Bluefin

Privacy Policy

Effective 2026-09-11 · Draft pending legal review
Plain-language draft by the product team, not yet reviewed by a lawyer. We wrote it to be accurate about what the system actually does today.

What we collect about you

DataWhyWhere it lives
Name / handle you registerIt is the search term for monitoringOur tenant registry (AWS, us-east-1)
Email + passwordLogin, password reset, the daily emailAmazon Cognito (password is hashed; we never see it)
The mentions we find about youTo build your summary and answer your questionsPer-account storage and a per-account search index, isolated from other accounts
Which alerts we already sent youSo we don't repeat themPer-account storage
Request logs (IP, time, path)Abuse prevention and debuggingAWS logs, retained for a limited period

What we read about you — and what we don't

We only read public sources through their official interfaces: news (GDELT, Google News), the YouTube Data API, and — when enabled — Reddit and Twitch public search. We never read your direct messages, private comments, or anything behind a login; we do not scrape Instagram or TikTok; and we do not use facial recognition or any biometric matching. The full list of sources and their status is published in our source registry.

Other people who appear in your report

The mentions we show are public posts by other people. We store the post's title, link, and our automated read of it. We do not build profiles of those people, and impersonation flags are shown only to you, as proposals for your review.

Automated analysis

Summaries, sentiment, and impersonation scoring are produced by AI models run inside our cloud account (Amazon Bedrock). Your data is not used to train those models.

Email

We send a daily monitoring email and occasional alerts to the address you registered. Every email has a one-click unsubscribe link. Bounces and complaints are handled automatically so we stop mailing an address that rejects us.

Sharing

We do not sell or share your data. Our only processors are Amazon Web Services (hosting, email, AI models). We disclose data only if legally required.

Retention and deletion

Your data is kept while your account exists. You can delete your account yourself, instantly, from the dashboard footer (Manage my data) — this removes your registry entry, login, stored mentions, search index entries, and alert history immediately, not in 30 days. You can also download a copy of everything we hold about you from the same place before deleting it. If you cannot access your account, email support@bluefin.example (placeholder until the product domain is live) from your registered address and we will do it for you within 30 days.

Legal basis for monitoring

Bluefin processes two kinds of subject:

This is a product-level statement of the basis we believe applies, not a legal opinion. It has not yet been reviewed by a lawyer (see the draft notice at the top of this page). One feature is explicitly walled off from this reasoning rather than covered by it: our NCII/deepfake-exposure signal (ADR 0014) is restricted to self-subjects only and is not yet built — it is not available for third-party monitoring at all, regardless of this section.

Your rights

Depending on where you live (including under the GDPR and Brazil's LGPD), you can ask to access, correct, export, or delete your data, or object to processing. Use the contact above; we answer within 30 days.

Controller

[Operator legal name and address — to be completed on legal review.] Data is processed in the United States (AWS us-east-1).