Privacy Policy
Last updated: June 18, 2026
This policy explains what BlockDown collects, why we collect it, who else processes it, and what you can do about it. BlockDown is a block-based markdown editor operated by Codex42 Inc., based in Canada. It covers the marketing site at blockdown.io, the online app at app.blockdown.io, and the free BlockDown desktop app for Windows and macOS.
The short version
- The free desktop app works fully offline. It needs no account and does not upload your documents to us.
- If you create an online account, we store your email and the documents you choose to keep in the cloud.
- We do not sell your data. We do not run advertising, and we do not use third-party analytics or tracking cookies.
- Text you send to the AI writer or the spelling and grammar checker is processed by Anthropic to produce the result. It is not used to train models.
What we collect
Account data. When you create an online account we collect your email address and a password. Accounts are email plus password only; Google sign-in is currently disabled. Your password is never stored in readable form — it is hashed and stored by our authentication provider, and we cannot see it.
Your documents. Documents you create in the online app are stored in our database so you can open them from any device. Free accounts can keep up to 3 cloud documents; Pro accounts have no limit. We treat document content as private to you: we do not read it, mine it, or share it, except as needed to run the service (for example, storing and backing it up) or where the law requires it.
Subscription and billing status. If you subscribe to Pro ($9 per month), we store your plan status, subscription start and renewal dates, and the identifiers our payment processor gives us. Payments are handled by Stripe. BlockDown never sees or stores full card numbers.
Basic technical logs. Our servers record ordinary operational data such as IP address, browser and device type, the pages or API endpoints requested, timestamps, and error details. We use this to keep the service running, investigate faults, and detect abuse.
The free desktop app. The desktop app is a local editor. Your documents stay as files on your own computer, no account is required, and nothing you write is uploaded to BlockDown. If you sign in inside the desktop app to use cloud documents or Pro features, the online sections of this policy then apply to that activity.
How we use it
- To create your account, sign you in, and keep your session active.
- To store, sync, and display the documents you save to the cloud.
- To provide Pro features you ask for — AI writing (generate, continue, summarize, improve) and spelling and grammar checking.
- To take payment, manage your subscription, and apply the correct plan limits.
- To send service messages such as password resets, receipts, and important changes.
- To keep the service secure, prevent abuse, fix bugs, and meet legal obligations.
We do not use your document content to build advertising profiles, and we do not sell or rent personal data to anyone.
Service providers (subprocessors)
We use a small number of providers to run BlockDown. Each one only receives what it needs to do its job:
- Mortarbase — database, authentication, and storage hosting. Receives your account data (email, hashed password, account settings) and the documents you store in the cloud.
- Anthropic (Claude API) — AI features. Receives the text you send when you use the AI writer or the spelling and grammar checker, which may be a selection or the whole document. It is processed only to return a result to you and is not used to train models. If you never use these features, no document text is sent to Anthropic.
- Stripe — payment processing. Receives your billing details and card data, which you enter directly with Stripe. Stripe stores the payment method; BlockDown never receives full card numbers. We only receive the plan and payment status.
- Vercel — hosting for the web app. Processes requests to the app, including IP address and standard server logs.
- Hostinger — hosting for the marketing site. Processes requests to the public site, including IP address and standard server logs.
If we add or replace a provider, we will update this list and the "Last updated" date above.
Legal bases, in plain terms
- To deliver what you signed up for. Holding your account, storing your documents, and running AI or grammar requests you trigger are all necessary to provide the service you asked for.
- To meet a legal duty. Tax and accounting rules require us to keep certain billing records.
- Our legitimate interest. Keeping the service secure, preventing abuse, and diagnosing faults, balanced against your privacy.
- Your consent. Where we ask for it — for example, optional product emails. You can withdraw consent at any time.
How long we keep data
- Documents. Kept until you delete them. Deleting a document removes it from your account and from our live database.
- Account data. Kept while your account is open. Deleting your account removes your account record and the cloud documents attached to it.
- Backups. Deleted content may persist in encrypted backups for up to 30 days before those backups are overwritten.
- Technical logs. Kept for around 30 days, then deleted or aggregated.
- Billing records. Kept for as long as tax and accounting law in Canada requires, even after an account is closed.
Your rights
Whatever country you are in, you can ask us to:
- Access the personal data we hold about you.
- Export your data. You do not need to wait for us for your documents — you can export any document at any time from inside the editor as .md, .html, .pdf, or .docx.
- Correct anything inaccurate, such as your email address.
- Delete a document or your whole account.
- Object to or restrict certain processing, and to withdraw consent where we rely on it.
Depending on where you live you may also have the right to complain to a data protection regulator — in our case the Office of the Privacy Commissioner of Canada.
Security
- All traffic between your device and our servers is encrypted in transit over HTTPS.
- Data is stored on managed infrastructure with encryption at rest provided by our hosting provider.
- Our database uses row-level access control, so a signed-in account can only read and write its own rows. Users cannot read documents belonging to another account.
- Passwords are hashed by our authentication provider and are never visible to us.
- Access to production systems is limited to the people who need it.
No online service can promise perfect security, but we take these measures seriously and review them as the product grows.
Cookies
We use essential session and authentication cookies only — the cookies that keep you signed in and keep your session secure. We do not use advertising cookies, and we do not embed third-party analytics or tracking scripts. Because these cookies are strictly necessary to run the service, there is no tracking consent banner to click through.
Children
BlockDown is not intended for children. You must be at least 16 years old, or the minimum age required in your country, to create an account. We do not knowingly collect personal data from children. If you believe a child has created an account, contact us and we will delete it.
International transfers
We are based in Canada, and the providers listed above operate servers in several countries, so your data may be processed outside the country where you live. When data moves across borders we rely on the safeguards offered by those providers, such as standard contractual clauses and equivalent contractual protections.
Contact us about privacy
To make a privacy request — access, export, correction, or deletion — or to ask a question about this policy, email support@codex42.io. We will respond within 30 days. We may need to confirm that you control the email address on the account before we act on a request.
Postal address: Codex42 Inc., 2669 Southvale Cres, Ottawa, ON K1B 4V2, Canada, Canada.
Changes to this policy
We may update this policy as BlockDown changes. When we do, we will revise the "Last updated" date at the top. If a change materially affects how we handle your data, we will tell you by email or with a notice in the app before it takes effect. Continuing to use BlockDown after a change means you accept the updated policy.
This document is a starting template, not legal advice. Please have it reviewed by a qualified lawyer in your jurisdiction before you publish it.