Bloom

Privacy Policy

Bloom · Last updated: June 2026

1. Data Controller

The Data Controller for your personal data is:

Andrew Blewett
101 High Trees Close, Redditch, Worcestershire, B98 7XL, United Kingdom
Email: andyblewett991@gmail.com

This policy applies to the Bloom app on iOS, Android, and Web and is governed by the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018 (DPA 2018).

2. Special Category Data — Important Notice

Bloom processes special category health data as defined by Article 9 UK GDPR, including:

  • Sobriety start date and milestones
  • Relapse history and timestamps
  • Journal entries including mood ratings and freeform text
  • Craving tool usage records
  • Recovery-related notes and reflections

All of this data is stored exclusively on your local device. It is never uploaded to our servers or transmitted to any third party. The lawful basis for processing this special category data is your explicit consent under Article 9(2)(a) UK GDPR, given when you first set up the app. You may withdraw consent at any time by deleting your data via Settings → Reset Everything.

3. Data We Collect and Where It Is Stored

CategoryExamplesStorageLawful Basis
Recovery data (special category)Sobriety date, relapses, journal, mood, craving logsLocal device only — never uploadedExplicit consent (Art. 9(2)(a))
App preferencesTheme, pet name, custom labelsLocal device onlyConsent (Art. 6(1)(a))
Account credentials (optional)Email address, hashed passwordSupabase (EU) — only if you create an accountContract (Art. 6(1)(b))
Technical dataApp version, OS version, crash reports (anonymised)Local or anonymisedLegitimate interests (Art. 6(1)(f))

4. Data Retention

Data typeRetention period
All local health and recovery dataRetained on device until you delete it via Settings or uninstall the app
Optional account credentialsUntil you request account deletion; deleted within 30 days of request
Anonymised crash reports90 days

5. Third-Party Services

ProcessorPurposeLocationSafeguard
SupabaseOptional account authentication only — no health data storedEuropean UnionEU-hosted; DPA in place
Apple App Store / Google PlayApp distributionUSAApple/Google's own privacy policies

We do not use advertising networks, tracking SDKs, or sell your data.

6. Your Rights Under UK GDPR

  • Right of access – request a copy of the personal data we hold about you
  • Right to rectification – request correction of inaccurate data
  • Right to erasure – delete your account or data at any time via Settings
  • Right to restriction of processing – request we limit how we use your data
  • Right to data portability – export your data as JSON from Settings → Export Data
  • Right to object – object to processing based on legitimate interests
  • Right to withdraw consent – withdraw consent for health data processing at any time without affecting prior processing

To exercise any right, email andyblewett991@gmail.com. We will respond within one calendar month.

7. Right to Lodge a Complaint

Information Commissioner's Office (ICO)
Website: ico.org.uk
Helpline: 0303 123 1113

8. Age Restrictions

Bloom is intended for users aged 17 and over. The app deals with sobriety and addiction recovery. We do not knowingly collect data from users under 13. If you believe a child under 13 is using the app, please contact us immediately.

9. Data Security

  • All health data is stored only on your device and is never transmitted to our servers
  • Optional account data is encrypted in transit using TLS 1.2+
  • Passwords are hashed and never stored in plaintext
  • Supabase enforces row-level security ensuring accounts can only access their own data

10. Changes to This Policy

Material changes will be communicated via in-app notification at least 14 days before taking effect.