Privacy Policy
Last updated: April 4, 2026
1. Overview
BlockVault ("we", "us", "our") respects your privacy. This policy explains what data we collect, how we use it, and your rights regarding that data.
2. Data We Collect
When you use BlockVault, we may collect:
- Account information: Email address and hashed password when you register for cloud features.
- Block content: The Gutenberg block markup, names, and categories you save to your cloud library.
- Site information: The domain name of WordPress sites connected to your account (for site limit enforcement).
- Usage data: Basic request logs including timestamps and IP addresses for security and rate limiting purposes.
3. Data We Do Not Collect
- We do not collect personal data from your website visitors
- We do not track your browsing activity
- We do not sell or share your data with third parties for marketing
- We do not use cookies in the WordPress plugin
4. How We Use Your Data
We use your data solely to:
- Provide the BlockVault cloud sync service
- Authenticate your API requests
- Enforce plan limits (block count, site count)
- Send important service notifications (outages, security, billing)
- Prevent abuse and ensure service security
5. Data Storage & Security
Your data is stored securely on Supabase (PostgreSQL) with row-level security policies. Passwords are hashed using bcrypt. API keys are unique per account. All data transmission uses HTTPS encryption.
6. Third-Party Services
We use the following third-party services:
- Supabase: Database hosting (Privacy Policy)
- Railway: API hosting (Privacy Policy)
- Lemon Squeezy: Payment processing (Privacy Policy)
7. Local Mode
When used without an API key (local mode), BlockVault stores all data in your browser's localStorage. No data is sent to our servers. We have no access to locally stored blocks.
8. Data Retention
Your block data is retained as long as your account is active. Upon account deletion, all associated data (blocks, site records, profile information) is permanently deleted within 90 days.
9. Your Rights
You have the right to:
- Access: Request a copy of all data we hold about you
- Delete: Request deletion of your account and all associated data
- Export: Download your saved blocks at any time through the plugin
- Correct: Update your account information
10. Children's Privacy
BlockVault is not intended for use by children under 16. We do not knowingly collect data from children.
11. Changes to This Policy
We may update this policy from time to time. We will notify users of significant changes via email. Continued use of the Service after changes constitutes acceptance.
12. Contact
For privacy questions or data requests, contact us at support@block-vault.com.