Privacy Policy
Blast. Last updated 24 September 2026.
Blast has no server of its own. What you save and what you send live in your iCloud account and in the iCloud accounts of the people you send them to. We cannot read them. This policy explains the few things that do leave your device, why they leave, and what you can do about them.
Who we are
Blast is an iOS app for saving links into bundles and sending them to people you know. In this policy, "we" and "us" mean the developer of Blast, and "you" mean the person using it. If you are in the EEA or the UK, we are the data controller for the small amount of information described below.
You can reach us at privacy@blastit.space.
The short version
- We do not run a server that holds your content. Your bundles, saved links, messages, voice notes, pictures and stickers are stored in your iCloud, under your Apple Account, using Apple's CloudKit.
- We do not use analytics, advertising, attribution or crash reporting services. There are no third party SDKs in the app.
- We do not track you across other apps or websites, and we do not sell or share personal information.
- One thing is public by design: your username, so that friends can find you. Nothing else is.
- Sign in with Apple is the only way to sign in, and we ask it for your name only. We never ask Apple for your email address.
What Blast handles, and where it goes
| What | Where it is kept | Who can see it |
|---|---|---|
| Saved links, bundles, folder designs, your profile picture and name | Your device, and your own private iCloud database | You. Apple holds the encrypted store on your behalf. |
| Bundles you blast, messages, voice notes, photos, stickers and reactions | A shared iCloud area for that conversation | You and the people in that conversation. |
| Your username, an opaque account identifier and a one way hash of your Apple user ID | The app's public iCloud database | Anyone using Blast who searches for that username. We can see these records too. |
| Your display name next to that username | The same public record, only if you are discoverable | Anyone searching, until you turn discovery off. |
| Online status and how far you have read | The shared area of each conversation | The people in that conversation, unless you hide it in Settings. |
Sign in with Apple
Signing in gives Blast an opaque identifier for your Apple Account and, if you allow it, your name. We ask Apple for the name only. We never request your email address, so we never receive one, real or relayed. Your name is used to label what you send, so that your friends see who a bundle came from. Apple's own handling of Sign in with Apple is covered by Apple's privacy policy.
Your username
A username exists so that someone who knows your handle can send you a connection request. It is held in the app's public CloudKit database as one record per handle, containing the handle itself, an opaque CloudKit account identifier, a salted one way hash of your Apple user ID, the time it was claimed, and your display name if you have chosen to be discoverable. The hash is what lets the app recognise your own handle after you move to a new device. It cannot be turned back into your Apple ID.
This is the only part of Blast that is visible to people you have not connected with, and the only part we can read from the CloudKit dashboard. If you turn discovery off, your display name is removed from the record and only the handle remains.
What you save, and what you send
Saved links, bundles and their designs sit in your device's local store and in your own private iCloud database. Apple holds that data for you under your Apple Account. We have no access to it.
When you blast a bundle or send a message, it is written into a shared iCloud area for that conversation, which only you and the people you invited can open. That includes message text, voice notes, photos, stickers, reactions and the bundles themselves. Deleting a message for everyone removes it from that shared area, although anyone who already read it may have seen it, and a copy may remain on their device until their app next syncs.
Notifications
If you allow notifications, Apple's Push Notification service delivers a signal to your device telling the app to look for new items. The content of the notification is composed on your own device from data the app has already synced.
Blast+ subscriptions
Subscriptions are sold by Apple through the App Store. Payment details are handled by Apple and never reach us or the app. We receive only whether an active subscription exists on your device.
When something leaves your device to a third party
Websites you save from
When you save a link, Blast fetches that page directly from the website in order to read its title and preview picture. That request goes to the site itself, from your device, and the site sees it in the ordinary way a visit is seen, including your IP address. We do not receive anything from it. Nothing about what you save is sent to us.
GIF search
If you search for a GIF, the words you type and your IP address go to Tenor, which is operated by Google, in order to return results. This happens only while you are searching for a GIF. Tenor's handling of that request is covered by Google's privacy policy. No other part of Blast talks to Tenor, and no message content is ever sent there.
This website and invitation links
This website, blastit.space, is hosted by Cloudflare. When you open a page here, including an invitation link, Cloudflare receives the request in the ordinary way a website does, including your IP address and the address of the page, and keeps short lived logs to deliver the site and protect it from abuse. Cloudflare's handling of that is covered by Cloudflare's privacy policy. The site sets no cookies and runs no analytics, and we do not keep any record of who opens it.
An invitation link carries, inside its address, the iCloud link to the conversation it invites you to. If Blast is installed, your iPhone opens the link in the app and the website is not contacted. If it is not installed, the page only shows you how to get Blast, and it does not read, store or send on the invitation.
Apple
Blast is built on Apple's own frameworks: CloudKit for storage and sharing, Sign in with Apple for accounts, StoreKit for subscriptions, and the Push Notification service for alerts. Apple processes this data as described in Apple's privacy policy.
Things Blast deliberately does not do
- No analytics, product measurement or session recording.
- No advertising, and no advertising identifiers.
- No third party SDKs of any kind. Tenor is called directly over its web API and has no code inside the app.
- No App Tracking Transparency prompt, because there is nothing to track you with.
- No sending of your content to any artificial intelligence service. Pictures are checked for unsuitable content on your own device, and nothing is uploaded to do it.
- No selling or sharing of personal information, as those terms are used in United States state privacy laws.
How long things are kept
What is in your own iCloud stays until you delete it. What is in a shared conversation stays until you or the other people in it delete it, or until the conversation is left and its shared area is removed.
A username record stays while you hold the handle. When you change handles, the one you left is reserved for a short period so that nobody can take your name the moment you move off it, and is then released.
What you can do
- See and change what you hold. Everything Blast has about you is in the app itself. Items, bundles, conversations and your profile can all be edited or deleted in place.
- Hide your online status in Settings, and turn off discovery so your display name is not attached to your handle.
- Delete your account. Signing out and deleting the app removes the local store. To remove the iCloud copy, open Settings on your device, tap your name, then iCloud, then Manage Account Storage, and delete Blast's data. To remove your username record, write to us and we will delete it.
- Ask us. Write to privacy@blastit.space and we will answer. In practice the only records we are able to reach are the public username ones, because everything else is inside your own Apple Account and closed to us.
If you are in the EEA or the UK, you have the right to access, correct, delete, restrict and object to the processing of your personal data, and to lodge a complaint with your data protection authority. Our legal basis for the username record is our legitimate interest in letting people find each other, and for the rest it is the performance of our agreement with you. If you are in California, you have the right to know, delete, correct and opt out. There is nothing to opt out of, because we neither sell nor share personal information.
Children
Blast is not for children under 13, and we do not knowingly collect personal information from anyone under 13. If you believe a child has used Blast, write to us and we will remove what we can reach.
Where data is processed
Blast's data lives in Apple's iCloud infrastructure, which Apple operates across several countries. A GIF search reaches Google's Tenor service, which likewise operates internationally. Where personal data leaves the EEA or the UK, those transfers rely on the mechanisms Apple and Google respectively put in place.
Security
Data in transit is encrypted. Data in your private iCloud database is encrypted and reachable only by your Apple Account. Shared conversations are reachable only by their participants. No design is perfect, and nothing sent to another person can be unseen once they have read it.
Changes to this policy
If this policy changes in a way that matters, we will change the date at the top and, where the change is significant, say so in the app. Continuing to use Blast after a change means you accept the new version.