Policies

Privacy Policy

This policy explains how The Block Enterprises handles information when you use theblock.me, a The Block workspace, or an authorized provider connection.

Last updated August 13, 2026

1. Information we collect

We collect information you provide, such as your name, email address, business profile, project requirements, conversations, files, approvals, and support requests. We also collect service records needed to operate and secure the product, such as authentication events, browser and device details, IP address, feature usage, audit events, and error diagnostics.

Payment card and bank details entered in Stripe-hosted payment surfaces are handled by Stripe. The Block receives billing status, transaction identifiers, amounts, and other records needed to administer your subscription or funded work; it does not receive full card numbers from Stripe Checkout.

2. How we use information

We use information to authenticate users, provide and improve the workspace, scope and deliver requested work, process billing, maintain security and audit trails, provide support, and comply with legal obligations. We do not sell personal information or connected-provider data, and we do not use connected-provider data for advertising.

The Block uses AI services for product features such as planning, research, chat, and approved implementation. Workspace inputs may be sent to an AI service provider when needed to fulfill a request. The Block does not use proprietary workspace information or connected-provider data to train its own general-purpose models, and it does not authorize its AI service providers to use that data to train their general-purpose models.

3. Figma connection

The Figma connection is read-only. After you authorize it, The Block stores encrypted OAuth credentials and basic connection identity. It requests only the Figma files or frames whose links or keys you intentionally paste into The Block; it does not browse or index your Figma workspace.

For an item you choose to import, The Block reads the selected file or frame metadata and image content needed to show and store its preview in Design Assets. That selected preview may be used as reference for design or implementation work you request in The Block. Figma credentials and imported content are not used for advertising or model training, and The Block does not write to or publish into Figma.

4. Stripe account connection

The Stripe account connection is separate from Stripe payment processing for your The Block subscription. If you authorize the account connection, The Block stores encrypted OAuth credentials and requests Stripe's Account record. The Block retains and uses only the connected account identity, country, test-or-live mode, and whether charges and payouts are enabled. This lets the workspace confirm which Stripe account is connected and whether it is ready for an approved project.

The account connection does not request customer, payment method, charge, payout, invoice, subscription, balance, or transaction-list endpoints. The Block does not initiate payments, refunds, transfers, or account changes through this connection.

5. Google services and Gmail status

For an available Google connection, The Block requests only the scopes shown on Google's consent screen and uses the returned data only to provide the feature you authorize. Google user data is not sold, used for advertising, or used to train general-purpose AI models. The Block's use and transfer of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements.

The Gmail connection is not available. The Block does not currently access, read, send, store, or process Gmail mailbox data through a Gmail connection. A disabled tile or documentation page does not grant The Block access to a mailbox.

6. Credentials, retention, and disconnection

Provider access and refresh tokens are encrypted, masked in the interface, limited to the authorized workspace, and retained while the connection remains active. Disconnecting a provider removes the stored connector credentials and stops new provider requests. You can also revoke access from the provider's own account settings.

Disconnecting does not silently delete content you intentionally imported into a workspace. Imported previews, source records, audit history, and project deliverables remain until you delete the applicable content or account, or until they are removed under The Block's normal retention obligations. Limited security, billing, dispute, and compliance records may be retained when required by law or a legitimate operational need.

7. Sharing and service providers

The Block shares information only with vendors that help operate the service, with people or providers you direct us to involve, when required by law, to protect users or the service, or as part of a business transaction subject to appropriate safeguards. Vendors may include hosting, storage, authentication, email, payment, monitoring, and AI processing providers. They receive only the information needed for their role and are not authorized to use it for their own advertising.

A provider you connect, such as Figma, Stripe, or Google, continues to handle information under its own terms and privacy policy. The Block sends requests to that provider only after you authorize the connection.

8. Security

The Block uses technical and organizational safeguards designed to protect information, including access controls, encryption for connector credentials, restricted service identities, and audit records. No internet service can guarantee absolute security. Please report a suspected security issue promptly and do not send passwords or tokens through ordinary support messages.

9. Your choices and requests

You may update account information, disconnect providers, revoke provider access, opt out of marketing messages, and request access to or deletion of personal information. Some records may be retained when legally or operationally required. Send privacy and deletion requests to support@theblock.me from the email address associated with your account so we can verify the request.

10. Cookies, children, and international processing

The Block uses cookies and similar storage needed for authentication, security, preferences, and service measurement. Browser controls can limit cookies, but required cookies are necessary to sign in. The service is not directed to children under 18, and The Block does not knowingly collect personal information from children.

Information may be processed in the United States and other countries where The Block or its vendors operate. Those locations may have different data-protection laws.

11. Changes and contact

We may update this policy as the service or legal requirements change. Material updates will be posted here with a new revision date. Questions, security reports, and privacy requests can be sent to support@theblock.me.