Privacy Policy

Two kinds of data

Your account data is about you: it is ours to look after. Your event data is what your applications send us when they break: it is yours, and we process it on your instructions. If your errors contain other people's personal data, you are the controller of it and we are your processor.

What we collect

When you create an account

Your email address. If you sign in with Google or GitHub, we also receive the account identifier they give us, your name and your profile picture, and we check with them that the email is verified. We never receive your password from them, and we never ask you for one.

We record sign-in activity to keep the account safe: the IP address and browser user agent of each session, when it was last used, and the IP that requested each sign-in link.

When your applications report an error

Whatever the report contains. Typically: the error type and message, the stack trace and the lines of your code around it, the URL or job that was running, the release and environment, the browser or server version, the breadcrumbs leading up to it, and any context your application chose to attach. We also store the IP address the report came from.

We do not filter this for you. If your application puts a customer's name, email or address into an error message, it arrives here. Scrub it before it leaves your systems.

When you connect an Odoo instance

A one-way hash of your database identifier. It is not reversible and tells us nothing about your database contents. It exists so one key cannot be used by two installations, and so we can tell your production instance from your staging one.

When you join the waitlist

Your email address and which part of the site you signed up from. Nothing else.

What we do with it

We use account data to sign you in, to show you your workspace, to send the alerts you asked for, and to contact you about the service. We use event data to group errors into issues, to symbolicate stack traces, to count usage against your plan, and to put the alert in your inbox. We use logs and IP addresses to keep the service up and to stop abuse.

We do not sell your data. We do not share it with advertisers. We do not use your event data to train models, and we do not read it except when you ask us to help with a support request or when we must to keep the service running.

Where it lives

Blipit runs in Singapore. Our database is Neon on AWS Singapore, our ingestion and processing run on Fly.io in Singapore, and our queue is Upstash. The website and dashboard are served by Vercel, DNS goes through Cloudflare, and alert email is sent through Microsoft 365. Google and GitHub receive a sign-in request only when you choose to sign in with them.

Those companies are our processors. They hold data only to provide their part of the service and are not allowed to use it for anything else. If you are in the EU or UK, that means your data may be transferred outside it; those transfers rely on standard contractual clauses with the providers named above.

How long we keep it

Cookies

Only the ones the service cannot work without: a signed-in session cookie, a short-lived cookie that protects the sign-in round trip to Google or GitHub, and a one-time cookie that carries a newly created secret key to the page that shows it to you. All are set for blipit.io only, marked HttpOnly and Secure, and none of them follow you anywhere else. There are no advertising or cross-site tracking cookies on this site.

How we protect it

Everything travels over TLS. Session tokens, sign-in links and API keys are stored only as SHA-256 hashes, so a copy of our database does not hand anyone a working key. Secret keys are shown to you once, at creation, and never again. Links that act on your account from an email are signed, expire, and work only once. Access to production is limited to the people who run the service.

If we ever have a breach that puts your data at risk, we will tell affected customers by email without undue delay and within 72 hours of becoming aware, with what we know and what we are doing.

Your rights

You can ask us for a copy of your data, to correct it, to delete it, or to stop processing it. Write to privacy@blipit.io and we will answer within 30 days. Deleting your workspace deletes your events; we cannot recover them afterwards, so export first if you need them.

Depending on where you live, you may also have the right to complain to a data protection authority. In the Philippines that is the National Privacy Commission.

Children

Blipit is a tool for developers and is not intended for anyone under 16. We do not knowingly collect their data.

Changes

If we change this policy in a way that matters, we will email the address on your account before it takes effect. The date at the top always tells you the version you are reading.

Contact

Louward Labs, for Blipit — privacy@blipit.io.