1. Introduction and Scope
Bloom ("we", "us", or the "App") is a focus, mindfulness, and sleep habit-building app. This Privacy Policy explains what information Bloom processes, why it is processed, where it is stored, with whom it is shared, and the choices and rights available to you.
Bloom is offered in supported regions including mainland China. Our primary cloud infrastructure is located in mainland China. If you use Bloom outside mainland China, your information will be transferred to and processed in mainland China; see Section 5.
2. Information We Process
2.1 Account and profile information
- Email address and authentication information. Passwords are handled by our identity service and are not intentionally stored by us in plaintext. Email authentication may use a password or one-time verification code.
- If you use Sign in with Apple: the Apple account identifier and, when Apple makes them available, your email address and name.
- Your account identifier, nickname, and selected avatar. The current App uses a fixed set of flower illustrations and does not let you upload a photo.
- Profile and preference data, such as ambient-sound choice, reminder settings, garden layout, scene, pot, unlocked items, onboarding state, streaks, totals, focus minutes, coin balance, and entitlement state.
2.2 Activity and content
- Focus, mindfulness, and sleep session data, including session type, declared duration, start/completion times, status, cycle count, and anti-duplicate identifiers.
- Task or intention names you enter, flower records and their generated attributes, garden layout, timeline events, coin ledger entries, and shop or random-draw outcomes.
- Bedtime and wake-time preferences and nightly goal records. Bloom is not a medical product, and these records are not clinical measurements.
- Shared-garden data, including garden name, invitations, membership, and flowers contributed to the shared meadow.
2.3 Device, notification, and technical information
- If you enable remote notifications, we record your device operating-system type and the Expo push identifier used to send notifications to that device, together with its most recent update time.
- App version, platform, IP address, and ordinary request metadata visible to our cloud, update, and delivery providers when the App connects to their services.
- Interface language. Bloom reads device locale information locally to select a language and localized price presentation; the selected language may be sent as an
Accept-Language value so transactional emails use the appropriate language.
- App settings, cached server data, pending synchronization operations, and authentication-session data may be stored in app-private local storage on your device.
2.4 Complimentary access, purchase, and entitlement information
Each new account receives 14 days of complimentary access beginning at the server-recorded account creation time. We use that creation time to calculate when complimentary access ends. After it ends, you must purchase Bloom Plus to continue using Bloom's core features.
Apple processes Bloom Plus payments. We do not receive or store your card number or Apple ID password. To verify and grant access, Bloom processes the StoreKit-signed transaction, product identifier, transaction and original transaction identifiers, purchase and expiry times, displayed price, StoreKit environment, renewal status, and an account-binding token. These records prevent receipt reuse and bind access to the correct Bloom account.
2.5 Information Bloom does not collect through the current App
- No advertising SDK, third-party analytics SDK, behavioural analytics, cross-app tracking, or targeted advertising.
- No Bloom-operated crash telemetry. Errors may appear in device or platform logs, but the current App does not automatically send crash reports to us.
- No contacts, precise location, calendar, HealthKit/health-app data, camera recordings, or microphone recordings.
- No reading or uploading of your existing photo library. When you save a generated flower card, Bloom requests add-only access and writes only the card you chose to save.
3. How We Use Information
We process information to:
- create and secure accounts; provide timing, sleep, garden, sharing, synchronization, and shared-garden features;
- calculate server-authoritative rewards, prevent duplicate rewards, protect virtual-item and purchase integrity, and apply rate limits;
- send verification emails and notifications you enable;
- verify purchases, restore access, and maintain Bloom Plus entitlement status;
- provide support, investigate reports, maintain reliability and security, comply with law, and enforce our Terms.
For EEA/UK users, the legal bases may include performance of our contract, legitimate interests in operating and securing Bloom, consent where required, and compliance with legal obligations.
4. Sharing and Service Providers
We do not sell personal information and do not share it for cross-context behavioural advertising. We disclose information only as needed to:
- Tencent CloudBase / Tencent Cloud: authentication, PostgreSQL database, cloud functions, transactional email, and related backend infrastructure.
- Expo / EAS: app updates and Expo push delivery. Push tokens and notification content pass through Expo when remote notifications are sent.
- Apple: Sign in with Apple, App Store/StoreKit purchases, refunds, and APNs notification delivery. Android notifications may pass through Google FCM.
- Other shared-garden members: members of the same garden can see your account identifier within the service, nickname, accumulated focus minutes, streak, and shared-meadow flower attributes and timestamps. They do not receive your email address, password, purchase credentials, or private task names through the garden overview.
- Authorities, advisers, or a successor entity when required by law, needed to protect rights and safety, or involved in a merger, acquisition, financing, or asset transfer subject to appropriate protections.
If you use the system share sheet, the generated card is sent only to the app or recipient you choose, and that third party processes it under its own terms.
5. Storage Location and International Transfers
Important: Bloom's primary account and app-data backend uses Tencent CloudBase infrastructure in Shanghai, mainland China. If you use Bloom outside mainland China, your information is transferred to and processed in mainland China, where privacy laws and government-access rules may differ from those in your location.
We use HTTPS/TLS in transit, access controls, row-level authorization, least-privilege server credentials, and server-side validation for sensitive writes. Authentication-session data and caches are stored in app-private device storage and are also subject to your operating system's protections. No system can be guaranteed completely secure. Where applicable law requires a transfer mechanism or additional safeguards, we will use appropriate measures.
Remote notifications additionally pass through Expo and the relevant platform push gateway. Over-the-air updates are delivered through Expo's update infrastructure.
6. Retention and Account Deletion
- We retain account, profile, activity, garden, synchronization, and entitlement data while your account is active or as needed to provide Bloom.
- When an in-app account-deletion request succeeds, Bloom revokes a linked Apple authorization where required, deletes the profile that anchors your account data, cascades deletion through account-linked business tables (including sessions, flowers, sleep logs, ledgers, memberships, push tokens, subscription and purchase records), and deletes the platform login credential. Local signed-in state and app caches are cleared by the App. To let the same Apple purchase be restored safely after deletion while preventing entitlement theft between active accounts, we retain an irreversible hash of the account-binding token and its released status; this record contains neither the original token, your Apple ID, nor the deleted Bloom account identifier.
- Mistake protection: you can request recovery within 30 days of deletion. To prevent accidental permanent data loss, at deletion we create a single stored snapshot of the business data described above, held solely for recovery, retained for 30 days, and then automatically and permanently deleted by a scheduled job. The snapshot includes your email address and display name (needed to verify your identity and restore the account). It is accessible only to operations personnel handling a recovery request that you yourself make, and is used for no other purpose. To request recovery within the 30-day window, contact us at the email address below. If you would prefer immediate permanent deletion with no snapshot retained, tell us and we will delete the snapshot right away.
- A shared garden may remain for other members after you delete your account; your creator reference is cleared. Information no longer linked to your account may remain where necessary to preserve that shared resource.
- Service-provider backups, security logs, or records required by law may remain for a limited period and are then deleted or de-identified according to applicable retention rules.
- Deleting your Bloom account does not cancel an Apple auto-renewable subscription. Cancel it separately in Apple subscription settings to prevent future charges. Apple retains its own transaction records under Apple's policies.
7. Your Choices and Rights
Depending on your location, you may have rights to access, correct, delete, restrict, object, withdraw consent, and obtain a portable copy of personal information.
- Edit your nickname and flower avatar in the App.
- Enable or disable reminders and notifications in the App or system settings.
- Delete your account in the App at You → Account Management → Delete Account.
- Request a structured export or exercise another privacy right by emailing danyang.zhao@swiftpass.cn. We may need to verify your identity.
For users in mainland China, applicable rights under the Personal Information Protection Law of the People's Republic of China may include the right to know, decide, restrict or refuse processing, access, copy, correct, supplement, and delete personal information, withdraw consent where processing relies on consent, and cancel an account. Withdrawing consent does not affect processing carried out before withdrawal, and some information may still be processed where another lawful basis applies.
EEA/UK users may complain to their supervisory authority. California residents may exercise rights to know, correct, and delete; Bloom does not sell or share personal information as those terms are used for cross-context behavioural advertising, and we do not discriminate for exercising privacy rights.
8. Device Permissions and Capabilities
- Notifications: local focus, bedtime, session-completion, or leave-session reminders and, where enabled, remote account or garden notifications. Some iOS reminders may be marked time-sensitive.
- Add to Photos: add-only permission used solely when you choose to save a generated card; Bloom does not request read access.
- Background audio: allows selected ambient audio to continue while a session runs with the screen off.
- Screen-lock state: Android screen-off events and iOS protected-data notifications are used locally to distinguish locking the screen from leaving the App when applying focus-session rules. This signal is not uploaded as a separate data field.
Declining an optional permission disables only the feature that needs it.
9. Children's Privacy
Bloom is intended for a general audience. In mainland China, Bloom is not directed to children under 14; elsewhere, it is not directed to children under 13 or any higher minimum age set by local law. We do not knowingly collect personal information from children below the applicable age without legally required guardian consent. If you believe this has occurred, contact us so we can investigate and delete it.
10. Tracking and Advertising
Bloom does not request App Tracking Transparency permission because the current App does not track you across apps or websites owned by other companies and contains no advertising or analytics SDK.
11. Changes to This Policy
We may update this Policy when Bloom, our providers, or applicable law changes. We will revise the date above and provide an in-app notice or email when a material change requires notice.
12. Contact
SwiftPass Technologies Co., Ltd. Email: danyang.zhao@swiftpass.cn Address: Room 5401 & 5402, 5/F, Block A, Tower 2, Shenzhen Bay Innovation & Technology Center, No. 3156 Keyuan South Road, Gaoxinqu Community, Yuehai Sub-district, Nanshan District, Shenzhen, China