Privacy Policy
What we collect about you
| Data | Why | Where it lives |
|---|---|---|
| Name / handle you register | It is the search term for monitoring | Our tenant registry (AWS, us-east-1) |
| Email + password | Login, password reset, the daily email | Amazon Cognito (password is hashed; we never see it) |
| The mentions we find about you | To build your summary and answer your questions | Per-account storage and a per-account search index, isolated from other accounts |
| Which alerts we already sent you | So we don't repeat them | Per-account storage |
| Request logs (IP, time, path) | Abuse prevention and debugging | AWS logs, retained for a limited period |
What we read about you — and what we don't
We only read public sources through their official interfaces: news (GDELT, Google News), the YouTube Data API, and — when enabled — Reddit and Twitch public search. We never read your direct messages, private comments, or anything behind a login; we do not scrape Instagram or TikTok; and we do not use facial recognition or any biometric matching. The full list of sources and their status is published in our source registry.
Other people who appear in your report
The mentions we show are public posts by other people. We store the post's title, link, and our automated read of it. We do not build profiles of those people, and impersonation flags are shown only to you, as proposals for your review.
Automated analysis
Summaries, sentiment, and impersonation scoring are produced by AI models run inside our cloud account (Amazon Bedrock). Your data is not used to train those models.
We send a daily monitoring email and occasional alerts to the address you registered. Every email has a one-click unsubscribe link. Bounces and complaints are handled automatically so we stop mailing an address that rejects us.
Sharing
We do not sell or share your data. Our only processors are Amazon Web Services (hosting, email, AI models). We disclose data only if legally required.
Retention and deletion
Your data is kept while your account exists. You can delete your account yourself, instantly, from the dashboard footer (Manage my data) — this removes your registry entry, login, stored mentions, search index entries, and alert history immediately, not in 30 days. You can also download a copy of everything we hold about you from the same place before deleting it. If you cannot access your account, email support@bluefin.example (placeholder until the product domain is live) from your registered address and we will do it for you within 30 days.
Legal basis for monitoring
Bluefin processes two kinds of subject:
- You, monitoring yourself. The basis is your consent — you created the account and named yourself as the subject.
- A third party, monitored by a Brand/Agency account. This is a public figure acting in a public role (ADR 0011). We do not ask them for consent because we have no relationship through which to ask, and the product design deliberately keeps this narrow to make a legitimate-interest basis defensible: we read only what that person or their team already made public, we apply no biometric or facial-recognition processing (ADR 0003's bright line), impersonation and image-exposure findings are shown to the paying tenant as proposals for review — never auto-published or auto-acted — and the third party's own data-subject rights (access, objection, deletion of what we hold about the mentions of them) can be exercised through the same contact as any other request.
This is a product-level statement of the basis we believe applies, not a legal opinion. It has not yet been reviewed by a lawyer (see the draft notice at the top of this page). One feature is explicitly walled off from this reasoning rather than covered by it: our NCII/deepfake-exposure signal (ADR 0014) is restricted to self-subjects only and is not yet built — it is not available for third-party monitoring at all, regardless of this section.
Your rights
Depending on where you live (including under the GDPR and Brazil's LGPD), you can ask to access, correct, export, or delete your data, or object to processing. Use the contact above; we answer within 30 days.
Controller
[Operator legal name and address — to be completed on legal review.] Data is processed in the United States (AWS us-east-1).