Privacy Policy

Last updated: January 25, 2026

Introduction

Welcome to Bloom. We respect your privacy and are committed to protecting your personal data. This privacy policy explains how we collect, use, and safeguard your information when you use our application and services.

Bloom is a habit tracking application designed for families and individuals. We help you build better habits together through gamification and proven habit-building frameworks.

Information We Collect

Information You Provide

  • Account Information: Name, email address, and password when you create an account
  • Profile Information: Optional profile picture, display name, and family information
  • Habit Data: Habits you create, track, and complete, including habit names, descriptions, frequencies, and completion records
  • Family Data: Information about family members you invite and their habit tracking progress
  • Rewards and Tasks: Custom rewards and tasks you create within the application

Information Automatically Collected

  • Usage Data: How you interact with the app, features you use, and time spent in the application
  • Device Information: Device type, operating system, browser type, and app version
  • Session Data: Authentication tokens and session information to keep you logged in

How We Use Your Information

We use the information we collect for the following purposes:

  • Provide Services: Enable core functionality including habit tracking, family coordination, progress visualization, and gamification features
  • Personalization: Customize your experience and provide relevant recommendations
  • Communication: Send important updates about your account, habits, and streaks
  • Security: Protect your account and detect fraudulent or unauthorized activity
  • Improvement: Analyze usage patterns to improve our services and develop new features
  • Compliance: Meet legal obligations and enforce our terms of service

Data Storage and Security

We take the security of your data seriously and implement industry-standard measures to protect it:

  • Encryption: All data is encrypted in transit using HTTPS/TLS and at rest
  • Password Security: Passwords are hashed using bcrypt and never stored in plain text
  • Secure Infrastructure: We use secure, industry-standard database services (MongoDB, Redis) with access controls
  • Access Control: Limited employee access to user data on a need-to-know basis
  • Regular Backups: Your data is regularly backed up to prevent loss

Data Sharing and Disclosure

We do not sell your personal information. We may share your information only in the following circumstances:

  • Family Members: Your habit data is shared with family members you explicitly invite to your family group
  • Service Providers: Trusted third-party services that help us operate (hosting, authentication, analytics) under strict confidentiality agreements
  • Legal Requirements: When required by law, legal process, or to protect rights and safety
  • Business Transfers: In the event of a merger, acquisition, or sale of assets (you will be notified)

Third-Party Services

Our application may use the following third-party services:

  • Authentication Services: For secure login and account management
  • Cloud Hosting: For storing and processing data
  • Analytics: To understand how users interact with our app and improve the experience

These services have their own privacy policies. We encourage you to review them.

Children's Privacy

Bloom is designed for families, which may include children under 13. We comply with the Children's Online Privacy Protection Act (COPPA):

  • Children under 13 can only use the app as part of a family account managed by a parent or guardian
  • Parents have full control over their children's data and can delete it at any time
  • We collect only the minimum information necessary for children to use the habit tracking features
  • Children's data is not used for advertising or marketing purposes
  • Parents can review, modify, or delete their child's information in the app or by contacting us

Your Rights and Choices

You have the following rights regarding your personal data:

  • Access: Request a copy of your personal data
  • Correction: Update or correct inaccurate information
  • Deletion: Request deletion of your account and personal data in Settings
  • Export: Download your habit data in a portable format
  • Opt-out: Unsubscribe from promotional communications
  • Restriction: Request restriction of processing in certain circumstances

To exercise these rights, you can use the in-app Settings or contact us using the information provided below. For more details, see our Data Deletion instructions.

Data Retention

We retain your personal data for as long as necessary to provide our services and comply with legal obligations:

  • Account data is retained while your account is active
  • Upon account deletion, we begin removal or anonymization and complete it within 30 days
  • Some data may be retained for legal, security, or business purposes as required by law
  • Backups may retain data for up to 90 days before automatic deletion

International Data Transfers

Your information may be transferred to and processed in countries other than your country of residence. These countries may have different data protection laws. We ensure appropriate safeguards are in place to protect your data in accordance with this privacy policy.

Changes to This Privacy Policy

We may update this privacy policy from time to time. We will notify you of significant changes by posting the new policy on this page and updating the "Last updated" date. We encourage you to review this privacy policy periodically. Your continued use of the application after changes constitutes acceptance of the updated policy.

Contact Us

If you have questions, concerns, or requests regarding this privacy policy or your personal data, please contact us:

Legal Compliance

This privacy policy is designed to comply with:

  • General Data Protection Regulation (GDPR)
  • California Consumer Privacy Act (CCPA)
  • Children's Online Privacy Protection Act (COPPA)
  • Google Play Privacy Requirements
  • Apple App Store Privacy Requirements