blitz.cloudDeutschDESign inStart free

blitz.cloud privacy policy

Which personal data blitz.cloud processes, what for, on which legal basis, who receives it and how long we keep it.

Updated

This privacy policy applies to blitz.cloud: the website blitz.cloud, the dashboard at beta.blitz.cloud, sign-in at login.blitz.cloud and the interfaces api.blitz.cloud and mcp.blitz.cloud. It explains which personal data we process, what for, on which legal basis, who we pass it to and when we delete it. It exists in German and in English. If the two versions differ, the German one applies.

1. Controller

BlitzWorks UG (haftungsbeschränkt), represented by its managing director Simon Gloël, Graßer Weg 73, 93053 Regensburg, Germany, registered at the Amtsgericht Regensburg under HRB 21609, email hallo@blitzworks.io.

We have not appointed a data protection officer, because we are not required to. Please send questions about data protection to hallo@blitzworks.io or to the address above.

2. Where your data is

blitz.cloud runs on servers we rent from our data centre operator in Germany and operate ourselves. Your account, your apps, their files and their databases are stored there. Backup copies are kept separately, with the same operator, in the EU (Finland).

Some service providers process data on our behalf or receive it because you use their service. Each is named in the sections below. Where data goes to a country outside the EU, the section also says on which basis.

3. When you visit blitz.cloud

Cloudflare

Every request to blitz.cloud, beta.blitz.cloud, login.blitz.cloud, api.blitz.cloud and mcp.blitz.cloud passes through the network of Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA. Cloudflare delivers the pages, protects them from attacks and runs our name resolution (DNS). In doing so Cloudflare processes your IP address, the address requested, date and time, browser and device details and the content of the request, because Cloudflare accepts the encrypted connection and passes it on to our servers. Cloudflare may set a technically necessary cookie to recognise automated traffic (for example __cf_bm).

Cloudflare acts as our processor. The legal basis is our legitimate interest in secure and fast delivery (Art. 6(1)(f) GDPR). Cloudflare also processes data in the USA and at locations outside the EU that are closest to you. The transfer is based on the European Commission's adequacy decision for the EU-US Data Privacy Framework, under which Cloudflare is certified, and on standard contractual clauses. More at cloudflare.com/privacypolicy.

Server log files

With every request our servers process the technically necessary data (IP address, date and time, page requested, browser) to answer it and to detect faults and attacks (Art. 6(1)(f) GDPR). The log files are not collected in a central place and are overwritten continuously.

Fonts

We serve the Geist and Geist Mono fonts from our own servers. No fonts are loaded from Google Fonts or any other provider.

Visitor statistics with Matomo

We count visits to blitz.cloud and the dashboard with the open-source software Matomo, which we run ourselves at matomo.blitzworks.io, on our servers in Germany. No data goes to the makers of Matomo or to anyone else.

The statistics work without cookies and without access to your device. We process the shortened IP address (the last two blocks are removed before it is stored), the pages visited, the page you came from, date and time, browser and device type and your approximate region. In the dashboard we only record which kind of page was opened, such as "an app's overview", without names or identifiers of apps, without addresses and without account data. We respect "Do Not Track" and similar browser settings. The legal basis is our legitimate interest in measuring use of our own service with as little data as possible (Art. 6(1)(f) GDPR).

Only if you allow statistics cookies in the consent dialog does Matomo also set the cookies _pk_id (13 months) and _pk_ses (30 minutes) to recognise returning visits. The legal basis is then your consent (Art. 6(1)(a) GDPR, Section 25(1) TDDDG). You can withdraw it at any time with effect for the future: on blitz.cloud through "Cookie settings" in the footer, in the dashboard under Settings. The cookies are deleted when you do.

We do not measure the apps that customers run on blitz.cloud with Matomo.

We ask for your consent on the blitz.cloud website and in the dashboard with Clickio Consent, a Google-certified consent management platform under IAB Europe's Transparency and Consent Framework (TCF). The provider is ALZ Software Limited, 128 City Road, London EC1V 2NX, United Kingdom.

For this your browser loads a script from clickiocmp.com when a page opens. Clickio processes your IP address, to work out whether the dialog applies in your country, and details about your browser and device. Clickio stores your choice in your browser, in cookies for every address under blitz.cloud (13 months) so it applies on the website and in the dashboard, and passes it on to the providers you allowed or refused. The legal basis is our obligation to be able to prove consent (Art. 6(1)(c) together with Art. 7(1) GDPR). Storing your choice is technically necessary (Section 25(2) no. 2 TDDDG). The European Commission has adopted an adequacy decision for the United Kingdom.

You can change or withdraw your choice at any time with effect for the future: on the website through "Cookie settings" in the footer, in the dashboard under Settings.

Advertising with Google AdSense

On the free plan the dashboard shows one ad through Google AdSense, which helps pay for that plan. On Pro there is no ad, and the dashboard does not load Google's script. The blitz.cloud website includes Google's script so Google can review the site. There are no ads from us at sign-in, in the interfaces or in our customers' apps. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland ("Google").

When a page opens, your browser loads a script from Google (pagead2.googlesyndication.com). Google processes your IP address, the page requested (in the dashboard an address such as /apps/ with an internal identifier, no names), the page you came from, date and time, and details about your browser and device. Google uses this to deliver the ads, count views and clicks, settle payment with us and detect fraud. We do not pass account data, your email address or the content of your apps to Google.

Third party vendors, including Google, use cookies to serve ads based on a user's prior visits to this website or other websites. Google's use of advertising cookies enables it and its partners to serve ads to you based on your visits to this site and/or other sites on the Internet. Google and its partners only set or read such cookies and similar identifiers (such as web beacons) on blitz.cloud and in the dashboard if you agree in the consent dialog. Which providers these are, what they use the data for and how long they keep their cookies is listed in the consent dialog. The legal basis is then your consent (Art. 6(1)(a) GDPR, Section 25(1) TDDDG).

If you do not agree, we tell Google so through Consent Mode. Google then shows, where it can, only non-personalised or limited ads and sets no advertising cookies for them. Google still processes your IP address and the other details above to deliver the ad and detect fraud. The legal basis for that is our legitimate interest in paying for the free plan through advertising (Art. 6(1)(f) GDPR).

Google processes this data as a controller in its own right, also in the USA. The transfer is based on the European Commission's adequacy decision for the EU-US Data Privacy Framework, under which Google LLC is certified. How Google uses data on its partners' sites is explained at policies.google.com/technologies/partner-sites. You can also turn off personalised advertising from Google in Google's Ads Settings, and from many other providers at www.aboutads.info and www.youronlinechoices.eu.

4. Cookies and browser storage

The following are technically necessary and allowed without consent (Section 25(2) no. 2 TDDDG):

WhereNameWhat forHow long
beta.blitz.cloudblitz_session (split across numbered cookies when needed)Keeps you signed in. Holds your sign-in tokens, encrypted and unreadable to scripts on the pageuntil you close the browser or sign out
beta.blitz.cloudblitz_state, blitz_verifier, blitz_nextSecure the sign-in and remember where to go afterwards10 minutes
beta.blitz.cloudgh_returnRemembers which page to return to when you connect GitHub30 minutes
login.blitz.cloudCookies of the sign-in software Keycloak, such as AUTH_SESSION_ID, KEYCLOAK_IDENTITY, KEYCLOAK_SESSIONSign-in and sessionthe session, at most as long as the sign-in (section 5)
allCloudflare, see section 3Protection from automated trafficshort, as stated by Cloudflare
blitz.cloud and every address under it__lxG__consent__v2, __lxG__consent__v2_daisybit and __lxG__consent__v2_gdaisybit from Clickio, FCCDCF from Google, as cookies and in local storageStore your choice in the consent dialog13 months

In your browser's local storage (Local Storage and Session Storage) we also keep: your choice in the consent dialog, whether you want a light or dark look, an unsent draft in the wizard for new apps, and small notes such as "this tip was already seen". These entries stay on your device, are not sent to us and can be deleted in your browser's settings. Your choice in the consent dialog applies to every address under blitz.cloud. Our customers' apps run under those addresses too and can therefore read these cookies. They hold only your choice.

Only Matomo's statistics cookie and the cookies and identifiers for advertising on blitz.cloud and in the dashboard need your consent. Both are described in section 3.

5. Your account

Signing up and signing in

For sign-up and sign-in we run the software Keycloak ourselves, at login.blitz.cloud on our servers in Germany. When you sign up we process your email address and your password (only a hash is stored), and your name if you give it. If you set up a second step, we store what it needs: the secret for one-time codes or the public key of your passkey. We send you an email with a confirmation link. The contract for the free plan is made once you confirm.

The legal basis is performing the contract for blitz.cloud and the steps before it (Art. 6(1)(b) GDPR). At sign-up we also check whether the email address belongs to a disposable-address provider. That check runs against a list on our own server; nothing is sent anywhere.

Protecting sign-up with Cloudflare Turnstile

The sign-up form carries a Cloudflare Turnstile check, so accounts are made by people and not by scripts. For this your browser loads a script from Cloudflare when the form opens. Cloudflare processes your IP address and details about your browser and device and gives us a result, which we have Cloudflare confirm together with the IP address. The legal basis is our legitimate interest in preventing abuse and automatically created accounts (Art. 6(1)(f) GDPR). For the transfer to the USA, what section 3 says about Cloudflare applies. There is no such check when you sign in, or when you sign up with GitHub or Google.

Signing in with GitHub or Google

Instead of a password you can sign up and sign in with your GitHub or Google account. We then send you to GitHub (GitHub, Inc., 88 Colin P. Kelly Jr. Street, San Francisco, CA 94107, USA) or Google (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland). At the first sign-in we take your email address from there and, from Google, your first and last name. From GitHub we only ask for permission to read your email address, from Google for "openid email profile". We also store which GitHub or Google account belongs to your blitz.cloud account.

The legal basis is performing the contract (Art. 6(1)(b) GDPR), since you choose this way yourself. GitHub and Google process the sign-in under their own responsibility and their own privacy notices. GitHub processes data in the USA, based on the EU-US Data Privacy Framework.

Sign-in log and sessions

Keycloak logs sign-ins, failed sign-in attempts, changes to your password, passkeys and second step, and the sending of sign-in emails, each with the time and IP address. We use this to send you security notices, for example when your password was changed, and to detect attacks on accounts. After eight wrong passwords in a row Keycloak blocks sign-in for a while. The entries are deleted automatically after 30 days. The legal basis is our legitimate interest in keeping accounts secure (Art. 6(1)(f) GDPR).

A session ends after one hour without activity and after ten hours at the latest. Under Settings you can see where you are signed in (browser and operating system, IP address, start and last activity) and end single sessions.

6. When you use blitz.cloud

What we store

To provide the service we store for your account:

  • your email address, your name, your blitz.cloud address (such as lena.blitz.cloud) and your plan,
  • your apps with their settings, addresses and versions, your databases, custom domains and DNS records,
  • your apps' settings (environment variables, including passwords and connection details). We encrypt these before storing them,
  • build logs, meaning what was printed while an app was built, and for apps from GitHub the message of each commit,
  • an app's activity (deployed, restarted, went to sleep, restored) and a log of every change to your account: who (you, an AI assistant over MCP, one of our staff, or the system) did what and when,
  • traffic numbers per app (requests, data volume, errors), aggregated without IP addresses,
  • API keys (only as a hash) and the AI assistants you connected over MCP.

We show your apps' running output (logs) live. We do not store it in a database of our own. It stays on the server only until newer output overwrites it or the app restarts.

The legal basis is performing the contract (Art. 6(1)(b) GDPR). We keep the change log also out of legitimate interest, to be able to clear up errors, abuse and disputes (Art. 6(1)(f) GDPR).

Addresses and certificates

Addresses on blitz.cloud are public. HTTPS certificates are issued for them, and every certificate is listed in public logs (Certificate Transparency), as everywhere on the internet. Those logs show your main address and, for custom domains, their names. So don't pick an address name that says more about you than you want to make public.

How long we keep it

DataKept for
Account data, apps, databases, settingsuntil you delete them or your account
Build logs, versions and activity of an appas long as the app exists
Your account's change logno fixed period, also after the account is deleted, see section 13
Traffic numbers per app35 days
Sign-in log (Keycloak)30 days
Log of the emails we send youcontent 30 days, recipient, subject and time 180 days
Your address after a rename or deletionblocked for others for 14 days, so nobody takes it over at once
Backup copiessee section 11
Invoices and accounting recordsup to ten years, see section 9

7. Builds from GitHub

When you deploy a project from GitHub, blitz.cloud fetches the code of the chosen commit, builds an image from it and stores it in our own registry. For each project we keep the last ten versions that were online, so you can go back to an earlier one. Images of deleted apps are removed in the nightly clean-up.

Public projects are fetched without signing in to anything. For private projects and for automatic updates on every push you connect our GitHub App to your GitHub account. You decide at GitHub which repositories the app may access. For this we store the installation's identifier, the GitHub account's name and profile picture, and whether the app may access all or selected repositories. GitHub sends us a message on every push. You can disconnect the app at any time in your settings at GitHub.

The legal basis is performing the contract (Art. 6(1)(b) GDPR). GitHub is responsible for what GitHub itself does with your data.

8. AI assistance from Anthropic (Claude)

For some steps we use the language model Claude by Anthropic. Anthropic never receives account data, your email address or the values of your apps' settings. What Anthropic receives depends on the step:

  • When you set up an image from Docker Hub: the image's name and version, the ports and folders it declares, and the names of its environment variables.
  • When we write a Dockerfile for a project that has none, or improve it after a failed build: the repository's name and commit, the list of files, the content of project files such as package.json or requirements.txt, the start of the README and of the file the program starts in, and after a failure the Dockerfile that was used and the end of the build output.
  • When we explain why a build or start failed and suggest steps to fix it: the same project details, the end of the output, and also the app's name and address, the names (not the values) of its settings and the names of your other apps. This also applies to projects that bring their own Dockerfile.
  • When a project has several Dockerfiles and we work out which one is for what: the same project details and the project's Dockerfiles.

For a private repository this means parts of code you have not published. We keep the model's answers until your account is deleted, but not the questions. A Dockerfile written for a public repository is reused for the same repository for other customers too.

The legal basis is performing the contract (Art. 6(1)(b) GDPR), since these steps are part of what blitz.cloud does for you. The provider is Anthropic PBC, 548 Market Street, PMB 90375, San Francisco, CA 94104, USA. Anthropic processes the data in the USA. The transfer is necessary to perform the contract with you (Art. 49(1)(b) GDPR).

We use no other AI providers for blitz.cloud.

9. Paying for Pro through Stripe

When you buy Pro, we handle the payment through Stripe. The provider is Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin 2, Ireland. When you go to the payment page we create a customer record at Stripe with your email address, your name and your blitz.cloud account's identifier. You enter your payment details directly at Stripe; card and bank details never reach our servers.

Stripe processes your name, your email address, your billing address, for businesses the VAT ID, the payment details and information about subscription, invoices and payments. From Stripe we only receive whether and until when your subscription runs, and invoices and payment status.

The legal basis is performing the contract for Pro (Art. 6(1)(b) GDPR). We keep invoices and accounting records as long as tax and commercial law require, currently up to ten years (Art. 6(1)(c) GDPR together with Section 147 AO and Section 257 HGB). Stripe may also transfer data to the USA. The transfer is based on the European Commission's adequacy decision for the EU-US Data Privacy Framework, under which Stripe is certified, and on standard contractual clauses. More at stripe.com/privacy.

You can also cancel Pro without signing in, on the cancel page. For that we process the email address and name you enter there, and the reason if you give one, and send you a confirmation (Art. 6(1)(c) GDPR together with Section 312k BGB).

10. Emails

We send our emails from noreply@blitz.cloud through Google Workspace's mail relay. Google processes your email address and the email's content for this as our processor. The provider is Google Cloud EMEA Limited, 70 Sir John Rogerson's Quay, Dublin 2, Ireland. Google may also process data in the USA, based on the EU-US Data Privacy Framework and standard contractual clauses.

We email you about these topics:

  • Account, security, plan and billing, and service notices (maintenance, incidents, changes to the terms). You can't unsubscribe from these while you have an account, because they are part of the contract (Art. 6(1)(b) GDPR).
  • Notices about your apps: failed and successful deploys, stopped apps, finished restores, overnight updates, and once, two days after sign-up, a reminder if no app is online yet. They are on by default, and you can switch off each topic under Settings or with one click on the link in the email (Art. 6(1)(b) and (f) GDPR).
  • News about blitz.cloud, a few times a year at most, only if you switch it on under Settings (Art. 6(1)(a) GDPR). You can switch it off again at any time.

We keep a log of which email went to whom, so we can answer questions about delivery (Art. 6(1)(f) GDPR). We delete the content after 30 days and the entry after 180 days.

11. Backup copies

Every night we back up:

  • managed databases. We keep the copies for 7 nights on the free plan and 30 nights on Pro. Before every restore we save the current state, and that copy is kept for the same time.
  • on Pro, the files your apps keep. We keep these copies for 30 nights, the copy taken before a restore for 7 days.
  • the platform's own database, with all accounts and sign-in data. We keep these copies for 30 days, and an extra copy on our servers in Germany for 14 days.

All backups are encrypted before they leave our servers and are stored separately from them, with our data centre operator in the EU (Finland). The legal basis is performing the contract (Art. 6(1)(b) GDPR) and our legitimate interest in being able to restore the service after a failure (Art. 6(1)(f) GDPR).

12. Private networks with Tailscale or WireGuard

You can set apps to be reachable only from your own private network.

With Tailscale you sign in at Tailscale and so add a blitz.cloud device to your Tailscale network. The device is named after your address (such as blitz-lena), and your private apps show up in it under their names. Tailscale learns what it learns for every device on your network: the device's name, addresses and connection times. The connections themselves are end-to-end encrypted. Tailscale is your own provider and processes this data under its own responsibility and privacy notice. We store your Tailscale network's name, the name of our device in it, when its key expires and, if you connected Tailscale with an OAuth client, that client's secret, encrypted.

With WireGuard you upload a configuration file. We store it encrypted and only decrypt it to connect to your router. Nothing goes to third parties.

The legal basis is performing the contract (Art. 6(1)(b) GDPR). We delete the data when you disconnect the network or delete your account.

13. Deleting your account and downloading your data

Under Settings you can download everything we hold about your account as one JSON file. It includes the values of your apps' settings, which is why it asks for a sign-in within the last hour. The file does not contain your apps' files or what your databases hold. You can copy those yourself with your databases' connection details.

Under Settings you can also delete your account. We then:

  • remove your sign-in, which ends every session,
  • end a running Pro subscription at once,
  • delete all apps, databases, custom domains, DNS records, settings, build logs, traffic numbers and the AI's answers about your projects, and your apps' files together with the storage they were on,
  • delete the backup copies of your databases within a day and the backup copies of your app files the following night,
  • release your address again after 14 days.

What stays is a record without email address and without name that only carries the account's internal identifier, and the account's change log. Its entries hold that identifier and, where an action concerned one, the name of an app, a database or a custom domain. We keep it so we can still trace later what happened to an account, for example in a case of abuse or a complaint (Art. 6(1)(f) GDPR). We keep invoices as long as the law requires (section 9). Your account data remains in the platform database's backup for up to 30 more days, until those copies are deleted as scheduled.

If we close an account because of a serious breach of our terms, we keep its email address so that nobody can sign up with it again (Art. 6(1)(f) GDPR).

14. The content of your apps: us as processor

For personal data your apps process, such as your users' data in a database or the IP addresses of your app's visitors, you are the controller. We store and process it only on your behalf and on your instructions, as a processor under Art. 28 GDPR. You can get a data processing agreement by writing to hallo@blitzworks.io.

Requests to your apps also pass through Cloudflare (section 3), except on custom domains. Your apps' files and databases are stored on our servers in Germany, the backup copies in the EU (Finland). As section 8 describes, parts of your code may go to Anthropic during builds and troubleshooting. Beyond that we do not analyse your apps. We only count the requests from section 6.

15. Feedback and failure reports

When you write to us through "Give feedback" or "Missing a feature?" in the dashboard, your message goes by email to our inbox feedback@blitzworks.io, with your email address, your plan and the page you were on. When a build or deploy fails for good, we send ourselves a failure report to the same inbox. It contains your email address, your name, your address and your plan, details about the app and the repository, the build logs and the AI's answers. We use both to answer you and to improve blitz.cloud (Art. 6(1)(b) and (f) GDPR). The inbox is hosted by Google Workspace (section 10).

16. Who else sees your data

Within BlitzWorks, only the people who run blitz.cloud and help you see your data. Our data centre operator in Germany provides servers, network and the storage for backup copies and acts as our processor. We do not sell data. For advertising, data only goes to Google and its partners when you visit the blitz.cloud website, or the dashboard on the free plan, as section 3 describes. We never pass on data from your account or your apps for advertising. We only give data to authorities where the law obliges us to.

17. Your rights

You have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18) and data portability (Art. 20). You can withdraw consent at any time with effect for the future (Art. 7(3)). You can do much of this yourself in the dashboard: change your name and email address, download your data, delete your account. For everything else write to hallo@blitzworks.io.

Right to object

Where we process data on the basis of our legitimate interest (Art. 6(1)(f) GDPR), you can object at any time on grounds relating to your particular situation (Art. 21 GDPR). We then stop processing the data, unless we can show compelling legitimate grounds that override your interests, or we need it to establish, exercise or defend legal claims.

You can also complain to a data protection supervisory authority. The one responsible for us is the Bayerisches Landesamt für Datenschutzaufsicht, Promenade 18, 91522 Ansbach, Germany, www.lda.bayern.de.

18. Data you have to provide

For an account we need your email address, and for Pro also the details Stripe asks for to take the payment. Without them we cannot make a contract with you. Everything else is voluntary.

19. No automated decisions

We make no decisions based solely on automated processing that have legal effects on you or affect you in a similarly significant way (Art. 22 GDPR). What runs automatically are technical rules described in our terms and on our pages, for example that an app goes to sleep after two hours without visits or is stopped after 15 failed starts.

20. Changes

We update this privacy policy when blitz.cloud or the law changes. The version published here applies. We tell you about significant changes by email.