1. What this page is for
This explains, specifically rather than generically, what data Create.Blitch handles. Where a claim is absolute we say so; where something does leave your device we name it rather than glossing over it.
Create.Blitch is the data controller. Contact: support@createblitch.com.
2. What stays on your device, and what leaves it
- Font files you upload (TTF/OTF)
- Images you upload (PNG, JPG, WEBP)
- SVG files you upload
- Your saved designs and their parameters
- Your interface preferences
- Your email address and password, if you create an account
- The finished 3D shape, when a paid download is produced
- The filename you gave that download
- Which generator and format you used
- A random id for the browser you downloaded from
- Your store and licence details, if you give them
- Your billing details — sent to Paddle, never to us
Uploaded fonts and images are parsed entirely in your browser: the font is read into letter outlines, the image is traced into a silhouette, and only the resulting shape is ever used. The original file is never transmitted, and we have no way to reconstruct it.
Why the 3D shape is transmitted
When a paid download is produced, your browser sends the finished geometry — a list of triangle coordinates — to our server, which writes the STL or 3MF file and sends it back. Building the file server-side is how a download is tied to a plan.
It is only sent when a file is actually going to be produced. If you are signed out, or on the free plan, or on Creator attempting a bulk export, the app checks your plan first and shows the upgrade screen — nothing is transmitted at all.
What we write into the file
Every file we produce carries a short attribution and licence note — that it
was made with Create.Blitch, that the design is yours and we claim no ownership
of it, and what your plan allows you to do with it. In a 3MF this is standard
model metadata plus a readable LICENSE.txt inside the archive; in an
STL it is the one 80-character line the format allows.
On the Commercial plan the note names the licence holder — the name recorded when your commercial plan started. That is deliberate: it is what makes the file evidence of who was licensed. It also means that if you share the file itself, your name goes with it, so it is worth knowing before you do.
That geometry is used to build your file and is not stored afterwards. It contains no font file, no image, and no personal data beyond whatever you chose to model — if you type a name onto a keyring, that name exists in the shape, the same way it exists in the printed object.
3. What we store
This is the complete list, field by field, rather than a summary.
| What | Why | How long |
|---|---|---|
| Email address | To identify your account and send account email | Until your account is removed |
| Password | Sign-in. Stored only as a salted hash — we cannot read it | Until your account is removed |
| Account created, last sign-in, whether the email is confirmed | Support, and knowing which accounts are in use | Until your account is removed |
| Plan, and subscription status | To know what you are entitled to download | Until your account is removed |
| Renewal date, and any pending cancellation or pause | So your account panel can tell you what happens next | Until your account is removed |
| Store or brand name, legal name, country and website — whichever you give us | To issue and name a commercial licence | Until your account is removed |
| The licence holder name recorded when a commercial plan starts | A snapshot of who the licence was issued to. Not editable — renaming a shop must not rewrite a licence already issued | Until your account is removed |
| Terms version accepted, and when | To record which terms you agreed to | Until your account is removed |
| Paddle customer and subscription id | To match a payment to your account | Until your account is removed |
| If your account is deleted: when, by whom, and any reason given | To run the restore window and answer support questions | Until your account is removed |
| Staff role, if you are staff | Access control | Until your account is removed |
| Download log — see below | To measure which products people use, how free accounts become paid ones, and to spot abuse | Kept after the account is removed, without the account |
| Billing log — one row per message from the payment provider | So a payment is never applied twice, and a failed one can be reconciled | Kept permanently, with your email erased at removal |
| Staff action log — see below | So every staff action on an account is attributable | Kept permanently and cannot be edited or deleted, including by us |
The download log
Each download writes one row: the time, your account, your plan at that moment, whether it was allowed or refused, the format (STL or 3MF), whether it was a single design or a batch, which generator and preset you used, the size of the model as a triangle count, the size of the resulting file, and a random id for the browser you downloaded from.
Refused attempts are recorded too, and it is only fair to say why: as well as spotting abuse, this is how we understand which products make people want a paid plan. That is a commercial purpose, not only an operational one.
About that browser id. It is a random number your browser makes up the first time you download and then remembers — nothing about your device, your location or your software goes into it, and it is not shared with anyone. We use it to see whether one paid account is being used by several people. Clearing your site data resets it, and doing so does not affect your account or your ability to download.
The log deliberately does not record the name you gave your design, any parameter values, any geometry, your IP address, or your browser's user agent. Design names are frequently real people's names, which is exactly why they are not logged.
The billing log
Every message from Paddle is recorded so the same payment can never be applied twice. Most rows reference your account by id. A payment that cannot be matched to an account — a mistyped address at checkout, for instance — stores the email address Paddle gave us, because otherwise there is no way to work out whose payment it was.
These rows are kept permanently: deleting one would let a repeated message be applied again. When an account is removed, the email address is erased from them and the row is marked as redacted. The Paddle customer and subscription ids remain — Paddle is the merchant of record and must keep the invoice for tax regardless, and those ids are the only way to confirm afterwards that a subscription really was cancelled.
The staff action log
Every action a staff member takes on an account — changing a plan, granting staff access, deleting an account — is recorded with the staff member's email and the affected account's email, plus any reason typed at the time.
One consequence worth stating: if a signed-in account attempts a staff-only action it is not entitled to, that attempt is recorded with its email address, because an unauthorised attempt is exactly the thing this log exists to catch.
4. What we do not do
- No cookies from us. Our own pages set none at all — your sign-in is held in your browser's local storage, not a cookie. The one exception is not ours to promise about: when you open checkout, Paddle loads its own payment frame, which sets what it needs to process the payment. Their privacy notice covers it, and it only happens if you actually start a purchase.
- No analytics or tracking. No Google Analytics, no tag manager, no pixels, no session recording, no fingerprinting, no third-party scripts on the marketing site.
- No advertising, and no data shared with advertisers.
- We never sell or rent your data, to anyone, for any purpose.
- No profiling or automated decisions that produce legal effects.
5. Stored in your browser, not on our servers
Your saved designs live in your own browser's local storage. They are not
uploaded, we cannot see them, and they do not sync between your devices. To move
a design to another machine, export it as a .json file.
Two consequences worth knowing: clearing your browser data deletes your saved designs, and uploaded fonts and images are not stored with a design — you re-supply them when you reopen it. That is a direct result of never transmitting them.
6. Who processes data for us
| Who | What for | Where |
|---|---|---|
| Supabase | Accounts, authentication, database, the export service | United States (US-East) |
| Paddle | Merchant of record — payment, invoicing, tax | United Kingdom / EU |
| Cloudflare | Website hosting and delivery | Global edge network |
Payment details never reach us. Card numbers are entered into Paddle's own checkout and handled entirely by Paddle, who is the seller of record. We receive only a customer reference, a subscription id and a subscription status — never a card number, and never your billing address. Paddle determines the tax country and keeps it; we do not store it. The only country we hold is the one you type into your brand details yourself. Paddle's privacy notice covers their handling.
If you are in a country whose data protection law restricts transfers abroad, note that our database is hosted in the United States and using the service involves that transfer.
7. Legal basis
- Contract — account, plan and export data are needed to provide the service you signed up for.
- Legal obligation — Paddle retains transaction records for tax.
- Legitimate interests — the download log, to keep the service working, to detect abuse, and to understand which products lead people to a paid plan. It records no design names, parameters, geometry, IP or user agent — only a random browser id you can reset by clearing site data — and is deliberately minimal for that reason.
- Legitimate interests — the staff action log, so access to customer accounts is attributable and cannot be quietly revised.
We do not rely on consent for anything, because we do not do any of the things that would require it.
8. Your rights
You can request access to your data, correction, deletion, a portable copy, or that we restrict or stop processing. Email support@createblitch.com and we will respond within 30 days.
Most of it is immediate and self-service: your store and brand details are editable in your account panel, your designs are yours to export or delete locally at any time, you can cancel a subscription without contacting us, and you can delete your account yourself. The one field you cannot edit is the licence holder name recorded when a commercial plan starts — that is a snapshot of who a licence was issued to, and renaming a shop must not rewrite it. Ask us if it is genuinely wrong.
Deleting your account
Account → Delete your account. It takes your password and your email address typed back, and it happens straight away — no request, no waiting on us.
- Immediately — you are signed out everywhere and downloads stop. Any live subscription is cancelled at the end of the period you have paid for, so you are never billed again.
- For 7 days — the account is kept so you can sign in and restore it. We are telling you this rather than implying instant erasure, because it is what actually happens.
- After that — the account is permanently removed: profile, brand and licence details, subscription references, saved designs on our side, and the login itself, email and password hash included.
What survives, and why
Three things outlive the account. None of them is a way to look you up, but we would rather name them than let you assume otherwise.
- Download-log rows. These keep the account identifier they were written with, and there is no longer an account it resolves to. That is pseudonymous, not anonymous — an accurate word matters here — and a log that erased itself on request would not be a log.
- Billing-log rows, with your email address erased and the row marked as redacted. The Paddle references stay: Paddle is the merchant of record and must retain the invoice for tax whatever we do.
- The staff action log, if a staff member ever acted on your account — including the record of the deletion. It is append-only at the database level and cannot be edited or deleted by anyone, including us.
The designs saved in your own browser are never touched by any of this. Deleting your account does not clear them.
If you are in the EU or UK you may complain to your data protection authority; in the Philippines, to the National Privacy Commission.
9. Security
Everything travels over HTTPS. Passwords are stored only as salted hashes. Database access is restricted per-account at the database level, so one account cannot read another's data even if the application were compromised. Staff access is a separate, explicitly granted role, every use of it is recorded in an append-only audit log, and it does not include the ability to sign in as you or read your design parameters.
10. Children
Create.Blitch is not directed at children under 13, and we do not knowingly collect their data. If you believe a child has created an account, contact us and we will delete it.
11. Changes
If this policy changes materially, the version and date at the top change and we will notify account holders by email before the change takes effect.
12. Contact
Create.Blitch — support@createblitch.com