Privacy Policy
Last updated:
BlipJab collects the minimum needed to deliver a short sound from one friend to another. Signing in needs an email address and nothing else — no password, no phone number, no name, no photo. Other users see a 4-character invite code and, if you choose them, a display name and a profile photo. We do not sell your data or share it with advertisers.
What we collect
- Email address: required to have an account. You can sign in with Apple, with Google, or with an email and a 6-digit code we send you; whichever you pick, we keep the address so your invite code, friends, groups and purchases come back on a new phone or after a reinstall. If you sign in with Apple and choose to hide your address, we only ever see the relay address Apple gives us. It is held by our authentication provider, it is never shown to other users, and we do not use it for marketing.
- Blip recordings (audio): stored only to deliver the latest blip to the friend or group you choose. Blips are ephemeral — sending a new blip to the same friend or group deletes the file it replaces. Recordings are held in private storage: they are not published to the web, and playback goes through a short-lived link we only issue to the person the blip was sent to (or the members of the group it went to).
- Blips kept on a Mixtape (audio): the one exception to the line above, and the only audio we keep indefinitely. When somebody spends credits to keep a blip, we copy that recording into separate private storage so the latest-only cleanup cannot reach it, and we hold it until it is removed or the person who made it deletes their account. Who can play it back depends on where it was kept. A blip between two friends: those two people, and nobody else. A blip sent to a group: everybody who was in that group at the moment the blip was sent, for as long as they stay in the group — plus the person who made it and the person who paid, who keep it either way. That audience is fixed when the blip is kept, so somebody who joins the group afterwards is never given access to it. Playback is always through the same kind of short-lived link, issued only to those people.
- The name on a kept blip (optional): up to 60 characters, stored on the Mixtape beside the blip and kept for as long as the blip is. Only the person who made the blip and the person who paid to keep it can type, change or clear it, whichever of them wrote it. Everybody who can play that blip can read it, and nobody else can.
- Device ID: a random id stored on your phone that identifies the device to your account. It contains no personal details, and it is not your identity — your account belongs to the email, Apple ID or Google account you sign in with.
- Invite code: a short code, which you choose, so friends can connect with you. Groups get their own 5-character code. If you change your code we keep the old one for a short while so links already shared with it keep working.
- Display name (optional): a name you choose for yourself, shown to the friends and groups you are connected with. It is entirely optional — skip it and you are shown by your invite code. You can change or clear it at any time in Settings.
- Profile photo (optional): one square picture, if you pick one. Your phone shrinks it to 256 pixels and strips the file's camera data — including any location the camera recorded — before it is uploaded, so we never receive the original. It is shown beside your name to other people using the app: your friends and groups, and also where you appear next to someone you have not connected with — the nearby list in Local Jab, an incoming jab, a contact match. It is never published to the web, never on your invite-code page, and never visible to a visitor to this website or to anyone who is not signed in. Changing it deletes the previous file, removing it in Settings deletes the file, and if a photo is reported we may remove it.
- Shared blip links (optional): only if you choose to share a recording as a link. That publishes a second copy of the audio along with a random token, its length, any effect or emoji on it, your invite code, your display name if you have one, and a count of how many times the link has been played. Anyone holding the token can play the blip, so treat it as public. The row and its audio are deleted 7 days after you create it, and deleting your account removes them sooner.
- Which blips you have heard: the app remembers, per friend and per group member, which blip you last played and when. This is kept on your account as well as on your device, so a new phone does not announce blips you heard days ago as new. Nobody else can read it.
- Who has heard a group blip: when you play a blip in a group, that is recorded so the other members can see who has already heard it. This is the one read receipt other people can see, and it is groups only.
- Your colour theme: the theme pack and the light/dark setting you chose, so the app looks the way you left it when you sign in somewhere else. Nobody else can read it.
- When you last opened Activity: one timestamp, so the app knows which entries in your own activity list are new to you.
- Last-seen time: while the app is open it refreshes a timestamp roughly once a minute so your friends can see the small “online” dot. Only people you are friends with can see it, and it is cleared when you leave the app.
- Push token (optional): only if you enable notifications, so friends' blips can reach you. The notification says only that a blip arrived and who from; it never contains the audio.
- Hashed phone number (optional): only if you choose to be discoverable by contacts. We store a one-way SHA-256 hash, never the raw number.
- A rough area, only with Local Jab on (optional): if you switch Local Jab on, your phone works out which square of a fixed grid you are in — squares are about 4.8 miles across — and sends us that square, plus your town, region and country as your own device names them. We store one such row per account and overwrite it each time you refresh. Your latitude and longitude never leave your phone. There is no field in our system that could hold them, and we ask the operating system for a deliberately vague fix in the first place. Other people never receive your square either: they see a word for how near you are ("in your area", "in your city"), the town name, and — if you wave at them — how far apart the two squares were at that moment, rounded to the nearest few miles. Never a direction, never a map position, and never a figure that updates after the wave was sent. Switching Local Jab off deletes the row rather than hiding it, and so does deleting your account.
- Jabs, if you use Local Jab (optional): the fact that you waved at somebody and which of the twenty-one preset noises you picked. A jab never contains a recording or any text you wrote. We keep it so the other person can answer it, so nobody can be waved at twice, and so the ten-a-day limit can be enforced. If you have allowed alerts about jabs, we also record that one was sent to you, once per person, so the same person can never notify you a second time.
- Interests (optional): up to eight tags you pick from a fixed list of fifteen — meet, socializing, outdoors, indoors, sports, fitness, animals, cars, coffee & snacks, music, art, gaming, movies, tech, travel. There is no free-text field: you cannot write your own, and nothing you type ever goes here. They are shown to people nearby on Local Jab alongside your name, and they are used to put people who share one of them higher in your list. Remove them at any time and nothing is kept.
- Credits and unlocks: if paid features are enabled, we store your credit balance, a record of each change to it and the reason (so a purchase or a gift cannot be applied twice), and what you have unlocked along with when a temporary unlock expires. This is what lets purchases follow your email to a new device.
- Invites that paid out: if a friend joins on your invite and adds you with your code, we record the pair and the credits it paid, so the reward cannot be claimed twice.
- Credit gifts (optional): if you gift credits to a friend we store who sent them, who received them, the amount, and the short note you typed, so the gift can be delivered and both of you can see it in your gift history.
- Purchase records: if you buy something we store which product it was, the store’s transaction id, whether the store confirmed it, and what it granted, so a purchase can be restored on a new phone and cannot be applied twice. We never receive your card details or your billing address.
- Reports and blocks: if you report someone we store the reason, anything you typed, who you reported and which blip, so a human can review it. If you block someone we store that pair so the block keeps working across devices and stops their notifications.
Local Jab and your location
Local Jab is off until you switch it on, and the app is entirely usable without it. This is how it is built, so you can judge it rather than take our word for it.
When you turn it on, the app asks your phone for a low-accuracy position — the coarsest the operating system offers. On Android the app is not permitted to request a precise fix at all; that restriction is in the app's manifest, so the system enforces it whatever our code asks for. Your phone then divides the world into a fixed grid of squares roughly 4.8 miles on a side, works out which square you are in, and sends us that square and the name of your town. Your coordinates are discarded on the device and never transmitted.
We do not hand your square to anybody else. The people browsing nearby see a word describing how near you are and the town name, and nothing more — no distance, no direction, no map, no history of where you have been. If you wave at one of them, their copy of that wave carries one extra thing: roughly how far apart the two squares were at the instant you sent it, rounded to the nearest few miles and stored as that single number. It is never recalculated, so it cannot follow you.
Why the difference matters: a distance that refreshed as you moved could be read from two or three different places and crossed to work out where you live, which is how location features in other apps have been used to find individuals. One frozen reading, given only to a person you chose to greet, cannot be crossed with anything. There is still no direction, no map and no figure anywhere for somebody you have not waved at.
Being listed and being able to look are the same switch. There is no way to browse the people nearby without appearing to them, because a discovery screen with invisible watchers is a screen built for the watchers.
Turning Local Jab off deletes your row. We do not keep a "last known area" — where somebody was at the moment they opted out is, more often than not, their home.
Contacts
Contact matching is optional and done entirely on your device. Phone numbers are hashed with SHA-256 before anything leaves your phone. Raw contacts and phone numbers are never uploaded to us. Only the contacts that turn out to already be on BlipJab are remembered, and only on your device, so the list is still there the next time you open the screen — everyone else is discarded as soon as the check finishes. The app is fully usable without contacts access — just add friends by invite code.
The Blip Archive stays on your phone
If you have the Archive, the blips you send and receive are copied into it on your own device — audio files in the app's private storage, with a small index beside them. None of it is uploaded to us, none of it is shared with anyone, and it is capped: the oldest entries are dropped once the limit is reached, apart from the ones you star. Delete an entry, or the app, and that copy is gone. Two consequences worth knowing. A blip you sent may still exist in the Archive on the phone you sent it to, even after it has left our servers. And because the most recent blip to and from each friend is still on our servers until a newer one replaces it, signing in on a new phone re-fills the Archive there with those latest blips — that is a copy of your own blips coming back to you, not a second store of history on our side.
Other on-device data
Private nicknames you give friends, mute and notification settings, your language, and other preferences are stored locally on your device, not on our servers. So is your email address, so the app can pre-fill it and tell you which account this device belongs to. Two more are tied to contacts: the last four digits of your own number, if you make yourself discoverable (so the app can show you which number you saved — it cannot be read back from the hash), and the name a matched contact is saved under, which becomes their private label in the app. Three things are deliberately not device-only, because they have to survive a new phone: your display name, which your friends see; your colour theme; and which blips you have heard. Those live on your account, as listed above.
The holiday of the day
The observance shown on the app's home screen, and the shape of its animation, are generated once a day for everybody by an AI service and cached for that day. No user data of any kind is sent to produce it — not your blips, not your name, not your device id — and the answer is the same for every user in the world that day.
Payments
BlipJab is free to use, and recording and sending blips is always free. If you make an optional purchase (such as Blip+, credits, or an unlock), it is processed entirely by the Apple App Store or Google Play through their in-app purchase systems. We never receive or store your payment card details. Prices are shown before you buy, and any subscription renews only until you cancel it in your store account settings.
What we do not do
- No advertising identifiers (IDFA / GAID) and no ad networks.
- No cross-app tracking.
- No selling or sharing of your data with advertisers or data brokers.
- No collection of health, financial or browsing data — and no location at all unless you switch Local Jab on, which sends an area a few miles across and never your coordinates.
- No reading your photo library — choosing a profile photo hands us the one picture you picked, and if you never set one we hold no image of you at all.
- No reading your email, and no emails from us about anything other than signing in.
Children
BlipJab is not directed to children under 13, and we do not knowingly collect personal information from them. If you believe a child has provided us data, contact us and we will delete it.
How long we keep things
Most of it we keep only while your account exists — and several things go on their own, whether you ask or not.
- Blips: only the latest one to each friend and each group is on our servers at all. Sending the next one deletes the file it replaces. A replaced file survives up to 24 hours first, purely so the Archive on your own phone can copy it before it goes.
- A blip kept on a Mixtape: the one thing here with no expiry at all. It is copied into separate storage the moment it is kept, the latest-only cleanup never touches it, and it is held until whoever paid or whoever made it removes it — or until the person who made it deletes their account, which removes their blips from every Mixtape they were on. Any name given to it goes when the blip does.
- Shared blip links: 7 days from the moment you make one, then the link and its audio are deleted. You can hold 50 at a time, and publishing past that retires your oldest early.
- Last-seen time: cleared when you leave the app.
- Local Jab area: deleted the moment you switch Local Jab off, and it stops counting as nearby after 7 days without a refresh.
- An invite code you gave up: parked for a year before it can be handed to anyone else, so an old link of yours never lands on a stranger.
- A tally of the sign-in codes sent to an address: a one-way fingerprint of the address — not the address itself — with the times we sent to it, kept 3 days so that nobody can be buried in codes they never asked for, then deleted.
- Delivery notes that stop the same alert being sent twice: a line per message, deleted with your account.
- Kept while you have an account, because the app cannot do its job without them: your sign-in address, invite code, display name, photo, credit balance and the reason for each change to it, your unlocks, your purchase records (a purchase has to be restorable on your next phone), which blips you have heard, your theme and your jab history.
- Your Blip Archive is not ours to keep or delete. It is on your phone, it drops its oldest entries once it is full apart from the ones you star, and it goes when you delete the entry or the app.
One thing outlives the account on purpose, and it is named again below: a report where we need it to protect somebody or to meet a legal obligation. We do not keep backups of deleted accounts to bring them back.
Deleting your data
You can delete everything yourself, in the app: Settings → Delete my account & data. That removes your user record, invite code, display name, profile photo and its stored file, hashed phone number, push token, last-seen time, your Local Jab area and every jab you sent or received, every blip you sent, any blip links you published and their audio, your friendships, your group memberships, any groups you own, your credit balance, your unlocks, your purchase records, your saved theme, your heard-blip marks and your activity timestamp. It also wipes what the app stored on that device, including the Blip Archive. It happens immediately and cannot be undone. Blips are also removed automatically as newer ones replace them, and blip links expire on their own after 7 days. Three things survive it, and we would rather say so than let you find out: the sign-in itself — your email, Apple ID or Google account — which you can use again to start a brand-new empty account; copies of blips already delivered, in the Archive on the devices you sent them to; and reports you filed, which we may keep where we need them to protect other people or to meet a legal obligation. Any other privacy question: support@blipjab.com.
Your rights over your data
Wherever you live, you can do all of this — and the first two need nothing from us.
- Correct it. Your name, photo, interests, country and every switch in Notifications / Visibility are yours to change in the app at any time.
- Delete it. Settings → Delete my account & data, described above, is immediate and needs nobody's approval.
- Get a copy. Email support@blipjab.com from the address you signed in with and we will send you a file containing everything our servers hold for your account, within 30 days and normally much sooner. It leaves out three things on purpose, all of them somebody else's: no other person's email address or phone number, no identity for anyone you traded a Local Jab with, and not who reported you.
- Object, or narrow it. Every optional thing is a switch — Local Jab, contacts, notifications, your photo, your name — and turning one off deletes what it was holding rather than just hiding it. There is no marketing to opt out of, because we never send any.
The legal part of that, stated properly. If you are in the UK or the EU, our lawful bases are: performing our agreement with you (running your account and delivering your blips), your consent (Local Jab, contacts, notifications, your photo — each given by a switch and withdrawn by the same switch), our legitimate interest in keeping the app safe and working (reports, blocks, stopping a purchase or reward being claimed twice), and legal obligation (the narrow cases where we keep a report). You have the right of access, rectification, erasure, restriction, objection and portability — the copy we send is machine-readable JSON, which is what portability means in practice — and you can complain to your data protection authority; in the UK that is the ICO. If you are in California, we do not sell or share your personal information and never have, we do not use it for cross-context behavioural advertising, and you have the right to know, delete, correct and not be discriminated against for asking. No decision about you is made automatically. We will not charge you for any of this, and we do not require an account-holder to prove their identity beyond replying from the address the account signs in with — which is also why that reply has to come from that address.
Where your data lives
Our servers, and the storage the audio sits in, are run by our hosting provider, and they may be located outside the country you live in — including in the United States. Sign-in addresses are held by our authentication provider. Sending you a sign-in code also hands your address and that one code to an email delivery provider, whose only job is to put that message in your inbox; it holds nothing else about you and never receives anything else we know. Those last two are engaged by our hosting provider rather than contracted by us directly — sub-processors, in the language of data protection law — which means they are held to the same restrictions and our hosting provider answers to us for what they do with any of it. Notifications go through the push services Apple and Google operate, and purchases are handled entirely inside the App Store or Google Play. Those are the only companies that touch any of this. None of them are permitted to use it for their own purposes, and we do not sell or share it with anyone else, at all.
Changes to this policy
We may update this policy from time to time. When we do, we will revise the “Last updated” date above.
Contact
Questions about this policy? Email support@blipjab.com.