How we protect your AI keys
Your AI keys are encrypted, never shown again after saving, never logged, and only used by the part of Bloomtack that makes the call.
An AI key can spend money on your provider account, so Bloomtack treats it like a password.
What we do
- Encrypted at rest. Each key is encrypted with the same keys that protect Pinterest tokens. The master key is kept outside the database.
- Never shown again. After you save a key, Bloomtack shows only the provider, your name for it, the last four characters and when it was last used. The key never goes back to your browser.
- Used in one place. A key is decrypted only inside the background worker that makes the AI call, and only for that call. The rest of Bloomtack, including our support team's tools, cannot read it.
- Never logged. Keys never appear in logs, error reports or alerts. Neither do your prompts.
- Only your key. Bloomtack has no AI key of its own in production and never switches to one.
What we record
Each AI call is recorded with the task, provider, model, amount used and whether it worked, so you can see your usage under Usage in Settings → AI keys. The record never contains the key or the prompt text.
What you can do
- Set a monthly spending limit with your provider.
- Use a separate key for Bloomtack, so you can delete it on the provider's side at any time without affecting other tools.
- Replace or remove the key in Settings → AI keys whenever you like. Removing it switches its tasks to No AI at once.
Your content and AI
Prompts are built from your blog posts only. Pinterest data, such as your pin results, is never sent to an AI provider and never used to train AI.
Updated September 30, 2026.