Privacy Policy
This policy explains what BlueprintPortal collects, why it is needed, where it is stored, and the choices and rights available to you.
Effective and last updated: 13 August 2026 · Version 2026-08-13Scope and our commitment
This Privacy Policy explains how BlueprintPortal handles personal information when you visit or use BlueprintPortal. We aim to manage personal information transparently and in line with applicable Australian privacy law, including the Australian Privacy Principles where they apply.
You can browse public informational pages and public project links without creating an account. An account is required for project creation and most collaboration features.
Information we collect
Depending on how you use BlueprintPortal, we may collect:
- Account information: email address, display name, authentication identifier, profile image, and sign-in provider;
- Profile and project information: biography, idea or project descriptions, stages, tags, updates, comments, tasks, files, groups, and related metadata;
- Interest and collaboration records: follows, availability-contact choices, memberships, roles, invitations, notifications, and whether an NDA-access step was confirmed;
- Technical information: security, diagnostic, device, browser, network, and usage information generated when the Service is used; and
- Analytics information: public page views and related measurements only when you choose “Allow analytics”.
Please do not submit sensitive information unless it is genuinely necessary, you are authorised to do so, and the project visibility and membership are appropriate.
How we collect information
We collect information directly from you when you register, edit a profile, create or join a project or group, upload content, comment, or contact us. We also receive limited account information from Google if you choose Google sign-in, and technical information from Firebase and Google Cloud as they provide authentication, database, file storage, hosting, and security services.
If you submit personal information about another person, you must have a lawful basis and appropriate permission to do so.
Why we use information
We use personal information to provide accounts and idea/project features, apply visibility and membership controls, show followed progress in personal feeds, provide project managers with consented availability-contact details, display content to its intended audience, deliver invitations and notifications, secure and troubleshoot the Service, prevent misuse, respond to requests, comply with law, and improve usability and performance.
We do not sell personal information. BlueprintPortal does not currently use personal information for third-party behavioural advertising.
Following ideas and sharing contact details
Following an idea does not by itself reveal your email address to the idea owner. If you select “Tell me when it’s available”, BlueprintPortal stores that choice and makes your display name and account email available only to the project’s owner and admins. They are instructed to use it only for progress or availability information about that idea.
You can withdraw this choice and remove the shared details by stopping following the idea. If an owner has already copied or used the address, you may also need to ask them directly to stop further contact. Report misuse to BlueprintPortal using the contact details below.
Public content
Your display name, profile details, and content attached to a public project may be accessible without signing in and may be copied, indexed, linked to, or shared by other people and search engines. Changing a project to private limits future access through BlueprintPortal but cannot retrieve copies previously made by others.
Private content is limited through application access rules, but no online service can guarantee absolute confidentiality. Use care with trade secrets, regulated information, and material governed by a separate confidentiality agreement.
Service providers and overseas processing
BlueprintPortal uses Google Firebase and Google Cloud for authentication, Firestore database services, file storage, hosting, diagnostics, and security. Core Firestore data is presently configured in Google’s nam5 United States multi-region, and the Firebase Storage bucket is located in the United States. Google and its subprocessors may process limited information in other countries when providing support, resilience, security, and related services.
Google Analytics is loaded only after you opt in. When enabled, it receives page and device measurements under Google’s applicable terms. We may also disclose information to professional advisers, contractors, regulators, courts, or law-enforcement bodies where reasonably necessary, authorised, or required by law.
Security
We use authentication, role and membership checks, Firestore and Storage access rules, HTTPS, controlled administrative access, and service-provider security measures. Security depends partly on users choosing appropriate project visibility, managing members, and protecting their accounts. No internet transmission or storage system is completely secure.
If we identify an eligible data breach, we will assess and respond to it and make notifications required under Australia’s Notifiable Data Breaches scheme or other applicable law.
Retention and deletion
We retain account and project information while an account or project is active and for as long as reasonably needed to provide the Service, meet security and record-keeping needs, resolve disputes, enforce agreements, and comply with law. Deleted information may remain temporarily in backups, logs, or fraud-prevention records before being securely removed or de-identified.
Project owners and collaborators should keep independent copies of important product material. Account and content deletion controls are still developing; until self-service deletion is available, contact us to request deletion.
Access and correction
You can update certain profile and project information in the Service. You may also ask for access to personal information we hold about you or request a correction. We may need to verify your identity and may refuse or limit a request where permitted by law, explaining the reason where required.
Privacy questions and complaints
Contact us with enough information to understand your question or complaint. We will acknowledge it and aim to investigate and respond within a reasonable period. If you are not satisfied, you may be entitled to contact the Office of the Australian Information Commissioner.
Changes to this policy
We may update this policy as the Service, providers, or legal requirements change. We will update the effective date and version and provide reasonable notice of material changes.
Contact
Privacy requests, corrections, deletion requests, and complaints can be directed to: