Privacy Policy

Last updated: August 4, 2026

Blost (“Blost”, “we”, “us”) is operated by Corpus Communications Kft., registered at 1025 Budapest, Csalán út 26., Hungary (“the Company”). This Privacy Policy explains what data we collect when you use Blost (blost.ai), how we use it, and the choices you have.

1. What we collect

Account information: your name and email address, used to sign you in and identify your account.

Brand & site information: details you enter about your business, brand voice, and target audience, used to generate articles.

WordPress connection: if you connect your WordPress site, we store your site URL, WordPress username, and application password. The application password is encrypted at rest (AES-256-GCM) and is never displayed again after you enter it. We use it solely to publish and update articles on your site via the WordPress REST API.

Google Search Console data: if you connect Google Search Console (see Section 2 below for details specific to Google user data), we store an encrypted OAuth refresh token and the name of the property you selected, and we read aggregated search performance data (clicks, impressions, and average position per page) for the articles Blost published.

Generated content: the articles, images, and metadata Blost generates or that you edit within the app.

Usage data: basic technical logs (e.g. timestamps, error logs) needed to operate and troubleshoot the service.

2. Use of Google user data

When you click “Connect Google Search Console”, Blost requests read-only access to your Search Console data via the https://www.googleapis.com/auth/webmasters.readonly scope. Specifically:

Blost’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

3. How we use your data

We use the data described above to: operate and improve Blost; generate and publish articles on your behalf; show you performance statistics; provide customer support; and comply with legal obligations.

4. Third-party processors

To provide the service, we share limited data with the following processors, strictly for the purpose of running Blost:

We do not sell your personal data to anyone.

5. Data retention & deletion

We keep your data for as long as your account is active. You can disconnect WordPress or Google Search Console at any time from Settings, which deletes the corresponding stored credentials/tokens immediately. To request full account deletion, email us at the address below.

6. Security

Sensitive credentials (WordPress application passwords, Google refresh tokens) are encrypted at rest using AES-256-GCM with a server-only key. Access to the database is restricted and all traffic is encrypted in transit (HTTPS/TLS).

7. Your rights

If you are in the EU/EEA, you have the right to access, correct, export, or delete your personal data, and to object to or restrict certain processing, under the GDPR. To exercise any of these rights, contact us below.

8. Changes to this policy

We may update this policy from time to time. Material changes will be announced by email or in-app notice.

9. Contact

Corpus Communications Kft.
1025 Budapest, Csalán út 26., Hungary
Email: zoltan.nagy@corpuscom.hu