Privacy Policy
Last updated: July 23, 2026
1. Introduction
This Privacy Policy describes how Blockdis collects, uses, stores, and protects personal data when visitors use the Blockdis website, create an account, purchase a lifetime plan, or use the Blockdis desktop application and its connected API.
Personal data is processed in accordance with the General Data Protection Regulation (EU) 2016/679 ("GDPR") and applicable French data protection law.
2. Data controller
The data controller responsible for personal data is:
- Legal name: CHAARAOUI ABDELAZIZ
- Trading name: Blockdis
- Legal form: Sole proprietorship (individual entrepreneur / micro-enterprise)
- Country of establishment: France
- SIREN: 927 465 666
- SIRET: 927 465 666 00026
- RCS: 927 465 666 R.C.S. Versailles
- Contact: hello@getblockdis.com
3. Hosting and storage location
The Blockdis website, backend API, PostgreSQL database, and associated application data (account information, authentication records, saved block rules, and server logs) are hosted on servers operated by Hetzner in the European Union.
Personal data processed through the Service is therefore stored and processed within the European Economic Area, except where a third-party provider such as Stripe handles payment data under its own infrastructure.
4. Personal data collected
Blockdis stores account and block-rule data in a PostgreSQL database operated through the Blockdis backend API. Depending on how the Service is used, the following categories of data may be processed:
- Account data: name, email address, optional profile image URL, account creation and update timestamps, and last activity timestamp.
- Authentication data: password stored in hashed form (not readable in plain text), session tokens, session expiry dates, and optional session metadata such as IP address and user agent when a session is created. For password reset, a one-time verification code is generated and stored in hashed form until it is used or expires; the code itself is sent only to the email address associated with the account (or the address submitted for reset).
- Block rules saved to an account: website domains (for example,
example.com), application process names (for example,chrome.exe), and daily start/end times for each block. - Support communications: content of messages sent to hello@getblockdis.com.
- Server logs: technical information necessary to operate and secure the API, such as request metadata. Authentication headers and cookies are redacted from application logs where configured.
5. Data not collected
Blockdis does not store the following in the backend database:
- Browsing history, page visits, or full URLs with paths
- Keystrokes, screen content, or productivity analytics
- Contents of a hosts file or other local enforcement state on a device
- Lists of installed applications beyond process names explicitly chosen to block
- Payment card numbers or full payment credentials (collected and processed by Stripe at checkout, not stored in the Blockdis application database)
Local blocking on a computer (for example through the hosts file or process monitoring) happens on the device. That local processing enforces configured rules and is not continuously uploaded to Blockdis servers.
6. Desktop app and backend interaction
When a user signs in to the Blockdis desktop application, authentication occurs against the Blockdis API using a bearer token. The app may sync saved block rules between a device and an account so they can be restored on another device linked to the same account.
Creating, listing, or deleting a block rule through the app sends the relevant rule data to the Blockdis API. Blockdis does not receive a continuous stream of enforcement telemetry from a device.
7. Purposes and legal bases
- Account creation and management — performance of a contract (GDPR Art. 6(1)(b)).
- Authentication and session security — performance of a contract and legitimate interest (GDPR Art. 6(1)(b) and 6(1)(f)).
- Password reset by email — sending a one-time code to verify identity before a new password is set; performance of a contract and legitimate interest in securing accounts (GDPR Art. 6(1)(b) and 6(1)(f)).
- Storage and synchronization of block rules — performance of a contract (GDPR Art. 6(1)(b)).
- Payment processing at checkout — performance of a contract and legal obligation where applicable (GDPR Art. 6(1)(b) and 6(1)(c)). Payment details are handled by Stripe and are not stored in the Blockdis application database.
- Operation, security, and maintenance of the API — legitimate interest (GDPR Art. 6(1)(f)).
- Compliance with legal obligations — legal obligation (GDPR Art. 6(1)(c)).
8. Activity tracking and account retention
A last activity timestamp is maintained on each account. It is updated when a user authenticates or makes authenticated requests to the Blockdis API, subject to a throttle of at most once per hour per account.
An automated maintenance job deletes accounts that have had no backend activity for 3 years (this period may be configured in the infrastructure). The job runs daily, by default at 3:00 AM server time.
When an inactive account is deleted, associated data linked to that account is also deleted, including sessions, authentication records, and saved website and software block rules.
Account deletion may be requested at any time before the inactivity period expires by contacting hello@getblockdis.com.
9. Cookies and local storage
The Blockdis marketing website may use only strictly necessary cookies or similar technologies where required for basic functionality.
The Blockdis desktop application uses a locally stored bearer token and API requests for authentication. Browser cookies are not relied upon for authentication in the desktop app.
10. Recipients and processors
Personal data is not sold. Blockdis may rely on:
- Hetzner to host the Blockdis website, backend API, PostgreSQL database, and related infrastructure in the European Union
- Stripe to handle checkout and payment processing (payment card data is processed by Stripe in accordance with the Stripe Privacy Policy)
- Better Auth, the authentication library used to manage accounts and sessions
- Brevo (Sendinblue) to deliver transactional emails such as password-reset verification codes, in accordance with the Brevo Privacy Policy
These providers process data on behalf of Blockdis or under their own terms where applicable. Data may also be disclosed when required by law.
11. International transfers
Blockdis application data is hosted on Hetzner servers in the European Union and is not routinely transferred outside the European Economic Area for storage.
Some other service providers, including Stripe, may process data outside the European Economic Area. Where this occurs, appropriate safeguards are implemented as required by GDPR.
12. Data retention summary
- Account and block rules: kept while an account remains active.
- Inactive accounts: deleted after 3 years without authenticated backend activity, via the automated purge job.
- Sessions: kept according to session expiry managed by the authentication system.
- Password-reset verification codes: kept only until the code is used successfully or until it expires (whichever comes first), as managed by the authentication system.
- Server logs: retained for the period needed for security and operations, depending on hosting configuration.
- Billing records: retained for the periods required by applicable tax and accounting law.
13. Data subject rights
Under GDPR, data subjects have the right to access, rectify, erase, restrict, or object to certain processing of personal data, and the right to data portability where applicable.
To exercise these rights, contact hello@getblockdis.com. A complaint may be lodged with the CNIL (France).
14. Security
Technical measures include password hashing, authenticated API access, one-time codes for password reset (limited validity and attempt controls), and log redaction for sensitive headers. No method of transmission or storage is completely secure.
15. Changes to this policy
This Privacy Policy may be updated from time to time. The updated version will be posted on this page with a revised "Last updated" date.