1. What this page is for
This explains, specifically rather than generically, what data Create.Blitch handles. Where a claim is absolute we say so; where something does leave your device we name it rather than glossing over it.
Create.Blitch is the data controller, independently operated from the Philippines. Contact: support@createblitch.com — every request under this policy is read by a person and answered from that address.
2. What stays on your device, and what leaves it
- Font files you upload (TTF/OTF)
- Images you upload (PNG, JPG, WEBP)
- SVG files you upload
- The fonts and images behind a saved design — only the parameters sync (below), never the assets
- Designs you save while signed out (they stay in this browser)
- Your interface preferences
- Your email address and password, if you create an account
- The finished 3D shape, when a paid download is produced
- The filename you gave that download
- Which generator and format you used
- The ad campaign that first referred you, if any (a short label, not a web address) — kept on your account from the moment you sign up
- A random id for the browser you downloaded from
- Your store and licence details, if you give them
- The parameters of a design you save while signed in — the numbers and text, never the fonts or images behind it
- Whether you opted in to product-news email, if you tick that box
- Your billing details — sent to Paddle, never to us
Uploaded fonts and images are parsed entirely in your browser: the font is read into letter outlines, the image is traced into a silhouette, and only the resulting shape is ever used. The original file is never transmitted, and we have no way to reconstruct it.
Why the 3D shape is transmitted
When a paid download is produced, your browser sends the finished geometry — a list of triangle coordinates — to our server, which writes the STL or 3MF file and sends it back. Building the file server-side is how a download is tied to a plan.
It is only sent when a file is actually going to be produced. If you are signed out, or on the free plan, or on Creator attempting a bulk export, the app checks your plan first and shows the upgrade screen — nothing is transmitted at all.
What we write into the file
Every file we produce carries a short attribution and licence note — that it
was made with Create.Blitch, that the design is yours and we claim no ownership
of it, and what your plan allows you to do with it. In a 3MF this is standard
model metadata plus a readable LICENSE.txt inside the archive; in an
STL it is the one 80-character line the format allows.
On the Commercial plan the note names the licence holder — the name recorded when your commercial plan started. That is deliberate: it is what makes the file evidence of who was licensed. It also means that if you share the file itself, your name goes with it, so it is worth knowing before you do.
That geometry is used to build your file and is not stored afterwards. It contains no font file, no image, and no personal data beyond whatever you chose to model — if you type a name onto a keyring, that name exists in the shape, the same way it exists in the printed object.
3. What we store
This is the complete list, field by field, rather than a summary.
| What | Why | How long |
|---|---|---|
| Email address | To identify your account and send account email — and, only if you opted in, occasional product news | Until your account is removed |
| Password | Sign-in. Stored only as a salted hash — we cannot read it | Until your account is removed |
| Account created, last sign-in, whether the email is confirmed | Support, and knowing which accounts are in use | Until your account is removed |
| Plan, and subscription status | To know what you are entitled to download | Until your account is removed |
| Renewal date, and any pending cancellation or pause | So your account panel can tell you what happens next | Until your account is removed |
| Store or brand name, legal name, country and website — whichever you give us | To issue and name a commercial licence | Until your account is removed |
| The licence holder name recorded when a commercial plan starts | A snapshot of who the licence was issued to. Not editable — renaming a shop must not rewrite a licence already issued | Until your account is removed |
| Terms version accepted, and when | To record which terms you agreed to | Until your account is removed |
| Whether you opted in to product-news email, and when and how that last changed | To email product news only to people who asked for it, and to keep a record that the opt-in was yours | Until you withdraw it or your account is removed |
| Which product-news messages we have already sent you, if you opted in | So we never send you the same one twice | Kept after the account is removed, without the account (like the download log); your email is never stored in it |
| Designs you save while signed in — name, generator, product and the parameter values (numbers and text; never the fonts or images behind them) | So the same design opens on your other devices. Staff tools list your design names but never read the parameter values | Until you delete the design or your account is removed |
| Paddle customer and subscription id | To match a payment to your account | Until your account is removed |
| If your account is deleted: when, by whom, and any reason given | To run the restore window and answer support questions | Until your account is removed |
| Staff role, if you are staff | Access control | Until your account is removed |
| Download log — see below | To measure which products people use, how free accounts become paid ones, and to spot abuse | Kept after the account is removed, without the account |
| Billing log — one row per message from the payment provider | So a payment is never applied twice, and a failed one can be reconciled | Kept permanently, with your email erased at removal |
| Staff action log — see below | So every staff action on an account is attributable | Kept permanently and cannot be edited or deleted, including by us |
The download log
Each download writes one row: the time, your account, your plan at that
moment, whether it was allowed or refused, the format (STL or 3MF), whether it
was a single design or a batch, which generator and preset you used, the size of
the model as a triangle count, the size of the resulting file, a random id
for the browser you downloaded from, and — if you first arrived from one of our
ads — the campaign that referred you, stored as a short label (for example
facebook / paid), never a full web address or browsing history.
That same label is also kept on your account from the moment you sign up, so
we can tell which campaigns bring people who go on to register or subscribe;
it is removed with the account.
Refused attempts are recorded too, and it is only fair to say why: as well as spotting abuse, this is how we understand which products make people want a paid plan. That is a commercial purpose, not only an operational one.
About that browser id. It is a random number your browser makes up the first time you download and then remembers — nothing about your device, your location or your software goes into it, and it is not shared with anyone. We use it to see whether one paid account is being used by several people. Clearing your site data resets it, and doing so does not affect your account or your ability to download.
The log deliberately does not record the name you gave your design, any parameter values, any geometry, your IP address, or your browser's user agent. Design names are frequently real people's names, which is exactly why they are not logged.
The billing log
Every message from Paddle is recorded so the same payment can never be applied twice. Most rows reference your account by id. A payment that cannot be matched to an account — a mistyped address at checkout, for instance — stores the email address Paddle gave us, because otherwise there is no way to work out whose payment it was.
These rows are kept permanently: deleting one would let a repeated message be applied again. When an account is removed, the email address is erased from them and the row is marked as redacted. The Paddle customer and subscription ids remain — Paddle is the merchant of record and must keep the invoice for tax regardless, and those ids are the only way to confirm afterwards that a subscription really was cancelled.
The staff action log
Every action a staff member takes on an account — changing a plan, granting staff access, deleting an account — is recorded with the staff member's email and the affected account's email, plus any reason typed at the time.
One consequence worth stating: if a signed-in account attempts a staff-only action it is not entitled to, that attempt is recorded with its email address, because an unauthorised attempt is exactly the thing this log exists to catch.
4. Cookies, tracking and advertising
- Our own pages set no cookies of their own. Your sign-in is held in your browser's local storage, not a cookie. Two things can set a cookie, and only when you bring them about: Paddle, when you open checkout, loads its own payment frame and sets what it needs to process the payment (their privacy notice covers it, and it only happens if you actually start a purchase); and Meta's advertising pixel, described below, once it is active.
- Our analytics is cookieless. One measurement script runs on our pages: Cloudflare Web Analytics, loaded by our host. It sets no cookie, stores nothing in your browser, and cannot follow you to other sites — it produces anonymous, aggregate counts (pages, referrers, countries). Our own traffic dashboard reads similar aggregate counts server-side from Cloudflare's logs. We never see figures tied to you as a person, and no profile of you is ever built from it.
- Ad-arrival counts. The first time you arrive from one of our ads (a
link carrying a campaign tag), we record an anonymous +1 against that
campaign for the day — for example "one arrival from
facebook". For that same campaign we also count, once per browser, the first time you open the app and the first time you reach the export step — so we can see where interest drops off. Still no cookie, no id, no IP address, no referrer, nothing about you: just tallies that let us see which ads work. They cannot identify or follow you, and clearing your site data stops even the tag being remembered. - We never sell or rent your data, to anyone, for any purpose.
- No profiling or automated decisions that produce legal effects.
Advertising measurement — the Meta Pixel
We advertise Create.Blitch on Meta (Facebook and Instagram). To see whether those ads work, our pages can load Meta's pixel — a small script from Meta that reports a few actions back to them: that a page was viewed, that the app was opened, that an account was created, and that a file was exported. It also lets Meta read your IP address and set its own cookie, and Meta may match that activity to a Meta account to measure and target ads, including showing you our ads again elsewhere. For what it does with this, Meta acts as an independent controller; see Meta's privacy policy.
You control whether it loads. If you are in the EU, EEA or UK it does not load at all unless you accept it in the banner we show — decline and nothing from Meta is ever requested. Elsewhere it loads by default; you can opt out at any time by clearing this site's data (which resets the choice) or by using your browser's tracking protection. Either way your uploaded fonts and images are never part of it — they never leave your device.
5. Where your saved designs live
Every design you save lives in your own browser's local storage. If you are signed in, its parameters — the numbers and text that define it — are also saved to your account, so the same design opens on your other devices. The fonts and images behind it are never uploaded: a design that uses an uploaded asset restores its parameters and re-prompts for that asset on a new device.
Signed out, designs stay in this browser only. Either way you can export any
design, or all of them, as a .json file you keep (P-8 — nothing is
held hostage).
Two consequences worth knowing: clearing your browser data removes the local copies (the account copies, if you were signed in, remain and re-download next time you sign in), and uploaded fonts and images are not stored with a design — you re-supply them when you reopen it. That is a direct result of never transmitting them.
One small flag also lives in local storage: your choice about the advertising pixel (§4). If the pixel is active, Meta additionally sets its own cookie. Clearing this site's data removes both — the flag (so you are asked again where consent applies) and Meta's cookie.
6. Who processes data for us
| Who | What for | Where |
|---|---|---|
| Database & authentication provider | Accounts, authentication, database, the export service | United States (US-East) |
| Paddle | Merchant of record — payment, invoicing, tax | United Kingdom / EU |
| Website host & CDN | Website hosting, delivery, and cookieless aggregate analytics | Global edge network |
| Meta Platforms | Advertising measurement (the Meta Pixel, §4) — where you have not opted out | United States / Ireland |
| Email delivery provider | Sends account email and, if you opt in, product news | United States |
Payment details never reach us. Card numbers are entered into Paddle's own checkout and handled entirely by Paddle, who is the seller of record. We receive only a customer reference, a subscription id and a subscription status — never a card number, and never your billing address. Paddle determines the tax country and keeps it; we do not store it. The only country we hold is the one you type into your brand details yourself. Paddle's privacy notice covers their handling.
If you are in a country whose data protection law restricts transfers abroad, note that our database is hosted in the United States and using the service involves that transfer.
7. Legal basis
- Contract — account, plan and export data are needed to provide the service you signed up for.
- Legal obligation — Paddle retains transaction records for tax.
- Legitimate interests — the download log, to keep the service working, to detect abuse, and to understand which products lead people to a paid plan. It records no design names, parameters, geometry, IP or user agent — only a random browser id you can reset by clearing site data — and is deliberately minimal for that reason.
- Legitimate interests — the staff action log, so access to customer accounts is attributable and cannot be quietly revised.
- Consent — the Meta advertising pixel (§4) where consent applies (EU, EEA, UK): it loads only after you accept, and you can withdraw at any time by clearing this site's data. Withdrawing is as easy as giving it.
- Consent — product-news email. It is off unless you tick the box, which is separate from agreeing to the Terms and never pre-ticked. You can withdraw at any time from your account settings or the one-click unsubscribe link in every message; account email (like sign-in confirmations) is unaffected.
Aside from the advertising pixel and product-news email — both opt-in — we do not rely on consent; the rest of what we do is covered by the bases above.
8. Your rights
You can request access to your data, correction, deletion, a portable copy, or that we restrict or stop processing. Email support@createblitch.com and we will respond within 30 days.
Most of it is immediate and self-service: your store and brand details are editable in your account panel, your designs are yours to export or delete — locally and, when signed in, from your account — at any time, product-news emails can be turned off from your account settings or the unsubscribe link in any message, you can cancel a subscription without contacting us, and you can delete your account yourself. The one field you cannot edit is the licence holder name recorded when a commercial plan starts — that is a snapshot of who a licence was issued to, and renaming a shop must not rewrite it. Ask us if it is genuinely wrong.
Deleting your account
Account → Delete your account. It takes your password and your email address typed back, and it happens straight away — no request, no waiting on us.
- Immediately — you are signed out everywhere and downloads stop. Any live subscription is cancelled at the end of the period you have paid for, so you are never billed again.
- For 7 days — the account is kept so you can sign in and restore it. We are telling you this rather than implying instant erasure, because it is what actually happens.
- After that — the account is permanently removed: profile, brand and licence details, subscription references, saved designs on our side, and the login itself, email and password hash included.
What survives, and why
Three things outlive the account. None of them is a way to look you up, but we would rather name them than let you assume otherwise.
- Download-log rows. These keep the account identifier they were written with, and there is no longer an account it resolves to. That is pseudonymous, not anonymous — an accurate word matters here — and a log that erased itself on request would not be a log.
- Billing-log rows, with your email address erased and the row marked as redacted. The Paddle references stay: Paddle is the merchant of record and must retain the invoice for tax whatever we do.
- The staff action log, if a staff member ever acted on your account — including the record of the deletion. It is append-only at the database level and cannot be edited or deleted by anyone, including us.
The designs saved in your own browser are never touched by any of this. Deleting your account does not clear them.
If you are in the EU or UK you may complain to your data protection authority; in the Philippines, to the National Privacy Commission.
9. Security
Everything travels over HTTPS. Passwords are stored only as salted hashes. Database access is restricted per-account at the database level, so one account cannot read another's data even if the application were compromised. Staff access is a separate, explicitly granted role, every use of it is recorded in an append-only audit log, and it does not include the ability to sign in as you or read your design parameters.
10. Children
Create.Blitch is not directed at children under 13, and we do not knowingly collect their data. If you believe a child has created an account, contact us and we will delete it.
11. Changes
If this policy changes materially, the version and date at the top change and we will notify account holders by email before the change takes effect.
12. Contact
Create.Blitch — support@createblitch.com