Privacy Policy
Last updated: August 6, 2026
Bloomly ("we," "our," or "the app") is a career journaling app developed by Olana. This policy describes how we collect, use, and protect your information.
Information We Collect
- Account information: Name and email address when you sign in with Apple or Google
- Journal content: Journal entries, voice recordings (processed for transcription then discarded), performance reports, and career goals you create within the app
- Image attachments: Up to four images per entry (photos, screenshots, or documents) that you choose to attach. Attachments are stored in our cloud storage alongside the entry they belong to and are deleted when you delete the entry or your account.
- Work artifacts: If you use Work Capture, the emails you forward to your private Bloomly inbox address and the files, images, or PDFs you share into the app from elsewhere. We extract and summarize their text so they can serve as evidence in your reports. Forwarded email text and the generated summary are stored in our cloud database; shared images and PDFs up to a size limit are kept in our private cloud storage alongside their extracted text, so the original stays available with the entry it supports, and are deleted when you delete the artifact or your account; larger files are processed transiently and deleted once their text has been extracted. You control which email senders feed your reports — unrecognized senders are held for your review before anything they send is used.
- Connected Work data: If you choose to connect GitHub or Google Drive, we collect the connected account identity, the authorization and read-only OAuth credentials needed to maintain the connection, metadata used to show resources you can select, your selected repositories or Drive locations, and activity attributable to the connected account. The specific provider data and privacy boundaries are described in Connected Work below.
- Profile data: Job title, company, location, years of experience, resume text, and the career goals and challenges you share during onboarding or in Settings
- Usage analytics: Product usage events (e.g., onboarding steps, feature usage, and whether an export or share used the clipboard, share sheet, or a social composer) tied to a pseudonymous account identifier, collected through PostHog to improve the app experience. We do not send entry, artifact, report, or share-target identifiers, journal text, artifact content, profile free text, or report content to PostHog.
- Crash data: Crash reports and basic diagnostics through our crash reporting provider. For signed-in users, reports may include a pseudonymous account identifier so we can diagnose recurring problems. Journal content is not included.
- Subscription data: Purchase and subscription status managed by our subscription provider and Apple
- Push notification token: If you grant notification permission, your device's push token so we can deliver report-ready alerts (see Push Notifications below)
How We Use Your Information
- To provide app functionality: storing your journal entries, generating AI-powered insights, and performance reports
- To sync your data across devices when you sign in
- To process your voice recordings into text using our AI transcription service
- To generate AI insights and reports using our AI service provider
- To extract and summarize the work artifacts you forward or share, so they can serve as evidence in your reports
- To show available GitHub repositories and Google Drive locations, collect attributable activity from the sources you select, and turn that activity into private, editable career artifacts and report evidence
- To manage your subscription status
AI Processing
Your journal entries, profile information, the content of any work artifacts you forward or share — including the text of forwarded emails and text extracted from shared documents, PDFs, and images — and normalized activity from Connected Work resources you select may be sent to our AI service provider to generate insights, reports, coaching responses, summaries, artifacts, and voice transcription. Journal and profile data are sent through an authenticated server-side proxy (never directly from your device); work artifacts and Connected Work activity are processed server-side after they reach our systems. The proxy enforces rate limiting and only forwards specific, whitelisted models and fields — it cannot be used as a general-purpose AI relay. Your content is not used to train any third-party model: our AI provider's API data usage policy excludes data sent through their API from being used for model training.
For Connected Work, selected activity metadata and limited user-authored text, such as pull-request descriptions, bounded commit subjects, or Google Drive file descriptions, may be sent to our AI service provider solely to create the private summary the feature shows you. OAuth credentials are never sent to the AI provider. Bloomly does not access or send GitHub source code, diff patches, or Google Drive file contents through Connected Work.
Connected Work
Connected Work is optional. You choose whether to connect a provider, which available resources Bloomly should use, and which Bloomly Role should receive the resulting artifacts.
- GitHub: Bloomly uses read-only access to retrieve the connected account identity, available repository metadata, and attributable activity from selected repositories, including pull requests, reviews, issues, releases, and bounded commit subjects. Bloomly does not request or read repository source code or diff contents for this feature.
- Google Drive: Bloomly uses read-only access to retrieve the connected account identity and metadata needed to show available files, folders, and shared drives, including names, identifiers, types, links, parent or drive identifiers, modified times, descriptions, and attributable activity such as creating, editing, renaming, moving, commenting, changing permissions, or restoring an item. Bloomly does not request or read the contents of Drive files.
A provider may authorize Bloomly to see metadata for more resources than you ultimately select. Bloomly uses that broader metadata only to populate the resource picker; ongoing collection and summarization are limited to the resources you select and activity attributable to the connected account.
Bloomly uses Google user data only to provide or improve user-facing Connected Work features. Bloomly does not sell Google user data, use it for advertising, credit or lending decisions, or surveillance, or use Google Workspace API data to develop, improve, or train generalized or non-personalized AI or machine-learning models.
Bloomly's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Data Storage and Security
- Your data is stored locally on your device and synced to our cloud database when you sign in
- All data is transmitted over HTTPS
- Connected Work access and refresh tokens are encrypted server-side using authenticated encryption and are available only to restricted server-side services
- Sensitive credentials and private API keys are kept server-side. The app includes public client identifiers and client keys required to connect to its service providers; these values do not grant administrative access.
- Authentication uses industry-standard JWT tokens
International Users
Bloomly is operated from the United States. If you use Bloomly from outside the U.S. — including the European Economic Area, the United Kingdom, the United Arab Emirates, Saudi Arabia, Egypt, Bahrain, Kuwait, Morocco, or Qatar — your information will be transferred to and processed in the United States and other countries where our service providers operate, including cloud infrastructure for storage, AI processing for journal insights, subscription management, product analytics, and crash reporting. By using Bloomly, you consent to this transfer. We rely on standard contractual safeguards with our processors and apply equivalent protection regardless of where you live.
iOS App Advertising Measurement
To understand whether our own Apple Search Ads campaigns work, the iOS app uses only Apple's privacy-preserving attribution. If you install Bloomly after tapping one of our Apple Search Ads, Apple provides a privacy-preserving attribution token through its AdServices framework. Our subscription provider (RevenueCat) uses that token to attribute the install — and any resulting trial or subscription — to a campaign, in aggregate. This does not involve Apple's advertising identifier (IDFA), and it does not track you across other companies' apps and websites.
The iOS app does not use any third-party advertising or attribution SDKs, does not request App Tracking Transparency permission, and does not track you as defined by Apple. We use this data solely to measure the performance of our own Apple Search Ads campaigns. We do not build advertising profiles, and Bloomly never shows ads.
Website Analytics and Advertising
When you visit bloomly.cc, we use first-party analytics and service providers including PostHog and Ahrefs to understand website visits and page use. We also use the TikTok Pixel and Events API to measure the effectiveness of website advertising. Depending on your browser and settings, these tools may process the page URL, referring page, interactions, device and browser information, approximate location derived from your IP address, cookie or session identifiers, campaign parameters, and advertising click identifiers.
These website tools are separate from the iOS app. They do not receive your journal entries, reports, voice recordings, work artifacts, or other content stored in Bloomly.
Data Sharing
We do not sell or rent your personal information. Your data is only shared with the service providers required to operate the app:
- Our AI processing partner: To generate insights, reports, coaching responses, voice transcription, and summaries of the work artifacts you forward, share, or create through Connected Work
- Our subscription management provider: To track and validate your subscription status, and to attribute Apple Search Ads installs to a campaign in aggregate (see iOS App Advertising Measurement above)
- PostHog, our product analytics provider: For pseudonymous product usage measurement using an account identifier and coarse product or account characteristics, including a coarse clipboard, share-sheet, or social-composer category for the first export or share (no journal text, artifact content, profile free text, report content, name, or email included)
- Our crash reporting provider: For diagnostic crash data, which may include a pseudonymous account identifier for signed-in users (no journal content included)
- GitHub and Google: When you connect a provider, to authorize the connection, list resources available to your account, retrieve activity from the resources you select, refresh authorization where applicable, and process a disconnection or revocation request
- Apple and Google: To authenticate your Bloomly account when you choose Sign in with Apple or Sign in with Google. This sign-in use is separate from an optional Connected Work connection.
- Apple: As required for App Store and subscription processing, and for privacy-preserving Apple Search Ads attribution
We can provide the current list of subprocessors on request at the contact address below.
Push Notifications
If you grant notification permission, Bloomly delivers a single alert when a new performance report (weekly, mid-month, semi-annual, or annual) is ready, so you can open it from the Reports tab. We do not send marketing pushes, silent push, critical alerts, or time-sensitive interruptions, and the notification payload contains only the report period — never journal content. You can revoke notification permission at any time in iOS Settings → Bloomly → Notifications.
Third-Party Platform Posts
Bloomly can generate draft posts for LinkedIn and X based on your recent entries, either as feed suggestions at a cadence you set, or on demand. Drafts are produced server-side from your entries and shown to you for review. When you tap to share, Bloomly hands the draft to the LinkedIn or X app or website using their standard composer; from that moment forward, the content is governed by that platform's terms and privacy policy. Bloomly does not post on your behalf, and we do not receive engagement data from those platforms.
Data Retention and Deletion
- Your data is retained as long as your account is active
- Connected Work activity is normalized temporarily while Bloomly creates an artifact. The normalized activity is removed after the artifact is finalized; failed event rows expire after seven days. Minimal provider event identifiers may be retained to prevent duplicate artifacts.
- The resulting Connected Work summary and its limited evidence references remain with the artifact until you delete that artifact or your account.
- Disconnecting a provider stops future collection and removes Bloomly's stored authorization when the last connection using it is removed. Bloomly also makes a best-effort request to revoke provider access. Disconnecting does not delete artifacts already created; you can delete those artifacts separately. You may also revoke Bloomly directly from your GitHub or Google account settings.
- You can delete your account at any time from Settings → Account → Delete Account. Deletion attempts to revoke connected-provider access and cascades server-side through your journal entries, image attachments, work artifacts (including forwarded emails and Connected Work summaries), integration records, performance reports, profile, and your subscription-provider customer record. Active subscriptions must be canceled separately in your Apple ID settings, since Apple controls subscription billing.
- Local data can be removed by deleting the app
Your Rights
You can access your data in the app, disconnect Connected Work providers through Settings, delete individual artifacts, and delete your account through Settings. To request a copy of your data, or to exercise other data rights, contact us at [email protected]. Depending on where you live, you may have additional rights under local data protection law — including the right to access, correct, restrict, object to, or port your personal data, and to lodge a complaint with your local supervisory authority. To exercise any of these rights, contact us at the email above.
Children's Privacy
Bloomly is not intended for children under 13. We do not knowingly collect information from children.
Changes to This Policy
We may update this policy from time to time. We will notify you of significant changes through the app.
Contact
If you have questions about this policy, contact us at [email protected].