Blopus.ai

Privacy Policy

Effective 14 August 2026 · Version 1.1

This policy explains what Blopus Labs LLC collects, why, how long we keep it, and what you can ask us to do about it. It covers the Blopus API, the MCP server, the customer console and blopus.ai.

The short version. We do not log your search queries. We never see your card number. We do not sell your data, we do not run advertising, and we do not use your queries to train models. To remove your site from our index, or to make any data request, use the address in Contact.

Contents
  1. Who is responsible
  2. Your search queries
  3. What we collect
  4. Why we use it, and our legal basis
  5. Cookies
  6. Who we share it with
  7. International transfers
  8. How long we keep it
  9. Your rights
  10. The web index and removal requests
  11. Security
  12. Children
  13. Changes
  14. Contact

1. Who is responsible

Blopus Labs LLC, a Texas limited liability company, is the controller of the personal data described here. Contact details are in the Contact section.

2. Your search queries

We do not store the text of your searches. When you call the search or fetch endpoint we count that a call happened — which account and key made it, which endpoint, and how many credits it used — so we can show you your usage and apply your plan cap. The query text itself is never written to our database.

This means we cannot build a profile of what you or your agents are researching, and we cannot hand your query history to anyone, because we do not have it. We also do not use your queries to train models.

Searches are sent in the body of a POST request rather than in a URL, so your query text does not appear in web server access logs either. It exists in memory for as long as it takes to answer the call, and is then gone. There is no query history to retain, disclose or sell, because we never create one.

3. What we collect

Account data

Usage data

Security data

We keep these so you can see suspicious activity on your own account, and so we can investigate abuse. Security emails are always sent and cannot be switched off, because an attacker's first move would otherwise be to disable them.

Support data

Payment data

We never receive your card number. Checkout is hosted by Stripe and card details are entered on Stripe's systems. We store only a Stripe customer identifier and the subscription status Stripe reports back to us.

4. Why we use it, and our legal basis

For users in the European Economic Area and the United Kingdom, the GDPR requires us to name a legal basis for each purpose.

What we doData usedLegal basis
Create and run your accountAccount dataPerformance of a contract
Authenticate you and secure the serviceAccount, security dataLegitimate interests (security)
Meter usage and enforce your plan capUsage dataPerformance of a contract
Take payment and issue receiptsAccount, Stripe identifiersPerformance of a contract
Send service and security emailsEmail addressPerformance of a contract, legitimate interests
Send optional usage alerts at 50% and 75%Email, usage dataConsent, you can turn these off
Send product email — notes about your trial, new features, and offersEmail, usage dataLegitimate interests, you can turn these off at any time
Answer support ticketsSupport dataPerformance of a contract
Detect and prevent abuseUsage, security dataLegitimate interests
Meet legal and tax obligationsBilling recordsLegal obligation

The 100% quota notification is always sent, because at that point the service has stopped and you need to know. Usage alerts and product email are switched off from Account & Security → Notifications in your dashboard, and every product email carries the same link; turning them off never affects service, billing or security email.

5. Cookies

We use a small number of strictly necessary cookies, plus analytics cookies that tell us how the site is used. We do not use advertising cookies to profile you across other websites, and we do not sell your personal data.

If you are in the EEA, the UK or Switzerland, analytics cookies are set only if you accept them. You are asked once, and declining is a single click that costs you nothing. Elsewhere they are set by default, which is what local law allows — and you can still opt out at any time, see below.

We honour Global Privacy Control. If your browser or extension sends a GPC signal, we treat it as an opt-out automatically and load no analytics cookies at all. You do not have to ask us.

CookiePurposeLife
Session cookieKeeps you signed in to the consoleUntil you sign out, or 30 days
Sign-in state cookieSet only if you sign in with Google or GitHub, to protect that sign-in against tampering10 minutes
_ga, _ga_Y14R6JWHEHGoogle Analytics. Counts visits and shows us which pages get used. We do not use it to identify you personally.Up to 2 years
blopus_geoA two-letter country code from our network provider, so we know whether we have to ask you for consent. Contains no identifier of any kind.Session
blopus_consentRemembers whether you accepted or declined analytics. Held in your browser's local storage and never sent to us.Until you clear your browser data

6. Who we share it with

We do not sell personal data. We use Google Analytics to measure how the site is used; some US state privacy laws define that kind of measurement broadly enough to call it “sharing”, so to be unambiguous: you can opt out at any time by sending a Global Privacy Control signal, or by declining analytics if you were asked. We use a small number of processors:

ProcessorWhat forWhat they get
StripePayments, subscriptions, receiptsEmail, payment details you enter with them
CloudflareDNS, network protection, email routing, and privacy-preserving traffic measurement (Web Analytics)Network metadata, inbound email, and page views. Web Analytics sets no cookies and does not track you across other sites.
BrevoSending transactional and product emailEmail address, message content
Google, GitHubOptional single sign-onOnly if you choose to sign in with them
Google AnalyticsMeasuring site traffic and which pages are usedPage address, approximate location, device and browser type

We may also disclose data if we are legally required to, or to protect our rights or the safety of others. If our business is ever sold, account data may transfer with it, and we will tell you first.

A data processing agreement is available for business customers who need one. See Contact.

7. International transfers

We operate from the United States, and our infrastructure and processors are largely US based. If you are in the EEA or the UK, your data is transferred to the United States. Where required we rely on the European Commission's Standard Contractual Clauses and the UK Addendum, which our processors incorporate.

8. How long we keep it

Most of what we hold about you is short-lived. Detailed per-request records are deleted within 30 days. What survives longer is deliberately coarse: daily totals we need for your billing history, and a security trail so you can see who signed in to your account.

DataRetention
The text of your searchesNever written to our database at all
Per-request records30 days, and only for calls that returned an error
Hourly usage detail30 days — 90 days on Agentic Pro
Daily usage totals24 months, for billing history and your usage dashboard
Sign-in and security events12 months
Console sessions30 days, or until you sign out
Support tickets24 months after the ticket is closed
Account dataWhile your account is open. When you close it we delete it after a 30-day grace period, during which you can change your mind.
Billing and tax recordsAs long as tax law requires, typically 7 years

These periods are enforced by an automated job, not by hand.

9. Your rights

Wherever you live, you can ask us to:

Write to the privacy address in Contact. We respond within 30 days. We will not charge you or treat you differently for exercising a right.

If you are in the EEA or UK

You may lodge a complaint with your local supervisory authority. We would rather you came to us first so we can put it right.

If you are in California

You have the right to know what we collect, to delete it, to correct it, and to opt out of sale or sharing. We do not sell personal information for money. We do use Google Analytics, and if we run advertising campaigns the signals it sets may count as “sharing” for cross-context behavioral advertising as the CCPA and CPRA define that term. You can opt out at any time: send a Global Privacy Control signal, which we honour automatically and without you having to contact us, or email the address in Contact.

10. The web index and removal requests

Blopus operates a crawler that visits publicly accessible web pages and builds a search index. Some of those pages inevitably contain personal data, because public web pages often mention people. We return links and short extracts pointing back to the original source.

Want your site or a page out of the index? Just write to the address in Contact. Tell us the domain or the URL. There is no form, no charge, and no need for a lawyer. We aim to respond within 10 business days.

We can:

If you are an individual asking us to remove a page about you, we will handle it as a data erasure request under the GDPR or applicable local law, balancing your rights against the public interest in the information, in the same way other search engines do.

Copyright complaints are handled separately, under the DMCA process in our Terms of Service.

11. Security

No system is perfectly secure. If we discover a breach affecting your personal data, we will notify you and any regulator that applicable law requires, without undue delay.

If you find a security problem, please tell us using the details in Contact. We will not pursue researchers who report issues in good faith and give us reasonable time to fix them.

12. Children

Blopus is a developer tool and is not directed at children. You must be at least 18 to hold an account. We do not knowingly collect data from children. If you believe a child has given us data, contact us and we will delete it.

13. Changes

We may update this policy. If a change materially affects your rights we will give notice by email or in the console at least 30 days before it takes effect. The effective date at the top always reflects the current version.

14. Contact

For anything in this policy — a data request, a question about what we hold, or a request to remove a site or a page from our index — write to [email protected]. A person reads it.

For account, billing and technical questions, open a ticket from the support console, which keeps the conversation attached to your account.

Blopus Labs LLC
Frisco, Texas, United States