Privacy Policy
Bloom · Last updated: June 2026
1. Data Controller
The Data Controller for your personal data is:
Andrew Blewett
101 High Trees Close, Redditch, Worcestershire, B98 7XL, United Kingdom
Email: andyblewett991@gmail.com
This policy applies to the Bloom app on iOS, Android, and Web and is governed by the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018 (DPA 2018).
2. Special Category Data — Important Notice
Bloom processes special category health data as defined by Article 9 UK GDPR, including:
- •Sobriety start date and milestones
- •Relapse history and timestamps
- •Journal entries including mood ratings and freeform text
- •Craving tool usage records
- •Recovery-related notes and reflections
All of this data is stored exclusively on your local device. It is never uploaded to our servers or transmitted to any third party. The lawful basis for processing this special category data is your explicit consent under Article 9(2)(a) UK GDPR, given when you first set up the app. You may withdraw consent at any time by deleting your data via Settings → Reset Everything.
3. Data We Collect and Where It Is Stored
| Category | Examples | Storage | Lawful Basis |
|---|---|---|---|
| Recovery data (special category) | Sobriety date, relapses, journal, mood, craving logs | Local device only — never uploaded | Explicit consent (Art. 9(2)(a)) |
| App preferences | Theme, pet name, custom labels | Local device only | Consent (Art. 6(1)(a)) |
| Account credentials (optional) | Email address, hashed password | Supabase (EU) — only if you create an account | Contract (Art. 6(1)(b)) |
| Technical data | App version, OS version, crash reports (anonymised) | Local or anonymised | Legitimate interests (Art. 6(1)(f)) |
4. Data Retention
| Data type | Retention period |
|---|---|
| All local health and recovery data | Retained on device until you delete it via Settings or uninstall the app |
| Optional account credentials | Until you request account deletion; deleted within 30 days of request |
| Anonymised crash reports | 90 days |
5. Third-Party Services
| Processor | Purpose | Location | Safeguard |
|---|---|---|---|
| Supabase | Optional account authentication only — no health data stored | European Union | EU-hosted; DPA in place |
| Apple App Store / Google Play | App distribution | USA | Apple/Google's own privacy policies |
We do not use advertising networks, tracking SDKs, or sell your data.
6. Your Rights Under UK GDPR
- •Right of access – request a copy of the personal data we hold about you
- •Right to rectification – request correction of inaccurate data
- •Right to erasure – delete your account or data at any time via Settings
- •Right to restriction of processing – request we limit how we use your data
- •Right to data portability – export your data as JSON from Settings → Export Data
- •Right to object – object to processing based on legitimate interests
- •Right to withdraw consent – withdraw consent for health data processing at any time without affecting prior processing
To exercise any right, email andyblewett991@gmail.com. We will respond within one calendar month.
7. Right to Lodge a Complaint
Information Commissioner's Office (ICO)
Website: ico.org.uk
Helpline: 0303 123 1113
8. Age Restrictions
Bloom is intended for users aged 17 and over. The app deals with sobriety and addiction recovery. We do not knowingly collect data from users under 13. If you believe a child under 13 is using the app, please contact us immediately.
9. Data Security
- •All health data is stored only on your device and is never transmitted to our servers
- •Optional account data is encrypted in transit using TLS 1.2+
- •Passwords are hashed and never stored in plaintext
- •Supabase enforces row-level security ensuring accounts can only access their own data
10. Changes to This Policy
Material changes will be communicated via in-app notification at least 14 days before taking effect.