalf and are obligated to protect your information:

  • Firebase/Google Cloud: Authentication, database, and hosting (USA)
  • Vercel: Website hosting and deployment (USA)
  • Analytics providers: Usage analytics (anonymized where possible)

6.2 Legal Requirements

We may disclose your information if required to do so by law or in response to valid requests by public authorities (e.g., court orders, government agencies).

6.3 Business Transfers

If we are involved in a merger, acquisition, or sale of assets, your data may be transferred as part of that transaction. We will notify you before your data is transferred and becomes subject to a different privacy policy.

6.4 With Your Consent

We may share your information for other purposes with your explicit consent.

7. International Data Transfers

Your information may be transferred to and processed in countries outside the European Economic Area (EEA), including the United States. When we transfer data outside the EEA, we ensure appropriate safeguards are in place, including:

  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • Transfers to countries with adequacy decisions
  • Other legally recognized transfer mechanisms

Our primary service providers (Firebase, Google Cloud, Vercel) maintain GDPR-compliant data processing agreements and participate in recognized data protection frameworks.

8. Data Retention

We retain your personal data only for as long as necessary to fulfill the purposes outlined in this Privacy Policy, unless a longer retention period is required or permitted by law.

Data TypeRetention Period
Account dataDuration of account + 30 days after deletion request
User content (habits, goals)Duration of account + 30 days after deletion request
Usage logs12 months
Analytics data24 months (anonymized/aggregated)
Support communications3 years

9. Your Rights Under GDPR

As a data subject under GDPR, you have the following rights regarding your personal data:

Right of Access (Art. 15)

You can request a copy of your personal data and information about how we process it.

Right to Rectification (Art. 16)

You can request correction of inaccurate or incomplete personal data.

Right to Erasure / "Right to be Forgotten" (Art. 17)

You can request deletion of your personal data in certain circumstances.

Right to Restrict Processing (Art. 18)

You can request that we limit how we use your data in certain circumstances.

Right to Data Portability (Art. 20)

You can request a copy of your data in a structured, machine-readable format.

Right to Object (Art. 21)

You can object to processing based on legitimate interests or for direct marketing purposes.

Right to Withdraw Consent (Art. 7)

Where processing is based on consent, you can withdraw your consent at any time.

To exercise any of these rights, please contact us at privacy@blueprinthq.com. We will respond to your request within 30 days. You also have the right to lodge a complaint with a supervisory authority if you believe your rights have been violated.

10. Cookies and Tracking Technologies

We use cookies and similar tracking technologies to collect and track information about your use of the Service. Cookies are small data files stored on your device.

Types of Cookies We Use

  • Essential Cookies: Required for the Service to function (authentication, security)
  • Preference Cookies: Remember your settings and preferences
  • Analytics Cookies: Help us understand how the Service is used (with consent)

You can control cookies through your browser settings. Note that disabling essential cookies may affect the functionality of the Service.

11. Data Security

We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction. These measures include:

  • Encryption of data in transit (TLS/SSL) and at rest
  • Secure authentication mechanisms
  • Regular security assessments and updates
  • Access controls and employee training
  • Incident response procedures

While we strive to protect your personal data, no method of transmission over the Internet or electronic storage is 100% secure. We cannot guarantee absolute security.

12. Children's Privacy

The Service is not intended for individuals under the age of 18. We do not knowingly collect personal data from children under 18. If we become aware that we have collected personal data from a child under 18 without parental consent, we will take steps to delete that information.

13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new Privacy Policy on this page and updating the "Last updated" date. For significant changes, we will provide additional notice (such as email notification).

We encourage you to review this Privacy Policy periodically. Your continued use of the Service after changes become effective constitutes your acceptance of the revised policy.

14. Contact Us

If you have any questions about this Privacy Policy, wish to exercise your rights, or have concerns about how we handle your data, please contact us:

BlueprintHQ - Privacy Team
Email: privacy@blueprinthq.com

EU Representative: If you are in the European Union and wish to contact our EU representative, please email privacy@blueprinthq.com.

Supervisory Authority: You have the right to lodge a complaint with a data protection supervisory authority in your country of residence.