Blockplan (blockplan.build) is operated by BlockPlan, based in the Maldives. [A specific registered business entity type (sole proprietorship/company) and a full mailing address have not yet been confirmed — legal review before relying on this for formal notices.]
Blockplan works without an account — the editor, camera controls, building tools, and local export all run entirely in your browser with nothing sent to a server. The data below is only collected if you choose to create a cloud account.
.blockplan file).We do not currently run any analytics, tracking pixel, or third-party advertising script. If that changes, this policy will be updated first.
Photo-to-block-art images never leave your browser. When you use the "Photo to Block Art" tool, the image is decoded and processed entirely client-side using your browser's own canvas — it is never uploaded to any Blockplan server or third party. Only the resulting blocks (not the photo itself) become part of your build, and only if you then save that build to your cloud account.
Local .blockplan/.json/.zip design files you load are read directly in your browser the same way. Nothing is uploaded unless you explicitly click "Save to cloud" (or equivalent) while signed in.
We do not currently support audio uploads as a feature; if that changes, this section will be updated to describe exactly how that data is handled before the feature ships.
We use a small number of third-party services to run Blockplan. We don't sell or rent your data to anyone, and none of these providers get more than what's needed to do their specific job:
Each of these providers has its own privacy policy governing the data it processes on our behalf: Cloudflare, Paddle, Resend.
Blockplan uses exactly one cookie: bp_session, a random opaque session token (not a tracking identifier — it identifies a logged-in session, nothing else). It's HttpOnly (inaccessible to page JavaScript), Secure on the real deployed site, SameSite=Lax, and scoped only to API requests. It's set when you log in and cleared when you log out or it expires (30 days of inactivity by default).
We don't use third-party advertising or analytics cookies. The app also uses your browser's localStorage for purely local conveniences — remembered UI preferences, favorited blocks, recent structures — none of which is ever transmitted to us.
We share data only with the service providers in §4, only as needed to run Blockplan. We do not sell personal data. We may disclose information if required to by a valid legal process, or to protect the security or legal rights of Blockplan or its users — we're not aware of any such disclosure having occurred as of this policy's effective date.
You can delete your own account at any time from within the app (Account settings → Delete account). When you do:
You can also ask us directly (see §14) to access, correct, or delete data we hold about you, and we'll respond on a reasonable timeline even outside of any specific legal deadline. Depending on where you're located, you may have additional, more specific rights — see §10.
Maldives. Based on research conducted for this policy (September 2026), the Maldives does not currently have a comprehensive data protection statute in force — a Personal Data Protection Bill has been drafted and was reportedly submitted to the People's Majlis (Parliament) in 2026, but has not yet been confirmed enacted at the time of writing. We are not claiming compliance with that bill, since it isn't law yet; once it is enacted, we intend to review and update this policy accordingly. (legal review: re-confirm the bill's status before every future update to this policy.) The Maldives Consumer Protection Act (Law No. 12/2020) is in force and applies generally to online/digital consumer transactions, including a subscription service like Blockplan's paid plan.
If you're in the European Economic Area or UK. Depending on the extent to which Blockplan is offered to or used by people there, EU/UK GDPR may apply to some of our processing of your data. This policy is written to be broadly consistent with GDPR's transparency principles, but we are not making a formal compliance claim — this is a small, early-stage service, and a full GDPR compliance review (Art. 30 records, a DPO assessment, an international-transfer mechanism, etc.) has not been performed. (legal review.)
If you're in California. The CCPA/CPRA applies to businesses meeting certain revenue or data-volume thresholds. We do not currently believe Blockplan meets those thresholds, but we describe your rights above in §9 regardless as a matter of good practice, not as an admission that CCPA applies.
Blockplan is not directed at children under 13 (or the relevant minimum age in your jurisdiction), and we don't knowingly collect data from them. If you believe a child has created an account, contact us (§14) and we'll delete it.
Passwords are hashed with PBKDF2-SHA256 (never stored or logged in plain text). Sessions use random opaque tokens, not predictable identifiers. All traffic to the real deployed site is served over HTTPS. Administrative/API access is scoped so that one user's requests can only ever read or modify that same user's own data — this is enforced on every request, not just in the UI. No system is perfectly secure, and we can't guarantee against every possible attack, but this is the standard we hold the app to.
If we make a material change, we'll update the version/date at the top of this page. Continued use of Blockplan after a change means you accept the updated policy.
Questions, data requests, or privacy concerns: blockplan.build@gmail.com.