1. Scope and responsibility
This Policy covers My Blurbly at www.myblurbly.com. My Blurbly determines why and how service data is processed. Privacy questions, access requests and objections can be submitted through Contact; no unverified email address or Information Officer identity is published here.
2. Information we handle
We handle account and authentication data; profile and role choices; public content you choose to publish; private messages, notes and workspace records; support and safety records; feature activity; consent choices; referral attribution; and limited payment evidence.
We do not store full payment-card details. PayFast hosts payment entry. Payment records can include a checkout reference, plan, amount, currency, status, timestamps and verified provider-notification evidence.
3. Why we use it
We process information to create and secure accounts, deliver requested features, preserve private work, publish chosen public content, operate payments and manual renewals, attribute qualifying Founder referrals, send requested service email, prevent abuse, respond to support or legal requests and improve the service where optional consent permits.
4. Current service providers
My Blurbly is hosted on Netlify and uses Supabase for production database, authentication and storage services. PayFast provides hosted payment processing. Brevo supports configured service email. Cloudflare supports DNS and security delivery where applicable. PostHog receives optional product analytics only after consent. Buffer is used only for a member's deliberately connected social-publishing integration where configured.
Providers act under their own terms and may process data in other countries. The International Data Processing Notice provides more detail.
5. Public and private boundaries
Published profiles, books, reviews, creator pages and public community activity may be visible to anyone. Drafts, unpublished manuscripts, ARC files, applications, private feedback, messages, payment evidence and account settings remain restricted by account and role controls.
6. Analytics, referrals and consent
Essential authentication and security storage works without optional analytics consent. PostHog page-view analytics is enabled only after the user accepts optional analytics. Autocapture and session recording are disabled in the current implementation.
A referral code may remain in the signup address and be recorded with the new account so a Founder referral can be assessed. Anonymous referral-visit analytics and the 30-day referral visitor cookie are created only after optional analytics consent. Users can reopen Cookie preferences from the footer.
7. Retention and deletion
Records are kept only as long as reasonably needed for the service, security, disputes, legal duties and the purposes described. Account closure removes or de-identifies eligible information, but transaction, fraud-prevention, legal, consent, safety and audit evidence may need limited retention.
8. Your privacy rights
Depending on applicable law, including South Africa's POPIA, you may request access, correction, deletion, restriction or objection and may withdraw optional consent. Identity and scope may need to be verified. You may also complain to the competent privacy regulator.
9. Security and international processing
My Blurbly uses access controls, restricted service credentials and operational safeguards appropriate to the service. No internet service can promise absolute security. Some providers process information outside South Africa; the international-processing notice explains the transparency and safeguards used.
About this publication
This is My Blurbly's current product-grounded policy text. It records operating rules and transparency commitments; it does not claim formal legal endorsement or attorney approval.

