Privacy Policy
Last updated August 2026
Bloomessa is a gentle wellness app — daily quotes, small challenges, a forgiving streak, and short reads to help you build a kinder relationship with yourself. We believe privacy is part of self-care. This policy explains, in plain language, what personal data we collect, why we collect it, the legal grounds we rely on, who we share it with, and the rights you have over it. We aim to collect the minimum we need to run the service, and we never sell your personal data.
1. Who we are
Bloomessa (“Bloomessa”, “we”, “us”, “our”) provides the Bloomessa mobile app and the website at bloomessa.com. Bloomessa is based in the European Union (Hungary). For the purposes of the EU General Data Protection Regulation (GDPR) and applicable national data protection law, Bloomessa is the data controller of the personal data described in this policy.
If you have any questions about this policy or about how we handle your data, you can reach us at [email protected]. This is the best address for any privacy request, including exercising the rights described below.
2. A few definitions
To keep things clear, here is what a few terms mean in this policy:
- Personal data — any information relating to an identified or identifiable person, such as your name, email address or an online identifier like a device token.
- Processing — anything we do with personal data, including collecting, storing, using, sharing, or deleting it.
- Controller — the party that decides why and how personal data is processed. For the Bloomessa app and website, that is us.
- Processor — a third party that processes personal data on our behalf and under our instructions (for example, our hosting provider). Processors are covered in the section on recipients below.
3. What data we collect
We collect the following categories of personal data, depending on how you use Bloomessa:
- Account data. When you create an account, we store your name, email address, and password. Your password is always stored in a securely hashed form — we never store or see it in plain text. We also store the preferences you choose, such as your preferred tone, the interests or topics you care about, and your accent or language settings.
- Usage data. To power the core experience, we record activity such as your challenge completions, your streak progress, and the quotes or articles you save as favourites. This activity is anchored to your device’s local day so that a “day” always means your day, not a server’s.
- Device and technical data. To deliver notifications and keep the service secure and reliable, we may process a push notification token (a Firebase Cloud Messaging token), your timezone, the app version you are running, your device platform (for example, iOS or Android), and your IP address (used for security, abuse prevention, and rough diagnostics).
- Analytics data. We use Firebase Analytics / Google Analytics to understand how the app and website are used — for example, which features are opened and how often. This typically involves event data and identifiers rather than the content of what you write.
- Subscription data. If you buy Bloomessa Premium, the purchase is processed by the Apple App Store or Google Play, with subscription management handled through RevenueCat. We receive your entitlement status (whether a subscription is active, its type, and renewal state) — we do not receive or store your card number or full payment details.
- Marketing data. If you sign up to hear from us or contact us, we store the email address you provide so we can reply or send the updates you asked for.
4. Why we use your data and our legal bases
Under GDPR Article 6, we only process personal data where we have a lawful basis to do so. The bases we rely on are:
- To perform our contract with you (Art. 6(1)(b)). We use your account data, usage data and device data to create and secure your account, run your streak and challenges, remember your favourites and preferences, and send the notifications tied to the service you have chosen. Without this data, we cannot provide the app.
- Your consent (Art. 6(1)(a)). We rely on consent for optional things such as marketing emails, and for analytics and cookies on the website where consent is required. You can withdraw consent at any time, and doing so does not affect processing that happened before you withdrew it.
- Our legitimate interests (Art. 6(1)(f)). We rely on legitimate interests for keeping the service safe (preventing abuse, fraud and security incidents), for diagnosing problems, and for improving Bloomessa. We balance these interests against your rights, and you can object as described below.
5. Cookies and analytics on the website
Our website uses Firebase Analytics / Google Analytics to understand traffic and improve the experience. Depending on your settings and location, this may involve cookies or similar technologies. Where consent is required, we ask for it before setting non-essential cookies, and you can change your choice at any time. You can also control cookies through your browser settings — for example, by blocking or deleting them — though some parts of the site may work less smoothly as a result.
6. Who we share data with
We do not sell your personal data and we do not share it with advertisers. We do share data with a small set of trusted service providers (processors) and platforms that help us run Bloomessa:
- Google Firebase. Used for authentication-adjacent services, push notifications, analytics, and crash reporting.
- RevenueCat. Used to manage subscriptions and entitlements across the app stores.
- Apple and Google. As the operators of the App Store and Google Play, they process purchases and payments and provide app distribution.
- Our hosting provider. Hosts the backend that stores your account and usage data on our behalf.
- Anthropic. Used only on the admin side to help translate app content (such as quotes and articles). This does not involve your personal data.
International transfers. Some of these providers are based in, or process data in, countries outside the European Economic Area, including the United States. Where personal data is transferred outside the EEA, we rely on appropriate safeguards recognised under GDPR — such as the European Commission’s Standard Contractual Clauses (SCCs) — to protect your data. You can contact us for more detail on the safeguards in place.
7. How long we keep your data
We keep personal data only for as long as we need it:
- Account and usage data is kept while your account is active. If you delete your account or ask us to erase your data, we remove your personal data from our active systems, except where we are required to keep certain records by law.
- Technical logs (such as security and diagnostic logs) are kept only for a short period and then deleted or aggregated.
- Waitlist and marketing emails are kept until you unsubscribe or ask us to remove you, after which we delete them.
8. Your rights
Under GDPR, you have the following rights over your personal data:
- Access — to know what data we hold about you and to receive a copy.
- Rectification — to correct data that is inaccurate or incomplete.
- Erasure — to have your data deleted (“the right to be forgotten”), subject to legal exceptions.
- Restriction — to limit how we use your data in certain circumstances.
- Portability — to receive your data in a structured, commonly used format, or have it sent to another provider where technically feasible.
- Objection — to object to processing based on our legitimate interests, and to object to direct marketing at any time.
- Withdraw consent — where we rely on your consent, you can withdraw it at any time.
To exercise any of these rights, email us at [email protected]. We will respond within the timeframe required by law, and we may need to verify your identity first to protect your account.
9. Data breach notification
We take reasonable steps to prevent security incidents. If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within the timeframe required by law, and we will inform affected users without undue delay where the law requires it.
10. Complaints and supervisory authority
If you believe we have not handled your personal data properly, we would appreciate the chance to put it right — please contact us first. You also have the right to lodge a complaint with your local EU data protection authority. As a Hungary-based company, our lead authority is the Hungarian National Authority for Data Protection and Freedom of Information (Nemzeti Adatvédelmi és Információszabadság Hatóság, or NAIH). You may also complain to the supervisory authority in the country where you live or work.
11. Children
Bloomessa is not directed at children under 16, and we do not knowingly collect personal data from them. If you believe a child has provided us with personal data, please contact us at [email protected] and we will delete it.
12. How we keep your data safe
We use appropriate technical and organisational measures to protect your data. These include encryption of data in transit (HTTPS/TLS), securely hashed passwords, and access controls that limit who can reach personal data. No system is perfectly secure, but we work to reduce risk and to respond quickly if something goes wrong.
13. Changes to this policy
We may update this policy from time to time — for example, if we add a feature or change a provider. When we make a meaningful change, we will update the “last updated” date above and, where appropriate, let you know in the app or by email. Continuing to use Bloomessa after an update means you accept the revised policy.
14. Contact
Questions, requests, or concerns about privacy? Email us at [email protected]. We read every message and we are happy to help.
This is a starter policy provided for transparency and should be reviewed by a qualified professional before launch.