Privacy Policy
AI-Powered Event Decor, Designed in Seconds
Effective Date: June 10, 2026
Last Updated: July 13, 2026
Poppy Blum LLC | Minnesota, United States
Important notice
This Privacy Policy applies to all users of Poppy Blum worldwide, including users in the European Union (GDPR), California (CCPA), Canada (PIPEDA), and other jurisdictions. By using our services, you agree to the practices described in this policy. If you do not agree, please do not use Poppy Blum.
1. Introduction
Poppy Blum LLC (“Poppy Blum,” “we,” “us,” or “our”), a limited liability company registered in Minnesota, United States, operates the web application available at poppyblum.com (the “Service”). This Privacy Policy explains how we collect, use, disclose, and protect your personal information when you use our Service.
We are committed to protecting your privacy and being fully transparent about our data practices. This policy is written in plain language so you understand exactly what we do (and do not do) with your information.
If you have questions about this policy, you may contact us at any time at hello@poppyblum.com.
2. Information We Collect
2.1 Information You Provide Directly
When you create an account, use our Service, or contact us, we may collect the following categories of personal information:
- Account information: email address and password (stored as a secure hash; we never store plain-text passwords).
- Event details: event type, theme preferences, color choices, budget estimates, and guest count that you enter into our intake form to generate AI design concepts.
- Canvas design data: design elements, layouts, and configurations you create in our Canvas Studio editor.
- Uploaded images: photos or graphics you upload to the Canvas Studio for use in your designs (stored in private cloud storage linked to your account).
- Payment information: billing details processed by Stripe, Inc. We do not store credit card numbers, CVVs, or full payment card data on our servers. All payment data is handled exclusively by Stripe.
- Communications: any messages, support requests, or feedback you send to us.
2.2 Information Collected Automatically
When you visit or use our Service, we automatically collect certain technical information:
- Log data: IP address, browser type and version, operating system, referring URLs, pages visited, time and date of access, and time spent on pages.
- Device information: device type, screen resolution, and unique device identifiers.
- Usage data: features you use, buttons you click, AI generations you initiate, and how you interact with the Canvas Studio.
- Session data: session duration and navigation paths within the application.
- Account generation usage: when you are signed in, we track AI concept generation usage server-side on your account (for example, credits used against your subscription tier). This metering applies only after you create an account, since AI concept generation requires registration.
2.3 Browser Storage (localStorage and sessionStorage)
In addition to cookies, we use your browser's local storage and session storage for product functionality. AI concept generation requires a registered account; we do not use browser storage to meter anonymous AI generations.
Purpose
Sent to servers?
Purpose
Sent to servers?
Purpose
Sent to servers?
Purpose
Sent to servers?
| Purpose | Sent to servers? |
|---|---|
| Offline draft backup of in-progress canvas work. | No. Server autosave uses a separate authenticated checkpoint. |
| Session-only recovery of your intake form if a generation fails mid-submit. | No. |
| Your analytics cookie preference (accept or reject). | No. |
| One-time status message after a successful generation. | No. |
2.4 Information From Third Parties
We may receive limited information from the following third-party services you connect or that we use to operate the Service:
- Supabase (authentication provider): if you sign in via a third-party OAuth provider (e.g., Google), we receive only the information that provider shares with us, such as your name and email address.
- Stripe (payment processor): we receive transaction confirmation data, subscription status, and non-sensitive billing information (such as last-4 card digits) to manage your account credits.
3. How We Use Your Information
We use the information we collect for the following purposes:
Purpose
Details
Purpose
Details
Purpose
Details
Purpose
Details
Purpose
Details
Purpose
Details
Purpose
Details
Purpose
Details
| Purpose | Details |
|---|---|
| Providing the Service | To generate AI design concepts, operate the Canvas Studio, source retail product links, manage your account, and process payments. |
| Personalization | To tailor AI-generated design concepts based on your event details and preferences. |
| Account Management | To manage your subscription tier (Free, Event Pass, or Pro), track credit usage, and process upgrades or add-ons. |
| Communication | To send account-related emails (signup confirmation, password reset, email change) through Supabase Auth. Payment receipts are sent by Stripe at checkout. We do not send marketing emails without your explicit opt-in consent. |
| Analytics & Improvement | To understand how users interact with the Service via our third-party analytics provider (page views, product events, and interaction analytics). We do not sell this data. |
| Advertising Measurement | With your consent, to measure whether a signup followed one of our ads on Meta, Google, or Pinterest, so we know which ads are worth running. Loaded only if you choose "Accept all" in our cookie banner. See Section 8.2. |
| Security & Fraud Prevention | To detect and prevent unauthorized access, abuse, or fraudulent activity on our platform. |
| Legal Compliance | To comply with applicable laws, regulations, and legal processes. |
We do not sell your personal data to third parties, and we never share the content you create, such as your event designs, canvas boards, or shopping lists, with an advertising provider. With your consent, we do use advertising cookies to measure whether a signup followed one of our ads; the providers may use those tags to personalize ads to you on their own platforms. This is described in full in Section 8.2, and none of it loads unless you choose Accept all in our cookie banner.
4. AI Features & Automated Processing
4.1 How We Use Artificial Intelligence
Poppy Blum uses artificial intelligence to power its core features. Below is a full and transparent description of which AI systems process your data, what data they receive, and how that data is handled.
AI System
Purpose
Data Sent
AI System
Purpose
Data Sent
AI System
Purpose
Data Sent
AI System
Purpose
Data Sent
| AI System | Purpose | Data Sent |
|---|---|---|
| Text-generation AI provider | Generates concept-board text (themes, palettes, decoration ideas, structured output); researches user-specified themes via web search grounding; refines canvas items into retail search queries; judges DIY tutorial relevance. | Event intake details (event type, theme, colors, budget, guest count, venue, DIY tasks, planning mode, and related preferences). Canvas item labels and event context for retail sourcing. No email, payment data, or account identifiers are included in prompts. |
| Image-generation AI provider | Generates hero mood-board images for concept results. | A text image prompt derived from your concept output (no account or payment data). Images are stored in our cloud storage and linked to your design. |
| Canvas AI provider | Optional studio canvas AI features (design generation from a text prompt and design suggestions). | Your text prompt, event type, color palette, and existing canvas layout for authenticated requests. Not used for the main concept-board intake flow. |
| SerpAPI | Google Shopping product search (Save & Get Materials and concept pricing); YouTube and web search for DIY tutorial recommendations. | Product keyword strings and tutorial search queries only. No user identity or account data. |
4.2 Zero Training Data Policy
ZERO DATA RETENTION FOR AI TRAINING: Poppy Blum does not use your event details, design data, or any personal information to train AI models. Your data is sent to AI providers solely to generate your requested output and is not retained by those providers for model training under our enterprise agreements.
Specifically:
- Third-party AI providers: Concept text, hero imagery, and canvas AI features are generated through third-party AI providers under their standard commercial API terms. Under those terms, these providers do not use API inputs or outputs to train their models by default. Your prompts exclude email, payment data, and account identifiers.
- Retail & tutorial search: Search queries sent to our search provider contain only product or tutorial keyword strings. No user identity or account data is included in these queries.
4.3 No Automated Decision-Making With Legal Effect
Poppy Blum does not use automated processing (including AI) to make decisions about you that produce legal or similarly significant effects. AI is used solely to generate creative design output based on preferences you provide. You retain full control over whether to use, modify, or discard any AI-generated content.
5. Disclosure of Information
5.1 Service Providers
We share personal data with a limited set of third-party service providers who help us operate the Service. All service providers are contractually required to use your data only as directed by us and in accordance with this Privacy Policy.
Provider
Privacy Reference
Provider
Privacy Reference
Provider
Privacy Reference
Provider
Privacy Reference
Provider
Privacy Reference
Provider
Privacy Reference
Provider
Privacy Reference
Provider
Privacy Reference
| Provider | Privacy Reference |
|---|---|
| Supabase | supabase.com/privacy |
| Stripe, Inc. | stripe.com/privacy |
| Vercel, Inc. | vercel.com/legal/privacy-policy |
| Railway | railway.app/legal/privacy |
| Third-party analytics provider | — |
| Sentry | sentry.io/privacy |
| Third-party AI providers | — |
| SerpAPI | serpapi.com/privacy |
5.2 Legal Requirements
We may disclose your information if required to do so by law or in response to valid requests by public authorities (such as a court order or government agency), or when we believe in good faith that disclosure is necessary to:
- Comply with a legal obligation;
- Protect and defend our rights or property;
- Prevent or investigate possible wrongdoing in connection with the Service;
- Protect the personal safety of users or the public.
5.3 Business Transfers
If Poppy Blum is involved in a merger, acquisition, asset sale, or similar transaction, your personal data may be transferred as part of that transaction. We will provide notice before your data is transferred and becomes subject to a different Privacy Policy.
5.4 With Your Consent
We may share your information with third parties when you have given us explicit consent to do so.
6. Data Security
We implement industry-standard security measures to protect your personal information from unauthorized access, alteration, disclosure, or destruction. Our security practices include:
- Encryption in transit: all data transmitted between your browser and our servers uses TLS 1.2 or higher (HTTPS).
- Encryption at rest:databases and file storage are encrypted at rest using AES-256, provided by Supabase's managed infrastructure.
- Password security: we store passwords exclusively as bcrypt hashes via Supabase Auth. We never store plain-text passwords.
- Row-Level Security (RLS): our database enforces strict access controls using PostgreSQL Row-Level Security policies, ensuring users can only access their own data.
- Authentication tokens: user sessions are managed via short-lived JWT tokens. Stripe transactions are verified using cryptographic webhook signatures.
- Access controls: access to production systems is limited to authorized personnel and protected by multi-factor authentication.
- Error monitoring: we use Sentry to detect and respond to application errors and security anomalies.
While we take reasonable steps to protect your data, no method of electronic storage or transmission is 100% secure. We cannot guarantee absolute security, and you use the Service at your own risk. If you become aware of a security breach, please notify us immediately at hello@poppyblum.com.
7. Data Retention
We retain your personal information for as long as your account is active or as needed to provide the Service and comply with legal obligations. Specific retention periods:
Data Type
Retention Period
Data Type
Retention Period
Data Type
Retention Period
Data Type
Retention Period
Data Type
Retention Period
Data Type
Retention Period
Data Type
Retention Period
Data Type
Retention Period
Data Type
Retention Period
| Data Type | Retention Period |
|---|---|
| Account data (email, profile) | Until you request account deletion and we complete the request. |
| Event and design data | Until you delete the design or your account is deleted. |
| Canvas design files & uploaded images | Until you delete the file or your account is deleted. |
| Payment records | 7 years (required by US tax law and Stripe's compliance obligations). |
| Account generation usage records | Stored on your profile while your account is active; deleted when your account is deleted. |
| Async generation job data | Purged within 24 hours after the job completes. |
| Application logs | Retained per our hosting providers' standard log retention policies (Vercel, Railway). |
| Error tracking data (Sentry) | Per Sentry project retention settings (typically up to 30 days on the free tier). |
| AI prompt/response data | Not retained on our servers beyond the API call. See Section 4. |
To delete your account and all associated data, contact us at hello@poppyblum.com. We will process deletion requests within 30 days.
8. Cookies and Tracking Technologies
8.1 What We Use
Poppy Blum uses the following tracking technologies:
Technology
Purpose
Can You Opt Out?
Technology
Purpose
Can You Opt Out?
Technology
Purpose
Can You Opt Out?
Technology
Purpose
Can You Opt Out?
Technology
Purpose
Can You Opt Out?
| Technology | Purpose | Can You Opt Out? |
|---|---|---|
| Session cookies (Supabase Auth) | Maintains your authenticated session so you stay logged in. | No. Required for the Service to function. |
| localStorage & sessionStorage | Product functionality described in Section 2.3 (canvas offline drafts, intake recovery, analytics preference). | Yes. Clear your browser's site data at any time. |
| Functional cookies (Stripe) | Required for payment processing and fraud prevention on Stripe-hosted checkout pages. | No. Required for payment features. |
| Analytics (third-party provider) | When enabled: automatic page views, page-leave events, and UI interaction capture; plus custom product events (e.g., generation started/completed and subscription tier). We do not link analytics events to your email address by default. | Yes. Choose "Reject all" in the cookie banner or Cookie settings in the footer. |
| Advertising and marketing (Google Tag Manager, loading Meta / Google Ads / Pinterest conversion tags) | Measures whether a signup followed one of our ads. The providers may use these tags to attribute conversions and personalize ads to you on their platforms and partner sites. See Section 8.2. | Yes. These load only if you choose "Accept all." Choosing "Reject all" keeps them off entirely. |
8.2 Advertising and Marketing
We advertise Poppy Blum on other platforms. With your consent, we load Google Tag Manager, which delivers conversion tags for Meta (Facebook / Instagram), Google Ads, and Pinterest. These tags let us measure whether a signup followed one of our ads, and the providers may use them to attribute conversions and personalize ads to you on their own platforms and partner sites.
Two things must both be true before any advertising cookie is set: advertising must be switched on for the Service, and you must choose Accept all in our cookie banner. If either is not true, including any period when we are not running ads, nothing is loaded and no advertising cookie is set. Choosing Reject all keeps them off entirely, and you can change your choice anytime via Cookie settings in the site footer. We disclose these providers in advance so this policy is accurate before, not after, we begin advertising.
What we send them: a sign-up conversion event after you confirm your email address. We do not send your event designs, canvas boards, shopping lists, or payment details to any advertising provider, and we do not sell your personal data. For a provider-by-provider list and opt-out links, see our Cookie Policy.
8.3 Managing Your Preferences
You can control cookies through your browser settings. Most browsers allow you to refuse cookies, delete existing cookies, or be notified when cookies are set. Note that disabling authentication cookies will prevent you from logging in to the Service. For a cookie-by-cookie list and opt-out instructions, see our Cookie Policy.
We honor the Global Privacy Control (GPC) signal. If your browser or extension sends GPC, we treat it as a rejection of all optional cookies: analytics and advertising tags stay off, and we do not show you the cookie banner, because you have already told us your answer. GPC also overrides an earlier acceptance made in our banner, since the newer signal is the more recent instruction. See globalprivacycontrol.org.
9. Your Privacy Rights
Depending on where you live, you may have the following rights regarding your personal data. We honor all valid requests regardless of jurisdiction.
9.1 Rights Available to All Users
- Right to Access: request a copy of the personal data we hold about you.
- Right to Correction: request that we correct inaccurate or incomplete data.
- Right to Deletion: request that we delete your personal data. Note that we may retain certain data where required by law (e.g., payment records).
- Right to Data Portability: request your data in a structured, machine-readable format.
- Right to Withdraw Consent: where processing is based on consent, withdraw it at any time without affecting the lawfulness of prior processing.
9.2 EU / UK Users: GDPR Rights
If you are located in the European Economic Area (EEA) or the United Kingdom, you have additional rights under the General Data Protection Regulation (GDPR) and UK GDPR:
- Right to Object: object to processing of your data based on legitimate interests or for direct marketing purposes.
- Right to Restrict Processing: request that we limit how we use your data in certain circumstances.
- Right to Lodge a Complaint:you have the right to lodge a complaint with your local supervisory authority (e.g., the Information Commissioner's Office in the UK, or your national Data Protection Authority in the EU).
Our lawful bases for processing under GDPR are: (a) Contract, processing necessary to provide the Service you requested; (b) Legitimate Interests, analytics and security; (c) Legal Obligation, financial record retention; (d) Consent, marketing communications.
9.3 California Users: CCPA Rights
If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):
- Right to Know: the right to know what personal information we collect, use, disclose, and sell.
- Right to Delete: the right to request deletion of your personal information.
- Right to Opt-Out of Sale: we do not sell your personal information. If that changes, we will notify you and provide an opt-out mechanism. We honor the Global Privacy Control signal as an opt-out request (see Section 8.3), and you can opt out anytime via Cookie settings in the site footer.
- Right to Non-Discrimination: we will not discriminate against you for exercising your CCPA rights.
- Right to Correct: the right to correct inaccurate personal information.
To exercise CCPA rights, contact us at hello@poppyblum.comwith the subject line “CCPA Request.” We will respond within 45 days as required by law.
9.4 Canadian Users: PIPEDA Rights
If you are located in Canada, you have rights under the Personal Information Protection and Electronic Documents Act (PIPEDA):
- Right to Access: request access to your personal information held by us.
- Right to Correction: challenge the accuracy and completeness of your information.
- Right to Complaint: file a complaint with the Office of the Privacy Commissioner of Canada (OPC) at priv.gc.ca.
Poppy Blum is the organization accountable for personal information under its control. Our designated privacy contact is reachable at hello@poppyblum.com.
9.5 How to Exercise Your Rights
To submit any privacy rights request, email us at hello@poppyblum.comwith the subject line “Privacy Rights Request” and specify the right you wish to exercise. We will verify your identity before processing the request and respond within 30 days (or the timeline required by applicable law).
10. Children's Privacy
Poppy Blum is intended for users aged 13 and older. We do not knowingly collect personal information from children under the age of 13, consistent with the Children's Online Privacy Protection Act (COPPA) in the United States. We do not currently verify age at sign-up. By using the Service, you represent that you are at least 13 years old.
If we learn that we have inadvertently collected personal information from a child under 13, we will delete that information promptly. If you are a parent or guardian and believe your child under 13 has provided us with personal information, please contact us immediately at hello@poppyblum.com.
11. International Data Transfers
Poppy Blum is based in the United States. If you are located outside the United States, your personal information will be transferred to and processed in the United States, where data protection laws may differ from those in your country.
For users in the EEA and UK, we rely on the following legal mechanisms to transfer data internationally: (a) Standard Contractual Clauses (SCCs) approved by the European Commission, where applicable; (b) adequacy decisions, where they exist.
For Canadian users, data transfers comply with PIPEDA requirements for cross-border transfers to third parties.
By using our Service, you acknowledge and consent to the transfer of your information to the United States and other countries where our service providers operate.
12. Third-Party Links and Retail Products
Our Service displays links to third-party retail websites (such as Amazon, Target, and Etsy) as part of the “Save & Get Materials” product sourcing feature. These links are generated through our AI-powered retail sourcing engine using SerpAPI and are provided for your convenience.
We are not responsible for the privacy practices of any third-party websites. When you click a retail link and visit a third-party site, that site's own privacy policy governs the collection and use of your information. We encourage you to review the privacy policy of any third-party site you visit.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, the Service, or applicable laws. When we make material changes, we will:
- Update the “Last Updated” date at the top of this policy;
- Post the updated policy at poppyblum.com/privacy-policy;
- Notify registered users by email at the address associated with their account at least 14 days before material changes take effect.
Your continued use of the Service after the effective date of a revised policy constitutes your acceptance of the revised policy. If you do not agree with the changes, you must stop using the Service and may request deletion of your account.
We commit to reviewing this policy at least once every 12 months, or whenever there are significant changes to our data practices or applicable law.
14. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
Contact Method
Details
Contact Method
Details
Contact Method
Details
Contact Method
Details
Contact Method
Details
Contact Method
Details
| Contact Method | Details |
|---|---|
| hello@poppyblum.com | |
| Subject Line | Privacy Inquiry |
| Legal Entity | Poppy Blum LLC |
| State of Registration | Minnesota, United States |
| Website | poppyblum.com |
| Response Time | We aim to respond within 5 business days. Privacy rights requests will receive a formal response within 30 days (or as required by applicable law). |
For EU/UK users exercising GDPR rights or filing a complaint: you may also contact your national Data Protection Authority. A list of EU DPAs is available at edpb.europa.eu. For UK users, contact the Information Commissioner's Office at ico.org.uk.