BlitzGraph beta · occasional interruptions may occur
Last updated April 7, 2026

Privacy Policy

1. What we collect

Account info (email, name), usage data (API calls, query counts), and operational logs. That's it.

Full legal text

We collect the following categories of information:

  • Account information: email address, name, organization name, and authentication credentials when you sign up or sign in.
  • Usage data: API request counts, query and mutation metrics, storage usage, and feature usage within BlitzStudio.
  • Operational logs: server logs, error reports, and performance metrics necessary to operate and debug the Service.
  • Payment information: billing details are collected and processed by Stripe. We do not store your full credit card number.

2. What we don't collect

Your database content is yours. We don't sell it, share it with advertisers, or use it to train AI. We only access it when needed to run the service.

Full legal text

We do not sell, license, or share your stored data with advertisers or third parties for their own purposes. We do not use your data to train machine learning models. We do not build profiles based on your stored content.

We may access your data only as necessary to operate, maintain, and troubleshoot the Service, to comply with law, or to respond to your support requests. This is consistent with the data access terms in our Terms of Service.

3. How we use your information

To run the service, bill you, prevent abuse, and make the product better. Nothing surprising.

Full legal text

We use the information we collect to:

  • Provide, maintain, and improve the Service
  • Process billing and manage your subscription
  • Detect and prevent abuse, fraud, and security incidents
  • Send transactional communications (billing, security, service updates)
  • Understand usage patterns to improve the product

We do not send marketing emails unless you have explicitly opted in.

4. Cookies and analytics

We use PostHog for product analytics (linked to your account, not shared with advertisers) and essential cookies to keep you logged in. No ad trackers.

Full legal text

We use essential cookies for authentication and session management. These are required for the Service to function.

We use PostHog for product analytics to understand how the Service is used. PostHog receives pseudonymized usage events linked to your account identifier and email address to help us understand usage patterns and improve the product. This data is not shared with advertisers or used for ad targeting. We do not use advertising cookies or third-party ad trackers.

5. Subprocessors

AWS hosts your data, PostHog handles analytics, and Stripe processes payments. That's the full list.

Full legal text

We use the following third-party service providers to operate the Service:

ProviderPurposeLocation
Amazon Web ServicesInfrastructure and hostingUS
PostHogProduct analyticsUS / EU
StripePayment processingUS

We will update this list if we add new subprocessors and provide notice of material changes.

6. Data retention

Account data stays while you're active, then 30 days after deletion. Logs are kept for 90 days. Backups for 30 days.

Full legal text
  • Account data: retained while your account is active and for 30 days after account deletion.
  • Database content: deleted within 30 days of account or space deletion.
  • Operational logs: retained for 90 days, then automatically purged.
  • Backups: retained for up to 30 days, then automatically purged.

7. Your rights

You can access, correct, export, or delete your data anytime. Email us and we'll handle it within 30 days.

Full legal text

You have the right to:

  • Access the personal information we hold about you
  • Correct inaccurate personal information
  • Delete your account and associated data
  • Export your data through the API or by request

To exercise these rights, contact us at [email protected]. We will respond within 30 days.

8. Security

Your data is encrypted at rest and in transit. Grant tokens are hashed, not stored in plain text. Each space is isolated.

Full legal text

We implement industry-standard security measures to protect your data, including:

  • Encryption at rest and in transit (TLS 1.2+)
  • Grant tokens are stored as one-way hashes, never in plain text
  • Namespace and space isolation at the storage layer
  • Rate limiting and abuse detection

If you discover a security vulnerability, please report it to [email protected].

9. Children

BlitzGraph is not for children under 13. If we find out a child is using the service, we'll delete their account.

Full legal text

The Service is not intended for children under the age of 13. We do not knowingly collect personal information from children under 13. If we become aware that a child under 13 has provided us with personal information, we will delete their account and data promptly.

10. Changes to this policy

We'll email you if we make material changes. Keep using the service and you're agreeing to the updated policy.

Full legal text

We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email and through a notice in the BlitzStudio dashboard at least 30 days before the changes take effect.

11. Contact

Privacy questions? Email us.

Full legal text

For privacy-related questions or requests, contact us at [email protected].

Blitz Holdings Inc
San Francisco, California

The plain English summaries are not legally binding. They exist to help you understand what the legal text means. If there is a conflict, the full legal text governs.