# Security and compliance

> Legal entity, GDPR, data processing, hosting and sub-processors, privacy controls in the product, and what to request during procurement.

Source: https://bluepic.io/ai-info#security-compliance  
JSON: https://bluepic.io/ai-info/security-compliance.json  
Language: en  
Last updated: 2026-09-11

## Legal entity

Bluepic is operated by **FellowBlue GmbH**, Im Mediapark 5, 50670 Cologne, Germany (Amtsgericht Köln, HRB 116136; VAT ID DE364437752). The company is subject to the EU General Data Protection Regulation (GDPR) and German data protection law.

## GDPR and end users

- End users of a design generator need **no account, no app, and no tracking cookies**. They open a link or an embedded widget, fill in the form, and download or share the result.
- Only the optional LinkedIn integration (profile pre-fill and direct posting) asks the end user to connect their LinkedIn account.
- The marketing website bluepic.io sets no analytics or marketing cookies that require consent (only technically necessary cookies such as language and cookie settings): usage measurement is pseudonymous and cookieless; fonts are self-hosted with no requests to third-party font services.

## Hosting and sub-processors

- **Infrastructure and content delivery:** Cloudflare, Inc. (USA). End-user uploads (deleted after 24 hours), rendered outputs, and account assets are stored with EU jurisdiction pinning; templates, fonts, and backups without regional pinning.
- **Server-side rendering fallback:** Hetzner Online GmbH, Falkenstein, Germany.
- **Authentication and account management:** Auth0 (Okta, Inc.), EU region.
- **Payments and invoicing:** Stripe (Stripe Payments Europe Ltd., Ireland; Stripe, Inc., USA).
- **Product and website analytics:** PostHog Inc., EU infrastructure (Germany), pseudonymous.
- **Support widget:** Help Scout Inc. (USA); on the website loaded only after clicking the help button.
- **Email delivery:** Brevo GmbH, Berlin (transactional email for free tools, newsletters).
- A data processing agreement is in place with each sub-processor; US transfers rely on the EU-US Data Privacy Framework.

The authoritative list with legal bases and transfer safeguards is the privacy policy at `https://bluepic.io/privacy`.

## Privacy controls and access control inside the product

- Organisations with team members and role management; team campaigns can be restricted to team members and/or a password.
- API keys are account-level and can be created and revoked at any time. The key remains readable in the Studio for the account that owns it, so it should be handled like a password.
- Trackable links in LinkedIn posts can be switched off per campaign.
- Face-detection auto-crop for image fields runs entirely in the end user's browser; no image data leaves the device for it.
- Background removal is opt-in per image field. When enabled, the uploaded image is processed server-side by Cloudflare Images (Cloudflare, Inc., USA) as processor, without EU pinning, and deleted after 24 hours at the latest.
- Custom domains (Enterprise) let generators run under the customer's own domain.
