Skip to content

Trust Centre

Security controls, compliance, sub-processors, data location and vulnerability disclosure for Bloggable. Last updated 7 September 2026.

Compliance

  • UK GDPR / Data Protection Act 2018

    Privacy Policy, Data Processing Addendum, sub-processor list and rights process published.

  • PECR (cookies and marketing)

    Strictly necessary cookies only; cookieless analytics; unsubscribe on every marketing email.

  • PCI DSS

    Card processing is performed by Stripe, a PCI DSS Level 1 service provider. We do not store card data.

  • Infrastructure certifications

    Our hosting provider (Vercel) and database provider (MongoDB Atlas) hold SOC 2 Type II and ISO/IEC 27001 certifications. Their reports are available from the providers.

  • International transfers

    Transfers out of the UK rely on UK adequacy regulations, the UK Extension to the EU–US Data Privacy Framework where a provider is certified, or the UK Addendum to the EU SCCs / IDTA. The safeguard for each provider is shown in the sub-processor table.

Security controls

Infrastructure

  • Hosting location

    The application runs on Vercel and the database on MongoDB Atlas, both in Ireland (Dublin region). Cached public content is served from Vercel’s edge network.

  • Encryption in transit

    All connections use TLS. HTTP Strict Transport Security is enabled on our domains.

  • Encryption at rest

    The database and file storage encrypt data at rest using provider-managed AES-256 keys.

  • Integration credentials

    Credentials for services you connect (Search Console, WordPress, Ghost, webhooks) are encrypted at the application layer before storage and deleted when you disconnect.

  • Backups

    The database runs as a replicated cluster with automated backups.

  • Separate environments

    Development, preview and production are separate deployments with separate credentials.

  • Browser security headers

    Standard security headers, including HSTS, content-type, referrer and permissions policies, are set on responses.

Application

  • Authentication

    Sign-in is by Google OAuth or a single-use link sent by email. No passwords are stored.

  • Role-based access

    Accounts have owner, admin, member and viewer roles. Permissions are checked on the server for every request.

  • Tenant isolation

    Every record is scoped to the account it belongs to. Content, settings, assistant memory and integration credentials are partitioned by account.

  • Content sanitisation

    Customer-authored content is sanitised before it is rendered to readers, and embeds are limited to an allow-list of hosts.

  • Rate limiting

    Rate limits are applied to authentication, public endpoints and other abuse-prone routes.

  • Outbound requests

    Server-side requests to external URLs (imports, research, link previews) are restricted to prevent server-side request forgery.

  • Payments

    Checkout, card storage and the billing portal are hosted by Stripe. We hold a customer reference and the last four digits of the card only.

AI

  • No training on your content

    Prompts, content and outputs are used only to produce your result. Neither we nor our AI provider train models on them.

  • Model access

    Model requests are routed through the Vercel AI Gateway to Anthropic and attributed to the requesting account.

  • Untrusted content

    Web pages and search results are passed to models as untrusted data, not as instructions.

  • Confirmations

    The assistant asks before destructive actions. Confirmation is verified on the server.

  • Memory

    Preferences the assistant remembers are scoped to your account, and personal data is redacted before they are stored.

  • Billing

    The assistant cannot buy credits, change plans or access payment details. Autopilot has a monthly budget cap per blog.

Data protection

  • UK GDPR and Data Protection Act 2018

    We are the controller for account data and a processor for customer content and reader data. The Privacy Policy and Data Processing Addendum apply to every account.

  • Cookies and analytics

    Our site analytics set no cookies. Reader counts on customer blogs use a hash that is discarded within 24 hours. We set no cookies on customer blogs.

  • Retention

    Retention periods for each category of data are set out in the Privacy Policy. Content is deleted 30 days after an account closes.

  • Export

    Published posts are available in Markdown at their own URL, and content can be exported from the app while the account is open.

  • Sub-processors

    Every third party that processes personal data for us is listed on this page. Additions are published at least 30 days before they take effect.

  • Google API Limited Use

    Search Console access is read-only, used only to show your own performance data in your account, and complies with the Google API Services User Data Policy, including the Limited Use requirements.

Operations

  • Staff access

    Administrative access is restricted to named staff. Access to customer accounts is limited to support you request, security investigation and legal compliance.

  • Audit trail

    Credit movements are recorded in an append-only ledger, including manual adjustments by staff. Scheduled jobs and administrative actions are logged.

  • Secrets

    Secrets are held in the deployment platform’s encrypted environment configuration, not in source control.

  • Incident response

    A personal data breach affecting your data is notified to you without undue delay and within 72 hours of our becoming aware of it.

Sub-processors

Third parties that process personal data on our behalf, what they receive, where they process it, and the safeguard for any transfer out of the UK. Additions are published here at least 30 days before they take effect. List last updated 1 January 2026.

ProviderPurposePersonal dataLocationTransfer safeguardAdded
Vercel
Vercel Inc.
Application hosting and serverless compute, global edge network, file storage for uploaded media (Vercel Blob), cookieless web analytics, and the AI Gateway that routes our model requests.All service data in transit and at rest on the platform; uploaded media; request logs (IP address, user agent).Ireland (Dublin region); cached public content served from a global edge networkUK adequacy regulations (EEA); UK Extension to the EU–US Data Privacy Framework or the UK Addendum to the EU SCCs for any access from the United States2026-01-01
MongoDB Atlas
MongoDB, Inc.
Managed primary database.All account, content, billing-metadata, support and usage records.Ireland (Dublin region)UK adequacy regulations (EEA); UK Extension to the EU–US Data Privacy Framework or the UK Addendum to the EU SCCs for any access from the United States2026-01-01
Anthropic
Anthropic, PBC
Large language model inference (Claude) for research synthesis, drafting, editing, scoring, repurposing and the Joe assistant. Accessed through the Vercel AI Gateway.Prompts and content submitted for generation — post text, voice samples, brief and topic details, Joe conversations (with personal data redacted from stored memory). Not used to train models.United StatesUK Extension to the EU–US Data Privacy Framework, or the UK Addendum to the EU SCCs2026-01-01
Tavily
Tavily, Inc.
Web research search API used by the research and competitor pipelines.Search queries derived from the topic, keywords and competitor URLs a customer supplies. No account identifiers.United StatesUK Addendum to the EU SCCs / IDTA2026-01-01
Stripe
Stripe Payments UK Ltd and Stripe, Inc.
Payments, subscription billing, invoicing, the customer billing portal and payment fraud prevention.Name, email address, billing address, payment card details (entered directly with Stripe and never seen by Bloggable), transaction history.United Kingdom, European Union and United StatesUK Extension to the EU–US Data Privacy Framework, or the UK Addendum to the EU SCCs2026-01-01
Resend
Resend, Inc.
Delivery of transactional, notification and product-update email; receipt of inbound support email.Name, email address, message subject and content, delivery events (sent, bounced).United StatesUK Addendum to the EU SCCs / IDTA2026-01-01
Google
Google LLC
Sign in with Google (OAuth); and, only for customers who connect it, the Google Search Console API for search performance data.Google account email, name and profile image at sign-in; Search Console performance data for the sites a customer authorises.United StatesUK Extension to the EU–US Data Privacy Framework, or the UK Addendum to the EU SCCs2026-01-01
Unsplash
Unsplash, Inc.
Stock photography search and download for featured images.Image search terms only. No account identifiers or personal data.CanadaUK adequacy regulations (Canada)2026-01-01

Data location and retention

Location

Referr Ltd is a UK company. The application runs on Vercel and the database on MongoDB Atlas, both in Ireland (Dublin region). Cached public content is served from Vercel’s edge network. Other providers and their locations are listed in the sub-processor table.

Retention

  • Content: while the account is open, then 30 days for export, then deleted.
  • Assistant conversations: 90 days.
  • Reader hashes: 24 hours.
  • Billing records: 6 years, as UK law requires.
  • Full schedule in the Privacy Policy.

Export and rights requests

Published posts are available in Markdown at their own URL, and content can be exported from the app while the account is open. Rights requests go to hello@support.getbloggable.com.

Vulnerability disclosure

Email hello@support.getbloggable.com with “Security” in the subject, or see /.well-known/security.txt. We do not currently run a paid bug-bounty programme.

We ask that you

  • Give us reasonable time to fix an issue before disclosing it publicly.
  • Do not access, modify or delete data that is not yours; use test accounts you own.
  • Do not run denial-of-service, spam, social engineering or physical attacks.
  • Stop and tell us immediately if you encounter personal data belonging to someone else.

We commit to

  • Acknowledge your report within 2 business days.
  • Keep you informed of our progress and tell you when the issue is fixed.
  • Not take legal action against research carried out in good faith under these terms.
  • Credit you, if you wish, once the issue is resolved.

Frequently asked questions

Where is my data stored?
The application runs on Vercel and the database on MongoDB Atlas, both in Ireland (Dublin region). Cached public content is served from Vercel’s edge network. Other providers and their locations are listed in the sub-processor table.
Do you use my content to train AI models?
No. Your content is sent to our AI provider only to produce the result you asked for, and neither we nor the provider train models on it.
Who can see my content?
Members of your own account, according to their role, and the public once you publish. Our staff access accounts only for support you request, security investigation or legal compliance.
Do you have a Data Processing Addendum?
Yes. It applies automatically to every account and is published at /legal/dpa. A countersigned copy is available on request.
Can I delete my data?
Yes. Closing your account unpublishes your blogs and starts a 30-day export window, after which content is deleted from live systems. You can also ask us to delete specific data at any time.
Do I need a cookie banner on my blog?
Not because of us. We set no cookies on customer blogs and reader counts are cookieless. If you embed third-party content such as video, that platform may set cookies and you are responsible for any notice it requires.
How do I report a security vulnerability?
Email hello@support.getbloggable.com with “Security” in the subject line, or use the security.txt file at /.well-known/security.txt.
How will I know if you add a sub-processor?
The list on this page carries the date each provider was added. Additions are published at least 30 days before they take effect, and material changes are emailed to account owners. You can object under the DPA.

We use cookies

We use cookies to ensure you get the best experience on our website. For more information on how we use cookies, please see our cookie policy.