Bluobird
  • Pricing
  • Docs
  • FAQ
Sign InSign Up
Bluobird

Plan, draft with AI, and schedule your posts on X — your content calendar on autopilot.

© Copyright 2026 Bluobird. All Rights Reserved.

Get Started
  • Sign In
  • Sign Up
  • Documentation
Legal
  • Terms of Service
  • Acceptable Use
  • Refund Policy
  • Privacy Policy
  • Cookie Policy

Privacy Policy

How Bluobird handles your data.

Last updated: September 12, 2026

This Privacy Policy explains what information Bluobird (“we”, “us”) collects, how we use it, and the choices you have. It forms part of our Terms of Service.

1. Information we collect

  • Account information — your email address and authentication details needed to create and secure your account.
  • Third-party API credentials — the X (Twitter) API keys and the optional OpenAI API key you provide. These are encrypted at rest and used only to operate the Service on your behalf.
  • Your content & configuration — the posts, prompts, workflows, rules, media, and schedules you create.
  • Usage & operational data — records of actions the Service performs for you (e.g. posts sent, run logs), used for billing limits, diagnostics, and support.
  • Technical data — standard log and device data needed to run and secure the Service.

2. How we use information

  • To provide, operate, and maintain the Service;
  • To execute the automations you configure (e.g. publishing to X with your credentials, generating text with your OpenAI key);
  • To meter plan usage and enforce limits;
  • To secure the Service, prevent abuse, and provide support; and
  • To comply with legal obligations.

We do not sell your personal information, and we do not use your content to train our own models.

3. Sub-processors we use

We rely on a small set of vetted providers (“sub-processors”) to run the Service. Each processes data only to provide its function to us:

  • Supabase — database, authentication, and file storage (your account, encrypted credentials, content, and media).
  • Vercel — hosting and content delivery for the web app.
  • Railway — hosting for the background worker that runs your automations.
  • OpenAI — when you use AI features with your own key, your prompt (and any data you interpolate into it, such as an API response) is sent to OpenAI to generate text, subject to OpenAI’s policies.
  • Google (Gemini) — used as the AI fallback when you have not added your own OpenAI key; your prompt is sent to Google to generate text.
  • X (Twitter) API — to carry out the actions you schedule, using your credentials.
  • Paddle — our Merchant of Record; handles checkout, payment, and tax. Payment details are provided directly to Paddle — we never store your card data.
  • Resend — sends and receives our account and transactional email.
  • Cloudflare (Turnstile) — bot/abuse protection on sign-up; processes limited technical signals (e.g. IP address) to verify you are human.
  • Sentry — error monitoring; may process technical error data to help us diagnose problems. We do not send it your API credentials or content by default.
  • API calls you configure — if you add HTTP API calls to a prompt, the Service sends requests to the URLs you specify; you are responsible for those destinations.

4. Security

We encrypt third-party API credentials at rest (AES-256-GCM) and use row-level access controls so each account can only access its own data. No system is perfectly secure, and you are responsible for keeping your own login credentials and API keys safe.

5. Retention & deletion

We keep your information for as long as your account is active or as needed to provide the Service. You can delete your account at any time from the app; doing so removes your associated data, except where we must retain limited records to comply with law or resolve disputes.

6. Your rights

Depending on your location, you may have rights to access, correct, export, or delete your personal information, and to object to or restrict certain processing. You can download a copy of your data at any time from Settings → Export your data, and delete your account and its data from Settings. For anything else, contact us using the details below.

California residents (CCPA/CPRA): we do not sell or share your personal information, and we will not discriminate against you for exercising your privacy rights. You have the right to know what personal information we collect, to access and delete it, and to correct inaccuracies — exercisable via the tools above or by contacting us.

7. Children

The Service is not directed to anyone under 18, and we do not knowingly collect personal information from children.

8. Changes

We may update this Privacy Policy from time to time. We will update the “Last updated” date and, for material changes, provide additional notice where appropriate.

9. Contact

For privacy questions or requests, contact privacy@bluobird.com.