blip privacy policy

Effective August 22, 2026

blip is a private video-messaging app. This policy describes the information blip handles and why.

information you provide

information generated while using blip

how information is used

blip uses this information only to authenticate accounts; create profiles, friendships, and caller-controlled blocks; match contacts when explicitly requested; record, send, receive, and play private blips; deliver notifications; show sender-authorized viewed/not-viewed state; perform unsend and account deletion; receive, review, and act on account-safety reports; understand aggregate product funnels; and operate, protect, diagnose, and improve the service.

blip does not sell personal information, run third-party advertising, or track people across other companies’ apps and websites.

sharing and service providers

Information is processed by providers necessary to operate blip, including Apple for app distribution, device permissions, and push notifications; Twilio for SMS verification; Railway and the configured PostgreSQL provider for API and database hosting; and Cloudflare R2 for private media storage. These providers process information on blip’s behalf under their own service and privacy terms. Information may also be disclosed when legally required or necessary to protect users, the service, or others.

private-media access

blip media storage is private. The service uses short-lived signed URLs and server-authorized access. Recipients are resolved from accepted friendships by the server, not trusted from a client-supplied recipient list. Starting received playback marks the blip viewed; the recipient app removes its cached copy when playback exits. A sender may retain their own local or Photos copy and may unsend server access. Blocking removes the friendship and blip-managed media access between those accounts, but cannot erase copies someone already saved outside blip-managed storage.

No software can prevent a recipient from making an external copy, including through screen recording or another camera.

retention and deletion

Allowlisted analytics events are retained for up to 90 days. Deleting an account removes the live actor link while bounded aggregate/event records may remain until that limit. Resolved operational errors are scheduled for deletion 30 days after resolution. Operational-error occurrence history is limited to a rolling 90-day window; a continuously recurring category may remain as one current rolled-up record while older counts and first-seen history reset. Identical operational errors are deduplicated rather than stored as unrestricted logs.

Account and friendship information is retained while the account exists. Secret-keyed contact-discovery subscriptions expire after 90 days unless refreshed and are deleted with the subscribing account; completed contact-join delivery records are account-linked and deleted if either account is deleted. Private media is currently retained until the sender unsends it or an associated account is deleted, subject to short operational cleanup retries. Open safety reports are scheduled for deletion after one year; reviewed, actioned, or dismissed reports are scheduled for deletion 90 days after review, subject to a short operational cleanup interval and retries. If a reporter deletes their account, the live reporter link is removed while the limited report record remains for that safety-retention period. A reported account identifier and name snapshot, optional report text, status, timestamps, and contextual internal video IDs may remain for that period; the reporting system does not retain a second copy of the videos.

Account deletion immediately revokes account access, removes ordinary relational account data, and schedules deletion of blip-managed private objects, subject to the limited safety-report retention above.

Deleting a blip account cannot delete copies already saved to Apple Photos, exported files, screen recordings, another person’s device outside blip’s managed cache, or other storage outside blip’s control.

security

blip uses platform authentication, transport encryption, private storage, short-lived signed media access, and object-level authorization. No system can guarantee absolute security. Report suspected unauthorized access to the support address below.

children

blip is not intended for children under 13. If you believe a child under 13 has provided personal information, contact support so it can be investigated and deleted where appropriate.

changes

This policy may change as blip evolves. Material changes will be reflected by updating the effective date and, when appropriate, providing additional notice.

contact

support@blip.camera