blip privacy policy
Effective August 22, 2026
blip is a private video-messaging app. This policy describes the information blip handles and why.
information you provide
- Account information: phone number, full name, and username.
- Private media: videos, audio contained in those videos, and generated thumbnails that you choose to send.
- Contacts, only when requested: if you tap find people from contacts, blip sends up to 500 normalized phone numbers from your address book to find existing blip accounts and notify you if one of those contacts later completes Blip signup. The server does not retain the raw uploaded numbers or contact names for discovery; it retains secret-keyed phone digests for up to 90 days and replaces them when your authorized contacts are refreshed.
- Reports and support information: when you report an account, blip stores the reported account, your account while it exists, and any optional text you submit. The server may attach internal identifiers for up to ten recent blips that the reported account sent you; the report does not attach private video contents, playback links, phone numbers, notification payloads, or signed media URLs. Support messages contain whatever information you choose to provide; do not send verification codes or signed media links.
information generated while using blip
- Account and friendship identifiers.
- Intended-recipient, delivery, viewed/not-viewed, unsend, and deletion state needed for private messaging.
- An Apple Push Notification service device token and its sandbox or production environment.
- First-party product analytics: allowlisted account, onboarding, Lock Screen entry, capture, Blip lifecycle, first-view, friendship, block, and report events; timestamps; aggregate counts; and short-lived internal actor/entity references needed to deduplicate and audit state transitions. The admin dashboard returns aggregates rather than per-person activity.
- Operational errors: allowlisted feature context and error category, HTTP status when applicable, recurrence count, app version/build, OS version, and coarse device model. Client error reports do not include free-form messages, request bodies, URLs, stack traces, phone numbers, usernames, account/media/recipient IDs, private video contents, or signed media URLs.
how information is used
blip uses this information only to authenticate accounts; create profiles, friendships, and caller-controlled blocks; match contacts when explicitly requested; record, send, receive, and play private blips; deliver notifications; show sender-authorized viewed/not-viewed state; perform unsend and account deletion; receive, review, and act on account-safety reports; understand aggregate product funnels; and operate, protect, diagnose, and improve the service.
blip does not sell personal information, run third-party advertising, or track people across other companies’ apps and websites.
sharing and service providers
Information is processed by providers necessary to operate blip, including Apple for app distribution, device permissions, and push notifications; Twilio for SMS verification; Railway and the configured PostgreSQL provider for API and database hosting; and Cloudflare R2 for private media storage. These providers process information on blip’s behalf under their own service and privacy terms. Information may also be disclosed when legally required or necessary to protect users, the service, or others.
private-media access
blip media storage is private. The service uses short-lived signed URLs and server-authorized access. Recipients are resolved from accepted friendships by the server, not trusted from a client-supplied recipient list. Starting received playback marks the blip viewed; the recipient app removes its cached copy when playback exits. A sender may retain their own local or Photos copy and may unsend server access. Blocking removes the friendship and blip-managed media access between those accounts, but cannot erase copies someone already saved outside blip-managed storage.
No software can prevent a recipient from making an external copy, including through screen recording or another camera.
retention and deletion
Allowlisted analytics events are retained for up to 90 days. Deleting an account removes the live actor link while bounded aggregate/event records may remain until that limit. Resolved operational errors are scheduled for deletion 30 days after resolution. Operational-error occurrence history is limited to a rolling 90-day window; a continuously recurring category may remain as one current rolled-up record while older counts and first-seen history reset. Identical operational errors are deduplicated rather than stored as unrestricted logs.
Account and friendship information is retained while the account exists. Secret-keyed contact-discovery subscriptions expire after 90 days unless refreshed and are deleted with the subscribing account; completed contact-join delivery records are account-linked and deleted if either account is deleted. Private media is currently retained until the sender unsends it or an associated account is deleted, subject to short operational cleanup retries. Open safety reports are scheduled for deletion after one year; reviewed, actioned, or dismissed reports are scheduled for deletion 90 days after review, subject to a short operational cleanup interval and retries. If a reporter deletes their account, the live reporter link is removed while the limited report record remains for that safety-retention period. A reported account identifier and name snapshot, optional report text, status, timestamps, and contextual internal video IDs may remain for that period; the reporting system does not retain a second copy of the videos.
Account deletion immediately revokes account access, removes ordinary relational account data, and schedules deletion of blip-managed private objects, subject to the limited safety-report retention above.
Deleting a blip account cannot delete copies already saved to Apple Photos, exported files, screen recordings, another person’s device outside blip’s managed cache, or other storage outside blip’s control.
security
blip uses platform authentication, transport encryption, private storage, short-lived signed media access, and object-level authorization. No system can guarantee absolute security. Report suspected unauthorized access to the support address below.
children
blip is not intended for children under 13. If you believe a child under 13 has provided personal information, contact support so it can be investigated and deleted where appropriate.
changes
This policy may change as blip evolves. Material changes will be reflected by updating the effective date and, when appropriate, providing additional notice.