blueprint

Legal

Privacy Policy

Effective 2026-08-08 · Controller: Blueprint, New York 1st, US

1. Scope and contact

This Policy explains how Blueprint handles personal data when you visit trybp.page, authenticate through app.trybp.page, generate or publish a site, download source, contact us, or report abuse. Blueprint is the controller for the product data described here.

Privacy requests: samzong.lu@gmail.com.

2. Data we collect

Identity and account data

Cloudflare Access provides your verified email address and an authentication token. Cloudflare and your selected identity provider may also process login time, IP address, country, device, and authentication events. Blueprint stores the normalized email, Terms version and acceptance time, account timestamps, and credit balance.

Content and project data

We store project names, prompts, replies, generated source, published HTML, public site addresses, revisions, and assistant responses. Public sites can be viewed by anyone who has or discovers their trybp.page URL.

Usage, credit, and technical data

We store task identifiers and status, credit ledger entries, payment checkout and order identifiers, displayed amount and currency, Mosoo Run and file identifiers, artifact hashes and sizes, errors, timestamps, retention state, and security or operational logs. Cloudflare may process request metadata such as IP address, user agent, route, and timing at its edge.

Communications and reports

We process information you send by email. If you use Report abuse, you leave Blueprint for a public GitHub issue page. Your GitHub account, issue content, and related metadata are handled by GitHub under its own privacy terms.

3. How we use data

  • authenticate users and maintain account and project isolation;
  • generate, revise, validate, publish, retain, and provide source for sites;
  • create payment checkouts and grant, reserve, spend, refund, and audit credits;
  • enforce limits, investigate abuse, secure the service, and prevent fraud;
  • operate, debug, measure, and improve reliability;
  • respond to support, privacy, legal, and abuse requests;
  • comply with law and protect users, Blueprint, and the public.

4. Legal bases

Where data-protection law requires a legal basis, we process account, content, and task data to perform the Terms you accept; security, anti-abuse, reliability, and product-operation data for our legitimate interests; and records when needed to comply with legal obligations or establish, exercise, or defend legal claims. If we ask for consent for a separate purpose, you may withdraw it as described at that time.

5. Service providers and disclosures

  • Cloudflare provides Access, Workers, D1, R2, DNS, edge security, delivery, and logs.
  • Mosoo receives prompts, project identifiers, current source attachments for revisions, and generation instructions, and coordinates the AI systems used for generation.
  • Waffo receives the account email as the buyer identity and processes checkout, order, payment, tax, refund, and order-support data as the online reseller and Merchant of Record.
  • Google processes authentication data if you choose Google OAuth.
  • GitHub processes public abuse reports you choose to submit.

We may disclose data to professional advisers, authorities, or other parties when reasonably necessary for law, safety, security, a business transaction, or enforcement of the Terms. We do not sell personal data or use product content for third-party advertising.

6. Public information

Generated sites are public by design. Do not place secrets, private personal data, access tokens, confidential business information, or material you are not permitted to publish in a prompt or generated site.

A user-generated site may include third-party scripts or collection chosen by that user. Blueprint does not control those site-specific practices. Report suspected abuse through the link in the footer.

7. Retention

We retain account, project, message, task, payment checkout, and credit records while the account is active and as reasonably needed to operate the service, resolve disputes, prevent abuse, and meet legal obligations. Each project normally retains its three newest successful versions, including the active version. Replaced artifact versions beyond that limit are deleted under the service retention process.

Security and request logs are retained for the operational period configured with the relevant provider. Deletion requests are evaluated against security, fraud-prevention, legal, backup, and public-content obligations. We may retain de-identified records that no longer identify you.

8. International transfers

Blueprint and its providers may process data in the United States and other countries. Where required, providers use contractual or other lawful transfer safeguards. Privacy protections may differ from those in your country.

9. Security

We use Access authentication, signed-token verification, tenant checks, private object storage, immutable published versions, least-privilege service bindings, bounded logs, and other safeguards. No system is completely secure. You are responsible for protecting access to your email and identity-provider account.

10. Your choices and rights

Depending on where you live, you may have rights to access, correct, delete, restrict, object to, or receive a portable copy of personal data, and to complain to a data-protection authority. Contact us from the account email so we can verify the request. We will not discriminate against you for exercising applicable privacy rights.

You can download generated source through the product. You can stop future processing by no longer using the service and request account or content deletion by email.

11. Children

Blueprint is not directed to children under 18, and we do not knowingly create accounts for them. Contact us if you believe a child has provided personal data.

12. Changes

We may update this Policy as the service or law changes. The page shows the effective date. Material changes may also be presented in the authenticated service.