blip
blip

Privacy Policy

Last updated August 3, 2026

Who we are

blipblip is operated by SmartApps LLC. For any privacy question, or to make a request about your data, email info@smartapps.design.

What we collect

The studio can be used without an account. Before you sign in, we do not create an account record or store your sounds. Vercel still processes ordinary request logs, including IP addresses, to deliver and protect the service. Sensitive endpoints also use short-lived rate-limit counters; for an anonymous invalid webhook request, the counter key contains the requesting IP address.

If you sign in with Google or GitHub, we store the account identifier from that provider and your email address. We never receive your password.

We use Vercel Web Analytics to see aggregate page views and page-load performance. It is cookieless, does not use a persistent identifier, and cannot follow you to another site. We do not use advertising, and we do not embed any other third-party tracking scripts.

Saved sounds

A saved sound is stored as synthesis parameters, a title, and timestamps — not as audio. Sounds are generated in your browser. Saved sounds are private to your account, enforced at the database level, and you can delete any of them from the studio. An account can hold up to 200 saved sounds.

Payments

Payments are processed by Creem, which acts as merchant of record. Your card details go to Creem directly — we never see or store them.

We store what is needed to know what you have access to: your Creem customer and subscription identifiers, subscription status, whether you hold a lifetime purchase, the current billing period end, and a count of free exports used.

When checkout begins, we send Creem a random checkout-attempt identifier and your internal account identifier as metadata. The account identifier lets a signed payment notification update the correct account; it is not your email address.

Payment event records

Creem notifies us of payment events. We store those signed notifications for 90 days so a payment problem can be investigated and so the same event is never applied twice. Personal fields — name, email, phone, addresses, tax identifiers, and IP address — are replaced with a redaction marker before the record is written. Records older than 90 days are deleted automatically.

How long we keep data

Account and billing state remain until the account is deleted. A saved sound remains until you delete that sound or the account. Redacted payment-event records are kept for 90 days. Rate-limit rows older than one hour are removed by request-time cleanup and daily maintenance; depending on when the daily job runs, an inactive row can remain for about 25 hours. Vercel keeps hosting logs according to the retention configured for the hosting plan.

Cookies

We set only what sign-in requires: Supabase authentication cookies while you are signed in, and a short-lived value used to protect the sign-in exchange against cross-site request forgery. Vercel Web Analytics does not set cookies. There are no advertising cookies, which is why you are not asked to accept any.

Who processes data for us

Supabase provides authentication and the database. Creem processes payments as merchant of record. Vercel hosts the application, provides Web Analytics, and, like any web host, records request logs including IP addresses.

Why we process data

Account, saved-sound, export, and billing data are processed to provide the service you request and administer your purchase; the legal basis is taking steps at your request and performing our contract with you. Security logs, webhook audit records, and rate-limit counters are processed for our legitimate interests in preventing abuse, diagnosing failures, and protecting the service and its users. Where law requires records to be kept, the legal basis is compliance with that obligation.

Your rights

You can request access to your data, correction, deletion, or a copy in a portable form, and you can object to processing. Email info@smartapps.design and we will handle the request.

There is currently no self-service account-deletion button in the product — account deletion is handled by email. You can delete individual saved sounds yourself at any time.

If you are in the EU or UK and believe we have handled your data improperly, you may complain to your local data protection authority.

Changes

If this policy changes materially, the date above changes with it. See also our Terms of Service.