In plain English. We collect what we need to run your account, bill you, generate content when you ask, keep the service secure and help you when something goes wrong. We do not sell personal data, we do not use your content to train AI models, and we do not run advertising trackers. Your content goes to our AI providers only to produce the result you asked for. You can access, correct, export or delete your data by contacting us. The detail is below.
1. Who we are
1.1 This Privacy Policy explains how Referr Ltd, trading as Bloggable, collects and uses personal data. We are the controller of the personal data described in this policy unless section 12 says otherwise. We are a company registered in England and Wales under number 14651607, with our registered office at 2nd Floor College House, 17 King Edwards Road, Ruislip, London, HA4 7AE, United Kingdom.
1.2 We pay the data protection fee to, and are registered with, the Information Commissioner's Office (ICO).
1.3 Questions about this policy or about your personal data should go to hello@support.getbloggable.com, or by post to the registered office above, marked "Privacy".
2. Who this policy covers
This policy applies to:
- visitors to our websites at getbloggable.com and bllog.io;
- customers and their team members who create or are invited to a Bloggable Account;
- people who contact us, join a waitlist, or go through our sign-up questionnaire;
- readers of blogs that our customers publish using Bloggable, in the limited way described in section 12; and
- people whose personal data appears in our customers' content, also described in section 12.
3. The personal data we collect
| Category | What it includes | Where it comes from |
|---|---|---|
| Identity and contact | Name, email address, profile image, job title, company name and website, country. | You, or your Google account when you sign in with Google. |
| Account and workspace | Your role, the Account you belong to, invitations you send or receive, settings, notification preferences, time zone, onboarding progress. | You, and the person who invited you. |
| Billing | Plan, subscription status, trial dates, invoices, currency, the identifier Stripe assigns to you, and the last four digits and expiry of your card as reported by Stripe. We never receive or store full card numbers. | You, via Stripe. |
| Content | Blogs, posts, drafts, revisions, images and media, writing samples used to learn your voice, brand guidelines, personas, reusable elements, competitor and content-source URLs, imported content from an existing blog. | You and your team. |
| AI interaction data | Instructions you give to AI features and to Joe, the content sent to generate a result, the result itself, scores, and the preferences Joe remembers (with personal data removed before storage). | You. |
| Integration data | Where you connect them: Google Search Console performance data for the sites you authorise; credentials for WordPress, Ghost or webhook destinations (stored encrypted); records of what was published where. | You, Google, and the services you connect. |
| Support | Support tickets, emails you send us, the Joe conversation you choose to attach to a ticket, and our replies. | You. |
| Usage and technical | IP address, browser and device type, pages and features used, sign-in times, error reports, rate-limit counters, and credit usage (an itemised ledger of every AI action and its cost). | Generated automatically when you use the Services. |
| Website analytics | Aggregated page-view statistics for our marketing site, collected without cookies using a daily-rotating hash rather than a persistent identifier. | Generated automatically. |
| Leads and waitlists | Answers to the sign-up questionnaire, your email address and name if you give them, and the campaign parameters in the link you arrived from. | You. |
| Marketing preferences | Whether you have opted out of product updates and other marketing email. | You. |
We do not deliberately collect special category data (such as health or political opinions) or data about criminal convictions, and we ask you not to include it in content you give to AI features or to support.
4. Why we use personal data, and our lawful basis
| Purpose | Lawful basis (UK GDPR Article 6) |
|---|---|
| Creating and running your Account, hosting your blogs, and providing every feature you use, including AI generation and Joe. | Performance of a contract with you (Art. 6(1)(b)). |
| Billing, collecting payment, preventing payment fraud, and keeping accounting records. | Contract (Art. 6(1)(b)) and legal obligation (Art. 6(1)(c)). |
| Sending service messages: sign-in links, invitations, receipts, renewal and trial reminders, low-credit warnings, publishing confirmations, and notices about changes to our terms. | Contract (Art. 6(1)(b)), and legal obligation where a notice is required by law. |
| Personalising Joe and content generation using preferences it remembers about how you like to work. | Legitimate interests (Art. 6(1)(f)): making the product more useful to you. You can ask Joe to forget any preference. |
| Keeping the Services secure: authentication, rate limiting, abuse and spam prevention, detecting attacks, investigating incidents. | Legitimate interests (Art. 6(1)(f)): protecting our customers, the Services and ourselves; and legal obligation where security measures are required by law. |
| Providing support and handling complaints. | Contract (Art. 6(1)(b)) and legitimate interests (Art. 6(1)(f)). |
| Understanding how the Services are used so that we can improve them, fix problems and plan capacity. | Legitimate interests (Art. 6(1)(f)). We use aggregated data wherever possible. |
| Sending product updates and marketing email to customers. | Legitimate interests (Art. 6(1)(f)), relying on the "soft opt-in" for existing customers, with an unsubscribe link in every message. |
| Following up with people who go through the sign-up questionnaire or join a waitlist. | Consent (Art. 6(1)(a)), which you give by submitting your details, and which you can withdraw at any time. |
| Complying with legal obligations, responding to lawful requests from authorities, and establishing, exercising or defending legal claims. | Legal obligation (Art. 6(1)(c)) and legitimate interests (Art. 6(1)(f)). |
| In connection with a merger, acquisition, financing or sale of our business. | Legitimate interests (Art. 6(1)(f)). |
Where we rely on legitimate interests, we have assessed that the processing is necessary and that our interests are not overridden by your rights. You can ask for a copy of that assessment or object to the processing (section 11).
5. How AI features use your data
5.1 When you use an AI feature, the content needed to produce the result, for example a topic brief, your writing samples, the post you are editing, or your message to Joe, is sent to our AI provider, Anthropic, through the Vercel AI Gateway, and the result is returned to you. Research features additionally send search queries derived from your topic to Tavily, a web search provider. No account identifiers are sent with those queries.
5.2 Your content is not used to train AI models. We do not train models on it and our providers are contractually prohibited from doing so. Providers may retain inputs and outputs for a short period for abuse monitoring and reliability, under contractual limits.
5.3 Joe's memory. Joe may record preferences about how you like to work (for example "prefers short paragraphs") to personalise future conversations and generation. Personal data such as names and email addresses is redacted before a preference is stored. Memory is scoped to your Account, and to you personally for communication preferences. You can ask Joe what it remembers and tell it to forget anything, or contact us.
5.4 No solely automated decisions with legal effect. AI features produce content and suggestions; they do not make decisions about you that have legal or similarly significant effects. Autopilot publishes content on your instructions and settings, not decisions about people.
5.5 Please keep personal data out of prompts unless you need it there. Content you publish becomes public (section 12).
6. Who we share personal data with
6.1 Sub-processors. We use the following providers to run the Services. Each acts on our instructions under a written contract that meets the requirements of UK GDPR Article 28. The current list is also published on our Trust Centre, where we announce additions.
| Sub-processor | Purpose | Personal data | Location | Transfer safeguard |
|---|---|---|---|---|
| Vercel (Vercel Inc.) | Application hosting and serverless compute, global edge network, file storage for uploaded media (Vercel Blob), cookieless web analytics, and the AI Gateway that routes our model requests. | All service data in transit and at rest on the platform; uploaded media; request logs (IP address, user agent). | Ireland (Dublin region); cached public content served from a global edge network | UK adequacy regulations (EEA); UK Extension to the EU–US Data Privacy Framework or the UK Addendum to the EU SCCs for any access from the United States |
| MongoDB Atlas (MongoDB, Inc.) | Managed primary database. | All account, content, billing-metadata, support and usage records. | Ireland (Dublin region) | UK adequacy regulations (EEA); UK Extension to the EU–US Data Privacy Framework or the UK Addendum to the EU SCCs for any access from the United States |
| Anthropic (Anthropic, PBC) | Large language model inference (Claude) for research synthesis, drafting, editing, scoring, repurposing and the Joe assistant. Accessed through the Vercel AI Gateway. | Prompts and content submitted for generation — post text, voice samples, brief and topic details, Joe conversations (with personal data redacted from stored memory). Not used to train models. | United States | UK Extension to the EU–US Data Privacy Framework, or the UK Addendum to the EU SCCs |
| Tavily (Tavily, Inc.) | Web research search API used by the research and competitor pipelines. | Search queries derived from the topic, keywords and competitor URLs a customer supplies. No account identifiers. | United States | UK Addendum to the EU SCCs / IDTA |
| Stripe (Stripe Payments UK Ltd and Stripe, Inc.) | Payments, subscription billing, invoicing, the customer billing portal and payment fraud prevention. | Name, email address, billing address, payment card details (entered directly with Stripe and never seen by Bloggable), transaction history. | United Kingdom, European Union and United States | UK Extension to the EU–US Data Privacy Framework, or the UK Addendum to the EU SCCs |
| Resend (Resend, Inc.) | Delivery of transactional, notification and product-update email; receipt of inbound support email. | Name, email address, message subject and content, delivery events (sent, bounced). | United States | UK Addendum to the EU SCCs / IDTA |
| Google (Google LLC) | Sign in with Google (OAuth); and, only for customers who connect it, the Google Search Console API for search performance data. | Google account email, name and profile image at sign-in; Search Console performance data for the sites a customer authorises. | United States | UK Extension to the EU–US Data Privacy Framework, or the UK Addendum to the EU SCCs |
| Unsplash (Unsplash, Inc.) | Stock photography search and download for featured images. | Image search terms only. No account identifiers or personal data. | Canada | UK adequacy regulations (Canada) |
6.2 Your team. Members of your Account can see the Account's content and settings according to their role. The Account owner and admins can see who is in the Account and what has been published.
6.3 Services you connect. If you connect Google Search Console, WordPress, Ghost or a webhook, we send data to that service on your instruction. Those services are not our sub-processors; they are yours, and their privacy policies apply.
6.4 The public. Content you publish, including the author name or persona you attach to it, is public.
6.5 Professional advisers, authorities and successors. We may share personal data with our lawyers, accountants, auditors and insurers; with courts, regulators and law enforcement where the law requires or permits it; and with a buyer or successor of our business, who must honour this policy.
6.6 We do not sell personal data, and we do not share it with advertising networks or data brokers.
7. International transfers
7.1 We are based in the United Kingdom. Our application and database are hosted in Ireland. Some of our other providers process data in the United States and, for content delivery, at edge locations around the world. Where personal data leaves the UK we make sure it is protected by one of the safeguards recognised by UK law: the provider's certification under the UK Extension to the EU–US Data Privacy Framework; the International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses issued by the ICO; or transfer to a country that the UK has found to provide adequate protection. Details for each provider are in the table in section 6, and you can ask us for a copy of the relevant safeguard.
8. How long we keep personal data
| Data | Retention |
|---|---|
| Account, profile and settings | While your Account is open, then deleted within 30 days of closure (section 9 of the Terms), except for records we must keep for legal reasons. |
| Content, media and AI-generated material | While your Account is open, then 30 days after closure so you can request an export, then deleted from live systems. Backup copies expire on their normal rotation. |
| Joe conversations | Automatically deleted 90 days after the last message in the conversation. A conversation you attach to a support ticket is kept with the ticket. |
| Joe memory (preferences) | Until you ask Joe or us to forget it, or your Account is closed. |
| Credit ledger and billing records | 6 years after the end of the financial year they relate to, as required by UK tax and company law. |
| Support tickets and emails | Up to 6 years after the ticket is closed, as a business record and to defend legal claims. |
| Email delivery queue | 30 days after the email is sent. |
| System and job logs | Up to 90 days. |
| Rate-limit and abuse counters | Between one minute and 24 hours, depending on the limit. |
| Visitor hashes used to count unique readers of blogs | 24 hours. The aggregate daily counts that remain contain no personal data. |
| Sign-up questionnaire answers | 180 days if you do not create an Account, otherwise as part of your Account. |
| Waitlist entries | Until the waitlist closes or you ask to be removed. |
| Marketing opt-outs | Indefinitely, so that we continue to honour them. |
9. Security
9.1 We protect personal data with measures that include encryption in transit (TLS) and at rest, application-level encryption of integration credentials, role-based access control enforced on every request, tenant isolation of every Account's data, rate limiting, content sanitisation, and logging of administrative actions. Payment card details are handled entirely by Stripe. Our security programme is described in more detail on our Trust Centre.
9.2 No system is perfectly secure. If we become aware of a personal data breach that is likely to result in a risk to you, we will notify you and, where required, the ICO without undue delay.
10. Your rights
10.1 Under UK data protection law you have the right to:
- access the personal data we hold about you and receive a copy;
- rectify inaccurate or incomplete data;
- erase your data in certain circumstances, for example where it is no longer needed;
- restrict processing in certain circumstances;
- data portability: receive data you gave us in a structured, machine-readable format, where processing is based on contract or consent and is automated;
- object to processing based on legitimate interests, and to direct marketing at any time;
- withdraw consent at any time where consent is the basis for processing, without affecting processing already carried out; and
- not be subject to a decision based solely on automated processing that produces legal or similarly significant effects.
10.2 You can update most of your details and preferences in Settings, and export your content from the app. For anything else, email hello@support.getbloggable.com. We may need to confirm your identity. We will respond within one month, or tell you if we need longer for a complex request. We do not charge for requests unless they are manifestly unfounded or excessive.
10.3 You have the right to complain to the ICO at ico.org.uk/make-a-complaint or on 0303 123 1113. We would appreciate the chance to resolve your concern first.
11. Marketing and communications
11.1 Service messages (sign-in links, receipts, renewal reminders, security notices, and notices about changes to our terms) are part of running your Account. You can turn off optional notifications, such as the monthly digest and Autopilot activity, in Settings, but you cannot opt out of messages we are required to send.
11.2 Product updates and marketing email go to customers under the soft opt-in. Every such email contains an unsubscribe link, and you can also opt out in Settings → Notifications. We will honour an opt-out within a few days.
11.3 If you gave us your email through the sign-up questionnaire or a waitlist, we will contact you about that subject. You can withdraw at any time using the link in the email or by contacting us.
12. Readers of our customers' blogs, and personal data in customer content
12.1 Blogs published with Bloggable belong to our customers. For the data of their readers, and for any personal data in the content they publish, the customer is the controller and we are a processor acting under our Data Processing Addendum. If you have a question or a rights request about a blog, please contact its owner; if you cannot reach them, contact us and we will pass your request on.
12.2 When you read a blog hosted by us, we process the following on the customer's behalf:
- Server logs held by our hosting provider, including your IP address, browser type and the page requested, for security and reliability.
- Reader counts: a first-party beacon records that a page was viewed. To count unique daily readers without cookies, we create a hash of your IP address, browser identifier and the date. The hash cannot be reversed, is not linked to any profile, and is discarded after 24 hours. No cookies or persistent identifiers are set by us on a customer's blog.
- Embedded content such as video, audio or social-media posts that a customer places in an article is loaded from the third-party platform, which may set its own cookies. The customer is responsible for any notice or consent that requires.
12.3 A persona shown as the author of a post may not be a real person. Where a customer attributes content to a real named person, the customer is responsible for that person's data.
13. Cookies
13.1 We use only cookies that are strictly necessary to sign you in and keep the Services secure, plus a cookie that records your response to our cookie notice. Our analytics do not use cookies. See our Cookie Policy for the full list.
14. Children
14.1 The Services are not directed at, and may not be used by, anyone under 18. We do not knowingly collect personal data from children. If you believe a child has given us personal data, contact us and we will delete it.
15. Links to other sites
15.1 Our websites and our customers' blogs may link to sites we do not control. Their privacy policies, not ours, apply there.
16. Google user data
16.1 If you sign in with Google, we receive your Google account email address, name and profile image, and use them to create and identify your Bloggable login.
16.2 If you connect Google Search Console, we request read-only access to Search Console data for the properties you choose and use it to show search performance, detect declining pages and suggest content to refresh, inside your Account. We store the access token encrypted and delete it when you disconnect. Bloggable's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In particular, we do not use Google user data for advertising, we do not sell it, and we do not allow humans to read it except with your consent, for security purposes, to comply with the law, or in aggregated form for internal operations. You can revoke our access at any time from Settings → Integrations or at myaccount.google.com/permissions.
17. Changes to this policy
17.1 We will update this policy when our processing changes. Material changes will be notified by email to Account owners or by a notice in the app before they take effect. The effective date and version are shown at the top of this page, and previous versions are available on request.
18. Contact
- Controller: Referr Ltd, trading as Bloggable
- Address: 2nd Floor College House, 17 King Edwards Road, Ruislip, London, HA4 7AE, United Kingdom
- Email: hello@support.getbloggable.com