Legal

Privacy Policy

Version 2026-07-31 · Last updated 31 July 2026
The short version
  • Fonts and images you upload never leave your device. They are read and traced in your browser.
  • When you download a file on a paid plan, the finished 3D shape is sent to our server to be written. It is not stored.
  • We keep your email, your plan, and a row per download recording what kind of thing it was — never the design itself.
  • No advertising, no cross-site tracking, nothing sold or shared — and no cookies from our own pages.
  • The one measurement on our pages is our host's cookieless counter (Cloudflare Web Analytics), plus aggregate server-log counts — anonymous totals, never a profile.
  • Your designs are saved in your own browser, not on our servers.

1. What this page is for

This explains, specifically rather than generically, what data Create.Blitch handles. Where a claim is absolute we say so; where something does leave your device we name it rather than glossing over it.

Create.Blitch is the data controller, independently operated from the Philippines. Contact: support@createblitch.com — every request under this policy is read by a person and answered from that address.

2. What stays on your device, and what leaves it

Never leaves your device
  • Font files you upload (TTF/OTF)
  • Images you upload (PNG, JPG, WEBP)
  • SVG files you upload
  • The fonts and images behind a saved design — only the parameters sync (below), never the assets
  • Designs you save while signed out (they stay in this browser)
  • Your interface preferences
Leaves your device
  • Your email address and password, if you create an account
  • The finished 3D shape, when a paid download is produced
  • The filename you gave that download
  • Which generator and format you used
  • The ad campaign that first referred you, if any (a short label, not a web address) — kept on your account from the moment you sign up
  • A random id for the browser you downloaded from
  • Your store and licence details, if you give them
  • The parameters of a design you save while signed in — the numbers and text, never the fonts or images behind it
  • Whether you opted in to product-news email, if you tick that box
  • Your billing details — sent to Paddle, never to us

Uploaded fonts and images are parsed entirely in your browser: the font is read into letter outlines, the image is traced into a silhouette, and only the resulting shape is ever used. The original file is never transmitted, and we have no way to reconstruct it.

Why the 3D shape is transmitted

When a paid download is produced, your browser sends the finished geometry — a list of triangle coordinates — to our server, which writes the STL or 3MF file and sends it back. Building the file server-side is how a download is tied to a plan.

It is only sent when a file is actually going to be produced. If you are signed out, or on the free plan, or on Creator attempting a bulk export, the app checks your plan first and shows the upgrade screen — nothing is transmitted at all.

What we write into the file

Every file we produce carries a short attribution and licence note — that it was made with Create.Blitch, that the design is yours and we claim no ownership of it, and what your plan allows you to do with it. In a 3MF this is standard model metadata plus a readable LICENSE.txt inside the archive; in an STL it is the one 80-character line the format allows.

On the Commercial plan the note names the licence holder — the name recorded when your commercial plan started. That is deliberate: it is what makes the file evidence of who was licensed. It also means that if you share the file itself, your name goes with it, so it is worth knowing before you do.

That geometry is used to build your file and is not stored afterwards. It contains no font file, no image, and no personal data beyond whatever you chose to model — if you type a name onto a keyring, that name exists in the shape, the same way it exists in the printed object.

3. What we store

This is the complete list, field by field, rather than a summary.

WhatWhyHow long
Email addressTo identify your account and send account email — and, only if you opted in, occasional product newsUntil your account is removed
PasswordSign-in. Stored only as a salted hash — we cannot read itUntil your account is removed
Account created, last sign-in, whether the email is confirmedSupport, and knowing which accounts are in useUntil your account is removed
Plan, and subscription statusTo know what you are entitled to downloadUntil your account is removed
Renewal date, and any pending cancellation or pauseSo your account panel can tell you what happens nextUntil your account is removed
Store or brand name, legal name, country and website — whichever you give usTo issue and name a commercial licenceUntil your account is removed
The licence holder name recorded when a commercial plan startsA snapshot of who the licence was issued to. Not editable — renaming a shop must not rewrite a licence already issuedUntil your account is removed
Terms version accepted, and whenTo record which terms you agreed toUntil your account is removed
Whether you opted in to product-news email, and when and how that last changedTo email product news only to people who asked for it, and to keep a record that the opt-in was yoursUntil you withdraw it or your account is removed
Which product-news messages we have already sent you, if you opted inSo we never send you the same one twiceKept after the account is removed, without the account (like the download log); your email is never stored in it
Designs you save while signed in — name, generator, product and the parameter values (numbers and text; never the fonts or images behind them)So the same design opens on your other devices. Staff tools list your design names but never read the parameter valuesUntil you delete the design or your account is removed
Paddle customer and subscription idTo match a payment to your accountUntil your account is removed
If your account is deleted: when, by whom, and any reason givenTo run the restore window and answer support questionsUntil your account is removed
Staff role, if you are staffAccess controlUntil your account is removed
Download log — see belowTo measure which products people use, how free accounts become paid ones, and to spot abuseKept after the account is removed, without the account
Billing log — one row per message from the payment providerSo a payment is never applied twice, and a failed one can be reconciledKept permanently, with your email erased at removal
Staff action log — see belowSo every staff action on an account is attributableKept permanently and cannot be edited or deleted, including by us

The download log

Each download writes one row: the time, your account, your plan at that moment, whether it was allowed or refused, the format (STL or 3MF), whether it was a single design or a batch, which generator and preset you used, the size of the model as a triangle count, the size of the resulting file, a random id for the browser you downloaded from, and — if you first arrived from one of our ads — the campaign that referred you, stored as a short label (for example facebook / paid), never a full web address or browsing history. That same label is also kept on your account from the moment you sign up, so we can tell which campaigns bring people who go on to register or subscribe; it is removed with the account.

Refused attempts are recorded too, and it is only fair to say why: as well as spotting abuse, this is how we understand which products make people want a paid plan. That is a commercial purpose, not only an operational one.

About that browser id. It is a random number your browser makes up the first time you download and then remembers — nothing about your device, your location or your software goes into it, and it is not shared with anyone. We use it to see whether one paid account is being used by several people. Clearing your site data resets it, and doing so does not affect your account or your ability to download.

The log deliberately does not record the name you gave your design, any parameter values, any geometry, your IP address, or your browser's user agent. Design names are frequently real people's names, which is exactly why they are not logged.

The billing log

Every message from Paddle is recorded so the same payment can never be applied twice. Most rows reference your account by id. A payment that cannot be matched to an account — a mistyped address at checkout, for instance — stores the email address Paddle gave us, because otherwise there is no way to work out whose payment it was.

These rows are kept permanently: deleting one would let a repeated message be applied again. When an account is removed, the email address is erased from them and the row is marked as redacted. The Paddle customer and subscription ids remain — Paddle is the merchant of record and must keep the invoice for tax regardless, and those ids are the only way to confirm afterwards that a subscription really was cancelled.

The staff action log

Every action a staff member takes on an account — changing a plan, granting staff access, deleting an account — is recorded with the staff member's email and the affected account's email, plus any reason typed at the time.

This log is append-only at the database level: it cannot be edited or deleted by anyone, including us, and it is not erased when an account is removed. That is the point of it — a record of who did what, that the people with access cannot quietly revise. It means a deletion request cannot remove the record that a deletion happened.

One consequence worth stating: if a signed-in account attempts a staff-only action it is not entitled to, that attempt is recorded with its email address, because an unauthorised attempt is exactly the thing this log exists to catch.

4. Cookies, tracking and advertising

Advertising measurement — the Meta Pixel

We advertise Create.Blitch on Meta (Facebook and Instagram). To see whether those ads work, our pages can load Meta's pixel — a small script from Meta that reports a few actions back to them: that a page was viewed, that the app was opened, that an account was created, and that a file was exported. It also lets Meta read your IP address and set its own cookie, and Meta may match that activity to a Meta account to measure and target ads, including showing you our ads again elsewhere. For what it does with this, Meta acts as an independent controller; see Meta's privacy policy.

You control whether it loads. If you are in the EU, EEA or UK it does not load at all unless you accept it in the banner we show — decline and nothing from Meta is ever requested. Elsewhere it loads by default; you can opt out at any time by clearing this site's data (which resets the choice) or by using your browser's tracking protection. Either way your uploaded fonts and images are never part of it — they never leave your device.

5. Where your saved designs live

Every design you save lives in your own browser's local storage. If you are signed in, its parameters — the numbers and text that define it — are also saved to your account, so the same design opens on your other devices. The fonts and images behind it are never uploaded: a design that uses an uploaded asset restores its parameters and re-prompts for that asset on a new device.

Signed out, designs stay in this browser only. Either way you can export any design, or all of them, as a .json file you keep (P-8 — nothing is held hostage).

Two consequences worth knowing: clearing your browser data removes the local copies (the account copies, if you were signed in, remain and re-download next time you sign in), and uploaded fonts and images are not stored with a design — you re-supply them when you reopen it. That is a direct result of never transmitting them.

One small flag also lives in local storage: your choice about the advertising pixel (§4). If the pixel is active, Meta additionally sets its own cookie. Clearing this site's data removes both — the flag (so you are asked again where consent applies) and Meta's cookie.

6. Who processes data for us

WhoWhat forWhere
Database & authentication providerAccounts, authentication, database, the export serviceUnited States (US-East)
PaddleMerchant of record — payment, invoicing, taxUnited Kingdom / EU
Website host & CDNWebsite hosting, delivery, and cookieless aggregate analyticsGlobal edge network
Meta PlatformsAdvertising measurement (the Meta Pixel, §4) — where you have not opted outUnited States / Ireland
Email delivery providerSends account email and, if you opt in, product newsUnited States

Payment details never reach us. Card numbers are entered into Paddle's own checkout and handled entirely by Paddle, who is the seller of record. We receive only a customer reference, a subscription id and a subscription status — never a card number, and never your billing address. Paddle determines the tax country and keeps it; we do not store it. The only country we hold is the one you type into your brand details yourself. Paddle's privacy notice covers their handling.

If you are in a country whose data protection law restricts transfers abroad, note that our database is hosted in the United States and using the service involves that transfer.

7. Legal basis

Aside from the advertising pixel and product-news email — both opt-in — we do not rely on consent; the rest of what we do is covered by the bases above.

8. Your rights

You can request access to your data, correction, deletion, a portable copy, or that we restrict or stop processing. Email support@createblitch.com and we will respond within 30 days.

Most of it is immediate and self-service: your store and brand details are editable in your account panel, your designs are yours to export or delete — locally and, when signed in, from your account — at any time, product-news emails can be turned off from your account settings or the unsubscribe link in any message, you can cancel a subscription without contacting us, and you can delete your account yourself. The one field you cannot edit is the licence holder name recorded when a commercial plan starts — that is a snapshot of who a licence was issued to, and renaming a shop must not rewrite it. Ask us if it is genuinely wrong.

Deleting your account

Account → Delete your account. It takes your password and your email address typed back, and it happens straight away — no request, no waiting on us.

What survives, and why

Three things outlive the account. None of them is a way to look you up, but we would rather name them than let you assume otherwise.

The designs saved in your own browser are never touched by any of this. Deleting your account does not clear them.

If you are in the EU or UK you may complain to your data protection authority; in the Philippines, to the National Privacy Commission.

9. Security

Everything travels over HTTPS. Passwords are stored only as salted hashes. Database access is restricted per-account at the database level, so one account cannot read another's data even if the application were compromised. Staff access is a separate, explicitly granted role, every use of it is recorded in an append-only audit log, and it does not include the ability to sign in as you or read your design parameters.

10. Children

Create.Blitch is not directed at children under 13, and we do not knowingly collect their data. If you believe a child has created an account, contact us and we will delete it.

11. Changes

If this policy changes materially, the version and date at the top change and we will notify account holders by email before the change takes effect.

12. Contact

Create.Blitch — support@createblitch.com