PRIVACY POLICY
How we collect, use, and protect your personal data
BLU TECH LIMITED("BLU," "we," "us," or "our") operates the myblu.ai platform. This Privacy Policy explains what information we collect, how we use it, and your rights regarding your data.
Effective Date: March 1, 2026 | Last Updated: August 16, 2026
1. Information We Collect
Account Information
When you register for a BLU account, we collect:
- • Name, email address, and password
- • Country and mobile phone number
- • Date of birth and gender (optional, provided during setup)
- • Payment information (processed by Stripe; we do not store card numbers)
- • Invitation token used to join
AI Interaction Data
When you use your personal AI, we collect:
- • Text conversations with your personal AI
- • Voice conversation audio (processed in real-time, not permanently stored as audio files)
- • Preferences you set for your AI (name, personality, goals)
- • Memory data your AI retains to personalize your experience
Connected App Data
If you connect third-party apps (Google, Spotify, WhatsApp, etc.) through BLU:
- • We store an authorization token that allows BLU to act on your behalf with that service
- • We do not store your passwords for these services — authentication uses industry-standard OAuth
- • You can disconnect any app at any time from your Account settings, which revokes our access
- • Connected app data (emails read, calendar events, etc.) is processed in real-time and not permanently stored by BLU
- • For WhatsApp: your phone number is stored to route messages. Message content is processed in real-time by your AI and not stored separately from your conversation history
Automatically Collected Information
When you use our platform, our servers automatically log:
- • IP address (for security and fraud prevention)
- • Browser type and device information (from HTTP headers)
- • Error logs when something goes wrong (for debugging)
We do not use analytics or tracking tools. We do not use Google Analytics, Facebook Pixel, or any third-party tracking scripts. We do not build advertising profiles or sell your data.
Invitation Request Data
If you submit a request for an invitation, we collect your name, email, and country to process your request and send you an invitation if approved.
2. How We Use Your Information
Primary Uses
- • Power your personal AI: Conversations, memory, and personalized experience
- • Manage your account: Authentication, membership status, billing
- • Process payments: Through Stripe (credit/debit) or BluPass codes
- • Calculate affiliate commissions: Track referral relationships and earnings
- • Send transactional emails: Welcome emails, password resets, membership notifications
- • Security: Protect accounts, detect fraud, enforce two-factor authentication
Your AI is yours alone. Your conversations, memories, and preferences train your personal AI instance only. We do not use your data to train general AI models, and we do not share your conversations with other users or third parties.
• No advertising: We do not serve advertisements and do not use your data for advertising purposes.
• No automated decisions: We do not make solely automated decisions that produce legal or similarly significant effects on you.
3. Cookies & Local Storage
We use minimal cookies and browser storage, only for functionality — never for tracking or advertising.
| Name | Type | Purpose | Duration |
|---|---|---|---|
| sb-*-auth-token | Cookie | Keeps you logged in (authentication session) | Session |
| blu_last_thread_id | Local Storage | Remembers your last conversation | Persistent |
| blu_locale | Cookie | Your language preference | Persistent |
| voice-settings | Local Storage | Voice chat display preference | Persistent |
The authentication cookie is strictly necessary for the service to function and does not require consent. All other storage items are user preferences set after you log in. We do not use any third-party tracking cookies.
4. Information Sharing
We do not sell your personal information. We do not share your data with advertisers, data brokers, or marketing companies.
We share limited data only with service providers who help us operate BLU:
- • Google Cloud (Vertex AI)— Powers your personal AI conversations and voice processing. Text is processed via Gemini models; voice audio is processed in real-time and not permanently stored. Google's enterprise API terms contractually prohibit the use of your data — including prompts, responses, and audio — for training their models or any other generally available models.
- • OpenRouter— Routes specialized AI tasks to Claude models for complex reasoning. We configure all requests with data collection disabled, and the underlying model providers' API terms contractually prohibit the use of your data for model training.
- • Supabase — Database hosting, authentication, and row-level data isolation. Your data is encrypted at rest. Your AI memory data is stored exclusively in our Supabase database and does not leave our infrastructure.
- • Stripe — Payment processing (PCI-DSS compliant; we never store card numbers)
- • SendGrid — Transactional email delivery (welcome emails, password resets, membership notifications)
- • Google Cloud Run — Cloud infrastructure for AI agent hosting
- • Meta (WhatsApp Business)— If you link your WhatsApp number, messages are routed through Meta's platform. Your phone number and message content are processed to deliver BLU's replies. You can disconnect at any time.
We may also disclose information when required by law, court order, or to protect the safety of our users or the public.
5. Business Transfers
If BLU TECH LIMITED is involved in a merger, acquisition, or sale of assets, your personal data may be transferred as part of that transaction. We will notify you before your data is subject to a different privacy policy.
6. Data Security
We protect your data with:
- • HTTPS encryption on all connections
- • Row-Level Security (RLS) on all database tables — your data is isolated from other users
- • Two-factor authentication (TOTP) for account protection
- • Secure, HttpOnly authentication cookies
- • Security headers (HSTS, X-Frame-Options, Content-Type protection)
- • JWT token validation on every request
- • Rate limiting on authentication endpoints (login, registration, password reset)
- • Complete data deletion across our databases, file storage, AI conversations, and memory systems
No system is 100% secure. If we discover a data breach affecting your personal information, we will notify you and applicable authorities as required by law.
7. Data Retention
We offer two separate actions, and they do different things. Both are available to you at any time from Account Settings.
Delete My Data — clears everything we hold about you and returns your BLU to its original state, as if you had just joined. Your account and login stay active. This removes your AI conversations, memories, personal facts, uploaded files, generated images, tasks, connected app tokens, notification settings, and activity history.
Because this is not reversible by hand, we keep a backup for 30 days so you can ask us to restore it if you change your mind. It is stored encrypted at rest and is reachable only by authorized BLU personnel — restoring it requires a person here to act on your request. After 30 days it is deleted from our active systems and restoration is no longer possible. Any residual copies held in our routine system backups are removed on our standard backup rotation. The backup is used for nothing else.
Delete My Account — does everything above, and also deletes the account itself. Your login stops working immediately, and a 30-day window opens to change your mind: logging back in during those 30 days cancels the deletion and restores your account — free if your membership is still active, or by paying again if it lapsed. Once the 30 days pass, the account moves into permanent erasure, and any of our backup systems still holding a copy are purged within a further 30 days. After that point, nothing about the account can be recovered by us or anyone else.
One record is kept: an anonymous placeholder holding your position in the affiliate referral chain. It carries no name, email, or contact details. We keep it so the people who joined through you do not lose their own referral history.
You may delete your account at any time. If you paid by credit or debit card through Stripe and you request deletion within 7 days of that payment, you are entitled to a full refund — see our Refund Policy for how to request one.
- • Account data: Retained while your account is active. Cleared when you delete your data (Delete My Data); permanently erased once your account is deleted or terminated.
- • AI conversations and memories: Retained while your account is active; permanently deleted across all systems once your account is deleted or terminated
- • Connected app tokens: Deleted when you disconnect an app, and when your account is deleted or terminated
- • Payment records: Deleted when your account is deleted or terminated. Stripe retains its own records per its privacy policy, and we retain the minimum transaction record required by tax and accounting law.
- • Invitation requests: Retained while your request is pending and, if you register, linked to your account
- • Server logs: Retained for operational monitoring and debugging; reviewed periodically
- • Terminated accounts: If your membership expires and you do not renew for 6 consecutive months, or BLU terminates your account for cause under our Terms of Service, your account is terminated and all associated data permanently deleted, with backups still holding a copy purged within 30 days. No notice is sent beforehand for inactivity, and there is no undo window for either trigger — that is unique to deleting your own account.
8. Your Rights
Depending on your location, you may have some or all of the following rights:
- • Access: View your personal data anytime in Account Settings. Your AI memories are visible and manageable in the Memory section.
- • Correction: Edit your profile, preferences, and AI persona directly in your account — no request needed
- • Data deletion: Clear everything we hold about you from Account Settings → Security, keeping your account active. Requires two-factor authentication. Recoverable on request for 30 days, then permanent.
- • Account termination: Delete your data and your account together, from Account Settings → Security. Requires two-factor authentication. Immediate, permanent, and not recoverable.
- • Memory control: View, search, and delete individual AI memories at any time from the Memory page. You control what your AI remembers.
- • App disconnection: Disconnect any connected third-party app (Google, Spotify, Slack, etc.) at any time from Account Settings → Apps
- • Portability: Request a copy of your data by contacting us at the address below
- • Opt-out: Manage notification preferences in Account Settings → Settings
Most rights can be exercised directly in the app without contacting us. For data portability requests or any questions, contact us at the address below. We will respond within 30 days.
9. International Users
BLU is operated from the United States. If you access our services from outside the US, your data will be transferred to and processed in the United States.
EU/UK residents: You have additional rights under GDPR/UK GDPR, including the right to lodge a complaint with your local data protection authority. Our legal basis for processing your data is your consent (provided at registration) and our legitimate interest in providing the service you requested.
California residents: Under CalOPPA, you have the right to know what personal information we collect and how it is used. We do not sell personal information. If you would like to exercise your California privacy rights, contact us at the address below.
10. Children's Privacy
BLU is not intended for anyone under 18 years of age. We do not knowingly collect personal information from children under 18. If we learn that we have collected data from a child under 18, we will delete it promptly. If you believe a child has provided us with personal information, please contact us.
11. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email at least 30 days before the changes take effect. The "Last Updated" date at the top of this page indicates when the policy was most recently revised.
12. Contact Us
For privacy questions, data requests, or concerns:
BLU TECH LIMITED — Privacy
3911 Concord Pike #8030, SMB#89267
Wilmington, DE 19803
privacy@myblu.ai