Resources

Privacy and data handling

A tool that watches your team only earns that if it collects almost nothing. Blank is built so you can prove it does. This is the operational summary. The full legal policy is at useblank.dev/privacy.

What Blank collects

Blank locally inspects supported text-entry fields and outbound request content across websites for credentials, personal identifiers, financial information, and organization-defined sensitive patterns. Prompt and message content may be inspected, but raw content and matched values stay on the device. Page and network signals also help identify candidate AI tools. After successful enrollment, Blank reports metadata to your organization's service:

  • which catalogued AI tools are visited;
  • detections: the page domain, detector, category, severity, source, time, match position and length, plus confidence and aggregate counts when available. Network-source findings are reported only on catalogued AI-tool pages; paste and text-entry findings can also be reported from supported fields on other pages, including uncatalogued tools;
  • unknown AI tools ("candidates"), which is the domain of a tool not yet in the catalog;
  • an inventory of installed browser extensions, including IDs, names, versions, enabled state, installation type, and declared permissions;
  • enforcement events, meaning that a coaching prompt was shown or a request blocked.

Each device carries an identifier and your organization's enrollment token.

Blank does not send a full browsing-history log. Visit events are limited to catalogued and candidate AI-tool domains. Findings from other supported fields can still reveal the domain where the finding occurred. Network-layer blocking is limited to catalogued AI tools and requires an enterprise-policy installation and a blocking policy.

What it never transmits

Blank does not send the text you type or paste, the secret or personal data that trips a detector, the contents of the pages you visit, your keystrokes, or your passwords. Only finding metadata leaves the browser, never the matched content. Local inspection is processing on your device, not transmission of that content to Blank.

Pseudonymization

You can turn on a mode that replaces the device identifier with a pseudonym everywhere it appears, in dashboards and exports. Re-identifying a specific person is then a deliberate, logged action that requires a second administrator's approval and is limited to a 24-hour window. It's one-way by default, and the exception is governed and recorded.

Retention and deletion

Event data defaults to 30 days on Free, 365 days on Team, and 396 days on Business, then is deleted automatically. A paid-to-Free transition preserves existing event and feedback data for 30 days before Free retention applies. Organization deletion has a reversible 30-day period before the scheduled purge. Deletion certificates and the audit log are append-only, so they can't be quietly rewritten.

Where data is processed

Blank is operated from the United States; its Supabase database is in US East, Northern Virginia. Netlify handles hosting and APIs; Resend handles transactional email. Stripe handles paid billing and has both processor and independent-controller responsibilities. Google sign-in and customer identity providers are optional. The provider list describes the data and locations for each, including customer-configured integrations.

Review the DPA template and contact us to complete any required transfer agreement before deploying. The template becomes binding when completed and signed or incorporated into a separately signed agreement; it does not execute transfer clauses by itself.

For the complete policy, including controller and processor roles, data-subject rights, and international transfers, see the privacy policy.

View this page as Markdown →