Blip
Back to tryblip.app

Blip Privacy Policy

Effective: 13 September 2026
Last updated: 13 September 2026

The short version

  1. People see you type. In a Blip conversation, the others in it see your words as you write them, before you press send. That is what the app is, not a setting you forgot to turn off.
  2. Text you never send still passes through our servers, and is then deleted. It goes to the people you are talking to, and is removed the moment you send it, clear it, leave the conversation, switch away from the app, or lose your connection. It is never added to your message history, never put in a notification, and never written to a log. A copy stays on your own phone for up to seven days so a crash does not cost you your sentence.
  3. Blip is not end-to-end encrypted. Your data is encrypted in transit and encrypted at rest on Google's servers, but we could technically read it. The one routine time a person actually does is when someone files a report, which takes a copy of the reported message.
  4. Nothing here is collected for advertising or analytics. No analytics library, no advertising identifiers, no tracking across other apps, no location, no contacts, no payment details. Every kind of data Blip holds is there to make the app work. Section 3 lists them.
  5. You can delete everything from inside the app — Profile, then Delete account — and you have to be at least 13 to be here in the first place.

The rest of this document is the detail.


1. Live typing: what happens to text you have not sent

This is the part of Blip least like other messaging apps, so it goes first.

While you are typing in a conversation, your in-progress text is sent to the other people in that conversation and appears on their screens as you write it. Not a "typing…" dot — the actual words, in the place your message will sit once you send it. Within a conversation this cannot be switched off, because it is the app.

Here is exactly what happens to that text.

A copy of your own unsent text is also kept on your device, so coming back to a conversation does not lose your work. This is real storage, not a cache we can wave away, so here is how it is held: the file is written with iOS complete file protection, meaning it cannot be read while your device is locked, and it is excluded from device backups. It is deleted when you sign out or delete your account, and any draft more than seven days old is discarded. We check that when the app launches and again when you open that conversation, so an untouched draft can sit on your own phone slightly past the seven days until one of those happens.

Two other things live only on your device and never reach us: which conversations you have pinned, and which you have removed from your inbox. They sit in the app's own preferences, labeled with your account, and are cleared when you sign out or delete your account.

What no policy can fix. The people in your conversation can read, remember, screenshot or write down anything you type, including the sentence you decided not to send. Blip cannot prevent that and no technical measure could. Treat anything you type in a Blip conversation as something you have said.

2. Who is responsible for your information

Blip is made and run by Andrew Bui, an individual in California, United States. Blip is not a company. There is no team, no office, and no data protection officer — when this policy says "we", it means one person.

ForWrite to
Privacy, access to your data, deletion, anything about this policyprivacy@tryblip.app
Abuse, threats, safetysafety@tryblip.app
General helpsupport@tryblip.app
Legal and copyright noticeslegal@tryblip.app

3. What Blip collects

Apple asks every app to declare the kinds of data it collects, and Blip's declaration lives in the app itself, in PrivacyInfo.xcprivacy. This table is that declaration in plain words, and it is the whole list. Apple's categories are broad, so one row can hold several kinds of record — the User ID row below is the clearest example, and it names them.

Apple's categoryWhat that is, in BlipWhyTied to your accountUsed for tracking
Email addressThe address you sign in withTo identify your account, sign you in, let you reset your password, and contact you about the accountYesNo
NameYour display name and your usernameSo people you talk to can recognize you, and so people can find youYesNo
User IDYour account's internal id, your username claim, and the records keyed to that id: who is in which conversation, your block list, which conversations you have muted, when you last read one, your private nicknames for other people, the result of the age check, and the date you acknowledged live typingTo run the app: deliver messages, decide who may read what, and remember your own settingsYesNo
Emails or text messagesThe text of messages you send; the text you are typing but have not sent (section 1); the copy of a message kept in your in-app Notifications tab; and the copy of a reported message kept in a report (section 8)To deliver your conversations, and to act on reportsYesNo
Photos or videosPhotos and videos you send in a conversation, your profile picture, and group picturesTo deliver them to that conversation, and to show your pictureYesNo
Device IDThe push notification token for each device you allow notifications onTo send a notification to the right phoneYesNo

Everything in that list is used for one purpose: making the app work. None of it is used for advertising, analytics, or tracking, and none of it is sold or shared.

Where it lives:

WhatWhere
Email address, passwordFirebase Authentication
Display name, username, settings, age-check resultCloud Firestore, under users/{yourId}
Messages and reactionsCloud Firestore, under the conversation
Photos, videos, profile and group picturesCloud Storage
Unsent live text, and whether you are currently in a conversationFirebase Realtime Database, and nothing durable
ReportsCloud Firestore, under reports/
Your own unsent text, pinned and removed conversationsYour device

Your password

Your password is handled entirely by Firebase Authentication, which stores it as a salted hash. Blip's own code never receives it, never stores it, and never logs it. We cannot see your password, and it is not kept anywhere in a form anybody — including us — could turn back into the password you chose. If you forget it, the only thing we can do is help you reset it. That is not a limitation we are apologizing for; it is the point.

Date of birth

Asked once, at sign-up, to check you are at least 13, and then discarded. Section 9 sets out exactly what happens to it.

4. What Blip does not collect

This list is unusually short for a messaging app, and all of it is verifiable in the app's own build:

We also do not build a browsable directory of users. Our rules allow looking up one account by its exact username and specifically refuse any request to list accounts, so nobody — including another Blip user — can harvest the user base.

One honest footnote. The Firebase libraries Blip is built on report a small amount of their own technical information to Google as part of making a request, such as which Firebase components and versions are in use. It carries none of your content, we never see it, and it is not used to profile you. Google also keeps its own operational logs for the services Blip runs on, under Google's retention, which we do not control.

5. Photos and videos, and the metadata inside them

A photo or video straight from a camera usually carries hidden metadata, and the most sensitive part of it is where it was taken. Blip removes that before anything is uploaded.

Your photo library. The first time you tap attach, or choose a profile or group picture, iOS asks whether Blip may see your library. The alert is Apple's; we never re-skin it, and you can answer allow, limit to a selection, or don't allow.

6. Notifications

If you allow notifications, we send one when a message arrives for you.

7. Who else can see your information

Other people

What blocking does. Blocking stops someone sending you messages, stops their live typing reaching you, and stops anything they do producing a notification for you. It is enforced on our servers, not hidden in the app. Three limits, stated plainly: in a group you both belong to their messages still appear, because silencing someone in a shared conversation is the group admin's call and not a side effect of your private setting; it is not retroactive, so messages already in the conversation stay; and it is one way for messages — you can still write to them, and they still get a notification when you do. Live typing is the exception, because it belongs to the conversation rather than to either of you: a block switches it off in both directions, so you stop seeing them type, they stop seeing you, and neither of you shows as present there. A reaction stops writing a row to the top of either inbox for the same reason.

Service providers

Two companies are involved in running Blip, and no others.

Google (Firebase) is where Blip runs, and the only company we send your information to. Google processes it for us under Firebase's terms and does not use it for its own purposes.

Firebase serviceWhat it handles
Firebase AuthenticationYour email address, your password hash, and signing you in
Cloud FirestoreProfiles, usernames, conversations, messages, notification entries, reports, your settings
Realtime DatabaseLive unsent typing, and who is currently in a conversation
Cloud StoragePhotos, videos, profile pictures, group pictures
Cloud FunctionsThe server code that completes sign-up, runs the age check, sends notifications, handles reports, and deletes accounts
Firebase Cloud MessagingDelivering push notifications, together with Apple's service
Firebase App CheckConfirming a request came from a real copy of Blip rather than a script. On iOS this uses Apple's DeviceCheck, which produces a token for the device that Google verifies. It carries none of your content

Apple distributes the app and delivers push notifications to your phone.

There is no analytics vendor, no advertising network, no CRM, no email marketing tool, and no customer support platform holding your messages.

We do not sell your information, and we do not share it for anyone else's purposes.

We may have to disclose information in response to a valid legal demand — a court order or a binding request from law enforcement. If that happens we will look at whether the request is valid, narrow it where we can, and tell the affected user unless the law or a court forbids it. There is no transparency report today; if that changes, this policy will say so.

8. Reports, and how moderation actually works

This is the one routine way a person other than your conversation's members sees message content, so it deserves to be spelled out rather than summarized as "we may review content".

The honest limit. Blip is run by one person. Review is not instant, there is no 24/7 team, and nobody reads everything. If something is urgent or dangerous, write to safety@tryblip.app and block the person in the app, which takes effect immediately and does not wait for us.

How reporting works in more detail, including what a report does and does not capture, is set out in Safety and moderation.

9. Age, and what happens to your date of birth

You must be at least 13 to use Blip. People under 13 must not create an account. Blip is not directed to children, and we do not knowingly collect anything from anyone under 13.

When you sign up, Blip asks your date of birth once. Exactly what happens to it:

  1. It is sent once, over an encrypted connection, to our server.
  2. The server works out whether you are at least 13.
  3. It records only that you met the minimum, the date it checked, which rule it applied (a 13+ minimum), and that the age was self-declared rather than verified.
  4. The date of birth itself is never stored. It is not written to the database and not written to the logs — a failure records a reason code such as "underage", never the date. It exists only for the moment the check takes.
  5. If you are under 13, no account is created. Your device creates the sign-in credential first, so your password is only ever handled by Firebase Authentication; the age check then runs on our server; and if it says you are under 13, that same call deletes the credential before it answers. No profile, no username, nothing else is written. A date we cannot read is refused without deleting anything, so you can correct it and try again; a daily sweep removes any credential left without a profile behind it, whether sign-up was never finished or that deletion itself failed.

We do it this way because a date of birth is a permanent identifier, and keeping one for every user would create a risk far out of proportion to the question it answers.

The limit, stated plainly: this is a self-declared age check, not verification. Someone can type a false date. Stronger age assurance would mean collecting an identity document, a payment instrument, or a face scan, which would be a far larger intrusion on everyone.

If we learn that an account belongs to someone under 13, we delete it. If you are a parent or guardian and believe your child under 13 has an account, write to privacy@tryblip.app and we will delete it.

10. Security, stated precisely

No system is perfectly secure. If personal information is exposed in a breach, we will email the affected users without unreasonable delay — email, because that is the channel that exists — and notify the authorities where the law requires it.

11. How long things are kept

WhatHow long
Unsent live text, on our serversOnly while you are connected and typing. Deleted on send, on clear, on leaving the conversation, on backgrounding the app, and on disconnection
Unsent live text, on your deviceUp to 7 days, and deleted when you sign out or delete your account
Whether you are currently in a conversationNot retained. Removed when you leave or disconnect
Messages, photos, videosUntil you delete them, or until your account is deleted
A message removed for everyoneThe text and any photo or video are deleted. A marker stays so the conversation reads "Message removed" instead of quietly rewriting itself
A message you hid from your own viewThe record that you hid it, until you unhide it or delete your account. The message is untouched for everyone else
Account details, settings, age-check resultUntil you delete your account
Notification entriesUntil the message behind one goes away: retracting or deleting a message deletes the entry that quoted it. There is no dismiss — the tab is history, not a list you clear. All of yours go with your account
Push tokensUntil you sign out on that device or the token stops working
Reports12 months after resolution. Not deleted with either account involved (section 8)
An account created but never completedRemoved by a daily sweep, so up to about a day
Google's own operational logsGoogle Cloud's retention, which we do not control

12. Your choices

See and correct your information. Your display name, username and profile picture are editable in the app, in Profile. For anything you cannot see or fix there, write to privacy@tryblip.app.

Delete your account. In the app: Profile, then Delete account. It is not a deactivation. It removes:

For groups, you are removed from the membership and your messages are deleted, but the group continues for the people who remain. If you created it, admin passes to the member who has been in it longest, and they are told by a notification that names you, so they do not discover it by accident.

Three consequences worth being clear about:

Get a copy of your data. There is no export button today. If you want a copy of what Blip holds about you, write to privacy@tryblip.app and it will be put together by hand, which means it will not be instant. We would rather tell you that than advertise a mechanism that does not exist.

Turn things off. Notifications and photo library access are both yours to change any time in iOS Settings, and Blip keeps working with both switched off. Live typing is the one thing you cannot switch off inside a conversation, because it is what the app is — so the way to withdraw from it is to delete your account, which you can do yourself, in the app, in one place.

Block someone. Blocking is in the conversation's menu and in a person's profile, and takes effect immediately.

No retaliation. Using any of these choices will never get your account treated worse.

13. If you live in California

Andrew is a Californian, and many of Blip's users will be. To be straight with you about the legal position: a free app run by one person almost certainly does not meet the revenue or volume thresholds that make an operator a "business" under the CCPA and CPRA, so this policy does not claim that status. It offers you the substance of those rights anyway, as a matter of policy:

There is no sale of personal information and no sharing of it, in the CCPA sense or any other. No money and no data change hands, there is no advertising, and there is no cross-context behavioral advertising. We have no actual knowledge of selling or sharing the personal information of anyone under 16, because we do not sell or share anyone's.

Write to privacy@tryblip.app to exercise any of this. We will ask you to send the request from the email address on the account, because that is the only way we can tell it is you.

14. Where your data lives, and who Blip is for

Blip runs on Google Cloud in the us-central1 region, in the United States, and is operated from the United States. It is intended for users in the United States.

If you use Blip from outside the United States, your information is stored and handled in the United States, under United States law. This policy does not claim compliance with the GDPR, the UK GDPR or any other non-US data protection regime, and there is no EU representative — claiming otherwise would be the exact kind of promise this document is written to avoid. Access and deletion requests are honored for anyone who asks, wherever they are.

15. Changes to this policy

Every change updates the "last updated" date at the top, and where a change materially affects you we will also email the address on your account. There is no in-app notice of a policy change today, and this policy will not promise one before it is built. Smaller corrections — a clearer sentence, a fixed typo — just get the new date. The current version always lives at https://tryblip.app/privacy.

16. Contact

Questions about this policy, or about your information:

privacy@tryblip.app

Blip is operated by Andrew Bui, California, United States. See also the Terms of Service.