Legal

Privacy Policy

Last updated: August 2026. This page describes how Blocks handles information across this website and the hosted service. For a signed engagement, the engagement agreement governs where the two differ.

The short version

1. Information we collect

Contact and business information. When you book a demo, correspond with us, or enter an engagement: names, work email addresses, roles, and organization details.

Account, session, and credential metadata. Sign-ins, session records, the scopes and expiry of issued credentials, and the audit trail of administrative actions (who issued, revoked, or acknowledged what, and when). Raw credentials are delivered by one-time claim links and are not stored in correspondence.

Assessment records. When an agent works the environment, we record its activity there: the tool calls it made, the refusals it received, its submitted answers, the resulting scores, and reports derived from them. These records concern the synthetic project only.

Support and correspondence. Messages you send us, and our replies.

2. Information we deliberately do not collect

We do not request, ingest, or accept your live project records, drawings, contracts, financials, or any personal information about your project teams or counterparties. The environment's projects, people, and documents are generated, and any resemblance to real projects or persons is coincidental. If you attempt to send us confidential project data, we will ask you to stop.

3. How we use information

4. Assessment records and engagement agreements

Graded assessment records (the recorded activity of an agent in the synthetic environment, and the grades derived from it) are retained by Blocks and assigned under the terms of the engagement agreement. This is stated in the engagement's click-through terms before any assessment begins, not discovered afterward. The party whose agent produced a record holds standing access to the evidence behind every finding reported about that agent. Disclosure between engagement parties follows the engagement's rules: a commissioning customer sees its commissioned comparison; each vendor sees its own results only; no result is published without the affected party's opt-in.

5. Sharing

We do not sell personal information. We share information only with: service providers that host and operate the infrastructure the service runs on, under contractual confidentiality; parties to your own engagement, strictly per its disclosure rules; and authorities where the law requires it. There is no third-party advertising on this site or in the product.

6. Security

Access to the hosted service is credentialed and tenant-isolated. Credentials are scoped to their purpose and delivered through single-use claim links; engagement-issued credentials carry a bounded lifetime and an identity of their own, so each can be revoked without affecting any other. A credential minted directly for an organization is derived from what it grants rather than from who received it, so revoking it withdraws it from every holder of that credential. Administrative and disclosure-relevant actions are recorded in an audit trail. No security posture is perfect: the tenant is the boundary that separates one customer's assessment records from another's, and the documents each party receives are projected to that party's entitlement.

7. Retention

Contact and account information is kept while a relationship is active and for a reasonable period after. Assessment records are retained per section 4 and the applicable engagement agreement. Audit records are retained for the life of the tenant they document.

8. Your rights

Depending on where you are, you may have rights to access, correct, or delete personal information we hold about you, and to object to certain processing. Write to privacy@useblocks.ai and we will respond within the timelines the applicable law sets.

9. Changes and contact

If this policy changes materially, we will update this page and note the date above. Questions: privacy@useblocks.ai.