← Back

Privacy Policy

Last updated: July 1, 2026

1. Controller

BlindLock, LLC
131 Continental Dr, Suite 305
Newark, DE 19713, USA
Represented by: David Domingo, CEO
Email: [email protected]

A Data Protection Officer has not been appointed as the conditions under Art. 37 GDPR are not met.

2. Principles

BlindLock is designed with privacy as its core principle:

3. Data Processed and Legal Basis

a) Licence Validation

To verify your licence, BlindLock sends technical licence information, a pseudonymised hardware identifier, app version and platform, plus a random one-time value (nonce), to our server. This check happens during activation and each new unlock session. Passwords, notes, 2FA secrets, files and other vault contents are never transmitted.

b) Update Checks

Your app version and platform are sent to determine version status. BlindLock may require a minimum version for security-critical releases; routine updates remain optional.

c) Server Logs

Each access to our server automatically generates log data (IP address, timestamp, HTTP method, response code). These are used solely for operational and security purposes.

e) Payment Processing via Paddle

Payment processing is handled by Paddle.com Market Ltd as Merchant of Record. Paddle processes your payment data (name, email, payment method) as an independent controller. We receive only your email address and order number from Paddle for licence issuance.

f) Licence delivery by email (Brevo)

To send you your licence key and related transactional emails, we use Brevo (Sendinblue SAS, France). For this we process your email address and the email content (your licence key). Brevo acts as our processor under Art. 28 GDPR and processes the data on servers within the European Union.

g) Email Communication

If you contact us by email, your information is stored to process your inquiry.

h) Founders list / launch notifications (Brevo, double opt-in)

If you sign up for our founders list, we process only your email address to notify you about the public launch and the opening of the lifetime phases. Sign-up uses a double opt-in: after you enter your address we send a confirmation email, and you are only added to the list once you click the confirmation link. We store the confirmation timestamp and IP address as proof of consent. The list is managed by Brevo (Sendinblue SAS, France) as our processor under Art. 28 GDPR, on servers within the European Union. You can unsubscribe at any time via the link in every email or by writing to [email protected]; we then delete your address from the list without undue delay.

4. Data Storage

Passwords, notes and 2FA secrets are stored encrypted inside your PNG carrier file. Larger files use separate disguised, encrypted file-vault containers. Both remain on storage you control unless you deliberately export them, copy an encrypted backup into a cloud-synchronised folder or enable a third-party network feature. We have no central access to or recovery copy of these vault contents.

5. Server Infrastructure

Our licence-validation server is located in a data centre in the European Union. Communication with that service uses HTTPS encryption. Licence data is processed on these EU servers.

Paddle as payment provider may process data outside the EU. Paddle uses Standard Contractual Clauses pursuant to Art. 46(2)(c) GDPR for such transfers.

6. Your Rights (GDPR)

Under the EU General Data Protection Regulation, you have the following rights:

To exercise these rights, contact us at [email protected].

7. Right to Lodge a Complaint

You have the right to lodge a complaint with a data protection supervisory authority — in particular in the EU member state of your habitual residence, place of work, or the place of the alleged infringement (Art. 77 GDPR).

8. Automated Decision-Making

No automated decision-making or profiling within the meaning of Art. 22 GDPR takes place.

9. Cookies and Tracking

The BlindLock application and this website use no cookies. No tracking, analytics, or advertising services are used. The website stores only a language preference in your browser's local storage — this is technically necessary and not a cookie under the ePrivacy Directive.

10. California Privacy Rights (CCPA)

We do not sell personal information and have never done so. California residents have the right under the California Consumer Privacy Act (CCPA) to request disclosure of the categories of personal data collected, request deletion of their data, and not be discriminated against for exercising their rights. Requests may be directed to [email protected].

11. Changes

We may update this privacy policy. Changes will be posted on this page with an updated date. For material changes, we will notify you by email if your email address is on file.