Bleenk logo

Bleenk – Privacy Policy

Last Updated: July 6, 2026

Introductory Compliance Declaration

ROBI LABS LLC, A LIMITED LIABILITY COMPANY INCORPORATED, REGISTERED, AND EXISTING UNDER THE LAWS OF THE REPUBLIC OF ARMENIA, DOING BUSINESS AS BLEENK(HEREINAFTER "ROBI LABS," "BLEENK," "WE," "US," OR "OUR"), OPERATES THE BLEENK AND OPENSAIL AI DEVELOPMENT ENGINE (THE "PLATFORM" OR "SERVICES").

WE ARE COMMITTED TO PROTECTING THE PRIVACY, SECURITY, AND CONFIDENTIALITY OF THE DEVELOPMENT WORKSPACES, SOURCE CODE, PERSONAL REGISTRATION DATA, AND INTEGRATION AUTHENTICATIONS BELONGING TO OUR USERS. THIS PRIVACY POLICY IS DESIGNED TO CLEARLY AND TRANSPARENTLY DISCLOSE WHAT DATA WE COLLECT, HOW WE PROCESS AND STORE IT, OUR ENCRYPTED KEY MANAGEMENT PROTOCOLS, THE ISOLATION STANDARDS OF OUR RUNTIME CONTAINERS, AND THE AUTOMATED SOFT-TO-HARD PURGE PIPELINE UNDER WHICH REPOSITORIES AND BACKUPS ARE RETRIEVED OR DESTROYED.

THIS PLATFORM IS SYSTEMATICALLY DESIGNED TO ALIGN WITH GLOBAL PRIVACY FRAMEWORKS, INCLUDING THE EUROPEAN UNION GENERAL DATA PROTECTION REGULATION (GDPR) AND SUBSTANTIVE DATA PRIVACY STATUTES. BY REGISTERING AN ACCOUNT, PROMPTING OUR AGENTS, RUNNING CONTAINERS, OR PURCHASING CREDITS, YOU EXPLICITLY ACCEPTS AND CONSENTS TO THE COMPILATION, TRANSMISSION, ANALYSIS, STORAGE, AND DELETION PROCEDURES DETAILED IN THIS PRIVACY POLICY.

Section 1: Data Controller and Data Processor Status

1.1 Robi Labs as a Data Controller

Robi Labs LLC operates as the Data Controller under European privacy laws with respect to your basic personal details, registration profiles, payment metadata (relayed securely via Stripe), analytics, cookies, and system billing balances.

1.2 Robi Labs as a Data Processor

Robi Labs LLC operates as a Data Processor with respect to the technical, private files, source codes, container environment configurations, private environment variables, database records, and custom user media that you import, upload, mount, or execute within your isolated Project Workspaces. You remain the Data Controller over your workspace data and bear the ultimate legal responsibility to secure your users' databases.

SECTION 2: INFORMATION WE COLLECT & PROCESSING SOURCES

To deliver a functional developer ecosystem, we compile information across several structural boundaries:

2.1 Profile & Registration Information

  • Core Credentials: Display name, primary email address, salted and encrypted password hashes, unique usernames (manually specified or automatically derived from the email address), and system-generated UUID slugs.
  • Account Presets: Choice of design themes, accessibility preferences (screen-reader optimizations, color configurations), display badges, referral history, and subscription history.

2.2 Project Workspace & Execution Data

  • Repository Source Code: All files, HTML codes, CSS rules, JavaScript modules, Python scripts, database structures, and backend assets compiled or written inside your sandboxed workspaces.
  • Continuous Database Records: Any schema models, test records, tables, or database volumes initialized for your isolated project databases (using PostgreSQL, SQLite, or similar).
  • Backup Volume Snapshots: Complete SSD/EBS volume snapshots (up to five snapshots per active project) captured by our snapshot manager to facilitate timeline rollbacks and container state persistence.
  • Runtime Terminal Output: Execution logs, console printouts, runtime errors, and resource consumption parameters generated during live container performance.

2.3 AI Prompt & Interactive Conversational Traces

  • Natural Language Queries: Transcripts of the text chats, command prompts, and code instructions sent to our builder agents.
  • Agent Operations Logs: Step-by-step trace files detailing how the AI agent requested tools, executed local shell processes, performed patch edits, and constructed the filesystem layout.

2.4 Secure External API Keys & OAuth Credentials

  • Outbound Integrations: Access tokens, OAuth authorization hashes, and private developer keys connected by you to link with external services (such as GitHub, Vercel, Google, Linear, Netlify, or custom SMTP mail configurations).
  • Encryption standard: All external API keys and authorization tokens are isolated from general database tables, encrypted-at-rest using industrial cryptography standards, and are never logged, compiled, or printed in plain text formats.

2.5 Billing and Payment Transaction Data

Stripe Processing: All payment processing, subscription management, card validations, and recurring billing transactions are directed through Stripe, Inc. Bleenk does not directly capture, view, transmit, or store your raw debit/credit card numbers or CVV codes. Bleenk only maintains a secure Stripe Customer ID, Stripe Session identifiers, card brand, expiration month/year, and your billing country.

Section 3: Legal Bases for Processing Under GDPR

If you reside in the European Economic Area (EEA) or Switzerland, we process your personal and development data under the following legitimate legal bases:

3.1 Performance of a Contract

Processing is necessary to perform our contractual obligations under our Terms of Service. This includes maintaining your user profile, routing network traffic to your active containers, running AI workflows under your direction, and administering your credit balances.

3.2 Legitimate Business Interests

Processing is necessary to support our legitimate business interests, provided such interests are not overridden by your privacy rights. This includes:

  • Enforcing password complexity constraints, registration allowlists, and compliance blocklists.
  • Analyzing performance traces and logs to prevent server exploits, DDoS activities, and container breakout attempts.
  • Enhancing our software's UI responsiveness and accessibility features (WCAG AA standard audits).

3.3 Compliance with Legal Obligations

Processing is necessary to comply with Armenian corporate registries, taxation requirements, and international anti-money laundering, fraud prevention, and corporate compliance protocols.

3.4 Consent

Where required, we process your information based on your explicit, affirmative consent (for instance, when subscribing to promotional communications or allowing optional third-party telemetry). You can withdraw your consent at any time.

SECTION 4: DATA USAGE & INTELLECTUAL PROPERTY RECTIFICATION

4.1 Operation of the AI Platform

We use your data, prompts, and code files to allow our multi-agent computational worker (the ARQ worker) to analyze, write, and execute code within your project.

4.2 Non-Use of Private Prompts for General Model Training

We respect the confidentiality of your proprietary source code and custom ideas:

  • Private Code Integrity: The raw prompt sequences, custom files, and database records processed inside your Bleenk projects are routed securely to upstream LLMs (such as OpenAI, Anthropic, or DeepSeek) using dedicated API agreements.
  • No Public Training: Our upstream integrations explicitly specify that your private developer prompt inputs and custom generated files are not utilized to train public, foundational, or third-party Large Language Models.

Section 5: Data Sharing, Downstream Transfers, and Subprocessors

Robi Labs LLC does not sell, lease, rent, or trade your personal data, source code, or private files to any marketing brokers or third parties. We share data only with authorized, PCI-compliant, and secure subprocessors:

Subprocessor / ServicePurpose of TransferTransfer Location / Privacy Alignment
Stripe, Inc.Payment processing, billing management, fraud screening.Global / Stripe Privacy Policy
AWS / Amazon Web ServicesSecure cloud hosting, gp3 persistent block storage, EBS snapshots, isolated server nodes.Ireland, Germany, USA / GDPR Standard Contractual Clauses
LiteLLM / AI Model GatewaysAPI routing to upstream models (OpenAI, Anthropic, DeepSeek).Ireland, USA / API-level strict privacy terms (No model training)
Google Cloud / FirebaseOptional OAuth authentications, avatar assets, and analytics.Global / GDPR Compliance

Section 6: Cookies, Session Data, and Local Storage

6.1 Authentication Storage

The Platform utilizes secure, encrypted, and cookie-based sessions, as well as Browser LocalStorage, strictly to maintain your active authentication states (such as JWT bearer tokens and active project session histories).

6.2 Preferences Storage

We utilize LocalStorage to persist your design preferences, code editor configurations (Monaco configurations), keyboard shortcut mappings, and custom dashboard layouts. These elements are kept strictly in your local browser and do not compile any tracking profiles.

Section 7: Storage Architecture, Container Isolation, and Deletion Procedures

7.1 Namespace and Network Isolation

In production mode, our container orchestrator schedules and launches your project applications within dedicated Kubernetes namespaces or Docker Compose networks. Every project workspace runs inside an isolated security envelope with strict NetworkPolicy parameters. This configuration blocks other platform users from inspecting your files, capturing your container network traffic, or accessing your database volumes.

7.2 The Secure Deletion Pipeline

To satisfy GDPR guidelines, we operate an automated, rigorous soft-to-hard deletion procedure. If you initiate account deletion, the progressive workflow operates as follows:

Account Deletion & Data Purge Flow:

  1. Step 1: User Triggers Deletion

    You initiate deletion through your profile settings dashboard or by contacting support.

  2. Step 2: Immediate Soft Delete (Access Suspended)

    Your account is marked as is_deleted = True. Login and authentication tokens are immediately revoked. Your running project containers are permanently shut down and removed from the active Kubernetes pod registry, and databases are detached.

  3. Step 3: 30-Day Inactive Cold Storage (Retention Grace Period)

    Your metadata, code directories, and database tables are kept in a cold, inactive, and encrypted state for exactly thirty (30) days. This protects against accidental deletion, allowing you to restore your account by contacting support.

  4. Step 4: Irreversible Hard Purge (Permanent Destruction)

    Upon the expiration of 30 days, background cleaning tasks perform an irreversible purge: User records are deleted/anonymized in PostgreSQL, workspace files are wiped from AWS physical SSD block storage, and EBS volume snapshots are permanently purged. All data is gone and cannot be recovered.

Section 8: your GDPR Data Protection Rights

As a user, you hold comprehensive rights regarding your personal and development data. If you are located in the EEA, UK, or Switzerland, you can exercise these rights directly through your settings panel or by emailing us:

  • The Right to Access: You can request a clear copy of your personal metadata and billing history stored on Bleenk.
  • The Right to Rectification: You can modify your email, name, and profile credentials directly on your settings dashboard at any time.
  • The Right to Erasure (Right to be Forgotten): You can trigger our progressive deletion pipeline (Section 7.2) to permanently remove all your database records, workspaces, and backups.
  • The Right to Data Portability: You can download a complete ZIP or archive of your workspace files directly from your workspace dashboard at any time before deletion.
  • The Right to Object or Restrict Processing: You have the right to request that we restrict processing of certain data parts (for instance, opting out of analytics or specific outbound agent telemetry).

Section 9: Children's Privacy Protection

Bleenk is built exclusively for software developers, engineers, operators, and enterprises. The Platform does not target, nor is it designed to attract, children under the age of thirteen (13). We do not knowingly compile or store personal data from children under 13. If we discover that a user under the age of 13 has registered an account, we will immediately execute an emergency hard-deletion process to remove all associated profiles and workspace volumes.

Section 10: Updates to This Privacy Policy

Robi Labs LLC reserves the right to modify, amend, or rewrite this Privacy Policy at any time. If we make material modifications to how we handle your personal data, integration credentials, or workspace files, we will notify you at least thirty (30) calendar days in advance via platform alerts, dashboard notifications, or direct emails. Your continued utilization of our Platform after the thirty-day notification period constitutes your legal acknowledgement and acceptance of the revised Privacy Policy.

SECTION 11: DATA PROTECTION OFFICER & CONTACT INFORMATION

If you have any questions, compliance requests, data export inquiries, or wish to exercise your GDPR rights, please contact our Legal and Data Protection departments:

🏒 Corporate Office:
Robi Labs LLC
Yerevan, Republic of Armenia

πŸ“§ Data Protection Officer: support@bleenk.app
πŸ“§ Support Department: support@bleenk.app
πŸ“§ Accessibility Department: support@bleenk.app