Privacy Policy

Last updated: 11 March 2026

1. Who we are

Blocsmith ("we", "us", "our") is an AI-powered website builder operated by Brandy Digital Ltd. Registered address: Primary House, Spring Gardens, Macclesfield, England, SK10 2DX. If you have questions about this policy, contact us at privacy@blocsmith.io.

2. What data we collect

Account data

When you sign up or provide your email during the free trial, we collect your email address and optionally your name. We use this to authenticate you via magic links and to communicate about your account.

Usage data

We collect information about how you use the service, including AI prompts sent, pages created, and features used. This helps us improve the product and debug issues. We do not read the content of your websites except when processing AI requests on your behalf.

Technical data

We collect IP addresses (hashed for rate limiting), browser fingerprints (for bot protection during free trials), and country of origin. IP addresses used for rate limiting are stored as one-way hashes and cannot be reversed.

Payment data

Payments are processed by Stripe. We store your Stripe customer ID and subscription status but never see or store your card details.

Published site analytics

When visitors view your published sites, we collect anonymous page view data (page path, device type, referrer, country) for your analytics dashboard. Visitor identifiers are hashed and cannot be traced back to individuals.

3. How we use your data

  • To provide and operate the Blocsmith service
  • To authenticate you via magic link emails
  • To process payments and manage your subscription
  • To send transactional emails (account confirmations, subscription changes, site unpublish notices)
  • To prevent abuse and bot accounts during free trials
  • To improve the product based on aggregate usage patterns

We do not sell your data to third parties. We do not send marketing emails unless you explicitly opt in.

4. Third-party services

ServicePurposeData shared
Anthropic (Claude)AI website generationYour prompts and page content
Google (Imagen)AI image generationImage generation prompts
StripePayment processingEmail, subscription data
SendGridTransactional emailEmail address
VercelHosting and deploymentSite content, technical logs
NeonDatabaseAll account and project data

5. Cookie consent

Published sites may use cookies for analytics (Google Analytics, GTM, Meta Pixel) if configured by the site owner. A cookie consent banner is shown to visitors. Blocsmith itself uses a session cookie (bs_session) for authentication — this is strictly necessary and does not require consent.

6. Data retention

  • Account data: retained while your account is active. Deleted on request.
  • Project data: retained while your account is active, including after subscription cancellation (so you can resubscribe).
  • Rate limit hashes: automatically purged monthly.
  • Cookie consent records: retained for 3 years per GDPR requirements, then pruned.
  • Analytics data: aggregated daily, raw events purged after 90 days.

7. Your rights (GDPR)

If you are in the EU/EEA, you have the right to:

  • Access your personal data
  • Rectify inaccurate data
  • Erase your data ("right to be forgotten")
  • Port your data to another service
  • Object to processing
  • Withdraw consent at any time

To exercise any of these rights, email privacy@blocsmith.io. We will respond within 30 days.

8. Security

We use industry-standard security measures including encrypted connections (TLS), hashed passwords and tokens, and access controls. Data is stored in EU-based infrastructure (Neon PostgreSQL, Vercel).

9. Children

Blocsmith is not intended for children under 16. We do not knowingly collect data from children.

10. Changes to this policy

We may update this policy from time to time. We will notify registered users of significant changes via email. The "last updated" date at the top reflects the most recent revision.