Privacy

Privacy Policy

Last updated August 2026

Bloomessa is a gentle wellness app — daily quotes, small challenges, a forgiving streak, and short reads to help you build a kinder relationship with yourself. We believe privacy is part of self-care. This policy explains, in plain language, what personal data we collect, why we collect it, the legal grounds we rely on, who we share it with, and the rights you have over it. We aim to collect the minimum we need to run the service, and we never sell your personal data.

1. Who we are

Bloomessa (“Bloomessa”, “we”, “us”, “our”) provides the Bloomessa mobile app and the website at bloomessa.com. Bloomessa is based in the European Union (Hungary). For the purposes of the EU General Data Protection Regulation (GDPR) and applicable national data protection law, Bloomessa is the data controller of the personal data described in this policy.

If you have any questions about this policy or about how we handle your data, you can reach us at [email protected]. This is the best address for any privacy request, including exercising the rights described below.

2. A few definitions

To keep things clear, here is what a few terms mean in this policy:

3. What data we collect

We collect the following categories of personal data, depending on how you use Bloomessa:

4. Why we use your data and our legal bases

Under GDPR Article 6, we only process personal data where we have a lawful basis to do so. The bases we rely on are:

5. Cookies and analytics on the website

Our website uses Firebase Analytics / Google Analytics to understand traffic and improve the experience. Depending on your settings and location, this may involve cookies or similar technologies. Where consent is required, we ask for it before setting non-essential cookies, and you can change your choice at any time. You can also control cookies through your browser settings — for example, by blocking or deleting them — though some parts of the site may work less smoothly as a result.

6. Who we share data with

We do not sell your personal data and we do not share it with advertisers. We do share data with a small set of trusted service providers (processors) and platforms that help us run Bloomessa:

International transfers. Some of these providers are based in, or process data in, countries outside the European Economic Area, including the United States. Where personal data is transferred outside the EEA, we rely on appropriate safeguards recognised under GDPR — such as the European Commission’s Standard Contractual Clauses (SCCs) — to protect your data. You can contact us for more detail on the safeguards in place.

7. How long we keep your data

We keep personal data only for as long as we need it:

8. Your rights

Under GDPR, you have the following rights over your personal data:

To exercise any of these rights, email us at [email protected]. We will respond within the timeframe required by law, and we may need to verify your identity first to protect your account.

9. Data breach notification

We take reasonable steps to prevent security incidents. If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within the timeframe required by law, and we will inform affected users without undue delay where the law requires it.

10. Complaints and supervisory authority

If you believe we have not handled your personal data properly, we would appreciate the chance to put it right — please contact us first. You also have the right to lodge a complaint with your local EU data protection authority. As a Hungary-based company, our lead authority is the Hungarian National Authority for Data Protection and Freedom of Information (Nemzeti Adatvédelmi és Információszabadság Hatóság, or NAIH). You may also complain to the supervisory authority in the country where you live or work.

11. Children

Bloomessa is not directed at children under 16, and we do not knowingly collect personal data from them. If you believe a child has provided us with personal data, please contact us at [email protected] and we will delete it.

12. How we keep your data safe

We use appropriate technical and organisational measures to protect your data. These include encryption of data in transit (HTTPS/TLS), securely hashed passwords, and access controls that limit who can reach personal data. No system is perfectly secure, but we work to reduce risk and to respond quickly if something goes wrong.

13. Changes to this policy

We may update this policy from time to time — for example, if we add a feature or change a provider. When we make a meaningful change, we will update the “last updated” date above and, where appropriate, let you know in the app or by email. Continuing to use Bloomessa after an update means you accept the revised policy.

14. Contact

Questions, requests, or concerns about privacy? Email us at [email protected]. We read every message and we are happy to help.

This is a starter policy provided for transparency and should be reviewed by a qualified professional before launch.