Privacy Policy – Bliip.me

Effective date: 26 June 2026
Contact: ask[at]bliip.me

1. Data Controller

The controller of personal data processed within the Bliip.me application is the creator of the service: Mateusz Biliński (Opole, Poland), reachable by email at: ask[at]bliip.me.

2. Categories of Data Collected

  1. Email address – required for registration and login.
  2. Username (nick) – publicly visible.
  3. Avatar – optional (uploaded by the user).
  4. User content – texts, photos, videos, comments, reactions.
  5. User identifier (ID) – a technical account number in the database.
  6. GPS coordinates (Location):
    1. While browsing: used in real time solely to filter content (not stored in the database),
    2. Upon publication: stored permanently only as content metadata (post geotag), not as user location tracking.
  7. Technical data: The App and server may automatically record system logs (including IP addresses) for security and diagnostic purposes.

3. Purposes and Legal Bases for Processing

We process your data for the following purposes:

  1. Service provision (Art. 6(1)(b) GDPR): enabling use of the App, account registration, content publication, the "Post-to-View" mechanism.
  2. Legitimate interest of the Administrator (Art. 6(1)(f) GDPR): ensuring security, detecting abuse (spam, bots), statistics and improvement of the App, pursuit of potential claims.

Data is not used for marketing profiling and is not sold to advertisers.

4. Recipients of Data

Your personal data (content, username, avatar) is publicly accessible to other App users in accordance with the App's operating principles. For technical purposes, the Administrator uses the services of trusted infrastructure providers (server hosting, database), with whom appropriate data processing agreements have been concluded.

Artificial Intelligence (AI): To ensure safety (detection of prohibited content) and to operate the App's entertainment features (the Curator), photos you publish are transmitted via an encrypted API connection to external AI technology providers (currently: OpenAI, L.L.C. and Anthropic, PBC – entities incorporated in the United States). Such transfers are carried out on the basis of Standard Contractual Clauses (SCCs) approved by the European Commission, ensuring an adequate level of data protection in accordance with the GDPR. Data is transmitted solely for the purpose of one-time analysis. Under the agreements with the API providers, your photos are not used to train their AI models and are not permanently stored by them.

The processing of images by AI systems does not constitute automated decision-making within the meaning of Art. 22 GDPR – all final moderation decisions are made by a human (the Administrator or a moderator).

5. Data Retention Periods

The Administrator retains data only for the period necessary to achieve the purposes for which it was collected. Given the unique nature of the App, the following retention periods apply:

  1. Account data: Email address, username, and avatar are stored for the entire duration of account ownership and are deleted promptly upon account deletion by the user.
  2. Standard publications (24h/48h posts): These posts are temporary in nature. They are visible in the App for a set period (e.g. 48 hours), after which they are automatically deleted from the database (full technical deletion occurs within a maximum of 5 days from expiry).
  3. Activity data (Views): Information about who viewed a given piece of content is stored only for the lifetime of that content. When a post is deleted, the list of users who viewed it is also deleted.
  4. Location data (Geotags): Coordinates attached to a post are deleted at the same time as the post itself.
  5. Extended-lifetime content (Pinned/Gallery):
    1. Content pinned to the profile (max 3 items) and content added to a Gallery are stored indefinitely – until manually unpinned or deleted by the user (or until the entire account is deleted).
  6. Inactive accounts: The Administrator reserves the right to delete an account (and all associated data) after 12 months of complete inactivity (no login).

6. User Rights

Under the GDPR, you have the right to:

  1. Access your data and receive a copy of it,
  2. Rectification (correction) of your data,
  3. Erasure of your data ("right to be forgotten") – exercised via the "Delete account" function in the App,
  4. Restriction of processing,
  5. Object to processing of your data based on the Administrator's legitimate interest,
  6. Data portability – receive your data in a structured, commonly used, machine-readable format, to the extent it concerns data processed on the basis of a contract and that still exists in the database at the time the request is submitted,
  7. Lodge a complaint with a supervisory authority – in Poland: the President of the Personal Data Protection Office (UODO), ul. Stawki 2, 00-193 Warsaw.

To exercise these rights (e.g. to request a copy of your data), please contact the Administrator at: ask[at]bliip.me. Due to the temporary nature of most data in the App, the scope of the right to data portability is limited to content that still exists in the database at the time the request is made.

7. Security

All communication with the App is encrypted (SSL/TLS). User passwords are stored in hashed (irreversible) form. The Administrator applies appropriate technical and organisational measures to protect data against unauthorised access.

8. Analytics, Cookies and the "Ghost Protocol"

1. Necessary (Technical) Data: The App uses LocalStorage and sessions to maintain login state and remember settings. This data is essential for the App to function and does not require consent.

2. Analytics (Optional): We use Google Firebase Analytics (provider: Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland) for statistical analysis (e.g. number of new users, installation sources). The App does not display ads and does not use advertising networks — Google's advertising consent signals are permanently disabled. These tools are disabled by default ("Ghost Mode").

3. Your Choice: Analytics tools are activated only upon your explicit click of the "Let them count" button (granting consent).
– If you grant consent: Google may process data about your activity within the App (usage statistics). We do not process your device's advertising identifier and we do not track you across other apps or websites. Data may be transferred to Google servers located outside the European Economic Area on the basis of Standard Contractual Clauses.
– If you do not grant consent ("I'll be a Ghost"): No analytics data is sent to Google.

4. Withdrawing consent: You may change your mind and disable analytics at any time in the App Settings.

9. Age Restriction

The App is intended solely for persons aged 16 or older. We do not knowingly process personal data of children. Should we detect that an account belongs to a person under 16, it will be immediately deleted along with all associated data.

10. Changes to This Policy

This Policy may be updated in the event of changes to App features or applicable law. Users will be notified of material changes via an in-App notification.