Privacy policy
Last updated
Who is responsible for your information?
Blendbyte GmbH, Friedrichstr. 155, 10117 Berlin, Germany, is the controller for personal information processed through the Textual website. Contact hello@blendbyte.com with privacy questions or requests; our legal notice contains further company details.
This policy covers the website, enquiries, new orders, and licence issuance and activation services operated by Blendbyte GmbH. Independent IRC networks and other third-party services have their own privacy information; we do not receive your IRC conversations through the checkout or licensing system.
Visiting the website
Your browser sends technical information needed to deliver a page, including your IP address, the requested address, request time, browser and operating-system information, and any referring page your browser supplies. Server and application logs may also record response codes and diagnostic information when an error occurs.
We process this information to deliver the website, investigate faults, and protect it against abuse. Our legal basis is our legitimate interest in operating a reliable and secure website under Article 6(1)(f) GDPR. This technical information is needed for the connection, but you do not need to provide a name or create an account to browse the public pages.
Cookies and local storage
The website uses first-party cookies for session continuity and request security. The session cookie, textual-session, identifies your session; XSRF-TOKEN helps protect requests against forgery. The session cookie expires after 120 minutes without renewed activity. The security cookie expires after 120 minutes unless renewed by another visit.
If you have an authorized account and choose “Remember me” when signing in, a separate cookie keeps you signed in for up to 400 days, unless you sign out or remove it sooner. You can delete cookies or block them through your browser, although signing in and other session-based features may then stop working.
Storage that is strictly necessary to provide a service you request is covered by § 25(2) TDDDG. Associated personal information is processed to provide that service or for our legitimate security interests under Article 6(1)(b) or (f) GDPR, as applicable. Optional storage requiring consent would only be used after that consent is obtained.
If you choose a light or dark appearance, we save that preference in your browser’s local storage as textual-appearance until you select System or clear your browser data. This setting stays on your device and is not sent to us.
We do not use advertising trackers. Images and core website assets are served locally, and the screenshot viewer does not store a tracking identifier. Optional website analytics and Paddle checkout are described below.
Contacting us and account access
If you use our contact form, we receive your name, email address, and message, which are sent to our support mailbox without creating a separate enquiry record in the website database. If you email us directly, we also receive any attachments and associated delivery information. We use these to respond and handle your request, relying on Article 6(1)(b) GDPR for contractual or pre-contractual enquiries and Article 6(1)(f) GDPR for other correspondence. Please only send information needed for your enquiry, especially when attaching chat logs.
For authorized website accounts, we also process the account name, email address, protected password credentials, and session or login-security information to manage access and prevent unauthorized use. We retain account information while access is needed and handle deletion requests subject to any legitimate security or legal retention requirements.
The contact form uses a hidden honeypot field, a form token, and timing checks to reduce automated spam without contacting an external CAPTCHA provider. We also keep a keyed hash of your IP address with a submission counter for ten minutes to limit repeated requests. We process this information under Article 6(1)(f) GDPR for our legitimate interest in protecting the form and our mail service against abuse. These checks may reject a submission; if that happens, you can contact us by email.
Downloads and other websites
Textual downloads are served through this website and use the technical information described above. Links to independent websites, including IRC networks and third-party projects in our documentation, take you to providers responsible for their own processing and privacy information.
IRC connections and activity within the desktop app are separate from browsing this website. Changes to other desktop services will be explained in the relevant privacy information before they change how we process personal information.
Recipients and international transfers
Blendbyte GmbH is responsible for operating this website and handling enquiries. Access is limited to authorized people and technical service providers who need the information to host the website, deliver email, or respond to you; website enquiries are not forwarded to Blendbyte Inc. in Taiwan. Service providers processing information on our behalf are subject to the data-protection obligations required by Article 28 GDPR.
We do not sell personal information. We may disclose information to professional advisers where necessary to establish or defend legal claims, or to authorities where legally required, relying on Article 6(1)(f) or (c) GDPR as applicable.
Following an external website link involves a separate provider, as explained above. Its processing locations and safeguards are described in its own privacy information.
Payments
Paddle provides our checkout as merchant of record and authorised reseller, acting as an independent controller for its payment, tax, fraud-prevention, and accounting activities. Its privacy policy identifies the relevant Paddle entities, recipients, international transfers, and safeguards. We send Paddle your email address, selected licence quantity, price, and an order reference when you continue to payment. Paddle may collect billing details, tax identifiers, payment information, and technical information directly; we do not collect or store your card number.
We retain the name chosen for the licence, purchase email, order and Paddle references, quantity, price and currency, payment and refund status, timestamps, and the version and acceptance time of the software terms. Paddle’s verified payment updates allow us to fulfil the order and handle refunds. We retain only the event references needed to process and retry these updates, rather than storing the full payment-event body. We use Article 6(1)(b) GDPR for order fulfilment and licensing, Article 6(1)(c) for applicable legal record-keeping, and Article 6(1)(f) for fraud prevention and reliable processing.
Licence issuance and activation
We associate the issued licence keys and signed licence files with your order and email address so we can deliver and support the licences. The signed file includes the licence name and purchase email address, so recipients of keys from a bulk order can see that address. Licence names, email addresses, recoverable keys, and signed files are encrypted in the database. A bulk purchaser receives a separate key for each licence and is responsible for sharing it only with its intended recipient.
When you activate Textual 7 through our service, we receive the key and technical request information, which may include the app version and language. We check the licence’s payment and revocation status and return its signed licence file. We keep a hashed-key activation counter for up to 24 hours and apply short-lived request limits to protect the service. Activation does not require a hardware identifier or access to your chat messages. Our bases are Article 6(1)(b) for providing the licence and Article 6(1)(f) for preventing abuse.
Fathom Analytics
We use Fathom Analytics, provided by Conva Ventures Inc. in Canada, to understand aggregate visits and improve the public website. When enabled, Fathom briefly processes connection information such as your IP address and browser user agent to create a daily, site-specific signature, then provides anonymised statistics. It does not use analytics cookies or build advertising profiles. Its data-processing explanation describes its short-lived security records and EU Isolation arrangements.
Our integration excludes checkout, order-status, and contact pages, sends page paths without queries or fragments, and reduces referrers to their website origin. We do not send emails, licence keys, order references, search terms, or form contents to Fathom. Our legal basis is Article 6(1)(f) GDPR, reflecting our interest in limited, privacy-conscious audience measurement. Fathom processes analytics on our behalf under a data-processing agreement; its privacy information and data-processing terms explain the provider’s safeguards.
We honour browser Do Not Track and Global Privacy Control signals. You can also disable analytics for this browser below; the preference is stored locally and applies to future page loads. Clearing browser storage removes that preference.
Anonymous aggregate statistics do not identify individual visitors. Fathom describes retention of short-lived security and request data in its data-processing explanation; we do not receive its raw IP-address records.
How long we keep information
We keep information only for the purpose for which it is needed. Uncompleted local orders without a Paddle transaction are removed after 30 days, and processed webhook references are removed after 30 days. Order and licence records are retained while needed to provide the continuing licence, resolve refunds or claims, or meet applicable accounting and tax-retention duties. Where a legal retention duty applies, we keep the required record for that statutory period and restrict its use to that purpose. Routine technical logs are retained for operational troubleshooting and security monitoring, then deleted when no longer needed for those purposes. Logs connected to a specific incident may be retained until the investigation is resolved and any related legal retention or claims requirements have ended.
Session information expires according to the periods described above and is cleared through routine session housekeeping. We retain correspondence until your enquiry is resolved, unless the record is still needed for a contract, a legal claim, or a statutory retention obligation. Information retained for those reasons is restricted to that purpose and deleted when the requirement ends.
Your rights
Under the GDPR, you can request access to your personal information, correction of inaccurate information, deletion, or restriction of processing where the relevant conditions are met. Where processing is automated and based on consent or a contract, you can also request a portable copy of information you provided.
You can object to processing based on legitimate interests for reasons relating to your particular situation. We will stop unless we demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or need the information for legal claims. You may object to direct marketing at any time.
If processing relies on consent, you may withdraw it at any time without affecting the lawfulness of earlier processing. Contact hello@blendbyte.com to exercise your rights; we may request proportionate information to verify your identity.
You may complain to a supervisory authority, particularly where you live or work or where an alleged infringement occurred. Our local authority is the Berlin Commissioner for Data Protection and Freedom of Information.
The website does not use automated decision-making or profiling that produces legal or similarly significant effects.
Changes to this policy
We update this page when our processing changes and show the revision date above. Where required, we provide a separate notice or request consent before using information for a new purpose.