Privacy Policy
Last updated 2 August 2026
blunlock hosts waitlist and roadmap pages. This policy explains what we collect, why we collect it, and who else touches it. It covers two different groups of people, and the distinction matters.
Two kinds of people, two different roles
Customers are people who create an account and run a project on blunlock. For their data, we are the controller — we decide how it is handled.
Subscribers are people who join a customer's waitlist, vote on their board, or comment on it. For that data, the customer is the controller and blunlock is only a processor — we store and send on the customer's behalf and do not use it for our own purposes.
Practically: if you joined a waitlist and want your data removed, the fastest route is the unsubscribe link in any email, or contacting the project owner. You can also contact us and we will act on it.
What we collect from customers
- Email address, and your name and profile email if you sign in with Google. We do not receive your Google password, and we request only your basic profile and email — nothing else in your Google account.
- Project content you create: project name, tagline, logo, roadmap posts, changelog entries and replies.
- Billing identifiers from Paddle — a customer ID and subscription ID. See payments below.
What we collect from subscribers
- Email address, and whether it has been confirmed.
- Referral relationships — a referral code, and which subscriber referred you, so waitlist position can be calculated.
- Your contributions — votes, posts and comments on a public board.
- A hashed IP address. We hash your IP with a one-way function and store only the hash, purely to rate-limit signups and prevent abuse. We do not store raw IP addresses and cannot recover them.
Email addresses of subscribers are never shown publicly. On a public board, contributions are attributed with a masked name derived from the email (for example sau***), never the address itself.
Analytics
We record basic events — page views, signups, votes — against a project so its owner can see whether their page is working. These events are not tied to an advertising profile, and we do not use third-party analytics or advertising trackers anywhere on blunlock.
Cookies and local storage
- Session cookie — keeps customers signed in. Strictly necessary.
blunlock_ref— set for 30 days when you arrive via someone's referral link, so their referral is credited if you sign up.- Local storage — remembers the email you used on a board so you do not retype it to vote again. It stays in your browser.
We do not use advertising or cross-site tracking cookies, so there is no consent banner.
Who else processes your data
- Supabase — database, authentication and storage.
- Vercel — application hosting and delivery.
- Resend — sends our transactional email (confirmations, referral and changelog notifications).
- Google — only if you choose to sign in with Google.
- Paddle — payments. See below.
We do not sell personal data, and we do not share it for advertising.
Payments
Paddle acts as the merchant of record for all purchases. Your card details go directly to Paddle and are never sent to, processed by, or stored on blunlock's servers. We receive only a customer ID, a subscription ID and which plan is active.
How long we keep things
Customer accounts and project content are kept while the account is open. Delete a project and its subscribers, posts, votes and comments are deleted with it. Delete your account and everything associated with it goes.
Unsubscribing marks a subscriber as unsubscribed and stops all email; the row is retained so the same address is not re-added by a later import. Ask for full erasure and we will delete the record.
Your rights
You can request access to, correction of, export of, or deletion of your personal data. Customers can export their subscriber list as CSV from the dashboard on a paid plan. Subscribers can unsubscribe from any email with one click.
For anything else, email hello@blunlock.com. We aim to respond within 30 days.
Security
Data is protected at the database level with row-level security, not only in application code. Subscriber email addresses are not readable by the public API under any circumstances. Email confirmation tokens are stored hashed, never in plain text, and IP addresses are stored only as one-way hashes.
No system is perfectly secure. If you find a vulnerability, please email us rather than disclosing it publicly, and we will fix it promptly.
Children
blunlock is not intended for anyone under 16 and we do not knowingly collect their data.
Changes
If this policy changes materially we will update the date above and notify account holders by email before the change takes effect.