Privacy Policy
Last updated: June 27, 2026
ProjectBlock ("we", "our", "the service") is operated by Saad Kaicar, a sole proprietor based in Italy. This policy explains what data we collect when you use project-block.com and the ProjectBlock API, and how it is processed under the EU General Data Protection Regulation (GDPR).
1. What we collect
- Account data — the email address you sign up with, your plan, and your API key.
- Usage metering data — token counts, cost, model names, and timestamps for each metered API call.
- Audit log content — by default we store only a cryptographic hash of any prompt/response text you choose to pass us, never the raw text, unless you explicitly opt in to richer logging in the future.
- Payment data — handled entirely by Stripe. We never see or store your card details.
2. Why we process it
We process this data to provide the service you signed up for: metering AI usage, enforcing budgets, generating audit trails, and billing your subscription. Where required by the EU AI Act (Regulation (EU) 2024/1689, Article 12), audit records are retained for the period tied to your plan, as record-keeping evidence for AI systems you operate.
3. Who else sees it
We use a small number of infrastructure processors, all of whom only see what they need to run their part of the service:
- Supabase (Ireland, EU) — database storage
- Upstash — Redis usage counters
- Stripe — payment processing
- Resend — transactional email (login links, receipts)
- Fly.io — application hosting
We do not sell your data, and we do not share it with advertisers.
Some processors handle data outside the EU (for example, application compute on Fly.io may run in the US). Where this happens, we rely on Standard Contractual Clauses or equivalent safeguards maintained by each processor to keep your data protected to EU standards.
4. Your rights
Under GDPR, you can ask us to:
- Access the personal data we hold about you
- Correct inaccurate data
- Export your data in a portable format
- Erase your personal identifiers — for end-users metered through your account, this is available self-service via the
DELETE /v1/gdpr/user/{user_id}API. It permanently pseudonymizes the identifier while keeping the underlying timestamp, cost, and model fields, which we are required to retain for compliance purposes.
To exercise these rights for your own account data, email support@project-block.com. You also have the right to lodge a complaint with the Italian Garante per la protezione dei dati personali.
5. Data location & retention
Infrastructure is hosted within the EU where possible (Supabase: Ireland). Account data is kept for as long as your account is active. Audit log retention follows your plan: 30 days (Free), 1 year (Starter), 10 years (Pro/Business) — matching EU AI Act record-keeping windows.
6. Cookies
The dashboard uses no tracking or advertising cookies. We do not run any analytics scripts that profile individual visitors.
7. Changes
If this policy changes materially, we'll update the date at the top of this page and, for significant changes, notify active subscribers by email.
8. Contact
Questions about this policy: support@project-block.com