Blockplan
Privacy Terms of Service Back to app

Privacy Policy

Version 1.0 — effective 25 September 2026. See Terms of Service for the rules that govern using Blockplan itself.

⚖️
Not a substitute for legal advice. This policy describes, as accurately as we can, what Blockplan actually collects and why, based on a technical review of the running application. It is not a certification of compliance with any specific law. Sections marked (legal review) are points a qualified lawyer should confirm before this policy is relied on for a real launch, particularly around a data protection law that is currently pending before the Maldivian Parliament (see §10).
Contents
  1. 1. Who operates Blockplan
  2. 2. What we collect
  3. 3. Photos, audio & your build files
  4. 4. Third parties we use
  5. 5. Cookies & local storage
  6. 6. Why we use your data
  7. 7. How long we keep it
  8. 8. Sharing & disclosure
  9. 9. Your rights & account deletion
  10. 10. Legal framework & your location
  11. 11. Children
  12. 12. Security
  13. 13. Changes to this policy
  14. 14. Contact

1. Who operates Blockplan

Blockplan (blockplan.build) is operated by BlockPlan, based in the Maldives. [A specific registered business entity type (sole proprietorship/company) and a full mailing address have not yet been confirmed — legal review before relying on this for formal notices.]

2. What we collect

Blockplan works without an account — the editor, camera controls, building tools, and local export all run entirely in your browser with nothing sent to a server. The data below is only collected if you choose to create a cloud account.

If you create an account

  • Email address — used to log in, verify your account, and send password-reset/verification emails.
  • Password — never stored in readable form. We store a PBKDF2-SHA256 hash (600,000+ iterations) with a random salt per password; the plaintext password is never written to our database or logs.
  • Display name — optional, shown back to you in the app only.
  • Cloud project data — the build designs you explicitly save to your account (block positions, layers, names — the same data format as a local .blockplan file).

Collected automatically

  • IP address — used transiently to rate-limit login/signup/password-reset attempts (abuse prevention). Your IP is never stored in readable form: it's cryptographically hashed (SHA-256) before it touches our database, and only a hashed counter is kept, not the address itself. It is not logged elsewhere and is not used to track you.
  • Security/audit events — account actions like "login succeeded," "password reset requested," or "account deleted" are logged with your account ID, the event name, and a timestamp — never your password, session token, or IP address.
  • Session cookie — see §5.

We do not currently run any analytics, tracking pixel, or third-party advertising script. If that changes, this policy will be updated first.

3. Photos, audio & your build files

Photo-to-block-art images never leave your browser. When you use the "Photo to Block Art" tool, the image is decoded and processed entirely client-side using your browser's own canvas — it is never uploaded to any Blockplan server or third party. Only the resulting blocks (not the photo itself) become part of your build, and only if you then save that build to your cloud account.

Local .blockplan/.json/.zip design files you load are read directly in your browser the same way. Nothing is uploaded unless you explicitly click "Save to cloud" (or equivalent) while signed in.

We do not currently support audio uploads as a feature; if that changes, this section will be updated to describe exactly how that data is handled before the feature ships.

4. Third parties we use

We use a small number of third-party services to run Blockplan. We don't sell or rent your data to anyone, and none of these providers get more than what's needed to do their specific job:

  • Cloudflare — hosts the site, database, and serverless functions (Cloudflare Pages/D1/Workers), and provides Cloudflare Turnstile (a CAPTCHA alternative) on signup/login forms to block automated abuse. Turnstile sees your browser/device signals, not your Blockplan password.
  • Paddle — if/when billing is enabled, Paddle acts as merchant of record for the paid "Pro" plan: it collects and processes your payment details directly. Blockplan's own servers never see or store your card number — we only receive a subscription status (active/canceled/etc.) from Paddle via a signed webhook.
  • Resend — sends verification and password-reset emails on our behalf. It receives your email address and the content of that specific email only.

Each of these providers has its own privacy policy governing the data it processes on our behalf: Cloudflare, Paddle, Resend.

5. Cookies & local storage

Blockplan uses exactly one cookie: bp_session, a random opaque session token (not a tracking identifier — it identifies a logged-in session, nothing else). It's HttpOnly (inaccessible to page JavaScript), Secure on the real deployed site, SameSite=Lax, and scoped only to API requests. It's set when you log in and cleared when you log out or it expires (30 days of inactivity by default).

We don't use third-party advertising or analytics cookies. The app also uses your browser's localStorage for purely local conveniences — remembered UI preferences, favorited blocks, recent structures — none of which is ever transmitted to us.

6. Why we use your data

  • To create and secure your account, and let you log in.
  • To store and let you retrieve your cloud-saved build projects.
  • To send you account-related email (verification, password reset) — never marketing email unless you separately opt in, which isn't currently a feature.
  • To detect and block abuse (credential stuffing, spam signups) via rate-limiting and Turnstile.
  • To process payment and manage your subscription, if you upgrade to Pro.

7. How long we keep it

  • Account & project data — kept until you delete your account (see §9), or delete individual projects yourself.
  • Email-verification / password-reset tokens — expire automatically (24 hours / 30 minutes respectively) and are single-use.
  • Rate-limit counters (hashed IP/email) — roll over automatically within a short fixed window (15 minutes to 1 hour depending on the action) and are not retained beyond that.
  • Audit/security event log — retained for account security history. (legal review: a specific maximum retention period has not yet been formally set — flagged for review.)

8. Sharing & disclosure

We share data only with the service providers in §4, only as needed to run Blockplan. We do not sell personal data. We may disclose information if required to by a valid legal process, or to protect the security or legal rights of Blockplan or its users — we're not aware of any such disclosure having occurred as of this policy's effective date.

9. Your rights & account deletion

You can delete your own account at any time from within the app (Account settings → Delete account). When you do:

  • Your cloud projects are permanently deleted.
  • All active sessions are invalidated (you're logged out everywhere).
  • Your email address and password are replaced with unusable placeholder values — the account can never be logged into again.
  • Billing/subscription and webhook records tied to your (now-anonymized) account are retained for financial record-keeping, as most payment/tax regimes require.

You can also ask us directly (see §14) to access, correct, or delete data we hold about you, and we'll respond on a reasonable timeline even outside of any specific legal deadline. Depending on where you're located, you may have additional, more specific rights — see §10.

10. Legal framework & your location

Maldives. Based on research conducted for this policy (September 2026), the Maldives does not currently have a comprehensive data protection statute in force — a Personal Data Protection Bill has been drafted and was reportedly submitted to the People's Majlis (Parliament) in 2026, but has not yet been confirmed enacted at the time of writing. We are not claiming compliance with that bill, since it isn't law yet; once it is enacted, we intend to review and update this policy accordingly. (legal review: re-confirm the bill's status before every future update to this policy.) The Maldives Consumer Protection Act (Law No. 12/2020) is in force and applies generally to online/digital consumer transactions, including a subscription service like Blockplan's paid plan.

If you're in the European Economic Area or UK. Depending on the extent to which Blockplan is offered to or used by people there, EU/UK GDPR may apply to some of our processing of your data. This policy is written to be broadly consistent with GDPR's transparency principles, but we are not making a formal compliance claim — this is a small, early-stage service, and a full GDPR compliance review (Art. 30 records, a DPO assessment, an international-transfer mechanism, etc.) has not been performed. (legal review.)

If you're in California. The CCPA/CPRA applies to businesses meeting certain revenue or data-volume thresholds. We do not currently believe Blockplan meets those thresholds, but we describe your rights above in §9 regardless as a matter of good practice, not as an admission that CCPA applies.

11. Children

Blockplan is not directed at children under 13 (or the relevant minimum age in your jurisdiction), and we don't knowingly collect data from them. If you believe a child has created an account, contact us (§14) and we'll delete it.

12. Security

Passwords are hashed with PBKDF2-SHA256 (never stored or logged in plain text). Sessions use random opaque tokens, not predictable identifiers. All traffic to the real deployed site is served over HTTPS. Administrative/API access is scoped so that one user's requests can only ever read or modify that same user's own data — this is enforced on every request, not just in the UI. No system is perfectly secure, and we can't guarantee against every possible attack, but this is the standard we hold the app to.

13. Changes to this policy

If we make a material change, we'll update the version/date at the top of this page. Continued use of Blockplan after a change means you accept the updated policy.

14. Contact

Questions, data requests, or privacy concerns: blockplan.build@gmail.com.

© 2026 Blockplan. See also the Terms of Service.