Back to blip

Privacy Policy

Last updated: March 2026

What we collect

  • Your email address and basic profile details from Clerk
  • Your spec content and run logs
  • Usage telemetry such as token counts and run timestamps
  • Structured run telemetry such as per-story retry counts, token budgets, and sandbox check summaries
  • Optional GitHub connection data including username, user ID, and granted scopes
  • Optional dedicated memory repo metadata such as repo owner, name, branch, and last sync timestamps
  • Optional watch-mode metadata such as watched specs, last checked commit, and read-only watch log events
  • Your encrypted Anthropic, OpenAI, or Google AI key if you save one in Profile

Secrets and access tokens

If you save an AI provider key, it is encrypted at rest using AES-256-GCM before being stored in our database. If you connect GitHub, the OAuth access token is also encrypted before storage. We only decrypt these secrets when needed to perform the action you requested.

How we use your data

  • To run blip agents on your behalf
  • To show profile, setup, run history, playbooks, and suggestions from past runs in the dashboard
  • To verify GitHub repository access and deliver repo-backed output when you opt in
  • To sync structured run summaries, specs, and playbooks into your dedicated private GitHub memory repo when you enable it
  • To read supported text files back from that memory repo during future spec generation and runs
  • To validate playbooks against the current repo and record whether they look verified, stale, or broken
  • To run optional read-only watch checks when you enable watch mode for a spec
  • To improve reliability, security, and support
  • We do not sell your data or use it to train foundation models

Third-party services

  • Clerk - authentication and account identity
  • GitHub - optional repository access, target repo delivery, and the dedicated private memory repo when you connect it
  • Supabase - database hosting in the US
  • Anthropic, OpenAI, and Google - inference for your runs and spec generation using the provider key you choose

Data deletion

You can delete your account and associated data from Profile. Deletion removes your specs, runs, playbooks, suggestions derived from past runs, saved GitHub connection details, and encrypted API key from our application database.

Contact

Questions? Email us at privacy@blip.dev