Privacy
Your data, and what we do with it.
Blimp lets you build your own AI agent. To do that we hold a small amount of data — your account, the agent you shape, and the conversations it needs to run and remember. This page says exactly what that is, where it lives, and the control you keep over it. Plain language, no fine print.
Last updated: 11 July 2026
01 · What we collect
We collect only what's needed to run your agent and your account:
Your email — so you can sign in, and so your agents belong to your account.
The agent config you create — the name, persona, instructions, and settings that make an agent yours.
Conversation content — the messages exchanged with your agent, which we store so it can respond and remember across a conversation.
That's the whole list. No advertising identifiers, no tracking profiles, nothing we don't need to make the product work.
02 · How we use it
We use your data for two things: to run your agent, and to run your account. Your email signs you in. Your agent config and conversation history are what let an agent reply the way you designed it and remember what you've told it. Nothing else — no advertising, no profiling, no behind-the-scenes analysis of your conversations.
03 · Where it's stored
Two systems hold your data, each with one job:
Supabase — handles authentication — your login and the identity behind your account.
The agent host database — stores the agent configs you create and the conversation content needed to run them.
Both are access-controlled. Your agents and conversations are scoped to your account and aren't visible to other users.
Blimp is operated from Malaysia; Malaysian law, including the PDPA, applies to how personal data is handled here.
04 · Third parties we rely on
Running an agent means passing some data to a short list of services, each for a single purpose:
OpenRouter — routes your agent's messages to the AI models that generate its replies. Message content is sent at the moment your agent responds, so the model can answer.
Supabase — authenticates your account — sign-in and sessions.
Telegram — only if you choose to connect a bot. When you do, messages pass between Telegram and your agent so it can reply in your pocket. Connect nothing and Telegram is never involved.
We don't hand your data to advertisers or data brokers.
05 · The short version
We do not sell your data, and we never will.
Your conversations and configs aren't a product we trade, rent, or share for marketing. They exist to run your agent — nothing more.
06 · Your rights
Your data stays yours, and you stay in control:
Access — everything you've built is visible in your account.
Delete — you can delete any single agent, or your whole account, from Settings. Deleting an agent removes its config and conversation history; deleting your account removes your agents and the account itself.
Deletion is permanent — that's the point of it.
07 · Retention
We keep your data while your account is active, so your agents keep working and remembering. When you delete an agent or your account, the associated data is removed. We don't hold onto data we no longer have a reason to keep.
08 · Security
Access to your data is authenticated and scoped to your account. Secrets and credentials live in protected configuration — never in code, logs, or this repository — and traffic to our services runs over encrypted connections. No system is perfectly secure, but we treat your conversations as private by default and design around that.
09 · Contact
Questions about your privacy, or want something removed that we haven't covered? Email loganjchandra@blimp.my and we'll help.