Privacy Policy
Last updated: 11 March 2026
1. Who we are
Blocsmith ("we", "us", "our") is an AI-powered website builder operated by Brandy Digital Ltd. Registered address: Primary House, Spring Gardens, Macclesfield, England, SK10 2DX. If you have questions about this policy, contact us at privacy@blocsmith.io.
2. What data we collect
Account data
When you sign up or provide your email during the free trial, we collect your email address and optionally your name. We use this to authenticate you via magic links and to communicate about your account.
Usage data
We collect information about how you use the service, including AI prompts sent, pages created, and features used. This helps us improve the product and debug issues. We do not read the content of your websites except when processing AI requests on your behalf.
Technical data
We collect IP addresses (hashed for rate limiting), browser fingerprints (for bot protection during free trials), and country of origin. IP addresses used for rate limiting are stored as one-way hashes and cannot be reversed.
Payment data
Payments are processed by Stripe. We store your Stripe customer ID and subscription status but never see or store your card details.
Published site analytics
When visitors view your published sites, we collect anonymous page view data (page path, device type, referrer, country) for your analytics dashboard. Visitor identifiers are hashed and cannot be traced back to individuals.
3. How we use your data
- To provide and operate the Blocsmith service
- To authenticate you via magic link emails
- To process payments and manage your subscription
- To send transactional emails (account confirmations, subscription changes, site unpublish notices)
- To prevent abuse and bot accounts during free trials
- To improve the product based on aggregate usage patterns
We do not sell your data to third parties. We do not send marketing emails unless you explicitly opt in.
4. Third-party services
| Service | Purpose | Data shared |
|---|---|---|
| Anthropic (Claude) | AI website generation | Your prompts and page content |
| Google (Imagen) | AI image generation | Image generation prompts |
| Stripe | Payment processing | Email, subscription data |
| SendGrid | Transactional email | Email address |
| Vercel | Hosting and deployment | Site content, technical logs |
| Neon | Database | All account and project data |
5. Cookie consent
Published sites may use cookies for analytics (Google Analytics, GTM, Meta Pixel) if configured by the site owner. A cookie consent banner is shown to visitors. Blocsmith itself uses a session cookie (bs_session) for authentication — this is strictly necessary and does not require consent.
6. Data retention
- Account data: retained while your account is active. Deleted on request.
- Project data: retained while your account is active, including after subscription cancellation (so you can resubscribe).
- Rate limit hashes: automatically purged monthly.
- Cookie consent records: retained for 3 years per GDPR requirements, then pruned.
- Analytics data: aggregated daily, raw events purged after 90 days.
7. Your rights (GDPR)
If you are in the EU/EEA, you have the right to:
- Access your personal data
- Rectify inaccurate data
- Erase your data ("right to be forgotten")
- Port your data to another service
- Object to processing
- Withdraw consent at any time
To exercise any of these rights, email privacy@blocsmith.io. We will respond within 30 days.
8. Security
We use industry-standard security measures including encrypted connections (TLS), hashed passwords and tokens, and access controls. Data is stored in EU-based infrastructure (Neon PostgreSQL, Vercel).
9. Children
Blocsmith is not intended for children under 16. We do not knowingly collect data from children.
10. Changes to this policy
We may update this policy from time to time. We will notify registered users of significant changes via email. The "last updated" date at the top reflects the most recent revision.