Skip to content
bloom

Privacy Policy

Last updated: 2026-08-07 (engineering draft, pending legal review)

This page explains what data Bloom collects when you use our platform, why, and what choices you have about it.

This page is an engineering-drafted template, not a substitute for legal review. Sections marked [LEGAL REVIEW REQUIRED] below contain placeholders — entity name, jurisdiction, and governing law — that must be confirmed before this page is relied on as a real legal agreement.

[Legal review required]This policy is written as if the data controller is "Bloom" with no registered legal entity specified. Before this page goes live, confirm: the controller's registered legal name and address, the governing jurisdiction (and whether GDPR, CCPA, or another regime applies based on where customers are located), and whether a Data Protection Officer or EU representative is required.

1. What we collect

Traced directly against Bloom's current database schema and API routes, not assumed:

  • Account data — full name, email address, a hashed (never plaintext) password, and the organization/workspace name you provide at signup.
  • Business/project data — whatever you submit through a Guided Brief (business description, target audience, contact details, style preferences) so Bloom can generate a website for you.
  • Generated content — the websites, copy, and images Bloom generates on your behalf, and any assets you upload.
  • Usage data — server-side structured logs (timestamps, route, status code, error details) for operating and debugging the platform. We do not log full request bodies or full user objects in these logs.
  • Contact-form submissions — name, email, and message, if you use the contact form.
  • Session cookies — see the Cookie Policy.

2. Why we collect it

To create and operate your account, to generate and publish the website(s) you request, to respond to support/contact requests, to keep the platform secure (rate limiting, abuse prevention, error diagnosis), and — once billing exists — to process payment.

[Legal review required]Bloom does not yet have a live billing/subscription system (see the Pricing page). This section must be revised the moment real payment processing is enabled, naming the actual processor and what data it receives.

3. Who we share it with

Bloom uses a small number of real, named third-party processors to operate the platform. We do not sell your data, and we do not share it with anyone beyond what is required to run the service:

  • A managed Postgres database provider, to store account and project data.
  • Cloudflare R2, to store generated and uploaded website assets.
  • Anthropic (Claude) and OpenAI, to generate website copy and images from your brief.
  • Vercel, to host and publish this platform and the websites it generates.
  • An SMTP email provider, to deliver password-reset and contact-form emails.
  • Sentry (once configured), to record error diagnostics if the platform fails.
[Legal review required]Confirm whether Data Processing Agreements (DPAs) are in place with each processor above, and whether any Standard Contractual Clauses (SCCs) are needed for data transferred outside the customer's jurisdiction.

4. How long we keep it

Account and project data is retained for as long as your account is active. Deleted-account data-retention timelines are not yet finalized.

[Legal review required]Bloom does not yet have an automated account-deletion or data-export flow. A real retention schedule, and the mechanism for a user to request deletion or export of their data, need to be decided and — once decided — built.

5. Your rights

Depending on where you're located, you may have rights to access, correct, export, or delete your personal data, and to object to certain processing.

[Legal review required]The specific rights that apply (GDPR Articles 15-22, CCPA, or another regime) depend on the jurisdiction decision noted above, and the actual mechanism for exercising them (today: email websitestudio8@gmail.com; a self-service flow is not yet built).

6. Security

Passwords are hashed (never stored in plaintext). Sessions use httpOnly cookies. All tenant data is isolated at the database level. Administrative routes are protected by a timing-safe secret comparison. A full account of Bloom's security posture is maintained internally and reviewed periodically.

7. Contact

Questions about this policy, or requests regarding your data, can be sent to websitestudio8@gmail.com.

Questions about this page? Contact us.