Legal
Privacy Policy
How Bloomopia collects, uses, stores, and protects your information — including special category health-related data where applicable.
Last updated: 10 July 2026
1. Data controller
Bloomopia (“we”, “us”) is the data controller for personal data processed through the Bloomopia application and website. For privacy enquiries or to exercise your rights, contact: privacy@bloomwellbeing.app
2. Scope & regulatory framework
This Privacy Policy is designed to meet the requirements of the UK General Data Protection Regulation (UK GDPR), the EU General Data Protection Regulation (GDPR) where applicable, and the Data Protection Act 2018 (UK).
3. What data we collect
Data stored locally on your device (via browser or app storage) may include:
- Account preferences (display name, plant theme, focus areas).
- Wellbeing entries: mood logs, journal reflections, habits, and programme progress.
- Chat conversation history and saved guides (where you choose to save them).
- Approximate location (city/country/coordinates) if you grant location permission — used to personalise local support resources.
- App settings: voice preferences, reminder schedules, premium status flags.
Data processed when you use connected features may include:
- Account email address if you register via Supabase authentication.
- Payment status via Apple, Google, or Stripe (we do not store full card details).
- AI chat message content transmitted to our AI provider when you send messages (see Section 5).
- Device type, app version, and anonymised usage metrics for reliability and security.
We do not knowingly collect data from children under 18 without verified parental consent.
4. Lawful bases for processing
- Consent — mood tracking, journal entries, location personalisation, marketing communications (where offered), and special category health-related wellbeing data you choose to record.
- Contract — providing the Service you request, including premium features.
- Legitimate interests — security, fraud prevention, service improvement, and anonymised analytics, balanced against your rights.
- Legal obligation — responding to lawful requests from authorities where required.
5. AI & third-party processors
BloommyAi is off by default. When you enable BloommyAi in Account → Privacy (or via an in-chat opt-in), Bloomopia may send chat messages and wellness context you choose to share to Google (Gemini API) using current-generation Gemini models. Sending a chat message alone does not turn BloommyAi on. This powers Ask Bloommy cloud chat, optional daily insights, and AI-assisted guides when you request them.
By plan: Free and paid subscriptions use the same Google Gemini cloud family when BloommyAi is on. Free cloud chat is limited by daily Cosmic Sparks; paid plans follow your subscription limits. When BloommyAi is off, you are offline, or cloud AI is unavailable, replies use on-device companion logic with no third-party LLM. See AI Transparency for plain-language details.
We instruct AI processors under data processing agreements to use your data only to provide the Service. Your identifiable content is not used to train public foundation models. AI output is for general wellness support only — not medical diagnosis or treatment.
Other third-party services may include authentication (Supabase), mapping (Google Maps links open externally), geocoding (OpenStreetMap Nominatim), and payment processors. Each operates under its own privacy policy when you interact directly with them.
6. Data retention
Local data persists on your device until you delete it or uninstall the app. Account-linked data is retained while your account is active and for a reasonable period thereafter for legal and backup purposes, unless you request erasure sooner.
7. Your rights (Access, Rectification, Erasure)
Under UK GDPR / GDPR, you have the following rights, subject to applicable exceptions:
- Right of access — request a copy of personal data we hold about you.
- Right to rectification — correct inaccurate or incomplete data.
- Right to erasure (“Right to be Forgotten”) — request deletion of your personal data where no compelling reason remains for processing.
- Right to restrict processing — limit how we use your data in certain circumstances.
- Right to data portability — receive your data in a structured, machine-readable format where applicable.
- Right to object — object to processing based on legitimate interests or direct marketing.
- Right to withdraw consent — at any time, without affecting prior lawful processing.
To exercise these rights, email privacy@bloomwellbeing.app. We respond within one month. You may lodge a complaint with the ICO (UK) or your local supervisory authority.
9. Security
We implement appropriate technical and organisational measures including encryption in transit (HTTPS/TLS), access controls, and secure authentication. No system is completely secure; please use a strong password and protect your device.
10. International transfers
Where data is transferred outside the UK/EEA, we rely on appropriate safeguards such as Standard Contractual Clauses or adequacy decisions, as required by applicable law.
11. Changes to this policy
We may update this Privacy Policy periodically. We will notify you of material changes via the app or email. The “Last updated” date at the top reflects the current version.
12. Contact
Data Protection Contact: privacy@bloomwellbeing.app