BlackboxContact

Legal

Privacy Policy

Effective 2 October 2026

Who We Are

BlackBox operates digital applications and tools designed to support clarity, decision-making, and structured communication.

Our current products are Subtext and AppShip (app-ship.io). We may add further applications in the future.

We also contact selected UK businesses directly by post. Section 5 explains how that works and what data it involves.

If you have any questions about this policy, contact:

BlackBox
Website: https://black-box.solutions/contact
Email: alison@black-box.solutions

Scope of This Policy

This policy applies to:

  • The BlackBox website
  • Subtext — see section 3
  • AppShip (app-ship.io) — see section 4
  • Our direct mail to businesses, including the QR code pages — see section 5
  • Any future tools released under the BlackBox brand

Sections 3, 4 and 5 describe what each product or activity does with your data. Sections 6 onwards apply to every BlackBox product, to our direct mail and to this website.

Subtext

This section applies to Subtext only

AText Submitted for Analysis

When you paste text or upload content into Subtext:

  • The text is processed temporarily to generate your requested analysis.
  • The text is not stored after the result is returned.
  • We do not sell, share, or use submitted text for advertising purposes.
  • We do not use submitted text to train models.

Text is processed only to provide the service you requested.

BAccount Information (Pro Users Only)

If you upgrade to a Subtext Pro subscription:

  • You must create an account.
  • We may store your email address and subscription status.
  • Payment processing is handled by third-party providers. We do not store full payment details.

Free users are not required to create an account.

CHow Free Usage Limits Work

Free access may be limited to one analysis per device per day.

To enforce this limit:

  • A local device-based record may be stored in your browser.
  • This record does not contain your message content.

No account is required for free usage.

AppShip

This section applies to AppShip (app-ship.io) only

AppShip helps you submit an iOS build to Apple’s App Store Connect from your browser. To do that it needs to know who you are, act on your behalf with Apple, and pass your build file to Apple.

AYour Account

  • You sign in with your Google account. An account is required to use AppShip.
  • Google shares your name, email address and profile picture with us. These are kept with your account record by our sign-in provider, Supabase.
  • We also store your email address, your account role and settings (for example, admin or tester access) and the date you joined.
  • Your signed-in session is kept in your browser’s local storage so you stay logged in.

BApp Store Connect Credentials

To upload to Apple, AppShip asks for your App Store Connect API Key ID, Issuer ID and private key (.p8).

  • These are held in your browser only while the page is open.
  • Each time Apple needs a fresh token, they are sent over an encrypted connection to our server, which uses them to create a short-lived token (valid for 20 minutes) and returns it to your browser.
  • We do not save your private key, Key ID or Issuer ID to our database or logs.
  • They are cleared when you reset the form or close the page.

We recommend using an API key with the lowest role that can upload builds, and revoking it in App Store Connect when you no longer need it.

CYour App Build

  • Your .ipa file is read on your device and sent in parts, through our server, straight to Apple’s upload location.
  • We do not keep a copy of your build.
  • We keep a record of each upload: your email address, the App Store app ID, version and build number, file name and size, upload status, any error message, and the request and response of the final upload step with Apple.

This record lets you see your upload history and helps us fix failed uploads.

DPre-flight Checklist

If you complete the pre-flight checklist, we store your answers (for example, whether your app has a privacy policy or a developer account) and your progress, linked to your email address.

ESAL Assistant

  • Messages you send to SAL, the in-app assistant, are sent to our AI provider (Anthropic) to generate a reply.
  • We do not store your SAL messages.
  • Please do not paste your private key or other secrets into SAL.

FPayments

  • Payments are taken by Stripe on its own checkout page. We never see or store your card details.
  • We store your email address, the plan bought, the Stripe payment reference, the purchase date, the expiry date for annual plans, and how many submissions you have used.

GWho Processes AppShip Data

  • Supabase — database, sign-in and server functions (data stored in London, UK)
  • Vercel — website hosting
  • Google — sign-in
  • Apple — receives your build and the upload requests you make
  • Stripe — payments
  • Anthropic — SAL assistant replies

Some of these providers process data outside the UK. Where they do, we rely on the transfer safeguards they provide under UK data protection law.

HHow Long We Keep AppShip Data

  • Your account, upload records and checklist answers are kept while your account is open.
  • If you ask us to delete your account, we delete this data within 30 days.
  • Purchase records are kept for six years to meet UK tax and accounting rules.

ICookies and Tracking

AppShip does not use advertising or analytics cookies. It stores only your sign-in session and a note that you have seen the introduction screen, both in your own browser.

Direct Mail to Businesses

This section applies if we have posted something to your business

Sometimes I send a small printed item by post to a UK business I think we could help. If one reached you, this section explains why, what we hold about you and how to stop it.

AWhere We Got Your Details

  • The Companies House public register: the company name and number, its registered office address, and the name and role of one director.
  • The company’s own website: its web address and logo.
  • We take only a director’s name and role from the register. We do not collect or store dates of birth or other personal details.

BWhat We Do With Them

  • We post the item to the company at its registered office. It may be addressed to the director.
  • We print your company’s logo and a QR code on a card inside it.
  • We keep a record in a spreadsheet and a database, so we know what has been posted and do not contact you twice.

CIf You Scan the QR Code

  • The code opens a page on this website made for your company. It shows your company name. It does not show the director’s name.
  • We record that the code was scanned, when, and how many times. We do not record who scanned it.
  • As on every page of this site, the visit also appears in our basic visit statistics (see section 6).
  • Nothing you type is sent until you press the button. If you complete the automation check, we receive your answers and the email address you give, and use them to send you the summary you asked for.

DWhy We Are Allowed To Do This

Our lawful basis is legitimate interests. We think the owner of a business may find our services useful, and one piece of post is a small intrusion. We have recorded our reasoning in a legitimate interests assessment, which we can share on request.

EAsking Us To Stop

You can ask us not to contact you again at any time by emailing alison@black-box.solutions. We will stop straight away. Your right to object to direct marketing is absolute, and you do not need to give a reason.

We keep only your company number on a do-not-contact list, so that we do not add you again.

FWho Handles This Data

  • Google — spreadsheet and file storage
  • Supabase — database (data stored in London, UK)
  • Vercel — website hosting
  • n8n — workflow automation
  • Brave Search — used to find a company’s website; it receives the company name

Some of these providers process data outside the UK. Where they do, we rely on the transfer safeguards they provide under UK data protection law.

GHow Long We Keep It

  • Lead records are kept for up to 12 months after we add them.
  • If you get in touch, we keep your details while we are talking or working together.
  • Do-not-contact entries are kept so that we can honour your request.

Usage Data

We may collect limited usage information such as:

  • Which features are used
  • General device or browser type
  • Basic analytics data (e.g., visits and session duration)

This data is used to improve service performance and reliability.

Legal Basis (UK GDPR)

Where applicable, we process data under the following lawful bases:

  • Consent (when you choose to submit content)
  • Contractual necessity (to provide the service you signed up or paid for)
  • Legal obligation (to keep purchase records for tax purposes)
  • Legitimate interest (to maintain and improve our services)
  • Legitimate interests (to contact selected businesses by post about our services — see section 5)

Data Retention

Each product’s retention is set out in its own section above. In summary:

  • Subtext: submitted text is not stored after processing; Pro account data is kept while the account is active.
  • AppShip: account and upload records are kept while your account is open; purchase records are kept for six years.
  • Direct mail: lead records are kept for up to 12 months after we add them (see section 5).
  • You may request deletion of your account at any time.

To request deletion, contact alison@black-box.solutions

Third-Party Services

BlackBox may use third-party providers for:

  • Hosting and infrastructure
  • Sign-in
  • Language processing
  • Analytics
  • Payments and subscription billing

These providers process data only as necessary to provide their services.

Data Security

We implement reasonable technical and organisational safeguards to protect your data.

However, no online service can guarantee absolute security.

Your Rights

Depending on your location, you may have rights to:

  • Access your personal data
  • Request correction
  • Request deletion
  • Restrict processing
  • Object to processing
  • Request data portability

To exercise these rights, contact us at alison@black-box.solutions

If we have contacted your business by post, you can object to that at any time and we will stop (see section 5).

You can also complain to the UK Information Commissioner’s Office (ico.org.uk) if you are unhappy with how we have handled your data.

Children

BlackBox products are not directed at children under 13.

If we become aware that personal data has been collected from a child without appropriate consent, we will delete it.

Changes to This Policy

We may update this Privacy Policy periodically.

Changes will be posted on this page with an updated effective date.