Effective 23 August 2026

Privacy Policy

Bloomy holds mood entries, journal writing, sleep records and habit history. That is sensitive material, so this page says plainly what is collected, what leaves our systems, and what you can do about it. It describes what the product actually does today, not what it may do later.

Who is responsible

Bloomy is operated by Ugurcan Ozcelik. For data protection purposes that is the data controller. Questions about anything on this page go to the contact address in the last section.

What we collect

Two categories, and the distinction matters. Account data is what we need to let you in. Wellbeing data is what you write.

DataWhy we hold it
Email addressIdentifies your account and receives sign-in links. Required.
Name and avatarOnly if you sign in with Google, which supplies them. Used to address you in the interface.
Passkey credentialsIf you register one, so you can sign in without a link.
Session recordsKeeps you signed in. Deleted when the session expires or you sign out.
Sign-in recordsEach sign-in, sign-up and sign-out, with the method used, the IP address and the browser string. Kept 90 days, then deleted. Used to spot account compromise and to see whether the product is being used at all.
Mood entriesThe daily readings the product is built around.
Journal entriesYour writing. Free text, whatever you put in it.
Sleep, activity and habit recordsThe other three data streams the correlation engine reads.
Meditation sessionsWhich sessions you played and for how long.
Goals, achievements and statsProgress tracking and the gamification layer.
Subscription recordsIf you subscribe: plan, status and period. Card details never reach us; the payment processor holds those.

We do not collect location, contacts, device identifiers for advertising, or health data from other apps.

What the AI features send out

This is the part worth reading twice. When you ask for coaching, an insight, or a habit recommendation, the entries relevant to that request are sent to our AI provider so it can produce the answer. That can include journal text and mood history.

The provider processes the request and returns a response. Under our agreement it does not use that content to train models and does not retain it beyond what is needed to serve the request. If you would rather no writing left our systems at all, do not use the AI features. Everything else in Bloomy works without them.

Sign-in records and who can see them

We log each sign-in, sign-up and sign-out: the time, the method, the IP address and the browser string. It is how an account compromise becomes visible, and it is the only way we can tell whether anyone is using the product. These records are deleted after 90 days.

An administrator can see the account list and this sign-in log. What they cannot see is what you wrote. The admin view is built to show counts, never content: it can tell that an account has 12 mood entries and 3 journal entries, and it cannot open any of them.

There is no analytics or advertising SDK, no session recording, and no behavioural tracking beyond the sign-in log described here.

Who else processes your data

We use a small number of processors. Each one only receives what it needs for its job.

ProcessorWhat it handles
Hosting and database providerRuns the application and stores every record described above.
AI providerReceives entry content when you use a coaching or insight feature. See the section above.
Email providerDelivers sign-in links. Receives your email address and nothing else.
GoogleOnly if you use Google sign-in, and only to verify who you are.
Payment processorOnly if you subscribe. Handles the transaction and holds the card details we never see.

We do not sell your data, and we do not share it for advertising. We would disclose it if legally compelled, and would tell you unless barred from doing so.

What you can do with your data

These are not promises for later. They are built and you can use them now, from Settings:

  • Export everything. A machine-readable file containing all of it.
  • Delete by category. Remove your journal, or your mood history, without touching the rest.
  • Delete the account. This removes the account and every record attached to it. It cannot be undone.

Depending on where you live you may also have the right to correct your data, object to processing, or complain to a supervisory authority. Write to us and we will act on it.

How long we keep it

Entries stay until you delete them or close the account. When you delete an account the records go with it, apart from anything we are legally required to keep, such as invoices for a paid subscription. Backups roll off within thirty days.

Security

Data is encrypted in transit and at rest. Sign-in links are single-use and expire in fifteen minutes; the link itself is stored only as a hash. Sessions are held in httpOnly cookies. Access to production data is limited to what is required to operate the service.

We do not claim any compliance certification. Bloomy is a consumer wellbeing product, not a medical record system, and it is not covered by HIPAA. If you need a product operating under that framework, this is not one.

Cookies

Bloomy sets a session cookie so you stay signed in, and remembers your theme preference. That is all. There are no advertising or analytics cookies, so there is no consent banner to dismiss.

Children

Bloomy is not intended for anyone under 16. We do not knowingly collect data from children. If you believe a child has created an account, contact us and we will remove it.

Changes

If this policy changes in a way that affects how your data is handled, we will email you before it takes effect. The effective date at the top always reflects the current version.

Contact

Questions, requests, or complaints: reach us through the address listed on the Terms of Service. We answer data requests within thirty days.