1. Who we are
BlinkPop (“BlinkPop”, “we”, “us”) is a mobile application and website operated by Tan Jin Xue, an individual based in Malaysia. We are the data controller for the personal data described here. There is no company behind BlinkPop yet — if that changes, we will update this page and tell you.
You can reach us about anything in this policy at hello@blinkpop.app.
2. Who can use BlinkPop
BlinkPop is for adults aged 18 and over. It arranges real-world meetings between people who may not know each other and it shares approximate location, and we are not equipped to make that safe for minors. We do not knowingly collect personal data from anyone under 18. If you believe a minor is using BlinkPop, email us and we will remove the account and its data.
3. What we collect
Information you give us
- Account details. When you sign in with Google or Apple, we receive your email address, your name, and your profile picture from that provider, along with an account identifier. We do not receive or store your password for those services.
- Your profile. Display name, username, gender, avatar, bio, the interest chips you pick, and any social or website links you add.
- What you post. Pops you create (title, description, vibes, place, time, capacity, cover image, and any informational price), posts, photos you upload, and messages you send in Pop chats and direct messages.
- Reports and blocks. If you report someone, we keep your report, including anything you write in it.
- Waitlist email. If you sign up on our website, we keep the email address you gave us until you ask us to remove it. The signup form runs a Cloudflare Turnstile check to keep bots out. It looks at your browser, not at what you typed, and Cloudflare states it does not use it to track you across sites.
Location
This is the part that deserves the most detail, because it is the part that matters most.
- Only while the app is open.BlinkPop requests “when in use” location permission and nothing more. It has no background location capability at all, so it cannot read your position when the app is closed or in the background.
- Blurred before it is stored.The location we save against your profile is rounded to roughly a 100-metre grid. This is not incidental — it exists specifically so that repeated “who’s nearby” lookups cannot be used to triangulate where you actually are.
- What it is used for. Showing Pops and people near you, calculating distances, sending nearby-Pop notifications if you turn them on, and confirming you are actually at a place when you check in (checking in requires being within about 150 metres).
- What it is never used for. We do not show your live position to other users, we do not build a movement history of you for our own purposes, and we do not sell location data to anyone.
- Places you publish are not blurred. The location of a Pop you create is content you are publishing to the people who can see that Pop, and it is stored and shown exactly as you set it.
Information collected automatically
- Session data. Your IP address and device user-agent are stored with your login session, for security and abuse prevention.
- Push token. If you allow notifications, we store the push token your device issues so we can deliver them.
- Server logs. Our hosting provider records standard request logs, which include IP addresses.
- Check-in and visit records.When you check in at a place, we record the live check-in (which stops being visible after an hour) and a durable visit record used for the “Regulars” feature.
What we do not collect
No contacts or address book. No advertising identifier and no App Tracking Transparency prompt, because there is nothing to track you with. No analytics SDK, no crash-reporting SDK, no advertising network. No payment details — BlinkPop never processes payments, and a price on a Pop is purely informational. No date of birth. No health, biometric, or financial data.
4. Why we use it, and our legal basis
Where European or UK data protection law applies to you, these are our legal bases:
- To provide the service — your account, profile, Pops, chats, discovery and check-ins. Basis: performance of our contract with you.
- To send you notifications you asked for — push notifications about your Pops, chats and nearby activity. Basis: your consent, given through the system permission prompt and the toggles in Settings, which you can withdraw at any time.
- To use your precise location for discovery, distance and check-in verification. Basis: your consent, given through the system location prompt, which you can withdraw in your device settings.
- To keep people safe — handling reports, blocks, bans and evasion of bans, and preventing spam and abuse. Basis: our legitimate interest in a safe service, and compliance with legal obligations.
- To fix and improve BlinkPop — investigating errors from server logs. Basis: our legitimate interest in a working product.
We do not use your personal data for advertising, for profiling that has a legal effect on you, or to train machine-learning models.
5. Who can see what
- Your profile — name, username, avatar, bio, links and interest chips — is visible to other signed-in users, and your public profile page on blinkpop.app is visible to anyone with the link. We ask search engines not to index personal profile pages.
- Pops.A public Pop and its participant list are visible to users who can find it. A private Pop is visible to the people invited to it. A Pop’s share link works for anyone who has it.
- Presence at a place.While you are checked in, other users can see you in “Here now” and “Regulars”. You can turn this off in Settings → Show me at places I visit. Turning it off hides you from those lists; the place still counts you in its anonymous totals, and your own visit history remains private to you either way.
- Chats. Pop chat messages are visible to members of that Pop. Direct messages are visible to you and the recipient.
- Approximate distance. Other users may see how far away you are, derived from the blurred location described above. They are never shown your coordinates or a live position.
6. Who we share it with
We do not sell your personal data, and we do not share it for advertising or cross-context behavioural advertising. We use the following service providers, who process data on our instructions:
- Cloudflare — hosting, network, and storage of uploaded images.
- Neon — our database, hosted in the United States.
- Google — sign-in, and place search. When you search for a place, your approximate coordinates are sent to Google Places to bias results towards where you are.
- Apple — Sign in with Apple, and delivery of push notifications to iPhones.
- Expo — delivery of push notifications and app updates. Note that the text of a notification, which can include the first part of a message someone sent you, passes through Expo and then Apple or Google in order to reach your device.
- OpenFreeMap — map tiles. Your device requests tiles directly, so OpenFreeMap receives your IP address and the area of the map you are looking at.
We may also disclose personal data where we are legally required to, to establish or defend legal claims, or to protect the safety of our users — and, if BlinkPop is ever transferred to a company or acquired, to that successor, subject to this policy.
7. Where your data goes
We are based in Malaysia, our database is hosted in the United States, and our hosting network is global. If you are in the European Economic Area or the United Kingdom, this means your personal data is transferred outside it. We rely on the European Commission’s standard contractual clauses, as incorporated into our providers’ terms, for those transfers.
8. How long we keep it
We keep your account data for as long as your account exists. Content you post, your messages, and your check-in and visit records stay until you delete them or delete your account. Live check-in visibility expires after one hour. Login sessions expire on their own.
We are candid about one gap: BlinkPop does not currently run automatic expiry of old messages or old visit records. If you want specific content removed sooner, delete it in the app or email us.
9. Deleting your account
Go to Settings → Delete account. You will be asked to type DELETE to confirm, and it cannot be undone.
This removes:
- Your account, profile, username and any host profile you created
- Pops you created, and their chats, members and invitations
- Your messages, chat memberships and blocks
- Your follows, in both directions
- Your posts and your check-in and visit records
- Your push tokens and your sign-in credentials
Two things deliberately survive. Reports that other people filed about you are kept as a moderation record — if deleting an account erased the reports against it, deleting and re-registering would be a way to wipe the slate. Invitation links you sent stay valid but are unlinked from you.
One thing we are still fixing. Images you uploaded may remain in our storage after deletion even though every reference to them is gone. We are aware of this and are correcting it. Until then, email us after deleting your account and we will remove them by hand.
10. Your rights
Wherever you live, you can ask us to give you a copy of your data, correct it, or delete it, and we will honour that. Much of it you can do yourself: edit your profile in the app, and delete your account from Settings. For anything else, email hello@blinkpop.app and we will respond within 30 days.
If you are in Malaysia, the Personal Data Protection Act 2010 gives you rights of access and correction, the right to withdraw consent, and the right to limit processing for direct marketing. We do no direct marketing.
If you are in the EEA or UK, you additionally have the right to object to processing based on legitimate interests, the right to restrict processing, the right to data portability, and the right to lodge a complaint with your local supervisory authority. Where we rely on consent, you can withdraw it at any time without affecting what we did before you withdrew it.
We will never charge you for making a request, and we will never treat you differently for making one.
11. Security
Traffic between the app and our servers is encrypted with TLS. Your session token is held in your device’s secure keychain. Access to our production database is restricted.
To be clear about the limits: your messages are not end-to-end encrypted. They are stored in our database in a readable form, which means we are technically able to read them. We access message content only to investigate a report or where we are legally compelled to. Please do not use BlinkPop to send anything you would not want stored this way. No service can promise perfect security, and we do not.
12. Cookies
The BlinkPop app does not use cookies. Our website uses only what is strictly necessary to serve the page — there are no analytics cookies, no advertising cookies and no third-party tracking pixels on blinkpop.app.
13. Changes to this policy
If we change this policy we will update the date at the top. For changes that materially affect your rights or how we use your data, we will give notice in the app or by email before they take effect.
14. Contact
Tan Jin Xue · Malaysia · hello@blinkpop.app
For how to report a user, delete your account, or get help, see our Support page.