BlurDrop — Privacy Policy
Effective date: August 20, 2026
This Privacy Policy explains how BlurDrop ("BlurDrop", "we", "us") collects, uses, and shares information when you use the BlurDrop mobile app and related services (the "Service"). BlurDrop is the controller of your personal data. If you don't agree with this policy, please don't use the Service.
At a glance
- BlurDrop lets you hide content behind a blur, share a link, and receive a recorded face reaction.
- We collect the info you give us (like email and date of birth), the content you create, and the video and audio of reactions — recording a face is the core of the app.
- We use facial recordings to deliver reactions and keep the app safe. We do not run facial recognition and do not create biometric profiles to identify you.
- Your data is stored in the European Union. We share it only with the service providers needed to run BlurDrop, and when required by law or safety.
- You can export or delete your data from the app, and you have privacy rights described below.
1. Information we collect
Information you provide
- Account: email address, username, optional display name, and date of birth (we store your age group for age-gating; we don't display your date of birth).
- Profile: avatar image (optional).
- Communications: messages you send to support.
Content you create
- Challenges: the photo, video, or text you hide, and related metadata.
- Reactions: video and audio recordings of your face and voice captured when you react to a challenge, and the split-screen reels generated from them.
- Reports you submit about other users or content.
Information collected automatically
- Device and technical data: device type, operating system, app version, language, and IP address (used to derive an approximate country and to secure the Service).
- Usage data and diagnostics: how you use features, and crash/performance data.
- Push tokens, if you enable notifications.
Purchase information
- Subscription status and transaction identifiers for PRO, received via the Apple App Store / Google Play and RevenueCat. We do not receive your full card or payment details — payments are handled by the app stores.
We do not intentionally collect special-category data beyond what is inherent in a face/voice recording (see Section 4).
2. How we use your information and our legal bases (GDPR)
| Purpose | Legal basis |
|---|---|
| Create and operate your account; deliver challenges and reactions | Performance of a contract |
| Record and process your face/voice reaction | Your consent (given when you record) |
| Video processing and stitching (composite reels) | Performance of a contract |
| Content moderation, safety, preventing abuse, protecting minors | Legitimate interests; legal obligation |
| Age verification (age gate) | Legal obligation; legitimate interests |
| Notifications you enable | Your consent |
| Subscriptions and billing | Performance of a contract |
| Analytics and improving the Service | Legitimate interests (or consent where required) |
| Marketing messages (if any) | Your consent |
| Responding to legal requests; enforcing our Terms | Legal obligation; legitimate interests |
You can withdraw consent at any time (for example, by not recording reactions, disabling notifications, or deleting your account); this doesn't affect processing already carried out.
3. Content moderation and safety
To keep BlurDrop safe, content is automatically screened when created, may be manually reviewed (including when reported), and may be blocked, removed, or reported. Content that hasn't passed screening cannot be revealed or reacted to. We have zero tolerance for child sexual abuse material; where we detect it, we preserve evidence and report to the National Center for Missing & Exploited Children (NCMEC) and relevant authorities, as required by law. These activities involve processing the content and related account data.
4. Face and reaction recordings
Recording a face is the core function of BlurDrop, so this deserves special attention.
- When you react to a challenge, the app records your face and voice, with your consent, and sends that reaction to the person who created the challenge.
- We process these recordings to deliver the reaction, to create the split-screen reel, and to moderate for safety.
- We do not perform facial recognition, we do not create faceprints or biometric templates, and we do not use your face or voice to identify you. We do not use these recordings to build advertising profiles.
- A recording is visible to the challenge creator, who may download a reel. Be mindful of what you record and with whom your reactions may be shared.
- You can delete your reactions and your account, which removes the associated recordings (subject to the retention rules in Section 6).
Depending on your jurisdiction, face/voice recordings may be treated as sensitive or biometric data. This policy reflects that we process them only to run the Service and not to identify you.
5. How we share information
We don't sell your personal data. We share it only:
- With service providers ("subprocessors") who process data on our behalf to run the Service:
| Provider | Purpose | Location |
|---|---|---|
| Supabase | Database, authentication, file storage, backend functions | European Union |
| RevenueCat | Subscription management | — |
| Apple App Store / Google Play | Payments, notifications delivery | — |
| Apple APNs / Google FCM | Push notifications | — |
| [MODERATION PROVIDER] | Automated content moderation | — |
| Amazon Web Services | Video stitching (composite reels) | European Union region |
| Railway | Deep-link (share link) service | — |
| Cloudflare | Security and delivery for share links | Global edge |
- For legal reasons and safety: to comply with law, respond to lawful requests, enforce our Terms, or protect the rights, safety, and property of users and the public (including child-safety reporting).
- In a business transfer: if BlurDrop is involved in a merger, acquisition, or sale, subject to this policy.
We enter into data processing agreements with our subprocessors as required by law.
6. Data retention
We keep data only as long as needed:
- Challenges: expire and are archived after 30 days.
- Temporary uploads: deleted within 24 hours.
- Composite reels: deleted within about 2 days after creation.
- Reactions and account data: kept while your account is active.
- Account deletion: when you delete your account, it is processed after a 30-day grace period, after which your personal data and media are removed, except limited records we're legally required or permitted to keep (for example, safety, security, or legal-compliance records, retained separately and for a limited time).
- Logs and diagnostics: kept for a limited period.
7. Where your data is stored and international transfers
Your data is stored in the European Union (our database, authentication, and file storage are hosted in an EU region, and video stitching runs in an EU region). Some of our providers may process limited data outside the EU. Where personal data is transferred outside your region, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses. You can request more information at support@blurdrop.com.
8. Your privacy rights
Depending on where you live, you may have the right to:
- access the personal data we hold about you;
- correct inaccurate data;
- delete your data ("right to be forgotten");
- receive a copy of your data in a portable format;
- object to or restrict certain processing;
- withdraw consent; and
- lodge a complaint with your data protection authority.
You can export and delete your data directly in the app, or by writing to support@blurdrop.com. You can also delete your account via the web form at blurdrop.com/delete. We respond to requests within the timeframes required by law.
EU/EEA/UK users: our EU representative (where applicable) is [EU REPRESENTATIVE]. Data-protection contact: [DPO CONTACT] / support@blurdrop.com.
9. Children
BlurDrop is not intended for children under 13 (or the higher minimum age of digital consent in your country). We apply an age gate at sign-up and remove accounts we believe belong to underage users. We don't knowingly collect data from children under the applicable age; if you believe a child has provided us data, contact support@blurdrop.com and we'll delete it.
10. California privacy (CCPA/CPRA)
If you're a California resident, you have rights to know, delete, and correct personal information, and to opt out of its "sale" or "sharing". We do not sell your personal information. You can exercise these rights via the app or at support@blurdrop.com, and we won't discriminate against you for doing so.
11. Security
We protect your data with measures including access controls (row-level security), private storage accessible only via short-lived signed links, app-integrity checks, encryption in transit, and restricted handling of secrets. No system is perfectly secure, but we work to protect your information and will notify you and regulators of a breach where required by law.
12. Cookies and the website
Our marketing website and share-link pages use minimal cookies/local storage needed to function; we don't use them to build advertising profiles. Where required, we'll ask for consent.
13. Changes to this policy
We may update this policy as the Service evolves. We'll post the updated version here with a new effective date and, for significant changes, notify you in the app or by email.
14. Contact
Privacy questions or requests: support@blurdrop.com.