Privacy Policy
Last updated 2026-09-17
This policy explains what blogi (operated by blogi, Israel) collects, why, who sees it and how to get it removed. It is written for creators who build a page, for visitors who use one, and for people who appear in a creator's Stories without ever using blogi.
1. Creators: what we collect
Your Instagram username and the public parts of your profile (name, picture, bio, follower and post counts, whether the account is private); the email address you register; the Highlights you select and every Story inside them (images, video, captions, stickers, location tags, tagged accounts, links); the AI output derived from them (transcripts, summaries, places, products, brands, codes, categories, a profile of your content style); your dashboard settings; and technical logs of your sign-ins.
We receive Highlight data from Instagram on your instruction, through Instagram's interface as used by our ingestion account or through a data provider (HikerAPI) for public accounts. We never ask for, see or store your Instagram password.
2. Visitors: what we collect
Searches and questions you type on a page and the answers shown, which the creator sees in aggregate as Insights (the query text, never who asked); which chips, codes, links and Stories are opened; a random identifier in a cookie so the creator's statistics can count unique visitors; product analytics through PostHog (hosted in the EU) covering pages viewed and features used; and your IP address, kept briefly for rate limiting and abuse prevention.
If you subscribe to a page or join a waitlist we keep your email address, the page it concerns, the time and the IP address it came from, until you unsubscribe.
If you create a follower account we keep your email address, your language, sign-in times, the boards you create and what you save to them (references to places, codes, Stories and creators), and the destinations, brands and creators you follow. Searches you run in Explore are logged in product analytics with your account id. You can delete the account and everything in it from your account page.
3. People who appear in Stories but do not use blogi
Stories mention venues, brands and people, and tag accounts. blogi extracts and shows those mentions because the creator chose to publish the Story. We show public information only (a username, a place name), never private contact details, and we do not build profiles of people across creators. If you appear on a page and would rather not, write to legal@blogi.ai or use the creator's contact on Instagram; we can hide the Story or the mention.
For creators who have not joined, we may show a preview built from their public Instagram profile (name, picture, follower count, Highlight titles) with a waitlist. It is hidden from search engines and can be removed by the creator with one click on the preview or by email.
4. Why we process it and on what basis
To provide the page a creator asked for (performance of our agreement with the creator); to answer visitors' questions and show them what they searched for (our legitimate interest in running the service and the creator's interest in reaching their audience); to send subscription and waitlist emails (your consent, withdrawn by unsubscribing); to keep the service secure and measure how it is used (legitimate interest); and to meet legal obligations.
Where the EU or UK GDPR applies to you, those are our legal bases. Under Israel's Protection of Privacy Law, this policy is the notice we are required to give when we collect your details, and you are not legally obliged to provide them; without an email address we cannot sign you in or notify you.
5. AI processing
Stories are transcribed and read by AI models from Anthropic (Claude) and OpenAI (Whisper), under their API terms, which do not allow them to train models on your content. Venues are located through Google Places and shown on Google Maps under Google's terms. AI output is stored with your page and can be corrected or hidden by the creator.
6. Who else sees the data
Service providers that process data for us, under contracts: Supabase (database and media storage, Frankfurt, Germany), Render (application hosting, Frankfurt), Cloudflare (network and security), Resend (email delivery), PostHog (product analytics, EU), Anthropic and OpenAI (AI processing, United States), Google (maps and places), HikerAPI (Instagram data for public accounts) and, if paid plans return, Lemon Squeezy (payments; we never see card numbers). We do not sell personal data and we do not share visitor identities with creators.
We disclose data when the law requires it, to protect our rights or the safety of others, and to a successor if blogi changes hands, under this same policy.
7. International transfers
Data is stored in the European Union. Some providers process it in the United States under the EU Standard Contractual Clauses or the EU-US Data Privacy Framework. Israel, where blogi is operated, is recognised by the European Commission as providing adequate protection.
8. How long we keep it
A creator's content and derived data stay as long as their page exists; deleting the page removes them, with backups following within 30 days. Visitor events are kept for the creator's Insights for up to 24 months. Subscriptions and waitlist entries stay until you unsubscribe or the creator's page is deleted. Server logs and rate-limiting records are kept for up to 90 days. Coordinates from Google Places are refreshed at least every 30 days as Google requires.
9. Your rights
You may ask what data we hold about you, have it corrected or deleted, object to or restrict its processing, receive a copy in a portable format, and withdraw any consent. Creators can delete their page and all its data themselves from the Dashboard (Account → Delete my page). Everyone else, and creators with any other request, can write to legal@blogi.ai; we reply within 30 days. If you are in the EU or UK you may also complain to your data protection authority; in Israel, to the Privacy Protection Authority.
10. Cookies
blogi sets a sign-in cookie for creators (hl_session, 30 days), a language preference (hl_locale), a random visitor identifier for a creator's Insights, and PostHog's analytics cookie. There are no advertising cookies. You can block cookies in your browser; the sign-in and language cookies are needed for those features to work.
11. Security
Data travels over TLS and is stored with access controls; visitors read pages through a restricted database role that cannot see creators' emails, billing details or raw imports. Sign-in uses one-time links rather than passwords. No system is perfectly secure; if a breach affects you, we will tell you and the relevant authority as the law requires.
12. Children
blogi is not directed at children under 16 and we do not knowingly collect their data. If you believe a child has created a page or subscribed, write to legal@blogi.ai and we will remove the data.
13. Changes and contact
We will post changes to this policy here and, for material changes, tell creators by email. The controller of the data described here is blogi, Israel. Contact: legal@blogi.ai.