Legal

Subprocessors

Every third-party service that processes personal data to run Blank: what it does, what it receives, and where.

Last updated 23 September 2026

1.Providers that process personal data for us

Each receives only what its job needs. Those marked “when enabled” receive nothing unless that feature is switched on for this service and you use it.

  • OpenRouter, Inc.

    What for
    Routes build requests to AI models
    Receives
    Your prompts, the relevant contents of your project, the text of documents you attach, and which model runs the build. Not your name or email.
    Where
    United States
    Used
    Always
  • Model providers reached through OpenRouter

    What for
    Run the model that answers a build turn
    Receives
    What OpenRouter forwards for that turn. Which provider depends on the model: for example DeepSeek, Cloudflare, Anthropic, OpenAI, Google, Moonshot AI, Z.ai, NVIDIA or Meta. Free models may be served by providers whose own terms allow them to log prompts.
    Where
    United States, China, Singapore, the EU and elsewhere, depending on the model
    Used
    Always
  • Razorpay Software Private Limited

    What for
    Payments and subscriptions
    Receives
    Your email, your account id and the plan you chose. Razorpay collects your card, UPI or bank details itself on its own page; we never see them.
    Where
    India
    Used
    Always
  • PostHog, Inc. (EU cloud)

    What for
    Product analytics, sent from our server
    Receives
    Your internal account id and a short list of events — project created, build finished (with model and token counts), site published with its address, plan started or cancelled. Not your email, name, prompts or code.
    Where
    Germany (EU), for a US-incorporated company
    Used
    When enabled
  • Google LLC

    What for
    “Continue with Google” sign-in
    Receives
    The request to sign you in. Google sends us back your name, email address, profile picture and Google account id.
    Where
    United States
    Used
    When enabled
  • TinyFish

    What for
    Reads web pages and runs web searches for the builder
    Receives
    Web addresses you ask the builder to read, and the search queries it makes while building. Not your account details.
    Where
    United States
    Used
    When enabled
  • Unsplash and Pexels

    What for
    Stock photographs and video for generated sites
    Receives
    Search terms the builder chooses. Thumbnails in the image picker load in your browser straight from their servers, which therefore see your IP address.
    Where
    United States / Canada (Unsplash), Germany (Pexels)
    Used
    When enabled
  • Pixabay GmbH and GIPHY, Inc.

    What for
    Music, sound and short animated loops for videos
    Receives
    Search terms for the audio or loop a video needs. Not your account details.
    Where
    Germany (Pixabay), United States (GIPHY)
    Used
    When enabled
  • Video generation engines (Higgsfield, Runway, Luma AI, Kling)

    What for
    Generate video clips when you ask for one
    Receives
    The prompt and any reference image for the clip.
    Where
    United States (Higgsfield, Runway, Luma AI), Singapore (Kling)
    Used
    When enabled
  • esm.sh

    What for
    Serves the open-source libraries a published site loads
    Receives
    Requests from your site's visitors' browsers for React and other libraries, which include the visitor's IP address. Nothing from your account.
    Where
    Global content delivery network
    Used
    Always
  • Our hosting and network providers

    What for
    Run the servers, the database and the connection to them
    Receives
    Everything stored in the product, held on their infrastructure on our behalf, and the network metadata of every request, including IP addresses.
    Where
    May be outside India; see the privacy policy on transfers
    Used
    Always

2.Services you connect yourself

These are your own accounts, used only when you ask and under your agreements with them — not our subprocessors:

  • Supabaseyour project's database, in your own Supabase organisation.
  • GitHubrepositories the builder pushes your project to.
  • Cloudflare, Stripe, Sentry, Vercel, Netlify and otherstools the builder can use through integrations you connect.
  • Your own model provider keywhen you add one, build requests bill to your account.

3.Changes to this list

We update this page before a new provider starts receiving personal data, and change the date at the top. Account holders are told by email when a change affects what we disclosed in the Privacy Policy. Questions: [email protected].