Privacy Policy
Effective Date: March 1, 2026
blipped ("we," "our," or "us") operates the blipped mobile application and website at blipped.ai (collectively, the "Service"). This Privacy Policy describes the personal information we collect, how we use it, who we share it with, and the rights you have over your data.
By using the Service you agree to the practices described in this policy. If you do not agree, please discontinue use and contact privacy@blipped.ai to request deletion of any data we hold about you.
1. Information We Collect
We collect information in three ways: information you provide directly, information collected automatically when you use the Service, and information received from third-party services you connect.
1.1 Account & Identity Data
When you create an account we collect the following, depending on the sign-in method you choose:
- Email & Password: Your email address and a securely hashed password when you register directly.
- Google Sign-In: Your Google user ID, email address, display name, and profile photo URL.
- Apple Sign-In: Your Apple user ID, email address (which may be an Apple-generated relay address), and name.
- Profile Information: Display name and profile photo that you set or that are imported from your chosen sign-in provider.
Your authentication credentials are stored securely on your device using platform-appropriate storage mechanisms.
1.2 Location Data
We request foreground-only location permission ("While Using the App"). We do not collect background location while the app is closed or not in use. Location is collected on-demand — when you open the app, perform a search, or request recommendations — and is used for:
- Determining your city and neighborhood to surface relevant local venues.
- Generating location-aware recommendations tailored to your area.
- Displaying maps and retrieving nearby venue data via Google Maps and Google Places APIs. Your location is transmitted to Google as part of these requests.
- Providing context to our AI planning features so they can suggest places near you.
You can revoke location permission at any time in your device Settings. Without location permission the app will have reduced functionality but remains usable.
1.3 Behavioral Data & Preference Profiling
To provide personalized recommendations, we collect and analyze your interactions with the Service. This is the most significant data collection activity in blipped and we want to be transparent about it.
Explicit actions: When you save a venue, mark it as visited, write a review, or dismiss a suggestion, we record that interaction and associate it with your account.
Usage activity: While you use the app we collect information about the venue pages you view, how long you spend on each page, your search queries, and which recommendations you interact with.
Recommendation feedback: For each recommendation shown to you, we record whether you engaged with it, dismissed it, or skipped it. This feedback directly influences how future recommendations are selected for your account.
Preference profiling: We analyze your accumulated activity to build a preference profile — categorizing your tastes and interests (e.g., "Foodie Explorer," "Nightlife Enthusiast"). This profile determines the type, style, and ordering of recommendations you receive. You may request details of your preference profile by contacting privacy@blipped.ai.
Behavioral data collection is integral to the core recommendation functionality and cannot be selectively disabled while using the Service. If you wish to stop all data collection, you may delete your account.
1.4 Camera & Photos
If you post content or reviews with photos, we may request the following device permissions:
- Camera: To capture photos and videos directly within the app.
- Photo Library: To select existing photos from your device.
Photos you submit are stored on our servers. Photos attached to public posts are visible to other users of the Service. We do not perform facial recognition or biometric analysis on uploaded images.
1.5 AI Conversation & Planning Data
blipped includes AI-powered planning features. When you use these features, the following data may be transmitted to third-party AI providers:
- Your current or last-known location
- Your inferred preferences derived from your activity
- A history of venues you have saved, visited, or recently viewed
- The full text of your conversation with the AI assistant
- Any trip details or itinerary context you provide
This data is processed by third-party AI providers including Anthropic and DeepSeek, each operating under their own privacy policies. Your conversations are also stored on our servers for context continuity and service improvement. We use monitoring tools to track AI quality and debug issues; these tools may process conversation data on their respective servers.
1.6 User-Generated Content & Social Data
- Posts: Text and photos you publish, which may be visible to your followers or publicly depending on your settings.
- Reviews: Written reviews and ratings you submit for venues.
- Social Connections: Your follow and follower relationships. Other users can find your profile by name when searching.
- Trip Plans: Itineraries and outing plans you create or that are generated by the AI assistant on your behalf.
1.7 Payment Information
If you subscribe to a paid plan, payment is processed by Stripe. Your full card number, CVV, and billing details are entered directly into Stripe's secure form and transmitted to Stripe's servers — they never pass through our servers. We receive and store only a customer identifier and subscription status.
1.8 Analytics & Device Data
We use analytics tools to understand usage patterns and improve the Service. These tools may collect page views, feature interactions, your IP address, browser or device type, and general session data. If you enable push notifications, your device push token is stored on our servers to deliver notifications. We may also use over-the-air update services for the mobile app, which may collect device identifiers.
We do not collect Apple's IDFA, Google's GAID, or any advertising identifier.
2. How We Use Your Information
- Personalized Recommendations: Build and refine your preference profile to surface venues, events, and experiences that match your interests.
- AI Planning: Provide context to our AI features so they can create itineraries and suggestions tailored to you.
- Location-Based Discovery: Identify venues near you and filter recommendations by your current city or neighborhood.
- Service Operation: Authenticate your account, store your content, deliver notifications, and process payments.
- Service Improvement: Analyze aggregate usage patterns to improve recommendation quality, fix issues, and develop new features.
- Safety & Security: Detect and prevent fraud, abuse, spam, and other harmful activity.
- Communications: Send you transactional messages (e.g., account confirmations), service announcements, and, with your consent, marketing messages.
- Legal Compliance: Comply with applicable laws, respond to legal process, and enforce our Terms of Service.
3. Third-Party Services and Data Sharing
We share your data with the third-party services listed below to operate the Service. We do not sell your personal information to data brokers or advertisers (see Section 9).
- Google: Provides authentication services (for Google Sign-In users), maps, venue search, and font delivery. Google receives your authentication credentials, GPS coordinates, venue search queries, and IP address depending on which features you use. Governed by Google's Privacy Policy.
- Anthropic: AI provider that receives your location, inferred preferences, venue history, and conversation text when you use AI planning features. Governed by Anthropic's Privacy Policy.
- DeepSeek: An alternative AI provider that may receive the same categories of data as Anthropic. DeepSeek is operated from China; by using the AI planning feature you acknowledge your data may be processed on servers located in China. Governed by DeepSeek's Privacy Policy.
- Stripe: Payment processor that receives your payment card information directly. We never receive or store your raw card data. Governed by Stripe's Privacy Policy.
- Yelp: Venue ratings and supplementary data are fetched from Yelp. Yelp receives venue identifiers and general location context in these requests. Governed by Yelp's Privacy Policy.
- Cloud Infrastructure Providers: We use cloud hosting services to store and process your data, including user profiles, uploaded photos, and application data. All data on our infrastructure resides in the United States.
- Analytics Providers: We use analytics tools that receive page view events, feature interaction events, your IP address, and browser or device metadata to help us understand how the Service is used.
- Weather Services: We query weather providers to contextualize recommendations (e.g., promoting indoor venues during rain). These queries include your general location at the city level.
We may also disclose your information: (a) to comply with a legal obligation or court order; (b) to protect the rights, property, or safety of blipped, our users, or the public; (c) in connection with a merger, acquisition, or sale of assets, in which case the acquiring entity will be bound by this policy or you will be notified of any material change.
4. Data Retention
- Account & Profile Data: Retained for the lifetime of your account. Deleted within 30 days of an account deletion request.
- Behavioral & Preference Data: Records of your interactions with venues and your preference profile are retained for the lifetime of your account and are used continuously to improve your recommendations. Deletion requires a request to privacy@blipped.ai.
- AI Conversation Logs: Stored for the duration of your account to maintain conversation context and improve service quality.
- Uploaded Photos: Retained until you delete the associated post or review, or request account deletion.
- Temporary Data: Certain data such as recommendation results and session information is cached temporarily for performance and is not stored long-term.
- Analytics Data: Retained according to our analytics providers' configured retention policies.
5. Data Storage and Security
All user data on blipped's infrastructure is stored in the United States. If you are located outside the United States, your data is transferred to and processed in the US.
We implement industry-standard security measures to protect your data, including:
- Data encrypted in transit and at rest using industry-standard protocols.
- Authenticated API requests using secure token-based authentication.
- Access restrictions limiting API access to approved origins.
- Rate limiting on API routes to prevent abuse.
- Role-based access controls for infrastructure and data systems.
- Passwords are never stored directly — authentication is delegated to trusted identity providers.
No method of electronic transmission or storage is 100% secure. While we work to protect your data, we cannot guarantee absolute security. If you believe your account has been compromised, contact privacy@blipped.ai immediately.
6. International Data Transfers
blipped's servers are located in the United States. If you access the Service from outside the United States — including from the European Economic Area (EEA), United Kingdom, Canada, or Australia — your personal information will be transferred to, stored, and processed in the United States.
When you use the AI planning feature, your data may additionally be processed by DeepSeek on servers located in China. Please review DeepSeek's privacy policy for information about their data handling practices before using this feature.
For users in the EEA or UK, we rely on your consent (given by accepting this policy and using the Service) as the mechanism for international data transfers. We are evaluating Standard Contractual Clauses (SCCs) as an additional transfer mechanism.
7. Your Privacy Rights
Depending on your location, you have some or all of the following rights regarding your personal information:
- Access: Request a copy of the personal data we hold about you, including your activity history, preference profile, and AI conversation logs.
- Correction: Request that we correct inaccurate or incomplete information.
- Deletion: Request deletion of your account and personal data. We will complete account deletion within 30 days and send confirmation.
- Data Portability: Request a machine-readable export of your data.
- Opt Out of Location: Revoke location permission at any time through your device's Settings app.
- Restrict Processing: Request that we limit how we use your data in certain circumstances (applicable to EEA/UK users under GDPR).
- Object to Processing: Object to processing based on our legitimate interests (applicable to EEA/UK users).
- Withdraw Consent: Where processing is based on your consent, withdraw that consent at any time.
To exercise any of these rights, email privacy@blipped.ai with the subject line "Privacy Rights Request." We will respond within 30 days (or as required by applicable law). We may ask you to verify your identity before fulfilling the request.
8. California Privacy Rights (CCPA / CPRA)
If you are a California resident, the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA) grants you additional rights.
8.1 Categories of Personal Information Collected
In the preceding 12 months we have collected the following CCPA categories:
- Identifiers (name, email, unique account IDs, Google/Apple user IDs)
- Personal information under Cal. Civ. Code §1798.80 (name, email, photo)
- Geolocation data (GPS coordinates, city, neighborhood)
- Internet or other electronic network activity (page views, search queries, recommendation interactions, dwell time, scroll depth)
- Inferences drawn to create a profile (preference categories, interest scores)
- Sensitive personal information: precise geolocation
8.2 Sources of Personal Information
Directly from you (account registration, posts, reviews), automatically from your device and app usage, and from third-party authentication providers (Google, Apple).
8.3 Business Purposes for Collection
As described in Section 2 above.
8.4 Disclosure to Third Parties
As described in Section 3 above. We disclose data to service providers for business purposes only.
8.5 Your CCPA Rights
- Right to know what personal information we collect, use, disclose, and sell
- Right to delete personal information we hold about you
- Right to correct inaccurate personal information
- Right to opt out of the sale or sharing of personal information
- Right to limit the use of sensitive personal information (precise geolocation)
- Right to non-discrimination for exercising your rights
To submit a CCPA request, email privacy@blipped.ai with "CCPA Request" in the subject line. You may also authorize an agent to submit a request on your behalf; we will require written authorization or power of attorney.
9. Do Not Sell or Share My Personal Information
blipped does not sell your personal information to third parties for monetary consideration.
We share certain data with third-party service providers (listed in Section 3) solely for the purpose of operating the Service. Under the CCPA's broad definition of "sharing," disclosures to analytics and AI providers may qualify. We continually review these practices for compliance.
To opt out of any sharing of your personal information, email privacy@blipped.ai with the subject "Do Not Sell/Share — Opt Out." Note that opting out of AI data sharing will disable the AI planning feature for your account.
10. EEA and UK Users — GDPR Rights
If you are located in the European Economic Area (EEA) or United Kingdom, the General Data Protection Regulation (GDPR / UK GDPR) applies to our processing of your personal data.
10.1 Legal Bases for Processing
- Contractual necessity: Processing required to provide the Service you have signed up for (account management, recommendations, venue search).
- Legitimate interests: Analytics, security, fraud prevention, and service improvement, where these interests are not overridden by your rights.
- Consent: Location data collection, push notifications, and sharing data with AI providers (Anthropic, DeepSeek).
- Legal obligation: Where required by applicable law.
10.2 Your GDPR Rights
In addition to the rights listed in Section 7, EEA/UK users have the right to lodge a complaint with your local supervisory authority. For UK users, this is the Information Commissioner's Office (ICO). For EEA users, this is your country's national data protection authority.
10.3 Data Protection Contact
For privacy inquiries related to GDPR, please contact privacy@blipped.ai.
10.4 Automated Decision-Making
Our preference profiling and recommendation system constitute automated decision-making that affects what content you see in the Service. Under GDPR Article 22, you have the right to request human review of these automated decisions, to express your point of view, and to contest the outcome. Contact privacy@blipped.ai to exercise this right.
11. Children's Privacy (COPPA)
The Service is not directed to children under the age of 13, and we do not knowingly collect personal information from anyone under 13. Under the Children's Online Privacy Protection Act (COPPA), we are prohibited from collecting personal information from children under 13 without verifiable parental consent.
If you believe we have inadvertently collected personal information from a child under 13, please contact us immediately at privacy@blipped.ai. We will take immediate steps to delete that information from our systems. Parents or guardians may also contact us to review and request deletion of information collected from a minor.
For users between 13 and 17, we encourage parents to supervise their use of the Service given the behavioral profiling and AI data sharing described in this policy.
12. Cookies and Tracking Technologies
The blipped web application may use cookies and similar tracking technologies including:
- Essential cookies: Required for authentication and session management.
- Analytics cookies: Used to understand how users interact with the web app and improve the Service.
- Third-party cookies: Loading resources such as fonts from third-party services may result in those providers setting cookies.
You can control cookie behavior through your browser settings, but disabling cookies may impair functionality. The mobile app does not use browser cookies.
13. Changes to This Policy
We may update this Privacy Policy to reflect changes in our practices, technology, or legal requirements. When we make material changes we will:
- Update the "Effective Date" at the top of this page.
- Post a notice in the app or send you an email notification for significant changes that affect how we use your data.
We encourage you to review this policy periodically. Continued use of the Service after the effective date of a revised policy constitutes your acceptance of the changes. If you do not agree to the updated policy, you must stop using the Service and request account deletion.
14. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
- Email: privacy@blipped.ai
- Subject line for deletion requests: "Account Deletion Request"
- Subject line for data access requests: "Privacy Rights Request"
- Subject line for CCPA requests: "CCPA Request"
- Subject line for Do Not Sell opt-out: "Do Not Sell/Share — Opt Out"
We will respond to all privacy-related inquiries within 30 days. For GDPR requests, we will respond within the legally required timeframe (generally 30 days, extendable to 90 days for complex requests with notice to you).