Privacy

Your data, and what we do with it.

Blimp lets you build your own AI agent. To do that we hold a small amount of data — your account, the agent you shape, and the conversations it needs to run and remember. This page says exactly what that is, where it lives, and the control you keep over it. Plain language, no fine print.

Last updated: 11 July 2026

01 · What we collect

We collect only what's needed to run your agent and your account:

  • Your emailso you can sign in, and so your agents belong to your account.

  • The agent config you createthe name, persona, instructions, and settings that make an agent yours.

  • Conversation contentthe messages exchanged with your agent, which we store so it can respond and remember across a conversation.

That's the whole list. No advertising identifiers, no tracking profiles, nothing we don't need to make the product work.

02 · How we use it

We use your data for two things: to run your agent, and to run your account. Your email signs you in. Your agent config and conversation history are what let an agent reply the way you designed it and remember what you've told it. Nothing else — no advertising, no profiling, no behind-the-scenes analysis of your conversations.

03 · Where it's stored

Two systems hold your data, each with one job:

  • Supabasehandles authentication — your login and the identity behind your account.

  • The agent host databasestores the agent configs you create and the conversation content needed to run them.

Both are access-controlled. Your agents and conversations are scoped to your account and aren't visible to other users.

Blimp is operated from Malaysia; Malaysian law, including the PDPA, applies to how personal data is handled here.

04 · Third parties we rely on

Running an agent means passing some data to a short list of services, each for a single purpose:

  • OpenRouterroutes your agent's messages to the AI models that generate its replies. Message content is sent at the moment your agent responds, so the model can answer.

  • Supabaseauthenticates your account — sign-in and sessions.

  • Telegramonly if you choose to connect a bot. When you do, messages pass between Telegram and your agent so it can reply in your pocket. Connect nothing and Telegram is never involved.

We don't hand your data to advertisers or data brokers.

05 · The short version

We do not sell your data, and we never will.

Your conversations and configs aren't a product we trade, rent, or share for marketing. They exist to run your agent — nothing more.

06 · Your rights

Your data stays yours, and you stay in control:

  • Accesseverything you've built is visible in your account.

  • Deleteyou can delete any single agent, or your whole account, from Settings. Deleting an agent removes its config and conversation history; deleting your account removes your agents and the account itself.

Deletion is permanent — that's the point of it.

07 · Retention

We keep your data while your account is active, so your agents keep working and remembering. When you delete an agent or your account, the associated data is removed. We don't hold onto data we no longer have a reason to keep.

08 · Security

Access to your data is authenticated and scoped to your account. Secrets and credentials live in protected configuration — never in code, logs, or this repository — and traffic to our services runs over encrypted connections. No system is perfectly secure, but we treat your conversations as private by default and design around that.

09 · Contact

Questions about your privacy, or want something removed that we haven't covered? Email loganjchandra@blimp.my and we'll help.