Privacy Policy
Last updated: August 30, 2026
1. Controller
BlindLock, LLC
131 Continental Dr, Suite 305
Newark, DE 19713, USA
Represented by: David Domingo, CEO
Email: info@blindlock.app
A Data Protection Officer has not been appointed as the conditions under Art. 37 GDPR are not met.
2. Principles
BlindLock is designed with privacy as its core principle:
- We do not collect, transmit or store your passwords, notes, 2FA secrets, files or other vault contents on BlindLock servers.
- We do not have access to your encryption keys or PIN.
- We do not analyse vault contents or use them for analytics, tracking or telemetry.
- We do not use cookies.
- We share only the limited data required for payment, licensing, version checks and any third-party network feature you explicitly enable.
3. Data Processed and Legal Basis
a) Licence Validation
To verify your licence, BlindLock sends technical licence information, a pseudonymised hardware identifier, app version and platform, plus a random one-time value (nonce), to our server. This check happens during activation and each new unlock session. Passwords, notes, 2FA secrets, files and other vault contents are never transmitted.
- Legal basis: Art. 6(1)(b) GDPR (performance of contract)
- Retention: Duration of the licence agreement, then 30 days
b) Update Checks
Your app version and platform are sent to determine version status. BlindLock may require a minimum version for security-critical releases. Routine updates remain optional.
- Legal basis: Art. 6(1)(b) GDPR (performance of contract)
- Retention: No persistent storage — processed only to respond to the request
c) Server Logs
Each access to our server automatically generates log data (IP address, timestamp, HTTP method, response code). These are used for operational and security purposes, and for aggregated access statistics — how many pages were requested, which ones, and from which country. These statistics contain no personal profile, no cookie and no identifier that follows you. They are produced from delivery logs our hosting provider records anyway, not by a script running in your browser.
- Legal basis: Art. 6(1)(f) GDPR (legitimate interest in operational security)
- Retention: Maximum 7 days, then automatically deleted
d) Explicitly enabled wallet network features
If you enable wallet network features, BlindLock may exchange public wallet addresses, balance queries, signed transactions and transaction status with vetted blockchain nodes. Private keys, seed phrases, passwords and notes are never transmitted.
- Legal basis: Art. 6(1)(b) GDPR (provision of the feature you chose)
- Recipients: the blockchain nodes used and their operators
e) Payment Processing
Payment processing is handled by Polar Software, Inc. (“Polar”) as external Merchant of Record, which processes your payment data (name, email, payment method) as an independent controller. We receive only your email address and order number from Polar for licence issuance. Polar’s privacy policy is available at polar.sh/legal/privacy.
- Legal basis: Art. 6(1)(b) GDPR (performance of contract)
f) Licence delivery by email (Brevo)
To send you your licence key and related transactional emails, we use Brevo (Sendinblue SAS, France). For this we process your email address and the email content (your licence key). Brevo acts as our processor under Art. 28 GDPR and processes the data on servers within the European Union.
- Legal basis: Art. 6(1)(b) GDPR (performance of contract)
- Brevo's privacy policy: brevo.com/legal/privacypolicy
g) Email Communication
If you contact us by email, your information is stored to process your inquiry.
- Legal basis: Art. 6(1)(b) or Art. 6(1)(f) GDPR
- Retention: Until your inquiry is fully resolved, maximum 2 years
4. Data Storage
Passwords, notes and 2FA secrets are stored encrypted inside your PNG carrier file. Larger files use separate encrypted file-vault containers. Both remain on storage you control unless you deliberately export them, copy an encrypted backup into a cloud-synchronised folder or enable a third-party network feature. We have no central access to or recovery copy of these vault contents.
5. Server Infrastructure
Our licence-validation server is located in a data centre in the European Union. Communication with that service uses HTTPS encryption. Licence data is processed on these EU servers.
Once sales open, Polar as payment provider may process data outside the EU. Standard Contractual Clauses pursuant to Art. 46(2)(c) GDPR are foreseen for such transfers. No such transfer takes place at this time.
6. Your Rights (GDPR)
Under the EU General Data Protection Regulation, you have the following rights:
- Access (Art. 15 GDPR) — What data we hold about you
- Rectification (Art. 16 GDPR) — Correction of inaccurate data
- Erasure (Art. 17 GDPR) — Deletion of your data
- Restriction (Art. 18 GDPR) — Restriction of processing
- Data Portability (Art. 20 GDPR) — Data in a machine-readable format
- Objection (Art. 21 GDPR) — Object to processing
To exercise these rights, contact us at info@blindlock.app.
7. Right to Lodge a Complaint
You have the right to lodge a complaint with a data protection supervisory authority — in particular in the EU member state of your habitual residence, place of work, or the place of the alleged infringement (Art. 77 GDPR).
8. Automated Decision-Making
No automated decision-making or profiling within the meaning of Art. 22 GDPR takes place.
9. Cookies and Tracking
The BlindLock application and this website use no cookies. No tracking, analytics, or advertising services are used. The website stores only a language preference in your browser's local storage — this is technically necessary and not a cookie under the ePrivacy Directive.
10. California Privacy Rights (CCPA)
We do not sell personal information and have never done so. California residents have the right under the California Consumer Privacy Act (CCPA) to request disclosure of the categories of personal data collected, request deletion of their data, and not be discriminated against for exercising their rights. Requests may be directed to info@blindlock.app.
11. Changes
We may update this privacy policy. Changes will be posted on this page with an updated date. For material changes, we will notify you by email if your email address is on file.