Privacy in plain language
BloxMind needs some account, usage, game/project context, and uploaded content to provide its features. We should collect only what is reasonably needed, protect sensitive credentials, and give users meaningful ways to delete their account and associated data.
1. Information we collect
- Account information: email address, account ID, authentication/session data, plan, credit balance, and account settings.
- Roblox-linked information: when you choose to connect Roblox, BloxMind may store the Roblox user ID and profile information returned through authorized OAuth scopes, such as username, display name, and avatar.
- Game and project context: saved game profiles, creator project descriptions, preferences, levels, goals, and other context you choose to provide.
- Uploads: screenshots, Luau/code files, JSON, text, Markdown, CSV, or other supported files you intentionally submit.
- AI conversations: prompts, responses, attachments, selected context, and related metadata needed to provide the service and conversation history.
- Usage and security data: timestamps, feature usage, credit consumption, error logs, device/browser information, IP-derived security signals, and abuse-prevention data.
- Billing data: plan, transaction identifiers, billing status, and limited payment metadata. Full card details should be handled by the payment processor rather than stored directly by BloxMind.
2. How we use information
- provide BloxMind features and personalize answers using the context you select;
- authenticate accounts and maintain sessions;
- process Roblox account connections you explicitly authorize;
- calculate credits, enforce plan limits, and process subscriptions;
- operate AI features and analyze uploaded content at your request;
- detect abuse, fraud, security problems, and service errors;
- communicate account, billing, security, or product information;
- improve product quality using appropriately controlled usage data.
3. AI providers and service providers
BloxMind may send prompts, selected context, and uploaded content to contracted AI/model providers when necessary to generate a response. We may also use service providers for authentication/database hosting, payments, analytics, error monitoring, email, hosting, and security.
The current billing integration uses Paddle for checkout, subscription management, tax/payment processing and hosted billing tools. BloxMind stores billing identifiers and subscription state, not full card numbers.
4. Roblox connection
Connecting Roblox is optional. BloxMind should request only the scopes needed for the feature being provided. You can disconnect Roblox from BloxMind when that control is available, and you may also be able to revoke access through Roblox's own account controls.
BloxMind does not need your Roblox password and should never ask you to type that password directly into a BloxMind form.
5. Cookies and sessions
BloxMind uses authentication/session cookies and may use other strictly necessary storage to keep you signed in, protect account security, and remember service preferences. Optional analytics or marketing cookies should be disclosed separately if added.
6. Retention
We retain information for as long as reasonably necessary to provide the service, maintain security, resolve disputes, comply with legal obligations, and enforce agreements. Different categories may have different retention periods. Production retention periods should be documented once the final storage architecture is confirmed.
7. Security
BloxMind uses technical and organizational safeguards intended to protect data, including server-side secret handling, restricted database access, and authenticated sessions. No online service can guarantee absolute security. Never submit passwords, private API keys, payment-card numbers, or other secrets inside AI prompts or uploaded source files.
8. Children and younger users
BloxMind is intended for users age 13 and older. We do not knowingly design the service to collect personal information from children under 13. If we learn that prohibited child data has been collected, we will take appropriate steps to delete it. Requirements can differ by country, so age-gating and parental-consent obligations should be reviewed before a broad public launch.
9. Your choices and rights
Depending on where you live, you may have rights to request access, correction, deletion, portability, objection, restriction, or information about how personal data is processed. You can contact us to make a privacy request.
10. International processing
BloxMind and its providers may process information in countries other than the country where you live. When required, appropriate legal mechanisms should be used for cross-border transfers.
11. Changes to this policy
We may update this Privacy Policy as BloxMind, its providers, or legal requirements change. Material changes should be communicated through the service, email, or another reasonable method.
12. Contact
Privacy questions or requests can be sent to bloxmind0@gmail.com.
