Last updated: September 16, 2026
Blost (“Blost”, “we”, “us”) is operated by Corpus Communications Kft., registered at 1025 Budapest, Csalán út 26., Hungary (“the Company”). This Privacy Policy explains what data we collect when you use Blost (blost.ai), how we use it, and the choices you have.
Account information: your name and email address, used to sign you in and identify your account.
Brand & site information: details you enter about your business, brand voice, and target audience, used to generate articles.
WordPress connection: if you connect your WordPress site, we store your site URL, WordPress username, and application password. The application password is encrypted at rest (AES-256-GCM) and is never displayed again after you enter it. We use it solely to publish and update articles on your site via the WordPress REST API.
UNAS connection: if you connect your UNAS webshop, we store your UNAS API key, encrypted at rest (AES-256-GCM) and never displayed again after you enter it. We use it solely to publish and update blog content, and attach it to your blog listing page, via the UNAS API.
Google Search Console data: if you connect Google Search Console (see Section 2 below for details specific to Google user data), we store an encrypted OAuth refresh token and the name of the property you selected, and we read aggregated search performance data (clicks, impressions, and average position per page) for the articles Blost published.
Generated content: the articles, images, and metadata Blost generates or that you edit within the app.
Usage data: basic technical logs (e.g. timestamps, error logs) needed to operate and troubleshoot the service.
When you click “Connect Google Search Console”, Blost requests read-only access to your Search Console data via the https://www.googleapis.com/auth/webmasters.readonly scope. Specifically:
Blost’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
We use the data described above to: operate and improve Blost; generate and publish articles on your behalf; show you performance statistics; provide customer support; and comply with legal obligations.
To provide the service, we share limited data with the following processors, strictly for the purpose of running Blost. Some of these processors process data outside the EU/EEA (typically in the United States); in those cases, the transfer relies on a data processing agreement (DPA) with that provider and, depending on the provider, the European Commission’s Standard Contractual Clauses (SCCs) and/or that provider’s EU-U.S. Data Privacy Framework (DPF) certification.
On request, we can provide a copy of the relevant data processing agreement or evidence of the applicable safeguard (SCC/DPF) for a given processor. We do not sell your personal data to anyone.
We keep your data for as long as your account is active. You can disconnect WordPress, UNAS, or Google Search Console at any time from Settings, which deletes the corresponding stored credentials/tokens immediately. To request full account deletion, email us at the address below.
Sensitive credentials (WordPress application passwords, UNAS API keys, Google refresh tokens) are encrypted at rest using AES-256-GCM with a server-only key. Access to the database is restricted and all traffic is encrypted in transit (HTTPS/TLS).
If you are in the EU/EEA, you have the right to access, correct, export, or delete your personal data, and to object to or restrict certain processing, under the GDPR. To exercise any of these rights, contact us below.
We may update this policy from time to time. Material changes will be announced by email or in-app notice.
Corpus Communications Kft.
1025 Budapest, Csalán út 26., Hungary
Email: mail@corpuscom.hu