Last updated: September 27, 2026
blackLen operates the blackLen platform and the websites blacklen.com and app.blacklen.com (“we”, “us”). For any question, request or complaint about your personal data, email support@blacklen.com.
Account details: name, email address, username, password (stored only as a hash), and optional profile details you add (photo, headline, bio, country, website, industry).
Why: To create and run your account. Basis: Contract.
Sign-in with Google or GitHub, if you choose it: your email address, name and account ID from that provider.
Why: To sign you in. Basis: Contract.
Two-factor data, if you enable it: authenticator secret (stored encrypted), backup codes, and one-time codes sent by email.
Why: To protect your account. Basis: Contract.
Security and device data: IP address, browser and device information, a device identifier, sign-in and session records, activity history, and failed sign-in counts.
Why: To secure accounts, detect abuse, and let you review and end your sessions. Basis: Legitimate interests (security).
Content you add to the platform: organizations, projects, assets, checklists, notes and evidence, scripts and payloads.
Why: To provide the service. We use it only for that. Basis: Contract.
Messages you send us: contact form details (name, email, message, IP address, browser) and emails to us.
Why: To reply to you. Basis: Legitimate interests (support).
Emails we send you: verification, password reset, security alerts, invitations and notifications.
Why: To provide the service. Basis: Contract.
Records of the policies you accepted: version, time, IP address, browser and device identifier.
Why: To show what you agreed to. Basis: Legitimate interests (proof of agreement).
Server logs: IP address, browser and pages requested.
Why: To keep the service secure and working. Basis: Legitimate interests (security and operations).
We share personal data only with providers that process it on our behalf to run the service: a hosting provider, an email delivery provider and, if you choose them, Google or GitHub for sign-in. We may also disclose personal data when the law requires it. We do not sell personal data.
Personal data may be processed in countries other than the one where you live, including by our providers.
We keep your personal data while your account exists. After your account is closed we keep it only as long as needed for legal and security purposes, and in backups that are overwritten on a regular schedule. Security and audit logs are kept only as long as needed for security purposes.
Depending on where you live, you can ask us to give you access to your personal data, correct it, delete it, give you a copy, restrict or stop certain processing, or withdraw consent where we rely on it. To make a request, email support@blacklen.com. We may need to verify your identity, and we will reply within the time the law requires. You can also complain to the data protection authority in your country.
We protect personal data with encryption in transit (HTTPS), passwords stored only as hashes, encrypted authenticator secrets, role-based access controls and optional two-factor authentication. No system is completely secure, and we cannot guarantee absolute security.
We do not use advertising or analytics cookies. The blackLen app stores sign-in tokens, a device identifier and your settings in your browser's local storage so that you stay signed in. The website blacklen.com does not store anything in your browser.