Privacy Policy
Last updated 23 June 2026
Blinkof.ai ("we", "us") is operated by Dutchcode B.V. This policy explains what we collect when you use blinkof.ai, why, and the choices you have. We try to collect as little as we can to run the service.
Who we are
Blinkof.ai is a testing tool that scans web apps and returns a report. The data controller is Dutchcode B.V. You can reach us about privacy at support@dutchcode.com.
What we collect
- Account information — if you sign in, we receive your name, email address, and avatar from your chosen provider (Google or GitHub). We do not receive your provider password.
- Email address — when you run a free scan, the email you give us so we can send the report and important service messages. If we send product follow-up, every message includes an unsubscribe option.
- What you scan — the URL you submit and the data we gather from that app to produce your report or grade, which can include contact email addresses the app lists publicly (see "Apps you submit" and "Instant grades" below).
- Test logins — if you choose to test behind your login, the username and password you save for one of your own apps (available free once you've verified you own the site). The password is stored encrypted and used only to sign in while we test (see "Test logins" below).
- Payment information — if you subscribe or buy credits, payments are processed by Stripe. We receive billing status and a customer reference; we never see or store your full card details.
- Technical data — IP address and browser/user-agent string, plus basic request data and error/diagnostic data from our error-monitoring tool. We use these for rate-limiting, abuse prevention, and to record that a scan was authorised (see "Authorisation to scan" below).
How we use it
- To run scans and deliver your reports.
- To turn raw scan signals into a readable report, using an AI model (see "How the report is written" below).
- To create and manage your account, subscription, and credits.
- To send you your report and important service messages.
- To prevent abuse, enforce our Terms, and keep the service secure.
- To improve the product (in aggregate — we don't sell your data).
We rely on your consent (the report email), on the performance of our contract with you (running the scan, billing), and on our legitimate interests (security, product improvement) as legal bases under the GDPR.
Apps you submit
When you ask us to run the full test on a URL, we first require ownership verification. We then fetch and interact with that app like a real user — loading pages, submitting forms, and (where applicable) creating and then deleting a temporary test account. We store the resulting data (e.g. detected issues, screenshots, and signals) so we can show you the report and track changes over time. In the process we may read information the app makes public, including contact email addresses listed on a page (we check whether their mail server is reachable, to flag dead contact addresses). You must only run the full test on apps you own or are authorised to test (see our Terms).
Instant grades
An instant grade reads only public information about a site — response headers, the code the site ships to browsers, SEO tags, third-party trackers, and any linked privacy policy — without signing up or submitting anything. Each grade gets a shareable page and preview image showing the grade and a short summary. We do not publish the specific contact addresses we may read from a page. If a grade is about a site you own and you'd like it removed, email support@dutchcode.com.
How the report is written
To turn the raw signals from a scan into a plain-language report, we send those signals to an AI model — Claude, provided by Anthropic — through Cloudflare's AI Gateway. We send what we observed about the app (such as page content, detected issues, and any contact addresses found); we do not send your account credentials or payment details. Anthropic processes this only to generate the findings for your report.
Test logins
If you save a test login for one of your own apps, we use it to sign in during a deep test so we can check the pages behind your login. The password is encrypted at rest with a key held separately from the database, and is used only to authenticate your tests — never shown back to you, shared, or used for anything else. We never delete or change the account you provide. You can remove a saved login at any time, and removing the app or deleting your account removes it too. We recommend a dedicated, low-privilege test account rather than an admin one.
Authorisation to scan
Because a scan actively probes the app you submit, we only run it after you confirm you own or are authorised to test that site. When you do, we record that confirmation together with the time, the IP address and browser/user-agent it came from, and the version of the confirmation wording — so both you and we have a clear record that the scan was authorised. We rely on our legitimate interest in security and in protecting against misuse as the legal basis for this.
Cookies & analytics
We use a single essential cookie to keep you signed in. We do not use advertising or cross-site tracking cookies. We use error monitoring to catch crashes; it may collect limited diagnostic data (such as browser, URL, and stack traces) when something breaks. We also use Cloudflare Web Analytics to understand overall traffic — it's privacy-first: cookieless, with no cross-site tracking or fingerprinting of visitors.
Who we share data with
We use a small number of trusted processors to run Blinkof.ai, each under their own privacy terms:
- Cloudflare — hosting, database, storage, browser rendering, the AI Gateway, and privacy-friendly traffic analytics.
- Anthropic — the AI model (Claude) that turns scan signals into the report's findings.
- Stripe — payments and subscription billing.
- Resend — sending report and account emails.
- Google / GitHub — sign-in (only if you choose to sign in).
- Sentry — error monitoring.
We don't sell your personal data, and we only share it with these providers as needed to run the service, or where required by law.
How long we keep it
We keep your account and scan data while your account is active and for a reasonable period afterwards, then delete or anonymise it. Free-scan emails and reports are kept to provide the service and may be removed on request. We keep the authorisation record for a scan (the confirmation, IP, user-agent, and timestamp described above) for up to 24 months, so we can address any later dispute about whether a scan was authorised. A saved test login is kept (encrypted) until you remove it or delete your account; a public grade is kept until you ask us to remove the grade for your site.
If you have an account, you can delete it from the dashboard. That removes your account, watched apps, saved test logins, API tokens, and reports tied to your account email. If you have an active paid subscription, you must cancel it in Stripe first so billing stops cleanly. We may keep a minimal suppression record so we do not email a deleted address again.
Where your data is processed
Our providers operate globally, so your data may be processed outside your country, including outside the EEA, under appropriate safeguards (such as standard contractual clauses).
Your rights
Depending on where you live (e.g. under the GDPR or CCPA), you can ask us to access, correct, export, or delete your personal data, and to restrict or object to certain processing. Account holders can delete their account from the dashboard; for anything else, email support@dutchcode.com and we'll respond within the time the law requires. You can also complain to your local data-protection authority.
Security
We protect data in transit with HTTPS and limit access to it. No method is perfectly secure, but we work to keep your data safe and to fix issues promptly.
Children
Blinkof.ai is not intended for anyone under 16, and we don't knowingly collect their data.
Changes
We may update this policy as the product evolves. We'll change the "last updated" date above, and for material changes we'll do our best to let you know.
Contact
Questions or requests: support@dutchcode.com.