Legal
Privacy Policy and data handling
Last updated 3 September 2026
This policy explains what Bladbase collects, why, where it is stored, and what you can ask us to do with it. It covers bladbase.com and the Bladbase application at app.bladbase.com.
Bladbase is in beta. The service is under active development and this policy will change as features ship. Material changes are announced in the app before they take effect.
Who we are
Bladbase is a collaborative documentation workspace operated by the Bladbase team ("Bladbase", "we", "us"). For anything in this policy, including requests about your data, use ourcontact form. For users in the EEA and UK, Bladbase is the data controller for account data and the data processor for the content you and your collaborators put into a workspace.
What we collect
Account information
When you create an account we collect your email address anddisplay name. Authentication is handled by Firebase Authentication. If you sign up with a password, Firebase stores and verifies it — we never see it. If you sign in with Google, we receive your email address, name and profile picture URL from your Google account, and no password is created.
Workspace content
The documents you write, their revision history, comments, page structure, uploaded files, and the workspaces and memberships that organise them. This is your content: we store and process it to provide the service, and we do not sell it, mine it for advertising, or use it to train machine-learning models.
Data from Google Drive, if you connect it
Connecting Google Drive is optional and off until you start it yourself. SeeGoogle user data below for exactly what is accessed and how it is used.
Technical and operational data
Server logs recording the time of a request, the route, a response status, a correlation identifier, and the account making it. We use these to keep the service running, investigate faults, and detect abuse. We do not build advertising or behavioural profiles from them.
Cookies
Bladbase sets no advertising or analytics cookies, and runs no third-party trackers on this site or in the app. The only cookies are strictly necessary ones:
| Cookie | Purpose | Lifetime |
|---|---|---|
bb_session | Keeps you signed in. Host-only, HTTP-only, secure. | 12 days, or until you sign out |
google_oauth | Protects the Google Drive connection flow against cross-site request forgery. Set only while you are connecting Drive. | Minutes |
Signing out revokes the session itself, not just your browser's copy of it, so a captured cookie stops working immediately.
Google user data
If you connect Google Drive, Bladbase requests one scope:drive.readonly — read-only access to the files in your Drive. We request no write scope, and Bladbase cannot create, modify or delete anything in your Drive.
What we do with it:
- Browse — list your folders so you can choose which ones to connect to a workspace.
- Import — convert a Google Doc you select into a Bladbase page. The imported copy then lives in Bladbase; the original stays in Drive, untouched.
- Index — read the text of files in a connected folder so they can be found in workspace search, and re-read them periodically so the index stays current.
Access is limited to the folders you connect. Content read from Drive is visible only to members of the workspace it was connected to, under that workspace's normal permissions. We do not transfer Google user data to anyone else, use it for advertising, or use it to train machine-learning models. Human beings do not read it, except where you specifically ask us to for support, where required by law, or where necessary to investigate a security incident.
Bladbase's use and transfer of information received from Google APIs to any other app adheres to theGoogle API Services User Data Policy, including the Limited Use requirements.
You can disconnect Drive at any time from workspace settings, which deletes the stored OAuth tokens, or revoke Bladbase's access directly atmyaccount.google.com/permissions. Pages you already imported remain in your workspace, because they are your workspace's content — delete them there if you want them gone.
Where your data lives
Bladbase runs on Google Cloud Platform in the United States (us-central1). Documents and uploads are stored in Cloud Storage, metadata in Firestore, presence in the Realtime Database, and the search index on a server we operate inside our own cloud project. If you are outside the United States, using Bladbase involves transferring your information there; where required, we rely on the European Commission's Standard Contractual Clauses for that transfer.
Who we share it with
We do not sell your data. We share it only with:
- People you share it with. Members of your workspace see content according to their role, and a page you publish or share by link is readable by whoever has that link.
- Google Cloud, as our infrastructure provider (hosting, database, storage, authentication, logging).
- Our email provider, to deliver transactional messages such as invitations and mention notifications. Only the recipient address and the message are shared.
- Law enforcement or regulators, where we are legally required to.
Nobody else sees you load a page. The fonts, scripts and styles on this site and in the app are served from our own domains, so opening a page sends your address to no third party — not a font service, not an analytics provider.
How long we keep it
- Deleted pages go to the workspace trash and can be restored. Purging removes them and their stored content.
- Deleted workspaces can be restored for 30 days, after which they and their content are permanently purged.
- Closed accounts leave a minimal tombstone so that historical revisions and comments in workspaces you contributed to keep their authorship, without retaining your profile.
- Operational logs are retained on a short rolling window for troubleshooting and security.
Security
Data is encrypted in transit (TLS) and at rest. Every request and collaboration connection is authenticated and authorised on the server before any workspace data is touched — access rules in the database are a second line of defence, not the only one. Access tokens for the API are stored only as hashes, are scoped, expire, and can be revoked at any time. Each service runs under its own least-privilege identity, and secrets live in Google Secret Manager. No system is perfectly secure, and during beta you should not store data you cannot afford to lose or expose.
Your rights
Depending on where you live, you may have the right to access, correct, export, delete or restrict the processing of your personal data, to object to processing, and to lodge a complaint with your data protection authority. You can export a workspace's content from workspace settings and delete your workspaces and pages yourself at any time. For anything else, use thecontact form and we will respond within 30 days.
Where we rely on consent — connecting Google Drive, for example — you can withdraw it at any time without affecting processing that already happened. Otherwise we process your data to perform our contract with you, or in our legitimate interest in operating and securing the service.
Children
Bladbase is not directed at children under 16, and we do not knowingly collect their personal data. If you believe a child has given us data, contact us and we will delete it.
Changes to this policy
We will update this page when our practices change and revise the date above. Material changes are announced in the app before they take effect. Continuing to use Bladbase after a change means you accept the revised policy.
Contact
Questions, requests, or complaints go through ourcontact form, which reaches us directly. We publish no email address on this site — an address in a privacy policy is harvested within days — but the form reaches the same people, and we reply by email.