BetaBloxSmith is currently in beta. Some things might not work perfectly, but we are here to improve!
BloxSmith logoBloxSmith
Get started

Privacy Policy

Last updated: May 26, 2026

This Privacy Policy explains how BloxSmith ("BloxSmith", "we", "us", or "our") collects, uses, stores, and shares information when you use our website, Roblox Studio plugin, AI builder, and related services (collectively, the "Service"). By using the Service you agree to the practices described below. If you do not agree, please stop using the Service.

1. Who we are

BloxSmith is an independent AI-assisted development tool for Roblox creators. We are not affiliated with, endorsed by, or sponsored by Roblox Corporation. "Roblox" and "Roblox Studio" are trademarks of their respective owners and are referenced here only for compatibility purposes.

2. Information we collect

We collect only what we need to operate, secure, and improve the Service:

  • Account data — email, display name, avatar URL, optional bio, specialization, and authentication identifiers from email/password or Google sign-in.
  • Project data — project names, descriptions, generated scripts, files, prompts, AI conversation history, and metadata you create inside the Service.
  • Studio plugin data — when you install the BloxSmith plugin and connect it to a project, the plugin uploads a structured snapshot of the open Roblox place (instance names, classes, properties, scripts, and hierarchy) so the AI can build with full context. The plugin reads only the place currently open in Studio and only while you are connected.
  • Usage data — credit balances, AI generations, payment requests, MCP server configurations you save, and audit logs of plugin actions.
  • Technical data — IP address, browser/user-agent, device type, and error/diagnostic logs needed to keep the Service reliable.
  • Payment data — when you buy credits we collect a PayPal transaction ID, amount, and pack ID. We do not store full payment card numbers — those are handled exclusively by PayPal.

3. How we use your information

  • To create and manage your account, projects, and credit balance.
  • To run AI generations, sync changes to your Roblox Studio session, and execute the actions you queue.
  • To process payments, prevent abuse, and detect fraud.
  • To send transactional emails (account, security, payment, and support messages).
  • To diagnose bugs, monitor reliability, and improve product quality.
  • To enforce our Terms of Service and comply with legal obligations.

We do not sell or rent your personal data. We do not use your project files or prompts to train third-party foundation models.

4. AI processing

When you send a prompt, BloxSmith forwards your prompt, relevant project context, and (when enabled) the Studio snapshot to AI providers (currently Groq and, where applicable, the Lovable AI Gateway / Google Gemini and OpenAI families) so they can generate a response. Providers may temporarily process this data to produce the response and for limited abuse-prevention purposes governed by their own policies. We do not authorise providers to train models on your content.

5. MCP servers and external integrations

You may optionally connect external Model Context Protocol (MCP) servers (e.g. Notion, Linear, Atlassian) or run BloxSmith's MCP endpoint from third-party clients such as VS Code, Cursor, Claude Code, Codex, or Antigravity. When you do, BloxSmith stores the server URL and any authentication header you provide so we can call the server on your behalf. You can remove these integrations at any time from Settings.

6. Legal bases (EEA / UK users)

If you are located in the European Economic Area or the United Kingdom, we process your personal data on the following bases:

  • Contract — to provide the Service you signed up for.
  • Legitimate interest — to secure and improve the Service and prevent abuse.
  • Consent — where required (e.g. optional analytics).
  • Legal obligation — to comply with tax, accounting, and law-enforcement requests.

7. Data sharing

We share information only with the providers required to run the Service:

  • Cloud hosting and database providers (Lovable Cloud / Supabase, Cloudflare Workers).
  • AI providers strictly for generating responses to your prompts.
  • PayPal for payment processing.
  • Email delivery providers for transactional messages.
  • Authorities when required by valid legal process.

We may disclose information in connection with a corporate transaction (merger, acquisition, or asset sale). We will give notice before your data becomes subject to a different privacy policy.

8. Data retention

We keep your account and project data for as long as your account is active. If you delete a project, its files and chat history are removed within 30 days. If you delete your account, we remove your personal data within 30 days, except for records we must retain for tax, billing, fraud-prevention, or legal compliance (typically up to 7 years for financial records).

9. Security

We protect data in transit with TLS and at rest with industry-standard encryption. Database access is scoped through row-level security policies so you can only access your own data. Plugin tokens and MCP credentials are stored as hashes or in restricted-access tables. No system is perfectly secure — please report suspected vulnerabilities to community100x@gmail.com.

10. Your choices and rights

Depending on where you live, you may have rights to:

  • Access, correct, or export the personal data we hold about you.
  • Delete your account and associated personal data.
  • Object to or restrict certain processing.
  • Withdraw consent at any time (without affecting prior lawful processing).
  • Lodge a complaint with your local data-protection authority.

To exercise any of these rights, email community100x@gmail.com.

11. Children

The Service is not directed to children under 13. Users between 13 and the age of majority in their jurisdiction must have parental or guardian consent to use the Service and to make any purchase. If you believe a child has provided personal data to us without consent, contact us and we will delete it.

12. International transfers

BloxSmith is operated globally and your data may be processed in countries outside your own, including the United States and the European Union. Where required, we rely on Standard Contractual Clauses or equivalent safeguards.

13. Cookies and local storage

We use strictly-necessary cookies and browser local storage to keep you signed in, remember preferences (theme, settings, MCP configuration), and run the chat UI. We do not use third-party advertising cookies.

14. Changes to this policy

We may update this Privacy Policy as the Service evolves. We will update the "Last updated" date and, for material changes, notify you in-product or by email before they take effect.

15. Contact

Questions about this policy? Email community100x@gmail.com or write to BloxSmith, Privacy Team.