Privacy Policy
This Privacy Policy explains how Superbloo, Inc. (“Superbloo”, “we”, “us”) collects, uses, stores, and shares personal information when you visit superbloo.com, sign up for an account, or use the Superbloo AI marketing platform (the “Services”).
01Who this policy applies to
This policy covers individuals who interact with Superbloo, including visitors to our marketing site, account holders, workspace members invited by an admin, and people who contact us by email or through the help form. If you use Superbloo through a workspace administered by your employer or another organization, that organization is the “Controller” of your workspace data and its own privacy notice may also apply.
02Information we collect
2.1 Information you provide directly
- Account details — name, email address, password hash, profile photo, and any other fields you fill in on your profile, supplied via our authentication provider (Better Auth).
- Workspace & billing details — workspace name, team members, role assignments, plan tier, and billing contact. Payment card data is collected and processed entirely by our payment processor (Dodo Payments); card numbers never reach Superbloo’s systems.
- Content you upload or generate — briefs, prompts, brand kits, product photos, videos, voiceovers, scripts, captions, canvas graphs, comments, and any AI-generated outputs produced on your behalf (collectively, “Customer Content”).
- Support communications — messages, screenshots, and screen recordings you share with our support and sales teams.
2.2 Information collected automatically
- Device & usage data — IP address, browser type, operating system, referring URL, pages and features used, timestamps, and crash diagnostics.
- Cookies & similar technologies — strictly necessary cookies for session management, plus optional web analytics and session-replay cookies. Web defaults depend on where you are; see section 9.
- Desktop telemetry — account-linked feature and screen usage, active/idle duration, performance, device class, errors, and session replay. This collection is always enabled in the installed desktop application.
- Generation telemetry — the model invoked, prompt length, output duration, and success/error status, used for metering, abuse detection, and quality improvement.
2.3 Information from third parties
- Identity providers — if you sign in with Google, Apple, GitHub, or another SSO provider, we receive your name, email, and a stable user identifier from that provider.
- Integrations — when you connect a third-party tool (e.g. TikTok, Meta, Shopify, Google Drive), we receive only the data covered by the scopes you authorize.
03How we use your information
We use personal information to:
- Provide, operate, and maintain the Services;
- Process AI generation requests by routing prompts and reference assets to the model provider you select (e.g. OpenAI, Anthropic, Google, fal, Replicate, ElevenLabs, Black Forest Labs);
- Store outputs and source assets in our object storage (Cloudflare R2) and database (Convex) so you can access them later;
- Bill you, prevent fraud, manage subscriptions, and reconcile invoices;
- Detect, investigate, and prevent abuse, security incidents, and policy violations (see our Acceptable Use Policy);
- Communicate with you about product changes, security alerts, policy updates, and — if you opt in — marketing;
- Improve and develop the Services, including aggregated, de- identified usage analysis.
04Legal bases for processing (EEA, UK, Switzerland)
If you are in the EEA, UK, or Switzerland, our legal basis for processing your personal information is:
- Contract — to provide the Services you signed up for.
- Legitimate interests — to keep the product secure, debug issues, prevent abuse, and improve features, where those interests are not overridden by your rights.
- Consent — for optional cookies, marketing communications, and any use of Customer Content for model improvement.
- Legal obligation — to comply with tax, accounting, and law-enforcement requirements.
05AI models and your content
Superbloo is a model-agnostic platform. When you run a generation we forward the prompt and any referenced assets to the third-party model provider you (or your workspace admin) selected for that node. We have data-processing terms with each of these providers that prohibit them from using your inputs or outputs to train their foundation models on a default basis.
Generated outputs are produced by probabilistic systems and may contain inaccuracies. You are responsible for reviewing outputs before publishing them and for complying with applicable laws (e.g. AI-disclosure rules, advertising regulations, and likeness rights).
06How we share information
We do not sell personal information. We share it only as follows:
- Subprocessors — vendors that help us run the Services, including infrastructure providers (Vercel, Cloudflare, Convex, AWS), AI model providers, our payment processor (Dodo Payments), email delivery (Resend), error tracking (Sentry), and product analytics (PostHog). A current list, including what each vendor receives and where it is hosted, is available at superbloo.com/subprocessors.
- Workspace members — Customer Content is shared with other members of your workspace according to the roles your admin sets.
- Business transfers — if Superbloo is involved in a merger, acquisition, or asset sale, your information may be transferred subject to standard confidentiality and continuity protections.
- Legal and safety — when required by law, valid legal process, or to protect the rights, property, or safety of users, the public, or Superbloo.
07International data transfers
Superbloo is headquartered in the United States and operates globally distributed infrastructure. When we transfer personal information out of the EEA, UK, or Switzerland, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses and the UK International Data Transfer Addendum.
Product analytics and error reporting are hosted in the European Union, so those categories do not leave the EEA in the ordinary course. Business customers can request a countersigned Data Processing Addendum, which incorporates those clauses.
08Data retention
We retain personal information for as long as your account is active and for a limited period afterwards as needed to comply with our legal obligations, resolve disputes, and enforce our agreements. You can delete individual projects, assets, and generations from inside the product at any time. Deleting your account triggers a 30-day grace period after which Customer Content is permanently removed from primary systems; encrypted backups expire on a rolling 90-day basis.
If your subscription ends — because you cancel, because a renewal payment fails, or because it expires — your workspace becomes read-only rather than closed. You keep full access to view and download everything in it for 30 days. During that window you can resubscribe at any time and your workspace is restored exactly as you left it; nothing is removed while the window is open.
We will email you when the window begins and again as the date approaches, and you can download your files at any point from your storage settings. If the subscription has not been reinstated by the end of that period, we permanently delete the uploaded and generated media in that workspace from primary systems — the files held in object storage. Your account, your workspace, and your project structure are retained; those projects will simply no longer contain media. Encrypted backups expire on the same rolling 90-day basis described above. Media deletion is irreversible and we cannot restore those files afterwards.
A workspace with an active subscription is never deleted on this basis, regardless of how much storage it uses or how long it has been inactive.
09Cookies & analytics
We use a small number of strictly necessary cookies to keep you signed in, remember your active workspace, and store your cookie preference. These cannot be turned off without breaking the product.
On the web, there are two optional categories: product analytics (which features you use, and a pseudonymous identifier that links your visits together) and session replay (a reconstruction of your clicks and navigation, used to diagnose bugs). Both are provided by PostHog and hosted in the European Union.
Web defaults depend on your region. If you are in the EEA, the UK, or Switzerland, both stay switched off until you opt in. Elsewhere they are enabled by default and you may switch them off at any time. Where we cannot determine your region, we apply the opt-in default. You can review and change your choice whenever you like from the cookie banner or at cookie settings.
The installed desktop application is different: account-linked product analytics, first-party usage records, crash reporting, and session replay are always enabled as part of the desktop service and cannot be disabled in the app. Desktop replay may reconstruct visible application text, prompts, transcripts, filenames, generated content, and, where supported, canvas or media surfaces.
We record a coarse location (country) derived from your IP address on the web in order to apply the correct cookie regime and understand where our users are. The desktop application does not send your IP address to our analytics provider.
Turning optional cookies off stops optional web measurement. It does not affect mandatory desktop telemetry, and it does not stop the server-side records we keep in order to operate and bill the Services — credits consumed, generations and exports run, storage used, and subscription events — which are processed on the contract and legitimate-interest bases in section 4 and are tied to your account rather than to a cookie. Error and crash reports are likewise sent regardless, scrubbed of personal content before transmission.
10Your rights
Depending on where you live, you may have the right to access, correct, delete, or port your personal information; to object to or restrict certain processing; and to withdraw consent. To exercise these rights, email privacy@superbloo.com or use the in-product data controls. We will respond within the timeframe required by applicable law. You can also lodge a complaint with your local data-protection authority.
10.1 California residents
We do not “sell” or “share” personal information for cross-context behavioral advertising as those terms are defined by the CCPA/CPRA. California residents have the right to know, delete, correct, and limit the use of sensitive personal information. You may exercise these rights via privacy@superbloo.com.
11Children
Superbloo is not directed to children under 16. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact privacy@superbloo.com and we will delete it.
12Security
We protect your data with encryption in transit (TLS 1.2+) and at rest, scoped access controls, least-privilege service accounts, continuous logging, and routine security reviews. Our Security page describes these controls in detail. No system is ever 100% secure; if you believe your account has been compromised, contact security@superbloo.com immediately.
13Changes to this policy
We will update this policy from time to time. If we make material changes, we will notify you by email or via an in-product notice before the changes take effect. The “Last updated” date at the top of this page always reflects the latest version.
14Contact us
For any privacy-related question or request, contact our team:
Superbloo, Inc.Attn: Privacy Team
San Francisco, California, USA
privacy@superbloo.com
