# Privacy and data handling

A tool that watches your team only earns that if it collects almost nothing. Blank is built so you can prove it does. This is the operational summary. The full legal policy is at [useblank.dev/privacy](/privacy).

## What Blank collects

On AI-tool pages in its catalog, Blank reports events about AI-tool use:

- which catalogued AI tools are visited;
- **detections:** the detector that fired, its severity, and the position and length of the match;
- unknown AI tools ("candidates"), which is the domain of a tool not yet in the catalog;
- an inventory of the browser extensions installed on the device;
- enforcement events, meaning that a coaching prompt was shown or a request blocked.

Each device carries an identifier and your organization's enrollment token.

## What it never collects

Blank does not send the text you type or paste, the secret or personal data that trips a detector, the contents of the pages you visit, your keystrokes, or your passwords. Only the finding leaves the browser, never the matched content. It does not run, or report, on anything outside catalogued AI tools.

## Pseudonymization

You can turn on a mode that replaces the device identifier with a pseudonym everywhere it appears, in dashboards and exports. Re-identifying a specific person is then a deliberate, logged action that requires a **second administrator's approval** and is limited to a 24-hour window. It's one-way by default, and the exception is governed and recorded.

## Retention and deletion

Event data is kept for the window associated with your plan and then deleted automatically. You can request deletion of your organization's data at any time, and it's honored after a short, reversible grace period. Deletion certificates and the audit log are append-only, so they can't be quietly rewritten.

## Where data is processed

Blank runs on a small set of service providers, each required to protect data and use it only to run the service: **Supabase** (database and authentication), **Netlify** (hosting and serverless functions), **Stripe** (billing), **Resend** (transactional email), and **Google** (optional administrator sign-in). Blank is operated from the United States.

For the complete policy, including controller and processor roles, data-subject rights, and international transfers, see the [privacy policy](/privacy).
