What this policy covers
This one policy covers both places BLVCKOS™ exists:
- The website, where you read about BLVCKOS™ and start signing up
- The app, where you actually run the 30 days
It does not cover Whop, which is a separate company. Signing up happens on Whop's system, and their privacy policy governs that part. There is a section about this below.
Who we are
In this policy, "we" and "us" mean BLVCKOS™.
Everything in this policy is handled by a person reading email at blvckosapp@gmail.com. That address is how you reach us about your data, and it is the right address for every request in this document.
The short version
BLVCKOS is free and we collect very little. We do not sell your data and we do not use AI on anything you give us. The website runs Whop’s conversion pixel, which sets a cookie in your browser so Whop can tell that a signup came from our page. Ask us to delete your account and we will.
The specifics are below, including the parts that are less flattering, because a privacy policy that only tells you the good bits is not a privacy policy.
When you are just reading the website
We collect no details from you for reading the page. There is no account and no form, and we do not learn who you are as an individual. Whop’s conversion pixel does set a cookie, which is covered below.
Two things do happen, and you should know about both:
- Our host keeps standard server logs. Vercel, who serve the site, record the ordinary things every web server records: the IP address that made the request, the browser, the time and the page. We use these to keep the site up and to deal with abuse. We do not use them to build a profile of you
- Your country is worked out from your IP address when the signup page loads, so the phone field starts on the right country flag instead of guessing. Working it out is all that happens while you are only reading. But if you go on to fill the form in, whichever country the flag is showing is saved along with your details — so if you leave the flag as it was set for you, the country we end up holding is the one worked out from your IP address
- Whop’s conversion pixel runs when the page loads. It sets two cookies that last 400 days and tells Whop that the page was viewed, so Whop can connect a later signup back to it. It does not tell us who you are
- The home page opens a connection to Whop before you click anything. Whop hosts the signup, and the page gets that connection ready in advance so it is quick when you arrive. Nothing about you is sent and no cookie is set, but Whop's servers do see that a browser at your IP address made contact
Fonts
The website loads two typefaces, Montserrat and Space Mono, from Google Fonts. That means your browser makes a request to Google's servers, and Google receives your IP address and basic browser information as part of it.
No cookie is set by this, no account is involved, and we receive nothing from it. We are telling you because it is a request to a third party that happens on every page load, and a privacy policy that leaves it out is not complete.
When you enter your details to start
The signup page asks for four things before it hands you to Whop:
- Your first name
- Your last name
- Your email address
- Your phone number, and the country that number belongs to
There is also a hidden field on the form that you will never see. It exists to catch automated spam bots and it collects nothing about you.
Saved alongside those four, so we can tell one signup from another and see where it came from: the country shown on the phone flag, which page you were on, whether the signup completed or not, a random reference number generated for that visit, and the times the record was created and last changed. If you complete signup, the plan and receipt references Whop gives us are saved too. That is the whole row, so nothing in it can surprise you later.
Here is exactly what happens to those four things. They go to our own server, which passes them into a private Google Sheet that we use to run the program. That spreadsheet is our internal record of who has started. It is not public, it is not passed to anyone else, and it is not sold or given to anyone for their marketing.
The Google Sheet is worth calling out because people do not expect a spreadsheet. It is where a human on our side looks to see who has come in and how they are going.
This happens as soon as the four fields are filled in, which is before you have finished signing up. So if you fill the form in and then change your mind and close the page, we still have that record, and we may contact you about it. We are telling you because most signup forms do not work that way and you would have no way of knowing.
Why we are allowed to do that. We rely on our legitimate interest in not losing a signup halfway through and in being able to help you finish it. We are not relying on your consent for this, which matters to you rather than to us: it means you do not have to do anything to stop it and you never have to justify asking. Ask and it is deleted.
If you want that record gone, email us and we will delete it. No reason needed.
Signing up happens on Whop, not on our site
The actual signup runs through Whop, the platform that hosts the free BLVCKOS™ community. Whop is a separate company.
Your name and email address reach Whop at the same moment they reach us, so the checkout box opens with them already filled in. That happens before you have typed anything into Whop's own form, and before you have decided whether to go through with it.
- Whop collects its own information from you to create your account, and Whop's own privacy policy governs that, not this one. Read it at whop.com/privacy
- Whop sets its own cookies inside the checkout box on our page. We do not control them and we cannot see them
- We do receive confirmation of your membership from Whop, including your membership email address, because that is how the app knows you are a member
What the app collects
When you join
- Your first and last name
- Your email address
- Your timezone
We do not ask for a password. You sign in with a 6-digit code we email you.
If you choose to add one
- A profile photo. This is optional and BLVCKOS works completely without it
Because the challenge requires it
- Which accelerators you selected and locked in before starting
- Your challenge state: current day, start timestamp, whether you are in Pre-Challenge or Challenge Mode
- Your daily results: which requirements you marked complete, and the Green or Red day the app recorded at each 24-hour cutoff
- Your ledger: the running record of the 30 days
Automatically, while you use the app
- Basic app events, for example that a screen was opened or a day was finalized, so we can tell whether the product is working
- If a sign-in attempt is refused because the email is not on the member list, we record that attempt
What we do not collect, anywhere
- No advertising or analytics trackers of any kind
- No location or GPS
- No biometrics
- No proof uploads, no screenshots, no verification that you did anything
- No password, because there isn't one
BLVCKOS is integrity-based. You mark your own days. The app records what you said. There is nothing to surveil because we deliberately built it not to.
Cookies
On the website, Whop’s conversion pixel sets three. Two of them, named _wuid and _wuid_link, are stored against our address and last 400 days, and they are what let Whop recognise your browser. The third, __cf_bm, belongs to Whop’s own servers and lasts under an hour. The pixel also stores the same identifier in your browser’s local storage. You can clear or block all of them in your browser settings without losing anything on this site.
Whop also sets its own cookies inside its checkout box, described above. In the app, one session cookie keeps you signed in, and that is the only one.
About your profile photo, specifically
If you upload a photo, it is stored in a public storage bucket. That means it sits at a web address that does not require a login to open.
The address contains a long random identifier unique to your account, so it cannot be guessed, listed or browsed by anyone, and we do not publish it anywhere. But we are not going to tell you it is private, because technically it is not. If that matters to you, do not upload a photo. The app works exactly the same without one.
Why we hold it
- To run the 30-day challenge and keep your day count and ledger accurate
- To let you sign in and confirm you are a member
- To know who has signed up, so we can welcome you and help you start
- To see whether the product works, so we can improve it
- To answer you when you contact us
How we will and will not contact you
You give us an email address and a phone number when you sign up, so you are entitled to know what we will do with them.
What we will do. Contact you about BLVCKOS™: getting you started, your challenge, and things we genuinely think help you finish it. From time to time that includes telling you about our other work, including The Quantum World™.
What we will not do. Sell or rent your email address or your phone number. Give them to anyone else for their marketing. Add you to anything unrelated to what you signed up for.
About your phone number, specifically. We ask for it so we can reach you about your signup if email does not get through. We do not run marketing text campaigns. If that ever changes we will ask you first rather than assume, and any message we send will say who it is from and how to stop it.
How to stop it. Every marketing email we send carries a working unsubscribe link, and it works. Or just email blvckosapp@gmail.com and say stop, and we will stop. You do not have to explain why, and stopping marketing does not affect your access to BLVCKOS™.
Who we share it with
We do not sell your data and we do not share it for anyone else's marketing. These providers run the service:
| Provider | What it does | What it sees |
|---|---|---|
| Vercel | Hosts and serves the website and the app | Standard server request data, including your IP address |
| Google Fonts | Serves the two typefaces on the website | Your IP address and basic browser information, on each page load |
| Whop | The free BLVCKOS™ community, the signup, and the member list the app checks | What you give it at signup, under its own policy, plus your membership email, and through its conversion pixel that your browser viewed our pages |
| Google (Sheets and Apps Script) | Our internal member tracker | Your name, email, phone number and progress summary, so a human on our side can see how members are going |
| Supabase | Database, sign-in, photo storage for the app | Everything in the app section above |
| Google (Gmail) | Sends your 6-digit sign-in code | Your email address |
Where your data is stored
The providers listed above store and process data in more than one country, including the United States. Your information is therefore likely to be held outside the country you live in, and by using the website and the app you accept that.
Once information is in another country it is subject to that country's laws, and those may be weaker than the ones where you are. We chose providers we consider reputable and secure. We are not going to pretend that removes the point.
We do not use your data with AI
Nothing you give us is sent to an AI system, used to train a model, or processed by one. We use AI tools to build our software, the same way we use a code editor. Those tools never receive your personal information.
How long we keep it, and what Restart actually does
We keep your account data while your account exists, and the signup record in our internal tracker until you ask us to delete it. We are not going to quote you a tidy number of months: we do not run an automatic deletion job, so any number we printed here would not be true. Ask, and it goes.
Restarting BLVCKOS™ clears your challenge, not your account. It removes your challenge state, your daily records, your ledger and your locked accelerators, so you begin again at Day 1. It does not delete your account, your name, your email or your profile photo, which stay so you can keep using the app. If you want those gone as well, ask us to delete the account.
Your rights
You can:
- See what we hold about you. Ask and we will tell you. That includes the signup record in our internal tracker, not only your app account
- Correct it if it is wrong
- Delete your account and everything attached to it, including your profile photo and your entry in our tracker
- Stop us contacting you, without losing access
- Restart the challenge, which is different from deleting, see above
Email blvckosapp@gmail.com to do any of these. There is no self-service delete button in the app yet. A person reads your email and actions it by hand, within 30 days and usually much sooner. We would rather tell you that plainly than point you at a button that does not exist.
Depending on where you live, you may also have the right to complain to your local data protection authority. Please tell us first, so we get the chance to fix it.
Security
Every table in our app database uses row-level security, so the database itself enforces that you can only read your own rows. That is a rule in the database, not a check in the app that could be bypassed.
The website is served over HTTPS only, and the details you enter on the signup page are sent over an encrypted connection.
The exception is your profile photo, described above.
No system is perfectly secure and we will not pretend otherwise. If we ever have a breach that puts you at real risk, we will tell you.
Children
BLVCKOS™ is for adults. It is not intended for anyone under 18 and we do not knowingly collect data from anyone under 18. If you believe a minor has an account, tell us and we will delete it.
Changes to this policy
If we change what we do with your data, we will publish an updated policy and change the version number. Where a change is significant we will tell members directly.
Contact
Email: blvckosapp@gmail.com