Privacy policy
Plain English, on purpose. Last updated July 2026.
What we collect
Account data: your name, email address and hashed password when a workspace member creates your account.
Project content: the pages, sections, comments and approvals your team creates. It belongs to you.
Reviewer details: when a client opens a review link they give a name and an email so approvals can be attributed. That’s the point of the feature, and it’s all we ask of them.
Early-access signups: the email (and optional name) you give us on this site, plus which page you signed up from.
What we don’t do
No third-party analytics, no advertising trackers, no pixels. This site sets no marketing cookies at all — we count page views in aggregate on our own server (date, path, referring site), with nothing tied to you.
We never sell data. Client reviewers only ever receive transactional email from Blocky — sign-in links, review requests and notifications about projects they were invited to. No marketing, ever.
We don’t train AI models on your project content.
Where it lives
Data is stored on our servers in the UK/EU. Backups are encrypted; sign-in tokens are hashed at rest, so a database leak does not expose working links.
Transactional email (sign-in links, review requests, notifications) is delivered by Mailgun from EU-region infrastructure. Mailgun processes recipient addresses and message content solely to deliver the email — nothing more.
Your rights
Export your projects at any time (Markdown and JSON — it’s a feature, not a request form). Ask us to delete your account and we will, completely. Questions: hello@blockyhq.com.