shield_person Privacy policy
Last updated: August 29, 2026
1. Who we are
Blooby is published by BIG et Nouf, a French SARL registered at 17 Boulevard de Strasbourg, 62000 Arras, France (RCS Arras 978 428 506, VAT FR55 978 428 506). For any privacy-related question, contact contact@bigetnouf.fr.
2. What the app sends
The Blooby desktop app runs on your machine, and your work never leaves it: we do not see your prompts, your code, your repositories or your session activity. What drives the mascot stays local.
The app does talk to blooby.me for one thing: fetching the mascots. It ships with none, so it downloads them (the catalogue, then the characters) and caches them. That happens whether or not you have an account. If you do sign in, it also syncs your credit balance and the mascots you have unlocked. As with any download, our server sees the request (and therefore your IP); we keep no profile of it.
The app sends no usage analytics today. If that ever changes, it will be opt-in, and this page will say so before it does.
3. Data we collect (site & account)
We collect only what an account and a purchase need:
- Account data: email address, display name, avatar URL, and the OAuth subject identifier returned by your sign-in provider (GitHub or Codeberg), or your email for magic-link sign-in.
- Entitlements: your credit balance and the mascots unlocked on your account.
- Referrals: a one-way hash of a visitor identifier, used to credit a download to the person who referred it (no personal data, best-effort de-duplication).
- Billing identifiers: a Polar order reference once you purchase. We never see or store card data.
4. Audience measurement
We do not use Google Analytics, Plausible or any third-party tracker. Two things measure this site, both ours and both anonymous. A home-grown counter stores daily aggregates only (e.g. "downloads on Windows today"), with no IP, no user-agent and no cookie. And a Matomo instance we host on our own servers, configured for the French CNIL consent exemption (which is why there is no cookie banner): no cookie, an anonymised IP address, a 180-day retention, no cross-site tracking and no account identifier. It counts page views and a handful of usage events, listed below with the exact data each one carries, which you can verify in your browser's network tab.
| Event | When | Data sent |
|---|---|---|
| download | You click a download button | The operating system you picked (Windows, macOS or Linux), nothing else. |
| checkout | You start a credit purchase | That it is a credit purchase (recharge), never the amount. |
| purchased | A credit purchase completes | That a purchase completed, never the amount or any transaction reference. |
| referral | You copy your referral link | Nothing but the fact you copied it. |
An event counts an action; it never carries content you typed, a payment amount, or an account identifier that points back to you. Page addresses are recorded as they appear in your browser, so a ?ref= referral code, being part of the URL, is counted like any other page; it is a public sharing code, not personal data.
5. Cookies
- Session cookie: a single first-party, httpOnly cookie that keeps you signed in on
/account. - Referral cookie: set for 30 days only if you arrive through a
?ref=link, to credit the friend who referred you at download time. - Sign-in cookie: a short-lived (5 minutes) first-party cookie set when you sign in, so the site can tell a fresh sign-in apart from a page reload. It carries no identifier and is cleared as soon as it is read.
No advertising or third-party tracking cookies are used, and audience measurement uses no cookie at all.
6. Sub-processors
- OVH (France): hosting and storage, in French datacenters.
- GitHub / Codeberg: OAuth sign-in.
- Polar Software, Inc. (United States): Merchant of Record handling billing, tax and payment data on our behalf.
Our Merchant of Record is established outside the European Union, so purchasing transfers the billing data listed above to the United States. That transfer is covered by the data protection terms of our agreement with them, including the European Commission's standard contractual clauses. Hosting and account data stay in France.
7. How long we keep it
- Account & entitlements: kept while your account is active; deleted when you close it from your account page.
- Billing records: retained for the period required by French accounting law (10 years).
8. Your rights
Under the GDPR you can access, rectify, port, restrict or erase your personal data. You can delete your account directly from your account page, or contact contact@bigetnouf.fr. You may also lodge a complaint with the CNIL.
9. Security
We use HTTPS for every connection, hash tokens, sign sessions, and keep the database on our host's infrastructure. If you spot a vulnerability, please email contact@bigetnouf.fr.
10. Changes
We may update this policy as the product evolves; the "last updated" date above is revised accordingly.