Blessu legal
Privacy Policy
Last Modified Date: 28 September 2026
1. Who we are and what this policy covers
Ginylil SL ("Ginylil", "we", "us", or "our"), based in Estepona, Spain, is the controller of personal data processed through Blessu. This Privacy Policy applies to the Blessu website, mobile applications, card creator, public card pages, contribution flow, account area, and related support (together, the "Services").
Contact us at support@ginylil.com about this policy or a privacy request.
This policy explains what we actually collect, why we process it, who receives it, how long we keep it, and your choices. The Services are also governed by our Terms of Service.
2. Personal data we process
2.1 Account and authentication data
When you sign in with Google or Apple, we receive the provider account identifier, verified email address, and any name or profile image the provider makes available. We assign an internal user identifier and store account status, plan, and last-sign-in information. Blessu does not receive your Google or Apple password.
2.2 Card, upload, and contribution data
We process the titles, messages, image descriptions, photos, audio, template choices, YouTube links, and other content you choose to upload or publish, including generated movies where that feature is available. We also process draft upload records, file metadata, card identifiers, publication paths, timestamps, and contribution settings. If you contribute to another person's card, we store your contributor identifier, optional display name and message, contribution files, and timestamps.
Google Photos is an optional photo source separate from Google sign-in. When a signed-in user explicitly chooses Google Photos, Blessu requests photospicker.mediaitems.readonly solely to open Google Photos Picker and import only the photos the user selects for the current card. Blessu does not browse the user's Google Photos library or request Google Photos Library or Drive scopes. Selected photos pass through encrypted private transient staging and then through the same uploader as device photos; Google authorization material, Picker/session identifiers, media item identifiers, and Google media URLs are not stored in card data or exposed to the browser. Provider access and session data are removed after transfer, cancellation, failure, or expiry, and transient staged copies are deleted after import or cancellation, with a one-day storage lifecycle as a final safety net. Imported copies then follow the card publication, sharing, retention, and account-deletion rules in this policy. We do not sell Google Photos data, use it for advertising, credit decisions, or AI model training, or disclose it except to service providers acting for us to operate the import and to people who receive a card the user chooses to publish.
Please do not upload sensitive personal data or content you are not permitted to share.
2.3 Technical, security, and usage data
Our systems process IP address, request and response details, timestamps, browser or device information, authentication and security events, error information, and similar operational logs needed to deliver and protect the Services.
On the website, Google Analytics and Microsoft Clarity are optional. They load only after you accept analytics cookies. If accepted, these providers may process cookie identifiers, approximate location derived from IP address, browser and device details, pages visited, interactions, session statistics, and, for Clarity, session-replay and heatmap information. The Blessu mobile app does not load these analytics tools.
2.4 Communications and voluntary support
If you contact us, we process your contact details and the contents of the communication. If you choose the external “Support our work” link, PayPal processes the payment and payment details under its own privacy notice. Blessu does not receive or store your full payment-card or bank-account number.
2.5 Credits and Apple In-App Purchase
When you buy credits in the iOS app, Apple processes your payment information. Blessu receives an account token used to associate the transaction with your Blessu account and stores the verified App Store transaction identifier, product purchased, credit quantity, purchase date, and Apple environment. We use this data to verify the purchase, add credits exactly once, prevent fraud, and support transaction questions. Blessu does not receive your full payment-card or bank-account number from Apple.
3. Public cards and contributions
A published Blessu card is available at a public, unlisted URL. Anyone who receives or discovers the URL can view the card and may copy or share its content. Do not publish content that should remain private. If contributions are enabled, people invited to contribute can add content that becomes visible on the card; the card owner can remove contributions or block contributors.
4. Why we process data and our legal bases
| Purpose | Personal data | Legal basis | | --- | --- | --- | | Create and manage accounts, authenticate users, create and publish cards, accept contributions, and provide requested support | Account, authentication, card, upload, contribution, and communication data | Performance of our contract with you or steps you request before entering it | | Keep the Services reliable and secure, prevent abuse, diagnose failures, and enforce our Terms | Technical, security, account, and relevant content data | Our legitimate interests in operating and protecting Blessu and its users | | Comply with lawful requests, tax/accounting duties where applicable, and establish or defend legal claims | Relevant account, transaction, communication, log, and content data | Legal obligation or our legitimate interests in legal compliance and claims | | Measure website use and improve the experience with Google Analytics and Microsoft Clarity | Optional analytics and interaction data | Your consent |
We do not use Blessu data for solely automated decisions that produce legal or similarly significant effects. We do not sell personal data or use it for cross-context behavioural advertising.
5. Cookies and local storage
Blessu uses necessary browser storage for security, authentication, session continuity, interface preferences, draft recovery, and recording your cookie choice. These functions are required to provide features you request.
Optional analytics cookies include Google Analytics cookies such as _ga and _ga_*, and Microsoft Clarity cookies such as _clck and _clsk. We do not load Google Analytics or Microsoft Clarity until you select Accept analytics. Selecting Reject analytics does not prevent you from using Blessu.
You can withdraw or change your choice at any time using Cookie settings in the site footer. This clears the saved choice and presents the choice again. Withdrawal does not affect processing that occurred before withdrawal. You may also delete or block cookies in your browser, although blocking necessary storage may affect sign-in or other requested features.
Provider information: Google Analytics privacy and data safeguards and Microsoft Clarity data collection.
6. Who receives personal data
We disclose personal data only as needed for the purposes above:
- Cloud hosting and authentication providers store and deliver account data, card content, uploads, sessions, and operational records for us.
- Google or Apple processes sign-in information when you choose that provider.
- Apple processes payment information when you choose an in-app credit purchase.
- Stripe processes payment details when you use web checkout. We send an opaque purchase reference and the selected bundle; we retain the account-linked purchase, Stripe transaction references, amount, currency, credit adjustments, and payment/refund status for delivery, reconciliation, and billing support. Blessu does not store your full card number or security code. Financial transaction records may be retained after account deletion where needed for reconciliation and legal obligations.
- Google Analytics and Microsoft Clarity process optional website analytics only after consent.
- PayPal processes a voluntary support payment if you choose to leave Blessu and use PayPal.
- Professional advisers, authorities, or counterparties may receive limited data where reasonably necessary for legal compliance, claims, fraud or security response, or a corporate transaction.
Public card content is disclosed to anyone with the public card URL. A YouTube video selected for a card is provided by YouTube and may cause the viewer's browser to communicate with YouTube under Google's terms and privacy policy.
We require service providers acting for us to protect personal data and process it only for authorised purposes.
7. Retention and deletion
- Published cards, generated movies, and contributions: Each card and its associated generated movies are scheduled to expire 12 days after card creation, as defined by the product plan. A daily cleanup removes the card record and published files, including published contribution content, after expiry. Having an account or signing in again does not extend this period. Removal is not guaranteed at the exact expiry second; save any available downloads before expiry.
- Movie processing and delivery copies: Where movie generation is available, private source files are scheduled to expire after 2 days, intermediate render files after 7 days, and private download copies after 14 days, measured from each file's creation. These storage windows do not extend the card's 12-day lifetime or download availability.
- Non-public recovery copies: When published card files or private movie files are replaced or deleted, previous storage versions may remain temporarily in non-public recovery storage. They are scheduled for permanent deletion 30 days after becoming a previous version. Storage lifecycle deletion is asynchronous and may take additional time. These copies are not an archive service and are not used to republish expired or deleted content.
- Direct uploads and upload jobs: Temporary incoming files and incomplete multipart uploads normally expire within one day. Upload-job records are also configured with a one-day expiry.
- Accounts: Account records remain while the account is active. A sign-in session can last up to 30 days unless you sign out, delete the account, or the session is revoked.
- Operational records: Current security and service logs are generally kept for one to three months.
- Cookie choice: The analytics preference cookie lasts up to 180 days unless you reset it sooner.
- Optional analytics: Google Analytics retains user and event data according to the retention controls configured for the Analytics property; aggregated reports may remain longer. Microsoft states that Clarity playback data is normally retained for 30 days and heatmap, click, and labelled or favourited session data for up to 13 months.
- Support and legal records: We retain communications and records only as long as reasonably needed to answer the request, meet legal obligations, resolve disputes, prevent fraud, or enforce agreements.
Signed-in users can permanently delete their account in Account settings. Confirmed deletion signs the user out and removes the profile, owned card records and published files, draft uploads and upload jobs, and the user's contributions and contribution files on other cards.
Limited security, operational, legal, or disaster-recovery records may remain until their applicable retention period ends. They are not kept as an active account or used to republish deleted content. Other organisations, such as Google, Apple, PayPal, or a person who copied a public card, control their own copies and retention.
8. International transfers
Ginylil is established in Spain. Some providers may process data outside Spain or the European Economic Area. Where required, we rely on an adequacy decision, the European Commission's Standard Contractual Clauses, or another lawful transfer safeguard. You may contact us for information about the safeguard relevant to your data.
9. Your rights
Subject to applicable law, you may ask us to:
- provide access to and a copy of your personal data;
- correct inaccurate or incomplete data;
- erase data;
- restrict processing;
- provide data you supplied in a portable format;
- object to processing based on legitimate interests or to direct marketing; and
- withdraw consent at any time for processing based on consent.
You may delete your Blessu account directly in Account settings and manage optional analytics through Cookie settings. For other requests, email support@ginylil.com. We may need enough information to verify your identity and protect other people's data.
You also have the right to lodge a complaint with the Spanish Data Protection Agency (AEPD) or another competent supervisory authority.
10. Security
We use technical and organisational measures intended to protect personal data, including encrypted transport, access controls, private upload storage, and deletion workflows. No internet service can guarantee absolute security. Protect access to your sign-in provider and share public card links only with intended recipients.
11. Children
Blessu is not directed to children under 16, and people under 16 may not create an account or upload content. If you believe a child has provided personal data, contact us so we can investigate and delete it where appropriate.
12. Changes to this policy
We may update this policy as the Services or legal requirements change. We will post the updated policy and change the date above. If a change materially affects how we use personal data, we will provide additional notice before it takes effect where required by law.
13. Contact
Ginylil SL
Estepona, Spain
support@ginylil.com