shield_person Privacy policy

Last updated: July 11, 2026

1. Who we are

Blooby is published by BIG et Nouf, a French SARL registered at 17 Boulevard de Strasbourg, 62000 Arras, France (RCS Arras 978 428 506, VAT FR55 978 428 506). For any privacy-related question, contact contact@bigetnouf.fr.

2. What the app sends

The Blooby desktop app runs on your machine, and your work never leaves it: we do not see your prompts, your code, your repositories or your session activity. What drives the mascot stays local.

The app does talk to blooby.me for one thing: fetching the mascots. It ships with none, so it downloads them (the catalogue, then the characters) and caches them. That happens whether or not you have an account. If you do sign in, it also syncs the packs you own. As with any download, our server sees the request (and therefore your IP); we keep no profile of it.

The app sends no usage analytics today. If that ever changes, it will be opt-in, and this page will say so before it does.

3. Data we collect (site & account)

We collect only what an account and a purchase need:

  • Account data: email address, display name, avatar URL, and the OAuth subject identifier returned by your sign-in provider (GitHub or Codeberg), or your email for magic-link sign-in.
  • Entitlements: the mascot packs, tiers and perks unlocked on your account.
  • Referrals: a one-way hash of a visitor identifier, used to credit a download to the person who referred it (no personal data, best-effort de-duplication).
  • Billing identifiers: a Paddle transaction reference once you purchase. We never see or store card data.

4. Analytics: home-grown & anonymous

We do not use Google Analytics, Plausible or any third-party tracker. Our own counter stores daily aggregates only (e.g. "downloads on Windows today") with no IP, no user-agent and no analytics cookie. It is disabled entirely when your browser sends Do-Not-Track.

5. Cookies

  • Session cookie: a single first-party, httpOnly cookie that keeps you signed in on /account.
  • Referral cookie: set for 30 days only if you arrive through a ?ref= link, to credit the friend who referred you at download time.

No advertising or third-party tracking cookies are used.

6. Sub-processors

  • OVH (France): hosting and storage, in French datacenters.
  • GitHub / Codeberg: OAuth sign-in.
  • Paddle.com Market Ltd (UK): Merchant of Record handling billing, tax and payment data on our behalf.
  • Ko-fi: optional tipping; if you use it, Ko-fi shares your tip email so we can grant the Patron mascot.

7. How long we keep it

  • Account & entitlements: kept while your account is active; deleted when you close it from your account page.
  • Billing records: retained for the period required by French accounting law (10 years).

8. Your rights

Under the GDPR you can access, rectify, port, restrict or erase your personal data. You can delete your account directly from your account page, or contact contact@bigetnouf.fr. You may also lodge a complaint with the CNIL.

9. Security

We use HTTPS for every connection, hash tokens, sign sessions, and keep the database on our host's infrastructure. If you spot a vulnerability, please email contact@bigetnouf.fr.

10. Changes

We may update this policy as the product evolves; the "last updated" date above is revised accordingly.