Blinq
blinq.meBlinq is a digital business card, event lead-capture, contact-enrichment and AI note-taking/transcription platform operated by an Australian entity (Blinq Technologies Pty Ltd). Its privacy documentation is comparatively detailed, addresses GDPR, UK GDPR and numerous US state privacy laws, and provides genuine opt-out mechanisms (enrichment suppression, colleague-discovery opt-out, Do Not Sell/Share, UOOM recognition). However, the supplied documents make no explicit certification claims (no SOC 2, ISO 27001/42001, or trust-center attestation was accessible), describe only 'reasonable'/'industry-standard' security in generic terms, and involve substantial data flows: contact enrichment from third-party data providers, AI transcription of recorded conversations (which may capture sensitive personal information about both users and non-users), and delivery of data to third-party AI clients via MCP. The AI Notetaker feature can incidentally collect health, biometric, religious and other SPI, and the retention language is largely open-ended ('period necessary'), with a specific recording-retention window of Membership plus 30 days. The website terms also assert a broad, irrevocable, perpetual licence over 'User Content' posted to the Site/social media. These factors warrant a YELLOW rating: usable for professional purposes with precautions, but sensitive/regulated data should not be recorded or processed without contractual protections that were not provided here.
AI Transparency Facts
Independent analysis by TermsWatchdog · © 2026 TermsWatchdog
Input Data Ownership
The privacy policy states 'Your data is yours to share with your network,' framing user data as belonging to the user. However, the website Terms of Use grant Blinq a broad worldwide, irrevocable, perpetual, non-exclusive, transferable, royalty-free licence over any 'User Content' posted on or through the Site or social media, which is unfavourable and could cover uploaded material. Ownership of in-product inputs (cards, recordings) is not expressly assigned to the user beyond the general 'your data is yours' statement.
Output Data Ownership
The documents describe generation of AI transcriptions and summaries of recorded conversations but do not explicitly state who owns those AI-generated outputs. The policy is silent on output ownership, and the retention clause treats recordings and 'related output data' as material Blinq may store and process. This silence is itself a risk signal for professional users.
Training Data Usage
The privacy policy does not explicitly state whether user inputs, recordings or transcripts are used to train Blinq's or third parties' models. It states Blinq 'may use any aggregated and anonymized data' after deletion, and lists improving services as a purpose, but there is no clear statement either permitting or prohibiting model training on user content. This silence on training use is a meaningful gap for a product that ships AI transcription features.
Data Retention & Deletion
Blinq provides deletion rights (contact support or use the privacy webform) and specifies a concrete retention window for recordings of 'the term of Membership plus 30 days.' However, general personal-information retention is open-ended ('period necessary to comply with our legal obligations, resolve disputes, and enforce our agreements and operate our services'), Blinq may keep unrevised copies after a deletion request, and no data-retention SLA, security audit-log retention, or deletion timeline (beyond statutory response windows) is disclosed.
Third-Party Data Sharing
Blinq states it does not sell personal information, and much sharing is integral to the service (sharing cards with recipients, sending recordings to AI transcription and hosting providers, delivering data to user-connected AI clients). Sharing is disclosed and largely purpose-limited, and marketing emails are not shared with advertisers. However, Blinq also collects from and provides data to third-party data providers for enrichment, and recordings (potentially containing SPI) may be shared with US-based AI providers, which widens the sharing surface beyond the user's direct network.
Opt-Out Rights
The documents provide multiple concrete opt-out mechanisms: a Do Not Sell or Share My Personal Information control, recognition of Universal Opt-Out Mechanisms/Global Privacy Control, a webform to opt out of contact enrichment (with a suppression list), the ability to opt out of appearing to colleagues, and unsubscribe from marketing. These are explicit and actionable, which the rating reflects positively.
Compliance & Certifications
As an enterprise SaaS tool, Blinq is assessed against the universal baseline plus SOC 2 Type II and ISO 27018. The documents claim compliance with GDPR, UK GDPR, the Australian Privacy Act, and numerous US state privacy laws, and Blinq names a GDPR Data Protection Officer — but these are asserted-compliance claims, not third-party attestations. No SOC 2, ISO 27001/27018, ISO 42001, or NIST CSF certification is evidenced in the supplied text (a trust center at trust.blinq.me was referenced but inaccessible). No relevant framework is certified with evidence, so the rating cannot be GREEN.
Model Explainability & Auditability
The supplied documents contain no information about model explainability, transparency into AI behaviour, or enterprise auditing capabilities for the AI transcription/summary or enrichment features. The policy confirms AI outputs are generated but provides no auditability commitments. This total silence is a high-risk signal for professional users relying on AI-generated summaries.
Security Practices & Breach History
Blinq references a responsible-disclosure program and describes 'industry-standard security measures, including encryption and access controls' and 'reasonable administrative, technical, and physical safeguards,' plus a data-breach notification process. However, the descriptions are generic: no specifics on encryption at rest vs in transit standards, penetration testing, or certifications are provided in the accessible text, and the vendor expressly disclaims that security 'cannot be guaranteed.' No breach history is disclosed. A security page and trust center are referenced but were inaccessible.
Enterprise vs. Consumer Risk Delta
The privacy policy notes that where a user accesses the Services via an organisation-provided account, the organisation can access and handle the user's data and controls it under its own policy. Beyond this, the accessible documents do not detail material data-handling differences between free and paid/enterprise tiers, and no enterprise agreement, DPA or MSA was retrievable. The consumer-facing documents therefore cannot establish enterprise carve-outs, which is a limitation for business buyers.
Human Review of User Inputs
The documents do not clearly state whether Blinq staff read or access user prompts, cards, or recordings/transcripts. For website User Content, Blinq reserves the right to review and remove it, implying human access to that content. For AI recordings, the policy describes automated transcription and sharing with providers but is silent on internal human review, which leaves the question partly unanswered.
Regulatory & Litigation Exposure
The policy discloses that Blinq may share personal information with government agencies, courts and tribunals where required or permitted by law, and may participate in legal and regulatory processes. It also flags that data may transfer in a merger or acquisition. No current litigation, government-request statistics, or transparency reporting are disclosed, so users have limited visibility into actual law-enforcement cooperation practices.
PII & SPI Data Inventory
Blinq collects extensive PII (name, email, phone, address, account credentials, IP/device data, geolocation lat/long, usage data) and, critically, can collect SPI through its AI recording feature. The policy expressly acknowledges recordings may capture sensitive categories including health/medical, biometric, religious/philosophical beliefs, genetic and neural data, union membership, and children's data, which may be shared with third-party AI and storage providers in the US. While Blinq discloses this and asks users not to include SPI and to obtain consent, the collection of broad SPI (including from non-users) with onward sharing warrants a RED rating.
Policy–Product Currency
The Privacy Policy is dated 'Last updated: July 09, 2026,' well within 12 months of the analysis date, and demonstrably covers the AI capabilities the product ships: it addresses AI transcription/summaries, contact enrichment, recordings, and even named third-party AI clients via the Model Context Protocol (ChatGPT/OpenAI, Claude/Anthropic, Copilot/Microsoft). The Terms of Use are older (January 21, 2025) but the governing privacy document keeps clear pace with the product surface (Digital Business Cards, AI Notetaker, Contact Enrichment).
Cross-Document Consistency
Three documents were supplied (Terms of Use, Privacy Policy, and a Security/responsible-disclosure page, though the last was truncated). Comparing the Terms of Use and Privacy Policy, no material or critical contradictions were identified: the privacy 'your data is yours / no selling' stance and the Terms' User Content licence address different content categories (in-product data vs Site/social-media posts) and are reconcilable. No conflicting retention periods, opt-out promises, or training statements were found across documents.
You've read all 15 risk ratings for Blinq. Create a free account to see the exact policy wording behind each rating.