What we collect
We collect the minimum needed to run the service: your email address and name (account), order and payment status (payments are handled by Paddle, our Merchant of Record — we never see or store your card details), a hashed copy of your license key, and hashed device identifiers with browser/OS labels used to enforce activation limits. If you sign in with Google, we receive your name and email address from your Google account — nothing else.
What the extension does NOT collect
The BlurSite extension never reads, stores, or transmits the content of the pages you visit or blur. Blur settings are stored locally in your browser.
Cookies
We use only essential cookies: secure session cookies that keep you signed in to your account. We do not use advertising or third-party tracking cookies.
How we use your data
To provide the service, deliver license keys, process payments and refunds, and respond to support requests. We do not sell your data or use third-party advertising trackers.
Service providers we rely on
Your data is processed by a small set of infrastructure providers, each only for its purpose: Supabase (account authentication and database hosting), Paddle (checkout, payment processing, tax, and invoicing as our Merchant of Record — Paddle collects your billing details and payment information directly), Resend (transactional email), Vercel (application hosting), and Upstash (abuse/rate-limit protection). We do not share your data with anyone else.
Data retention
Account data is kept while your account exists. If you delete your account, your profile, license, and device records are deleted; order and payment records are retained only as long as required for financial and tax compliance, then removed.
Your rights (GDPR)
You can delete your account at any time from Dashboard → Settings, which permanently removes your personal data as described above. To request a copy of the data we hold about you (data export), or for any other privacy request, contact us via the support page — we respond within 30 days.
Security
Data is encrypted in transit (TLS) and at rest. License keys and device identifiers are stored only as cryptographic hashes. Access to production systems is restricted and audited.
Contact
For any privacy question or request, reach us through the support page on this site. We will update this policy as the service evolves and change the date above when we do.