Privacy Policy

Last updated 27 August 2026

At a glance

BlinkPop is about meeting people in real life, which means it has to know roughly where you are. Here is the honest version of what that costs you.

  • We never track your live position. BlinkPop reads your location only while the app is open — never in the background — and no one is ever shown a moving dot of where you are.
  • Your stored location is deliberately blurred. We round it to about a 100-metre grid before saving it, so even we cannot work out your exact address from it.
  • No ads, no analytics, no trackers. There is no advertising network, no analytics SDK, and no crash reporter in BlinkPop. We do not sell or share your data for advertising, and we never will under this policy.
  • Direct messages are private, but not end-to-end encrypted. They are encrypted in transit and stored on our database. We can technically access them, and we only do so to investigate a report or where the law requires it.
  • You can delete everything from inside the app. Settings → Delete account removes your profile, Pops, messages and follows. Reports other people filed about you are kept.

This summary is here to be readable, not to replace the full text below. Where the two differ, the full text governs.

1. Who we are

BlinkPop (“BlinkPop”, “we”, “us”) is a mobile application and website operated by Tan Jin Xue, an individual based in Malaysia. We are the data controller for the personal data described here. There is no company behind BlinkPop yet — if that changes, we will update this page and tell you.

You can reach us about anything in this policy at hello@blinkpop.app.

2. Who can use BlinkPop

BlinkPop is for adults aged 18 and over. It arranges real-world meetings between people who may not know each other and it shares approximate location, and we are not equipped to make that safe for minors. We do not knowingly collect personal data from anyone under 18. If you believe a minor is using BlinkPop, email us and we will remove the account and its data.

3. What we collect

Information you give us

Location

This is the part that deserves the most detail, because it is the part that matters most.

Information collected automatically

What we do not collect

No contacts or address book. No advertising identifier and no App Tracking Transparency prompt, because there is nothing to track you with. No analytics SDK, no crash-reporting SDK, no advertising network. No payment details — BlinkPop never processes payments, and a price on a Pop is purely informational. No date of birth. No health, biometric, or financial data.

4. Why we use it, and our legal basis

Where European or UK data protection law applies to you, these are our legal bases:

We do not use your personal data for advertising, for profiling that has a legal effect on you, or to train machine-learning models.

5. Who can see what

6. Who we share it with

We do not sell your personal data, and we do not share it for advertising or cross-context behavioural advertising. We use the following service providers, who process data on our instructions:

We may also disclose personal data where we are legally required to, to establish or defend legal claims, or to protect the safety of our users — and, if BlinkPop is ever transferred to a company or acquired, to that successor, subject to this policy.

7. Where your data goes

We are based in Malaysia, our database is hosted in the United States, and our hosting network is global. If you are in the European Economic Area or the United Kingdom, this means your personal data is transferred outside it. We rely on the European Commission’s standard contractual clauses, as incorporated into our providers’ terms, for those transfers.

8. How long we keep it

We keep your account data for as long as your account exists. Content you post, your messages, and your check-in and visit records stay until you delete them or delete your account. Live check-in visibility expires after one hour. Login sessions expire on their own.

We are candid about one gap: BlinkPop does not currently run automatic expiry of old messages or old visit records. If you want specific content removed sooner, delete it in the app or email us.

9. Deleting your account

Go to Settings → Delete account. You will be asked to type DELETE to confirm, and it cannot be undone.

This removes:

Two things deliberately survive. Reports that other people filed about you are kept as a moderation record — if deleting an account erased the reports against it, deleting and re-registering would be a way to wipe the slate. Invitation links you sent stay valid but are unlinked from you.

One thing we are still fixing. Images you uploaded may remain in our storage after deletion even though every reference to them is gone. We are aware of this and are correcting it. Until then, email us after deleting your account and we will remove them by hand.

10. Your rights

Wherever you live, you can ask us to give you a copy of your data, correct it, or delete it, and we will honour that. Much of it you can do yourself: edit your profile in the app, and delete your account from Settings. For anything else, email hello@blinkpop.app and we will respond within 30 days.

If you are in Malaysia, the Personal Data Protection Act 2010 gives you rights of access and correction, the right to withdraw consent, and the right to limit processing for direct marketing. We do no direct marketing.

If you are in the EEA or UK, you additionally have the right to object to processing based on legitimate interests, the right to restrict processing, the right to data portability, and the right to lodge a complaint with your local supervisory authority. Where we rely on consent, you can withdraw it at any time without affecting what we did before you withdrew it.

We will never charge you for making a request, and we will never treat you differently for making one.

11. Security

Traffic between the app and our servers is encrypted with TLS. Your session token is held in your device’s secure keychain. Access to our production database is restricted.

To be clear about the limits: your messages are not end-to-end encrypted. They are stored in our database in a readable form, which means we are technically able to read them. We access message content only to investigate a report or where we are legally compelled to. Please do not use BlinkPop to send anything you would not want stored this way. No service can promise perfect security, and we do not.

12. Cookies

The BlinkPop app does not use cookies. Our website uses only what is strictly necessary to serve the page — there are no analytics cookies, no advertising cookies and no third-party tracking pixels on blinkpop.app.

13. Changes to this policy

If we change this policy we will update the date at the top. For changes that materially affect your rights or how we use your data, we will give notice in the app or by email before they take effect.

14. Contact

Tan Jin Xue · Malaysia · hello@blinkpop.app

For how to report a user, delete your account, or get help, see our Support page.

Questions about this page? Email hello@blinkpop.app.