Privacy Policy

This policy describes how MOBLUEHQ, Inc. (“MOBLUEHQ,” “we,” “us”) collects, uses, and shares personal information across three different shapes of product: locally-run desktop software, a hosted service, and evaluation software handed to design partners. Which parts apply to you depend on how you use MOBLUEHQ — each section below says which shape it covers.

1. Information we collect

Hosted service (blueMonster Premium; cloud tiers of blueMonster Pro and blueGlu)

  • Contact details (name, email) when you create an account or contact support
  • Billing information when you subscribe, processed by our payment processor (see §4)
  • Content you submit for processing (inputs, documents, prompts)
  • Device and browser type, IP address, and usage logs, collected automatically

Local desktop apps (blueMonster free/local tier, blueGlu local tier)

We collect nothing from local-mode use of the app itself — your inputs, outputs, and files never reach us; this is an architectural fact we verified by reading the local-mode code path, not a policy choice. If you create an account for a paid tier, or enable a cloud or bring-your-own-key feature, see the rows below for what changes. One exception, described in full in the next paragraph: blueMonster's install heartbeat runs by default, independently of any cloud or paid feature.

The install heartbeat. By default, roughly every 15 minutes while blueMonster is running, the app sends a small operational "install-ping" to our servers, whether or not you have enabled any cloud or bring-your-own-key feature. Reading the code that builds, sends, and receives it, the ping carries exactly these fields, and nothing else — the receiving server rejects the ping outright if a field it does not expect is present:

  • A pseudonymous installation ID. A random identifier generated once per install and stored in a file named installation_id inside blueMonster's local application-support folder on your device. It is not your name, your account, or a hardware serial number or MAC address. On receipt, our server transforms it with a one-way hash into a separate "analytics subject" identifier before anything is stored — the raw ID itself is discarded at that boundary and is not kept in the analytics database. Because the hash is repeatable, we can tell that pings received over time came from the same installation, without being able to reverse the hash back to the ID that produced it. If you later sign in to a blueMonster account on that same installation, our records can link that account to this installation's ping history — for example, so a support request can be tied to the right install.
  • App version and the specific build identifier (release SHA) of the copy of blueMonster you are running.
  • The time of the ping, and the version and timestamp of the consent notice your install last recorded.

The ping never carries your ideas, search content, files, directory paths, hostnames, or a device serial number. This is on by default: the underlying setting starts on, and pings continue until you turn it off. You can turn it off in the app's settings — toggle the Telemetry switch to disable check-ins. You can also set consent_telemetry to false in the app's local configuration file, or email privacy@mobluehq.com and we will turn it off for your install. Turning it off stops future pings; it does not remove pings we have already received — see §5 and §6.

When you enable a cloud or bring-your-own-key feature (either app)

The portion of your work needed to fulfill that specific request is sent to the third-party provider that feature uses. See §4 for exactly which providers, what each receives, and how we confirmed it.

Pilot / evaluation tools (blueAlibi, blueFloor, blueIntent, blueParity, bluePipeline)

We collect nothing. These tools run entirely on the design partner's own infrastructure; we verified no outbound network call exists in any of the five.

Launch waitlist (public website)

If you join a product's launch waitlist from our website, we collect the email address you provide and which product you asked to hear about. We use it only to send you a notification when that product ships, or occasional updates about it before then — see §2 and §5. Joining the waitlist does not create a MOBLUEHQ account.

2. How we use information

  • Provide, secure, and improve the services
  • Respond to inquiries and provide support
  • Process payments and send transactional messages
  • Comply with law and enforce our terms
  • With consent where required, send product updates — including the launch-waitlist notification described in §1
  • Tell whether an installed copy of blueMonster is in active use, via the install heartbeat described in §1 (meta-only: health, version, and counts — never your content)

3. Legal bases (EEA/UK)

Where GDPR applies, we rely on: performance of a contract; legitimate interests (security, improvement, fraud prevention) balanced against your rights; consent where required; and legal obligation.

4. Sharing & subprocessors

We share information only with the specific service providers named in the table on our Trust page, and only to the extent your product usage reaches them — the local desktop apps and the five evaluation tools reach none of them in normal operation. Each row on that page states what the vendor receives, which product sends it, and how we confirmed the status shown, rather than a generic description of vendor categories. We do not sell personal information. We may disclose information if required by law or to protect rights and safety.

5. Retention

We retain personal information only as long as needed for the purposes above, including to comply with legal obligations and resolve disputes. Account data is generally deleted within ninety days of account closure unless a longer period is required by law or your agreement. Verification inputs may be retained per plan settings; enterprise customers may negotiate custom retention. For local-mode use of the desktop apps, there is nothing to retain — we never received it. For pilot tools, retention is governed by the applicable pilot agreement, not this policy.

Install-ping records (§1) are kept indefinitely as of this writing. Our system has no automatic expiry or deletion job for them today; turning the setting off stops new pings from arriving but does not remove pings already received. We are stating this plainly rather than describing a retention period that does not exist in the code.

Launch-waitlist email addresses (§1) are held until we send the launch notification for the product you asked about, or until you ask us to remove you, whichever comes first — unless you separately become a customer, in which case ordinary account retention applies.

6. Deletion

You may request deletion of personal information, including a launch-waitlist signup, by emailing privacy@mobluehq.com. We will verify your identity and respond within the timeframe required by applicable law. Some data may be retained in backups or where retention is legally required.

Install-ping deletion works differently, because the record is keyed to a pseudonymous installation ID rather than your name or email. We can delete a specific install's ping history if you supply that installation ID (the file described in §1) or once it has been linked to your account by signing in on that installation. Without one of those, we have no reliable way to find the record to delete it.

7. Your rights

GDPR / UK GDPR

Depending on your location, you may have rights to access, rectify, erase, restrict, object, and port your data, and to withdraw consent. You may lodge a complaint with your supervisory authority.

California (CCPA/CPRA)

California residents may request access to, deletion of, and correction of personal information, and may opt out of “sale” or “sharing” (we do not sell personal information). You may designate an authorized agent. We will not discriminate for exercising these rights.

Submit requests to privacy@mobluehq.com.

8. Cookies

Our public marketing site does not set non-essential cookies today. When you sign in to a hosted MOBLUEHQ product, we use strictly necessary session cookies to keep you authenticated. The local desktop apps have no cookies at all. If we add analytics or preference cookies, we will update this section and, where required, obtain consent.

9. International transfers

We are based in the United States. If you access the services from other regions, your information may be processed in the U.S. and other countries where our subprocessors operate. When a cloud-escalation or bring-your-own-key feature is used, your data may also be processed in whatever country the vendor you configured (or, for blueMonster's cloud tier, Google) processes data in — that is layered on top of, not instead of, our own US-based processing. We use appropriate safeguards where required.

10. Children

Our services are not directed to children under 16. We do not knowingly collect their information.

11. Local-only products — stated plainly, because it is real and it is verified

The five evaluation tools (blueAlibi, blueFloor, blueIntent, blueParity, bluePipeline) and the local/free tiers of blueMonster and blueGlu transmit nothing to MOBLUEHQ or to any third party during normal operation. We did not infer this from an architecture diagram — we checked the source for outbound network calls and found none on the paths that matter. If that ever changes for a given product or tier, this policy and the subprocessor table on our Trust page will be updated first.

12. Changes

We may update this policy. Material changes will be communicated with reasonable notice. The version string recorded at signup identifies which policy you accepted.

13. Contact

Privacy inquiries: privacy@mobluehq.com · MOBLUEHQ, Inc., Delaware, USA