Privacy Policy

Last updated:

BlipJab collects the minimum needed to deliver a short sound from one friend to another. Signing in needs an email address and nothing else — no password, no phone number, no name, no photo. Other users see a 4-character invite code and, if you choose them, a display name and a profile photo. We do not sell your data or share it with advertisers.

What we collect

Local Jab and your location

Local Jab is off until you switch it on, and the app is entirely usable without it. This is how it is built, so you can judge it rather than take our word for it.

When you turn it on, the app asks your phone for a low-accuracy position — the coarsest the operating system offers. On Android the app is not permitted to request a precise fix at all; that restriction is in the app's manifest, so the system enforces it whatever our code asks for. Your phone then divides the world into a fixed grid of squares roughly 4.8 miles on a side, works out which square you are in, and sends us that square and the name of your town. Your coordinates are discarded on the device and never transmitted.

We do not hand your square to anybody else. The people browsing nearby see a word describing how near you are and the town name, and nothing more — no distance, no direction, no map, no history of where you have been. If you wave at one of them, their copy of that wave carries one extra thing: roughly how far apart the two squares were at the instant you sent it, rounded to the nearest few miles and stored as that single number. It is never recalculated, so it cannot follow you.

Why the difference matters: a distance that refreshed as you moved could be read from two or three different places and crossed to work out where you live, which is how location features in other apps have been used to find individuals. One frozen reading, given only to a person you chose to greet, cannot be crossed with anything. There is still no direction, no map and no figure anywhere for somebody you have not waved at.

Being listed and being able to look are the same switch. There is no way to browse the people nearby without appearing to them, because a discovery screen with invisible watchers is a screen built for the watchers.

Turning Local Jab off deletes your row. We do not keep a "last known area" — where somebody was at the moment they opted out is, more often than not, their home.

Contacts

Contact matching is optional and done entirely on your device. Phone numbers are hashed with SHA-256 before anything leaves your phone. Raw contacts and phone numbers are never uploaded to us. Only the contacts that turn out to already be on BlipJab are remembered, and only on your device, so the list is still there the next time you open the screen — everyone else is discarded as soon as the check finishes. The app is fully usable without contacts access — just add friends by invite code.

The Blip Archive stays on your phone

If you have the Archive, the blips you send and receive are copied into it on your own device — audio files in the app's private storage, with a small index beside them. None of it is uploaded to us, none of it is shared with anyone, and it is capped: the oldest entries are dropped once the limit is reached, apart from the ones you star. Delete an entry, or the app, and that copy is gone. Two consequences worth knowing. A blip you sent may still exist in the Archive on the phone you sent it to, even after it has left our servers. And because the most recent blip to and from each friend is still on our servers until a newer one replaces it, signing in on a new phone re-fills the Archive there with those latest blips — that is a copy of your own blips coming back to you, not a second store of history on our side.

Other on-device data

Private nicknames you give friends, mute and notification settings, your language, and other preferences are stored locally on your device, not on our servers. So is your email address, so the app can pre-fill it and tell you which account this device belongs to. Two more are tied to contacts: the last four digits of your own number, if you make yourself discoverable (so the app can show you which number you saved — it cannot be read back from the hash), and the name a matched contact is saved under, which becomes their private label in the app. Three things are deliberately not device-only, because they have to survive a new phone: your display name, which your friends see; your colour theme; and which blips you have heard. Those live on your account, as listed above.

The holiday of the day

The observance shown on the app's home screen, and the shape of its animation, are generated once a day for everybody by an AI service and cached for that day. No user data of any kind is sent to produce it — not your blips, not your name, not your device id — and the answer is the same for every user in the world that day.

Payments

BlipJab is free to use, and recording and sending blips is always free. If you make an optional purchase (such as Blip+, credits, or an unlock), it is processed entirely by the Apple App Store or Google Play through their in-app purchase systems. We never receive or store your payment card details. Prices are shown before you buy, and any subscription renews only until you cancel it in your store account settings.

What we do not do

Children

BlipJab is not directed to children under 13, and we do not knowingly collect personal information from them. If you believe a child has provided us data, contact us and we will delete it.

How long we keep things

Most of it we keep only while your account exists — and several things go on their own, whether you ask or not.

One thing outlives the account on purpose, and it is named again below: a report where we need it to protect somebody or to meet a legal obligation. We do not keep backups of deleted accounts to bring them back.

Deleting your data

You can delete everything yourself, in the app: Settings → Delete my account & data. That removes your user record, invite code, display name, profile photo and its stored file, hashed phone number, push token, last-seen time, your Local Jab area and every jab you sent or received, every blip you sent, any blip links you published and their audio, your friendships, your group memberships, any groups you own, your credit balance, your unlocks, your purchase records, your saved theme, your heard-blip marks and your activity timestamp. It also wipes what the app stored on that device, including the Blip Archive. It happens immediately and cannot be undone. Blips are also removed automatically as newer ones replace them, and blip links expire on their own after 7 days. Three things survive it, and we would rather say so than let you find out: the sign-in itself — your email, Apple ID or Google account — which you can use again to start a brand-new empty account; copies of blips already delivered, in the Archive on the devices you sent them to; and reports you filed, which we may keep where we need them to protect other people or to meet a legal obligation. Any other privacy question: support@blipjab.com.

Your rights over your data

Wherever you live, you can do all of this — and the first two need nothing from us.

The legal part of that, stated properly. If you are in the UK or the EU, our lawful bases are: performing our agreement with you (running your account and delivering your blips), your consent (Local Jab, contacts, notifications, your photo — each given by a switch and withdrawn by the same switch), our legitimate interest in keeping the app safe and working (reports, blocks, stopping a purchase or reward being claimed twice), and legal obligation (the narrow cases where we keep a report). You have the right of access, rectification, erasure, restriction, objection and portability — the copy we send is machine-readable JSON, which is what portability means in practice — and you can complain to your data protection authority; in the UK that is the ICO. If you are in California, we do not sell or share your personal information and never have, we do not use it for cross-context behavioural advertising, and you have the right to know, delete, correct and not be discriminated against for asking. No decision about you is made automatically. We will not charge you for any of this, and we do not require an account-holder to prove their identity beyond replying from the address the account signs in with — which is also why that reply has to come from that address.

Where your data lives

Our servers, and the storage the audio sits in, are run by our hosting provider, and they may be located outside the country you live in — including in the United States. Sign-in addresses are held by our authentication provider. Sending you a sign-in code also hands your address and that one code to an email delivery provider, whose only job is to put that message in your inbox; it holds nothing else about you and never receives anything else we know. Those last two are engaged by our hosting provider rather than contracted by us directly — sub-processors, in the language of data protection law — which means they are held to the same restrictions and our hosting provider answers to us for what they do with any of it. Notifications go through the push services Apple and Google operate, and purchases are handled entirely inside the App Store or Google Play. Those are the only companies that touch any of this. None of them are permitted to use it for their own purposes, and we do not sell or share it with anyone else, at all.

Changes to this policy

We may update this policy from time to time. When we do, we will revise the “Last updated” date above.

Contact

Questions about this policy? Email support@blipjab.com.