Privacy Policy
Last updated: July 1, 2026
1. Controller
BlindLock, LLC
131 Continental Dr, Suite 305
Newark, DE 19713, USA
Represented by: David Domingo, CEO
Email: info@blindlock.app
A Data Protection Officer has not been appointed as the conditions under Art. 37 GDPR are not met.
2. Principles
BlindLock is designed with privacy as its core principle:
- We do not collect, transmit or store your passwords, notes, 2FA secrets, files or other vault contents on BlindLock servers.
- We do not have access to your encryption keys or PIN.
- We do not analyse vault contents or use them for analytics, tracking or telemetry.
- We do not use cookies.
- We share only the limited data required for payment, licensing, version checks and any third-party network feature you explicitly enable.
3. Data Processed and Legal Basis
a) Licence Validation
To verify your licence, BlindLock sends technical licence information, a pseudonymised hardware identifier, app version and platform, plus a random one-time value (nonce), to our server. This check happens during activation and each new unlock session. Passwords, notes, 2FA secrets, files and other vault contents are never transmitted.
- Legal basis: Art. 6(1)(b) GDPR (performance of contract)
- Retention: Duration of the licence agreement, then 30 days
b) Update Checks
Your app version and platform are sent to determine version status. BlindLock may require a minimum version for security-critical releases; routine updates remain optional.
- Legal basis: Art. 6(1)(b) GDPR (performance of contract)
- Retention: No persistent storage; processed only to respond to the request
c) Server Logs
Each access to our server automatically generates log data (IP address, timestamp, HTTP method, response code). These are used solely for operational and security purposes.
- Legal basis: Art. 6(1)(f) GDPR (legitimate interest in operational security)
- Retention: Maximum 7 days, then automatically deleted
e) Payment Processing via Paddle
Payment processing is handled by Paddle.com Market Ltd as Merchant of Record. Paddle processes your payment data (name, email, payment method) as an independent controller. We receive only your email address and order number from Paddle for licence issuance.
- Legal basis: Art. 6(1)(b) GDPR (performance of contract)
- Paddle's privacy policy: paddle.com/legal/privacy
f) Licence delivery by email (Brevo)
To send you your licence key and related transactional emails, we use Brevo (Sendinblue SAS, France). For this we process your email address and the email content (your licence key). Brevo acts as our processor under Art. 28 GDPR and processes the data on servers within the European Union.
- Legal basis: Art. 6(1)(b) GDPR (performance of contract)
- Brevo's privacy policy: brevo.com/legal/privacypolicy
g) Email Communication
If you contact us by email, your information is stored to process your inquiry.
- Legal basis: Art. 6(1)(b) or Art. 6(1)(f) GDPR
- Retention: Until your inquiry is fully resolved, maximum 2 years
h) Founders list / launch notifications (Brevo, double opt-in)
If you sign up for our founders list, we process only your email address to notify you about the public launch and the opening of the lifetime phases. Sign-up uses a double opt-in: after you enter your address we send a confirmation email, and you are only added to the list once you click the confirmation link. We store the confirmation timestamp and IP address as proof of consent. The list is managed by Brevo (Sendinblue SAS, France) as our processor under Art. 28 GDPR, on servers within the European Union. You can unsubscribe at any time via the link in every email or by writing to support@blindlock.app; we then delete your address from the list without undue delay.
- Legal basis: Art. 6(1)(a) GDPR (consent)
- Retention: Until you unsubscribe or the launch campaign ends
- Brevo's privacy policy: brevo.com/legal/privacypolicy
4. Data Storage
Passwords, notes and 2FA secrets are stored encrypted inside your PNG carrier file. Larger files use separate disguised, encrypted file-vault containers. Both remain on storage you control unless you deliberately export them, copy an encrypted backup into a cloud-synchronised folder or enable a third-party network feature. We have no central access to or recovery copy of these vault contents.
5. Server Infrastructure
Our licence-validation server is located in a data centre in the European Union. Communication with that service uses HTTPS encryption. Licence data is processed on these EU servers.
Paddle as payment provider may process data outside the EU. Paddle uses Standard Contractual Clauses pursuant to Art. 46(2)(c) GDPR for such transfers.
6. Your Rights (GDPR)
Under the EU General Data Protection Regulation, you have the following rights:
- Access (Art. 15 GDPR) — What data we hold about you
- Rectification (Art. 16 GDPR) — Correction of inaccurate data
- Erasure (Art. 17 GDPR) — Deletion of your data
- Restriction (Art. 18 GDPR) — Restriction of processing
- Data Portability (Art. 20 GDPR) — Data in a machine-readable format
- Objection (Art. 21 GDPR) — Object to processing
To exercise these rights, contact us at info@blindlock.app.
7. Right to Lodge a Complaint
You have the right to lodge a complaint with a data protection supervisory authority — in particular in the EU member state of your habitual residence, place of work, or the place of the alleged infringement (Art. 77 GDPR).
8. Automated Decision-Making
No automated decision-making or profiling within the meaning of Art. 22 GDPR takes place.
9. Cookies and Tracking
The BlindLock application and this website use no cookies. No tracking, analytics, or advertising services are used. The website stores only a language preference in your browser's local storage — this is technically necessary and not a cookie under the ePrivacy Directive.
10. California Privacy Rights (CCPA)
We do not sell personal information and have never done so. California residents have the right under the California Consumer Privacy Act (CCPA) to request disclosure of the categories of personal data collected, request deletion of their data, and not be discriminated against for exercising their rights. Requests may be directed to info@blindlock.app.
11. Changes
We may update this privacy policy. Changes will be posted on this page with an updated date. For material changes, we will notify you by email if your email address is on file.