Last updated 22 September 2026

Privacy Policy

Blitzy Pty Ltd (“Blitzy”, “we”, “us”) operates blitzy.bot and the Blitzy SEO & Social Growth assistant. This policy explains what we collect, why, and how you can control it. It is written for Google OAuth verification and for our clients.

Who we are

Blitzy Pty Ltd is an Australian company. Contact: servicedesk@blitzy.com.au. Website: https://blitzy.bot. Product homepage: Blitzy SEO.

Data Access — Google user data (raw and aggregated)

When a client taps Connect Google, they sign in with their own Google account. We request only these two scopes:

Aggregated / derived data we store: daily totals and short history snapshots (sums and averages of those API rows) so the client can see trend lines in Blitzy SEO.

We do not access Gmail, Drive, Calendar, Contacts, Photos, Chat, YouTube, or Data Portability APIs. We do not change Google Analytics settings. We do not read Google account profile data beyond the email used to confirm the connection.

Data Use

Raw and aggregated Google user data is used only to provide or improve these user-facing features for the client who connected the account:

Figures are Google-reported estimates, not ranking promises. We do not use Google user data for advertising, remarketing, credit, lending, or eligibility decisions.

Data Transfer — who we share with

We do not sell Google user data. We do not share it with other Blitzy clients, data brokers, or advertisers.

We transfer data only to processors needed to run Blitzy SEO for that client:

We disclose data if required by Australian law. Optional paid AI briefs run on Blitzy-operated Overflow compute (our GPU). We do not send Search Console or Analytics user data to third-party AI APIs that train models on customer content.

Data Protection

OAuth access and refresh tokens are encrypted at rest, per subscription. API traffic uses HTTPS. Access to production systems is limited to Blitzy operators. Tokens are not logged in application traces. Hosting is Google Firebase and Microsoft Azure.

Data Retention and Deletion

Connector tokens are deleted when the client taps Turn off on the Google tab, or when the subscription ends. Metric snapshots and reports stay with the subscription until the organisation emails servicedesk@blitzy.com.au and asks us to delete them, or as required by law. We action deletion requests for that organisation’s Google-derived snapshots and tokens. The client can also revoke blitzy.bot in Google Account permissions, which stops further API access.

Limited Use

The use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Raw or derived user data received from Google APIs is used only to provide or improve user-facing features in Blitzy SEO. It is not used for serving advertisements. It is not transferred to third parties except as necessary to provide or improve those features or as required by law.

We do not use Google Workspace APIs or Photos APIs. We do not use Google user data to develop, improve, or train generalised AI/ML models. We do not transfer Google user data to third-party services that train AI/ML models on that data.

How to disconnect

In blitzy.bot → Assistants → Google tab, tap Turn off. That deletes the stored tokens. The client can also revoke blitzy.bot in their Google Account permissions.

Account and website data (not Google APIs)

We also store the email used to sign in to blitzy.bot, the locked website domain, connectors the client saves (for example a repository token they paste), and the cases and reports they run.

Your rights

Australian Privacy Principles apply. You can ask to access, correct, or delete personal information by emailing servicedesk@blitzy.com.au. You may complain to the Office of the Australian Information Commissioner.

Children

Blitzy.bot is a business product. It is not directed at children.

Changes

We will update this page when our practices change. The date at the top is the latest version.

Blitzy SEO homepage · Terms of Service