← BluumTerms and Conditions

Bluum — Privacy Policy

Version 1.3 · Effective date: 15 September 2026 Controller: MB Upular, a small partnership (mažoji bendrija) established under the laws of the Republic of Lithuania, company code 308114012, registered address Pamėnkalnio g. 1-26, LT-01116 Vilnius, Lithuania ("Bluum", "we", "us", "our") Contact: jp@upularstudio.com This policy covers the Bluum iOS app ("App") and the website https://dailybluum.com ("Website"). The current version is always available at https://legal.dailybluum.com/privacy and from the App's Settings.

The short version

Bluum needs an account (Sign in with Apple or Google, never a password) so your garden can follow you to a new phone. Your account stores your garden, mantras, favorites, followed topics, display name, and settings. Two things stay on your phone and are never uploaded or used for anything else: the personal answers you give during setup (about mood, beliefs, religion, gender, or therapy) and your voice, which Apple's on-device speech recognition matches in the moment without recording. We use anonymous statistics to improve the App. We also advertise Bluum, and to measure and improve that advertising we work with advertising platforms such as TikTok, Meta, Google, Apple, Snapchat, Pinterest, X, and Reddit; on iPhone this happens only if you allow tracking when the App asks, and you can change your mind at any time in Settings. We never use your setup answers, your voice, or the affirmations you practise to target advertising.

1. Who is responsible

MB Upular is the data controller for the personal data described in this policy. We are established in Lithuania (European Union), so the EU General Data Protection Regulation ("GDPR") and the Lithuanian Law on Legal Protection of Personal Data apply to everything we do with your data, wherever you live. We have not appointed a data protection officer because the law does not require one for a company of our size and activity; privacy questions go to jp@upularstudio.com.

2. What we process, why, and for how long

We do not make automated decisions that produce legal or similarly significant effects on you, and we do not use your data for any purpose not listed above. Personalisation inside the App (which affirmations you see) is rule-based and runs on your phone using the data on your phone; it is never used to target advertising.

3. What stays on your phone only

The App keeps everything it needs on your iPhone so that it works offline: the name and preferences you enter during setup, the topics you follow, your daily bloom progress, garden history, streaks, favorites, muted content, reminder settings, and subscription status. Some of this is mirrored to your account (section 2). The following is never uploaded to us or to anyone else:

Home-screen and lock-screen widgets read the affirmation of the day and your garden's flowers from a storage area shared between the App and its widgets on the same device; nothing leaves the phone. If you delete the App, its local copy is deleted; your synced data remains in your account until you delete the account (section 7).

4. Your voice

The spoken-affirmation feature uses Apple's on-device speech recognition, and the App explicitly requires on-device processing so that Apple's servers are never involved. Your microphone is active only while an affirmation card is on screen and you have granted the microphone and speech-recognition permissions. No audio recording is created and no transcript is kept: the App checks, in the moment, whether the sentence was spoken, then discards everything. Nothing your microphone hears ever leaves your phone. You can use Bluum fully without the microphone by using press-and-hold instead. Listen mode uses your device's built-in text-to-speech voice, also entirely on the device.

5. Your account and cloud sync

Bluum requires an account, created with Sign in with Apple or Google Sign-In. We never see or store a password. From your sign-in provider we receive only an account identifier and, depending on your choice, your email address (Apple lets you hide it behind a relay address). We use this to recognise you on another phone and to contact you about your account when necessary.

Your synced practice data (section 2) is stored on servers operated for us by Supabase in the European Union (Frankfurt, Germany). Access is restricted at the database level so that only your own sign-in can read or change your rows; our staff access individual accounts only to resolve a support request you made or to investigate abuse.

You can sign out without deleting anything, and you can delete your account at any time in Settings → Account → Delete account (section 7).

6. Purchases and subscriptions

Subscriptions, when offered, are bought through Apple's App Store and processed entirely by Apple. We never see your payment details, full name, or billing address. To unlock paid features and to let you restore or manage a subscription, the App uses RevenueCat, a subscription-management service, which receives the purchase data described in section 2 from Apple and from the App. RevenueCat does not receive your name, email address, or anything you do in the App. Apple's own privacy policy governs payment processing: https://www.apple.com/legal/privacy/. If the App is offered free of charge in your region, no purchase data is processed.

7. Deleting your data

8. Advertising, attribution, and marketing

We grow Bluum through paid advertising. The platforms we use or may use are Meta (Facebook and Instagram), TikTok, Google (Search, YouTube, and the Google network), Apple Search Ads, Snapchat, Pinterest, X, and Reddit; TikTok and Meta are our main channels, and the others are listed so that this policy stays accurate if we start using them. This section explains exactly what that involves and how you control it.

8.1 What "tracking" means here. With your permission, the App links data about your use of Bluum (install, first bloom, sign-in, trial, subscription, renewal, cancellation) with data held by advertising platforms, using your device's advertising identifier (IDFA) or a hashed (irreversibly scrambled) form of your email address. The platforms use this to tell us which ad you came from, to show Bluum ads to you and to people similar to you on their services, and to stop showing acquisition ads to people who already subscribe. Where the App integrates an advertising platform's software development kit (for example the Meta SDK), that kit may collect device information and app events directly for the platform.

8.2 Your permission comes first. On iPhone, none of this happens until you tap Allow on Apple's "Allow Bluum to track your activity across other companies' apps and websites?" prompt, which the App shows once, with its own explanation screen before it. If you tap Ask App Not to Track, no advertising identifier is read and no event linked to you is sent to any advertising platform; we then rely only on Apple's aggregated, anonymous measurement (SKAdNetwork / AdAttributionKit), which cannot identify you. You can change your choice at any time in Settings → Privacy → Personalised ads and measurement inside the App, or in iOS Settings → Privacy & Security → Tracking. Withdrawing permission stops future sharing; it does not undo data already lawfully shared, but you can ask us and the platforms to delete it (section 13).

8.3 What is never used for advertising. Your setup answers (mood, beliefs, religion, gender, therapy, and similar), your voice, the text of the affirmations or mantras you practise or write, and the topics you follow are never shared with advertising platforms, never used to build audiences, and never used to target you. Advertising events describe only commercial milestones (install, sign-in, trial, purchase) and generic device data.

8.4 Marketing messages. We do not currently send marketing emails or marketing push notifications. If we start, we will ask for your consent first, give you an unsubscribe link in every email and a switch in Settings, and update this policy. Service messages that we must send (for example about your account, a price change, or these documents) are not marketing and cannot be switched off while you have an account.

8.5 The advertising platforms. Advertising platforms are not our processors: they use the data they receive under their own privacy policies and, for the collection through their tools, as joint controllers with us as far as the law provides. Their policies and your controls on their side: TikTok https://www.tiktok.com/legal/privacy-policy · Meta https://www.facebook.com/privacy/policy · Google https://policies.google.com/privacy · Apple https://www.apple.com/legal/privacy/ · Snap https://values.snap.com/privacy/privacy-policy · Pinterest https://policy.pinterest.com/privacy-policy · X https://x.com/privacy · Reddit https://www.reddit.com/policies/privacy-policy. We sign the data-sharing terms each platform offers for EU advertisers before we send it any data.

8.6 Sale and sharing (US law). Under the California Consumer Privacy Act and similar US state laws, sending advertising data to these platforms can count as "sharing" for cross-context behavioural advertising and, in some readings, as a "sale". We do not sell personal data for money. If you are in the US you can opt out of sharing at any time through the same Settings → Privacy switch, or by emailing jp@upularstudio.com with "Do not sell or share" in the subject; we honour Global Privacy Control signals on the Website.

8.7 What we still do not do. We show no third-party advertisements inside the App. We do not sell your data for money. We never ask for or store a password. We do not upload your voice or your sensitive setup answers. We do not use the content of your practice to train artificial-intelligence models.

9. Children

The App is intended for adults and is not directed to children. We do not knowingly collect personal data from anyone under 16 (or a higher minimum age where your local law sets one). If you believe a child has created an account, contact jp@upularstudio.com and we will delete it.

10. Service providers, advertising platforms, and international transfers

We share personal data only with the parties below and only to the extent needed for the purpose stated. Processors act on our instructions under a written data-processing agreement. Advertising platforms (marked ★) receive data only with your tracking permission (section 8) and use it under their own policies, as independent or joint controllers.

That is the complete list. If it changes, we will update this policy before the change takes effect. Where data leaves the European Economic Area, we rely on the European Commission's adequacy decisions (including the EU–US Data Privacy Framework for certified companies) or on the Commission's standard contractual clauses, and you can ask us for a copy of the relevant safeguard. We may also disclose data where a law, court order, or public authority validly requires it, or to establish, exercise, or defend legal claims.

11. Website and cookies

The Website uses no cookies or tracking scripts until you accept them. When we run advertising, the Website shows a cookie banner and, only if you accept, loads the measurement pixels of the advertising platforms listed in section 10 (for example the TikTok Pixel and the Meta Pixel) so that the platforms can measure visits and conversions from their ads and show you Bluum ads later. Declining changes nothing about how the Website works. You can withdraw your choice at any time through the "Cookie settings" link in the footer. Strictly necessary technical logs are kept by Cloudflare as described in section 2. Links to Apple's App Store lead to Apple's services, which are governed by Apple's policies.

12. Security

On your phone, your data is protected by the device's own security (encryption at rest, your passcode or Face ID). Sign-in tokens are stored in the iOS Keychain. Synced data travels only over encrypted connections (TLS) and is stored encrypted at rest on EU servers, with per-account access rules enforced by the database itself, so that even a bug in the App could not expose one person's garden to another. No secret keys are shipped inside the App. No method of storage or transmission is perfectly secure, but we keep the most sensitive information — your voice and your setup answers — off our servers entirely. If a personal-data breach ever affects you in a way that creates a high risk to your rights, we will inform you and the supervisory authority as the GDPR requires.

13. Your rights

Under the GDPR you have the right to:

You can exercise most of these rights directly in the App: everything synced is visible in the App, Settings → Account lets you sign out or delete the account, Settings → Privacy lets you switch statistics off or erase all local data, and Settings → Account → Export lets you download your synced data as a file. For anything else, email jp@upularstudio.com; we respond within one month (extendable by two further months for complex requests, in which case we will tell you). We may ask you to confirm your request from the email address linked to your account so that we do not hand your data to someone else. Anonymous statistics cannot be linked to you and therefore cannot be looked up, corrected, or extracted for an individual.

The supervisory authority for Lithuania is the State Data Protection Inspectorate (Valstybinė duomenų apsaugos inspekcija, L. Sapiegos g. 17, LT-10312 Vilnius, https://vdai.lrv.lt). You may also complain to the authority in the EU country where you live or work.

United Kingdom. If you are in the UK, the UK GDPR gives you the same rights; the supervisory authority is the Information Commissioner's Office (https://ico.org.uk).

United States (including California). The categories of personal information we collect are those listed in section 2 (identifiers, commercial information, internet and app activity, and inferences limited to commercial milestones), collected from you, your sign-in provider, Apple, and advertising platforms, for the purposes listed there. With your tracking permission we "share" identifiers and app activity with advertising platforms for cross-context behavioural advertising (section 8.6); we do not sell personal information for money. California residents have the rights to know, delete, correct, opt out of sale or sharing, and not be discriminated against for exercising their rights; use Settings → Privacy in the App, the "Do Not Sell or Share My Personal Information" link on the Website, or email jp@upularstudio.com. We honour Global Privacy Control signals on the Website. We do not knowingly sell or share the personal information of anyone under 16.

14. Changes to this policy

If we change this policy, we will update the version number and effective date at the top. Material changes — new categories of data, new service providers, new purposes, or changes to your rights — will be announced inside the App before they take effect; where the law requires your consent to a change, we will ask for it. Minor clarifications may be posted without an in-app notice.

15. Contact

MB Upular Company code: 308114012 Registered address: Pamėnkalnio g. 1-26, LT-01116 Vilnius, Lithuania Email: jp@upularstudio.com