No cookies, no trackers.
This site is static pages: no cookies, no analytics, no scripts from anyone else, and a font served from here rather than from a font service. Nothing on it asks for consent because nothing on it needs consent. What it does do with data is below, in full.
Reading these pages
The pages are served by GitHub Pages. Like any web server, GitHub sees the address your browser connects from and the page it asks for, under GitHub's privacy statement; we do not receive or keep any of it. The site sets no cookies and loads nothing from a third party, with one exception: the Unreal Engine documentation pages that show a video embed YouTube’s privacy-enhanced player, from youtube-nocookie.com. When you scroll to one, your browser fetches the player from Google, which sees your address and the page it is on; YouTube sets no cookies until you press play, and from then on Google’s privacy policy applies. No other page loads anything from YouTube. Links to Discord, GitHub and Stripe take you to those services, where their own policies apply.
The viewer, the forge, the notebook
A file you open in the viewer, the forge or the notebook is read on your machine, in your browser, and is never uploaded: the readers and the kernel run there as WebAssembly. The same holds for the desktop and mobile apps and for the libraries in the SDK: a file you open stays where it is, and a license file is verified locally, with no call home. The browser apps remember a few settings in your browser's own storage (the viewer's colours, the forge's overlay toggles, a one-time reload flag): no identifier, nothing sent anywhere, cleared whenever you clear the site's data.
What a purchase leaves with us
Checkout and the customer portal are Stripe's pages: card details go to Stripe and never to us. When a payment completes, Stripe tells us the email address you paid with, the name on the order, your Stripe customer and subscription ids, and what you bought. We keep that record, with the license it belongs to, so the license can be issued, renewed, changed and cancelled with the subscription. It is stored with Cloudflare (the worker that runs the store) and Keygen (the license service), and the license email is sent through Resend; each processes it for us and for nothing else. Nothing is sold, shared or used for advertising, and there is no newsletter.
The legal basis is the contract: none of it can be issued without those details. The order record is deleted when the subscription ends. Stripe keeps the invoices for as long as Italian tax law requires (ten years), and the license itself stays valid until its expiry, so the file can still be fetched; write to us to have anything deleted sooner. The license download endpoint counts requests per address for one hour, to limit abuse, and keeps nothing else.
Ask, and it happens
Under the GDPR you can ask what we hold about you, have it corrected or deleted, receive a copy, or object to its use: write to info@blitter.studio and we answer within a month. You can also complain to the Italian supervisory authority, the Garante per la protezione dei dati personali. Email sent to us is kept for as long as the conversation needs it.
The controller is Blitter S.r.l., VAT IT16515071005, info@blitter.studio. Changes to this page are made here, with the date below.
Last updated 20 September 2026.