Last updated 12 September 2026
This policy explains what Blockshot collects, why, and who else sees it. Grewbie Technologies Private Limited, S.F. No. 120/9A, Plot No. 22, Murugan Nagar, Pirattiyur, Tiruchirappalli, Tamil Nadu 620009, India, is the data controller. Contact us at support@grewbie.com.
We do not use your content to train AI models, and we do not sell your data or share it for advertising. We do not send marketing email unless you ask for it.
You can ask us to give you a copy of your data, correct it, delete it, or stop a particular use of it. Write to support@grewbie.com and we will respond within [30] days. You can also export any project from the studio at any time without asking us — File → Save .json.
If you are in a jurisdiction with a supervisory authority for data protection, you may complain to it. [If you serve users in India, name your Grievance Officer and their contact details here, as the DPDP Act requires.]
We set two cookies of our own, and both are necessary. One is an opaque session identifier that keeps you signed in; it is httpOnly, so no script can read it, and it carries no information about you. The other, bs_consent, remembers your cookie choice for a year so we do not ask again, and holds that choice and nothing else.
Everything else is optional, and what happens before you choose depends on where you are connecting from. In the European Economic Area, the United Kingdom, Switzerland and India, nothing from Google, Microsoft or Meta loads until you have answered the cookie banner. Everywhere else, Google Analytics and the Meta Pixel load when you arrive, and Microsoft Clarity stays off unless you turn it on. Wherever you are, the three are separate choices, because they are not the same kind of thing: one counts visits, one records your session, and one is for advertising. You can change any of them at any time from Cookie settings. Turning something off stops it loading on the next page you open; a script already running in this tab cannot be unloaded, so reload the page if you want it gone immediately. If your browser sends a Global Privacy Control signal, none of the three loads and we do not ask.
Google Analytics sets its own cookies to count visits and to tell a returning visitor from a new one. We use it to see which pages people arrive on and where they stop, not to build a profile of you: we do not send it your name, your email or anything you type into the studio. Blocking it changes nothing about how the product works. Google's handling of that data is covered by their privacy policy.
The Meta Pixel is an advertising tag, and you can turn it off under Advertising. It tells Meta that a browser visited a page here, so we can see whether our ads on Facebook and Instagram bring anyone to the site, and so those ads can be shown to people who have visited before. Meta can connect that visit to a Facebook or Instagram account signed in on the same browser. We do not send it your name, your email or anything you type into the studio, and its automatic collection of button clicks and page contents is switched off. Meta sets its own cookies. Its handling of that data is covered by its privacy policy, and you can limit ads based on your activity in your Facebook or Instagram ad settings.
Microsoft Clarity does something more than counting, and it is worth stating plainly: it records sessions. It replays how a page was used — where the pointer moved, what was clicked, how far the page was scrolled — so we can see where the tool confuses people. It reads the page as it is drawn, so it also sees text on screen. We mask the fields that carry your own work and your identity: the prompt boxes in the studio and your email address on the settings page are hidden from every recording. The 3D view is drawn on a canvas, which a recording cannot capture at all, so your scenes are not in them either. Clarity sets its own cookies. Microsoft's handling of that data is covered by their privacy statement, and you can turn recording off for every site that uses Clarity at their opt-out page.
The studio also uses your browser's local storage to keep a copy of your current scene so you do not lose work offline; that copy never leaves your device.
Traffic is encrypted in transit. Sessions are server-side and can be revoked. Device and IP values are stored as salted hashes rather than in the clear. API keys are held in AWS Parameter Store and never reach your browser. No system is perfectly secure, and we will tell you promptly if a breach affects your data.
The Service is not directed at children and we do not knowingly collect their data.
If we change this policy in a way that materially affects you, we will tell you by email or in the app before it takes effect.