1. Introduction
Bloom ("we," "our," or "us") is a relationship wellness app that helps you nurture your personal connections. In Bloom, each person you care about is represented as a "plant" in your garden.
We take your privacy — and the privacy of the people you tend — seriously. Bloom is built so that the most identifying information, the names and contact details of the people in your life, never leaves your device.
This Privacy Policy explains what information we collect, how we use it, and your rights regarding that data. By using Bloom, you agree to the practices described here.
Minimum Age: Bloom is intended for users aged 13 and older. We do not knowingly collect personal information from children under 13. If you are under 13, please do not use this app.
2. Information We Collect
Bloom stores data in two clearly separated places: our servers and your device. What lives where is described below.
2.1 Information Stored on Our Servers
Account Information
- Your email address, used for account creation and authentication
We use passwordless authentication. Bloom never creates, stores, or transmits a password for your account. You sign in by entering your email and a one-time code (OTP) sent to that address.
Plant Records (the people you tend)
- The relationship archetype and care dimensions you choose for each plant
- The day and month of a person's birthday, if you enter one. Bloom does not collect or store birth years — the day and month are stored against a fixed placeholder year.
- The plant's care state and health values, which the app calculates from your activity
- The illustration you selected for the plant
Plant records on our servers do not contain the person's name. See Section 2.2.
Relationship Questionnaire Answers
When you add a plant, Bloom asks you a short series of questions about the relationship to work out what kind of care it needs. Your answers to those questions are stored on our servers alongside the plant record.
Care Logs
Each time you log an interaction, we store:
- The care action performed and which in-app suggestion (if any) you acted on
- A timestamp
- Four descriptors of the interaction that the care engine needs in order to score it:
- Channel — the general mode of contact: message, call, video, or in person. Bloom records the mode, never which specific app you used.
- Depth — roughly how substantial the interaction was
- Nature — what kind of exchange it was (for example: you caught up, one of you opened up, or there was tension or a boundary set)
- Tenor — how the interaction left you feeling: closer, fine, or off
Taken together, care logs form a record of how your relationships are going over time. Bloom needs this to calculate plant health, but we recognise it is sensitive, and we treat it accordingly. It is never used for advertising, sold, or shared.
Garden Organisation
- The names, descriptions, and emoji you give to custom garden tabs
These are free-text fields you write yourself. If you type a real person's name into a tab name or description, that text is stored on our servers — unlike plant names, we cannot separate it out automatically.
Plant Invitations
See Section 4 for a full description of this feature and exactly what it transmits.
2.2 Information Stored on Your Device Only
The following is written to your device's secure storage (iOS Keychain or Android Keystore) and is never transmitted to our servers, with the single exception described in Section 4:
- The names and nicknames you give your plants — the real names of the people you tend
- Contact details: phone numbers, email addresses, and handles for Instagram, WhatsApp, Snapchat, Telegram, Signal, and TikTok
- Greeting message preferences and which channel you prefer for calls, messages, and video
- Private notes you write about a plant
- Message drafts you compose in the app
- Conflict-preparation ("pruning") worksheet answers
Bloom also keeps an encrypted offline copy of your garden on your device so the app works without a connection. Because your plant names are merged into the garden view before it is cached, this cache contains names, birthdays, and care history. It is encrypted with an AES-256 key held in your device's secure storage, is scoped to your account, and is discarded when you sign out or when the app updates.
2.3 Information We Do NOT Collect
- We do not use any analytics, telemetry, or crash-reporting service in the app. Bloom contains no third-party analytics or crash SDK. We do not track which screens you visit, how long you use the app, or what you tap. We receive no error reports or crash logs from your device, and we do not generate an advertising or installation identifier. (This website is separate and is covered in Section 9.)
- We do not read the content of your messages on WhatsApp, SMS, Instagram, Telegram, Snapchat, Signal, TikTok, or any other platform. When you tap to contact someone, Bloom opens that app via a link — we have no visibility into what you send or receive.
- We do not access your device's contact list, phone book, photos, camera, or microphone.
- We do not collect location data of any kind.
- We do not collect birth years.
- We do not run advertising, and we do not sell your data.
If we ever add crash reporting or analytics to the app, we will update this policy and tell you in the app before it takes effect.
3. How We Use Your Information
| Purpose | Data Used | Legal Basis (GDPR) |
|---|---|---|
| Provide and operate the app | Account email, plant records | Contract performance |
| Calculate plant health and care guidance | Care logs, questionnaire answers, timestamps | Contract performance |
| Show you when a birthday is coming up | Birthday day and month you enter | Contract performance |
| Deliver a plant invitation you chose to send | Hashed recipient contact, your message, your email address | Contract performance |
| Respond to support requests | Email, issue details | Legitimate interest |
| Comply with legal obligations | As required | Legal obligation |
We do not use your data for advertising, for profiling on behalf of third parties, or for automated decision-making that produces legal effects concerning you.
4. Information About Other People
A core feature of Bloom involves recording information about other people — friends, family, colleagues. This section explains how we limit that, and where the limits end.
4.1 Names and Contact Details Stay on Your Device
Bloom is designed so that a person's name and contact details never reach our servers. Your garden on our servers is a set of unnamed plant records; the names are supplied by your device when the app renders them. If our database were ever exposed, it would not reveal who the people in your garden are.
4.2 The One Exception: Plant Invitations
Bloom lets you invite someone to share a plant with you, so you can both tend the relationship. This feature transmits that person's email address to our servers.
When you send an invitation:
- You type the recipient's email address, and it is sent to our servers over an encrypted connection.
- On arrival it is immediately converted to an irreversible cryptographic hash. We do not store the address itself — only the hash, which lets us recognise the recipient if they sign up, and which cannot be reversed back into an email address.
- The plaintext address exists only in transit and momentarily in our server's memory while it is being hashed.
- Any personal message you attach to the invitation is stored on our servers as written, until the invitation is accepted, declined, or expires.
- If the recipient opens the invitation, your own account email address is shown to them, so they can see who is asking. Do not send an invitation to someone you would not want to share your email address with.
Invitations expire automatically. Deleting your account removes every invitation you have sent or received, including those addressed to a recipient who never signed up.
4.3 Your Responsibility
You are solely responsible for ensuring you have an appropriate basis to record information about another person in Bloom. By entering someone's information, you represent that:
- You are doing so for your own personal relationship-management purposes
- You will not use it in a way that harms, surveils, manipulates, or harasses anyone
- You understand where that data is stored, as described in this policy
If someone asks you to remove their information from your Bloom garden, you can delete their plant, which erases both the server record and everything stored about them on your device.
5. Data Storage and Security
Where Your Data Lives
| Data | Location | Protection |
|---|---|---|
| Account email | Supabase (cloud) | Passwordless OTP; encrypted in transit and at rest |
| Plant records, care logs, questionnaire answers, garden tabs | Supabase (cloud) | Encrypted in transit (TLS) and at rest; contain no names |
| Invitation recipient contact | Supabase (cloud) | Stored only as an irreversible keyed hash |
| Names, contact details, notes, drafts, worksheets | Your device only | iOS Keychain / Android Keystore |
| Offline garden cache | Your device only | AES-256 encrypted, key held in device secure storage, scoped to your account |
Supabase
Our backend is provided by Supabase, which hosts data on infrastructure operated by Amazon Web Services (AWS). Supabase is our data processor. We have entered into a Data Processing Agreement (DPA) with Supabase as required by GDPR Article 28. For EU users, see Supabase's compliance documentation regarding GDPR and data residency.
Plant illustrations are served from Supabase storage. As with any image request, this means Supabase receives your device's IP address when artwork loads.
Security Measures
- All data is transmitted over HTTPS (TLS 1.2+)
- Authentication is passwordless; no password is created or stored for your account
- Access to your data is enforced at the database level, so one account cannot read another's records
- On-device data is held in the operating system's secure storage
- Access to production systems is limited to authorised personnel
No system is completely secure. If you believe your account has been compromised, contact us immediately at hello@bloomapp.co.
6. Data Retention and Deletion
| Data | Retention |
|---|---|
| Account, plant records, care logs, questionnaire answers, garden tabs | Until you delete your account |
| Invitations | Until accepted, declined, expired, or your account is deleted |
| On-device data (names, contacts, notes, drafts, worksheets) | Until you delete the plant, delete your account, or erase it as described below |
When You Delete Your Account
Deleting your account in the app (Profile → Delete Account) removes, in one operation:
- Every plant record, care log, questionnaire answer, garden tab, and invitation associated with you
- Your account itself
- All Bloom data stored on that device, including names, contact details, notes, drafts, worksheets, and the offline cache
Server-side data is deleted from our live database immediately. Copies may persist briefly in our hosting provider's encrypted backups until those backups rotate out, and we may retain limited records where required by law.
If You Uninstall Without Deleting Your Account
Your account and its server-side data remain, so you can sign back in later.
On Android, uninstalling removes all Bloom data from the device. On iOS, the operating system deliberately preserves items in the system Keychain when an app is deleted, so your encrypted on-device data may remain on the device after uninstalling. Bloom detects this and erases any leftover data automatically the first time the app is installed and opened again on that device. To remove it without reinstalling, delete your account before uninstalling, or erase the device.
7. Your Rights
For All Users
- Access: Email hello@bloomapp.co to request a copy of the personal data we hold about you. We will respond within 30 days. Note that data stored only on your device is already fully in your possession and is not something we can produce.
- Correction: You can edit plant details, birthdays, artwork, notes, and contact information directly in the app. For anything you cannot change in-app, email us.
- Deletion: Delete your account and all associated data in the app (Profile → Delete Account), as described in Section 6.
- Portability: Email hello@bloomapp.co to request a machine-readable export (JSON) of your server-side data. We will provide it within 30 days.
For EU/EEA Users (GDPR)
Under the General Data Protection Regulation, you also have:
- Right to restrict processing
- Right to object to processing based on legitimate interests
- Right to withdraw consent at any time, where processing is based on consent
- Right to lodge a complaint with your local data protection authority
To exercise any of these rights, contact hello@bloomapp.co. We will respond within one month, as GDPR requires.
For California Users (CCPA/CPRA)
California residents have the right to:
- Know what personal information we collect and how it is used
- Request deletion of personal information
- Correct inaccurate personal information
- Opt out of the sale or sharing of personal information — we do not sell or share your personal information, and we have not done so in the preceding 12 months
- Not be discriminated against for exercising these rights
To submit a request, contact hello@bloomapp.co or write to Bloom, [REGISTERED ADDRESS — REQUIRED FOR CCPA, NOT YET SUPPLIED].
8. Children's Privacy (COPPA)
Bloom is not directed at children under 13. We do not knowingly collect personal information from children under 13. If we learn that we have collected personal information from a child under 13 without parental consent, we will delete it promptly.
If you believe a child under 13 has provided us with personal information, contact hello@bloomapp.co.
9. Third-Party Services
| Service | Purpose | What it receives |
|---|---|---|
| Supabase | Authentication, database, artwork hosting | Your account email, the server-side data described above, your IP address |
| Expo (EAS Update) | Delivering app updates | Your device platform and app version when the app checks for an update at launch, plus your IP address |
| Apple App Store | App distribution (iOS) | Governed by Apple |
| Google Play Store | App distribution (Android) | Governed by Google |
The Bloom app contains no advertising networks, analytics providers, or crash-reporting services.
This website is a separate matter from the app. It uses Umami, a cookie-free analytics tool, to measure aggregate page traffic. Umami sets no cookies and does not follow you across sites.
Links to Messaging Apps
When you choose to contact someone, Bloom opens the relevant app on your device: the phone dialler, SMS, email, WhatsApp, Instagram, Telegram, Snapchat, Signal, or TikTok. This is a one-way handoff — Bloom passes the address or handle you stored on your device to the app you selected, and receives nothing back. We do not share any data with these services ourselves, and we cannot see whether or what you went on to send. Your use of those apps is governed by their own privacy policies.
10. International Data Transfers
If you are located outside the United States, your information may be transferred to and processed in the United States or other countries where our service providers operate. We take steps to ensure such transfers comply with applicable law, including the use of Standard Contractual Clauses where required.
11. Changes to This Policy
We may update this Privacy Policy from time to time. When we make significant changes, we will:
- Update the "Last Updated" date at the top
- Notify you in the app or by email for material changes
Your continued use of Bloom after changes take effect constitutes acceptance of the updated policy.
12. Contact Us
If you have questions, requests, or concerns about this Privacy Policy:
Email: hello@bloomapp.co Address: Bloom, [REGISTERED ADDRESS — REQUIRED FOR CCPA, NOT YET SUPPLIED] Response Time: We aim to respond within 5 business days; GDPR and CCPA requests within the statutory deadline.
Bloom is a relationship wellness tool designed to help you reflect on and nurture your personal connections. It is not a mental health service, therapeutic platform, or medical device.