Bluum — Privacy Policy
Version 1.3 · Effective date: 15 September 2026 Controller: MB Upular, a small partnership (mažoji bendrija) established under the laws of the Republic of Lithuania, company code 308114012, registered address Pamėnkalnio g. 1-26, LT-01116 Vilnius, Lithuania ("Bluum", "we", "us", "our") Contact: jp@upularstudio.com This policy covers the Bluum iOS app ("App") and the website https://dailybluum.com ("Website"). The current version is always available at https://legal.dailybluum.com/privacy and from the App's Settings.
The short version
Bluum needs an account (Sign in with Apple or Google, never a password) so your garden can follow you to a new phone. Your account stores your garden, mantras, favorites, followed topics, display name, and settings. Two things stay on your phone and are never uploaded or used for anything else: the personal answers you give during setup (about mood, beliefs, religion, gender, or therapy) and your voice, which Apple's on-device speech recognition matches in the moment without recording. We use anonymous statistics to improve the App. We also advertise Bluum, and to measure and improve that advertising we work with advertising platforms such as TikTok, Meta, Google, Apple, Snapchat, Pinterest, X, and Reddit; on iPhone this happens only if you allow tracking when the App asks, and you can change your mind at any time in Settings. We never use your setup answers, your voice, or the affirmations you practise to target advertising.
1. Who is responsible
MB Upular is the data controller for the personal data described in this policy. We are established in Lithuania (European Union), so the EU General Data Protection Regulation ("GDPR") and the Lithuanian Law on Legal Protection of Personal Data apply to everything we do with your data, wherever you live. We have not appointed a data protection officer because the law does not require one for a company of our size and activity; privacy questions go to jp@upularstudio.com.
2. What we process, why, and for how long
| Data | Purpose | Legal basis (GDPR) | Kept for |
|---|---|---|---|
| Account data: the identifier your sign-in provider gives us, your email address (or Apple's private relay address if you choose "Hide My Email"), the sign-in method, and the date your account was created | Creating and recognising your account; letting you restore your garden on another device | Performance of our contract with you (Art. 6(1)(b)) | Until you delete your account (section 7) |
| Synced practice data: your garden history (days completed, flower species, which affirmations you completed and when), mantras you wrote, favorites, muted content, followed topics, the display name you entered, and your App settings | Running the App's core feature (a garden that survives device changes and platform moves); keeping your practice consistent across devices | Performance of our contract with you (Art. 6(1)(b)) | Until you delete the item in the App or delete your account. Records of which affirmations you have seen (used only to avoid repetition) are deleted automatically after 90 days |
| Mantra voicing (optional): the text of a mantra you save (up to 200 characters) and the spoken recording made from it | Playing your mantra back in a recorded human voice, if you switch this on | Your consent (Art. 6(1)(a)), given in the App the first time; withdraw by not using the feature — existing recordings are deleted with the mantra or the account | Until you delete the mantra or your account; at most one new recording per week |
| Purchase data (only when a paid subscription is offered in the App): a random subscription identifier that does not include your name or email, App Store transaction and product identifiers, price and currency, subscription status and renewal dates, app version, device model and operating system, language, and the country derived from your IP address | Unlocking paid features you bought, restoring purchases, handling trials, renewals and refunds, and preventing fraud | Performance of our contract with you (Art. 6(1)(b)); our legitimate interest in preventing fraud and keeping accurate financial records (Art. 6(1)(f)) | For the life of the subscription and thereafter as long as accounting and tax law requires (in Lithuania, generally 10 years for accounting records) |
| Anonymous usage statistics: which screens and features are used, whether a session's ritual was completed, the App version and device type, and coarse country. Identifiers are irreversibly hashed before they are stored, so events cannot be traced back to a person, a device, or an account | Understanding which features help people and finding crashes and bugs | Our legitimate interest in improving the App (Art. 6(1)(f)). You can switch these statistics off in Settings → Privacy at any time; the App works identically | Anonymous aggregates are kept indefinitely; they contain no personal data |
| Crash reports: if the App crashes or freezes, a technical report of where in the code it happened, the App version, iOS version, device model, free memory, and the sequence of screens and buttons used just before (as technical identifiers, never the words on screen). Reports contain no name, email, account identifier, IP address, or content you wrote | Finding and fixing crashes | Our legitimate interest in keeping the App working (Art. 6(1)(f)). Switched off together with usage statistics in Settings → Privacy; the App works identically | 90 days |
| Advertising and attribution data (only if you allowed tracking, section 8): your device's advertising identifier (IDFA) or a hashed version of your email address; app events such as install, first bloom, sign-in, trial start, subscription start, renewal, and cancellation; app version, device model, operating system, language, and country; the ad or campaign that led you to install | Measuring which advertisements bring people to Bluum; showing you Bluum advertisements on other platforms; building audiences of similar people; excluding existing subscribers from acquisition ads | Your consent (Art. 6(1)(a) GDPR and the ePrivacy rules), given through Apple's tracking prompt and the App's own consent screen; you can withdraw it at any time in Settings → Privacy or in iOS Settings → Privacy & Security → Tracking | Kept by us for up to 24 months after the event; advertising platforms keep it under their own policies (section 10) |
| Aggregated campaign measurement (always, no consent needed): Apple's SKAdNetwork / AdAttributionKit and Apple Ads attribution report install and conversion counts per campaign to us and to the advertising platform without identifying you or your device | Knowing which campaigns work at an aggregate level | Our legitimate interest in measuring our advertising (Art. 6(1)(f)); no personal data reaches us | Aggregate reports kept indefinitely |
| Product experiments: which version of a screen, price, or message you were shown and what you did next, tied to your account identifier | Testing improvements and offers so that we can keep what works | Our legitimate interest in improving the App and its commercial performance (Art. 6(1)(f)) | 24 months |
| Support correspondence: your email address and whatever you tell us when you write to us | Answering your questions and resolving problems | Performance of our contract and our legitimate interest in providing support (Art. 6(1)(b) and (f)) | 24 months after the conversation ends, unless a legal claim requires longer |
| Website technical logs: the IP address, browser type, and pages requested when you visit https://dailybluum.com, recorded by our hosting provider | Serving the Website securely and defending it against abuse | Our legitimate interest in running a secure website (Art. 6(1)(f)) | Retained by Cloudflare for a short, rolling period (days, not months) and not accessible to us in identifiable form |
We do not make automated decisions that produce legal or similarly significant effects on you, and we do not use your data for any purpose not listed above. Personalisation inside the App (which affirmations you see) is rule-based and runs on your phone using the data on your phone; it is never used to target advertising.
3. What stays on your phone only
The App keeps everything it needs on your iPhone so that it works offline: the name and preferences you enter during setup, the topics you follow, your daily bloom progress, garden history, streaks, favorites, muted content, reminder settings, and subscription status. Some of this is mirrored to your account (section 2). The following is never uploaded to us or to anyone else:
- Your sensitive setup answers — mood, beliefs, religion or spirituality, gender, therapy or mental-health habits, and similar questions. These may be special categories of data under Art. 9 GDPR; they exist only in the App's local database on your device, under your control, and are used solely to choose which affirmations to show you. They are never uploaded, never shared with advertising platforms, and never used to build audiences or target advertising.
- Your voice (section 4).
Home-screen and lock-screen widgets read the affirmation of the day and your garden's flowers from a storage area shared between the App and its widgets on the same device; nothing leaves the phone. If you delete the App, its local copy is deleted; your synced data remains in your account until you delete the account (section 7).
4. Your voice
The spoken-affirmation feature uses Apple's on-device speech recognition, and the App explicitly requires on-device processing so that Apple's servers are never involved. Your microphone is active only while an affirmation card is on screen and you have granted the microphone and speech-recognition permissions. No audio recording is created and no transcript is kept: the App checks, in the moment, whether the sentence was spoken, then discards everything. Nothing your microphone hears ever leaves your phone. You can use Bluum fully without the microphone by using press-and-hold instead. Listen mode uses your device's built-in text-to-speech voice, also entirely on the device.
5. Your account and cloud sync
Bluum requires an account, created with Sign in with Apple or Google Sign-In. We never see or store a password. From your sign-in provider we receive only an account identifier and, depending on your choice, your email address (Apple lets you hide it behind a relay address). We use this to recognise you on another phone and to contact you about your account when necessary.
Your synced practice data (section 2) is stored on servers operated for us by Supabase in the European Union (Frankfurt, Germany). Access is restricted at the database level so that only your own sign-in can read or change your rows; our staff access individual accounts only to resolve a support request you made or to investigate abuse.
You can sign out without deleting anything, and you can delete your account at any time in Settings → Account → Delete account (section 7).
6. Purchases and subscriptions
Subscriptions, when offered, are bought through Apple's App Store and processed entirely by Apple. We never see your payment details, full name, or billing address. To unlock paid features and to let you restore or manage a subscription, the App uses RevenueCat, a subscription-management service, which receives the purchase data described in section 2 from Apple and from the App. RevenueCat does not receive your name, email address, or anything you do in the App. Apple's own privacy policy governs payment processing: https://www.apple.com/legal/privacy/. If the App is offered free of charge in your region, no purchase data is processed.
7. Deleting your data
- Delete account (Settings → Account → Delete account) permanently removes every row stored for you on our servers and signs you out. Deleted records are kept only as "tombstones" (a record that says "this was deleted", without content) for up to 30 days so that any other device you own can sync the deletion, then purged. Where our hosting provider keeps server backups for us, they are encrypted and rotated within 30 days; deleted data leaves any backup on that schedule. Your local data on the phone is not affected unless you also choose "Erase all my data".
- Erase all my data (Settings → Privacy) permanently deletes the App's local database on that phone and offers to delete your account at the same time.
- Deleting the App removes its local data but not your account.
- Purchase records held by Apple and RevenueCat are retained as described in section 2, because the law requires us to keep records of transactions; they contain no name or email.
8. Advertising, attribution, and marketing
We grow Bluum through paid advertising. The platforms we use or may use are Meta (Facebook and Instagram), TikTok, Google (Search, YouTube, and the Google network), Apple Search Ads, Snapchat, Pinterest, X, and Reddit; TikTok and Meta are our main channels, and the others are listed so that this policy stays accurate if we start using them. This section explains exactly what that involves and how you control it.
8.1 What "tracking" means here. With your permission, the App links data about your use of Bluum (install, first bloom, sign-in, trial, subscription, renewal, cancellation) with data held by advertising platforms, using your device's advertising identifier (IDFA) or a hashed (irreversibly scrambled) form of your email address. The platforms use this to tell us which ad you came from, to show Bluum ads to you and to people similar to you on their services, and to stop showing acquisition ads to people who already subscribe. Where the App integrates an advertising platform's software development kit (for example the Meta SDK), that kit may collect device information and app events directly for the platform.
8.2 Your permission comes first. On iPhone, none of this happens until you tap Allow on Apple's "Allow Bluum to track your activity across other companies' apps and websites?" prompt, which the App shows once, with its own explanation screen before it. If you tap Ask App Not to Track, no advertising identifier is read and no event linked to you is sent to any advertising platform; we then rely only on Apple's aggregated, anonymous measurement (SKAdNetwork / AdAttributionKit), which cannot identify you. You can change your choice at any time in Settings → Privacy → Personalised ads and measurement inside the App, or in iOS Settings → Privacy & Security → Tracking. Withdrawing permission stops future sharing; it does not undo data already lawfully shared, but you can ask us and the platforms to delete it (section 13).
8.3 What is never used for advertising. Your setup answers (mood, beliefs, religion, gender, therapy, and similar), your voice, the text of the affirmations or mantras you practise or write, and the topics you follow are never shared with advertising platforms, never used to build audiences, and never used to target you. Advertising events describe only commercial milestones (install, sign-in, trial, purchase) and generic device data.
8.4 Marketing messages. We do not currently send marketing emails or marketing push notifications. If we start, we will ask for your consent first, give you an unsubscribe link in every email and a switch in Settings, and update this policy. Service messages that we must send (for example about your account, a price change, or these documents) are not marketing and cannot be switched off while you have an account.
8.5 The advertising platforms. Advertising platforms are not our processors: they use the data they receive under their own privacy policies and, for the collection through their tools, as joint controllers with us as far as the law provides. Their policies and your controls on their side: TikTok https://www.tiktok.com/legal/privacy-policy · Meta https://www.facebook.com/privacy/policy · Google https://policies.google.com/privacy · Apple https://www.apple.com/legal/privacy/ · Snap https://values.snap.com/privacy/privacy-policy · Pinterest https://policy.pinterest.com/privacy-policy · X https://x.com/privacy · Reddit https://www.reddit.com/policies/privacy-policy. We sign the data-sharing terms each platform offers for EU advertisers before we send it any data.
8.6 Sale and sharing (US law). Under the California Consumer Privacy Act and similar US state laws, sending advertising data to these platforms can count as "sharing" for cross-context behavioural advertising and, in some readings, as a "sale". We do not sell personal data for money. If you are in the US you can opt out of sharing at any time through the same Settings → Privacy switch, or by emailing jp@upularstudio.com with "Do not sell or share" in the subject; we honour Global Privacy Control signals on the Website.
8.7 What we still do not do. We show no third-party advertisements inside the App. We do not sell your data for money. We never ask for or store a password. We do not upload your voice or your sensitive setup answers. We do not use the content of your practice to train artificial-intelligence models.
9. Children
The App is intended for adults and is not directed to children. We do not knowingly collect personal data from anyone under 16 (or a higher minimum age where your local law sets one). If you believe a child has created an account, contact jp@upularstudio.com and we will delete it.
10. Service providers, advertising platforms, and international transfers
We share personal data only with the parties below and only to the extent needed for the purpose stated. Processors act on our instructions under a written data-processing agreement. Advertising platforms (marked ★) receive data only with your tracking permission (section 8) and use it under their own policies, as independent or joint controllers.
| Provider | What it does for us | Where data is processed | Data involved | Transfer safeguard |
|---|---|---|---|---|
| Apple Inc. (for EU users, Apple Distribution International Ltd, Ireland) | App distribution, payments, Sign in with Apple, on-device speech recognition, local notifications | On your device; Apple systems in the EU and USA | Sign-in identifier and (optionally relayed) email; payment handled by Apple under your Apple Account | EU–US Data Privacy Framework certification and Apple's standard contractual clauses |
| Google LLC (for EU users, Google Ireland Limited) | Google Sign-In, only if you choose it | EU and USA | Sign-in identifier and email address | EU–US Data Privacy Framework certification and Google's standard contractual clauses |
| Supabase, Inc. (USA) | Account authentication and hosting of your synced practice data | EU (AWS, Frankfurt, Germany); limited support access from the USA | Account data and synced practice data | Data stored in the EU; standard contractual clauses in Supabase's data-processing agreement for any remote access |
| RevenueCat, Inc. (USA) | Subscription management, and forwarding of subscription events to the advertising platforms marked ★ when you have allowed tracking | USA | Purchase data (section 2); with tracking permission, also the advertising identifier or hashed email needed to forward events | Standard contractual clauses in RevenueCat's data-processing agreement |
| ★ Meta Platforms Ireland Ltd (for EU users) / Meta Platforms, Inc. (USA) | Advertising on Facebook and Instagram: campaign measurement, audiences, retargeting | EU and USA | Advertising and attribution data (section 2), via the Meta SDK in the App and server-to-server events from RevenueCat | Meta's EU data-transfer addendum (standard contractual clauses) and EU–US Data Privacy Framework certification |
| ★ Google Ireland Limited / Google LLC (Google Ads) | Advertising on Google Search, YouTube, and the Google network: campaign measurement and audiences | EU and USA | Advertising and attribution data, via server-to-server events from RevenueCat | Google Ads data-processing / controller terms; EU–US Data Privacy Framework certification |
| ★ TikTok Technology Limited (Ireland) / TikTok Inc. (USA) | Advertising on TikTok: campaign measurement and audiences | EU, USA, and other TikTok regions | Advertising and attribution data, via server-to-server events from RevenueCat | TikTok's data-sharing terms with standard contractual clauses |
| ★ Apple Inc. (Apple Search Ads) | Advertising in the App Store; attribution of installs to Apple Search Ads campaigns through Apple's attribution API | On device and Apple systems | Attribution token only; no identifier that names you | Apple's terms; EU–US Data Privacy Framework certification |
| ★ Snap Inc. (USA) / Snap Group Limited (UK, for EU users) | Advertising on Snapchat: campaign measurement and audiences | EU, UK, and USA | Advertising and attribution data, via server-to-server events from RevenueCat | Snap's data-sharing terms with standard contractual clauses |
| ★ Pinterest Europe Ltd (Ireland) / Pinterest, Inc. (USA) | Advertising on Pinterest: campaign measurement and audiences | EU and USA | Advertising and attribution data, via server-to-server events from RevenueCat | Pinterest's data-sharing terms; EU–US Data Privacy Framework certification |
| ★ X Corp. (USA) / Twitter International Unlimited Company (Ireland) | Advertising on X: campaign measurement and audiences | EU and USA | Advertising and attribution data, via server-to-server events from RevenueCat | X's data-sharing terms with standard contractual clauses |
| ★ Reddit, Inc. (USA) / Reddit Ireland Limited | Advertising on Reddit: campaign measurement and audiences | EU and USA | Advertising and attribution data, via server-to-server events from RevenueCat | Reddit's data-sharing terms with standard contractual clauses |
| ElevenLabs, Inc. (USA) | Turning the text of a mantra you save into a spoken recording — only if you switch this on in the App | USA | The mantra text only (never your setup answers, your voice, or affirmations) | Standard contractual clauses in ElevenLabs' data-processing agreement |
| TelemetryDeck GmbH (Germany) | Anonymous usage statistics | Germany (EU) | Irreversibly anonymized event data only | None needed — EU processing |
| Functional Software, Inc. (Sentry, USA) — EU data region | Crash reports | Germany (EU); support access from the USA under Sentry's data-processing agreement | Crash reports as described in section 2 (no account data, no content, IP address discarded) | Standard contractual clauses in Sentry's data-processing agreement |
| Cloudflare, Inc. (USA) | Hosting https://dailybluum.com | Cloudflare's global edge network, including EU data centres | Website technical logs (section 2) | EU–US Data Privacy Framework certification and standard contractual clauses in Cloudflare's data-processing addendum |
That is the complete list. If it changes, we will update this policy before the change takes effect. Where data leaves the European Economic Area, we rely on the European Commission's adequacy decisions (including the EU–US Data Privacy Framework for certified companies) or on the Commission's standard contractual clauses, and you can ask us for a copy of the relevant safeguard. We may also disclose data where a law, court order, or public authority validly requires it, or to establish, exercise, or defend legal claims.
11. Website and cookies
The Website uses no cookies or tracking scripts until you accept them. When we run advertising, the Website shows a cookie banner and, only if you accept, loads the measurement pixels of the advertising platforms listed in section 10 (for example the TikTok Pixel and the Meta Pixel) so that the platforms can measure visits and conversions from their ads and show you Bluum ads later. Declining changes nothing about how the Website works. You can withdraw your choice at any time through the "Cookie settings" link in the footer. Strictly necessary technical logs are kept by Cloudflare as described in section 2. Links to Apple's App Store lead to Apple's services, which are governed by Apple's policies.
12. Security
On your phone, your data is protected by the device's own security (encryption at rest, your passcode or Face ID). Sign-in tokens are stored in the iOS Keychain. Synced data travels only over encrypted connections (TLS) and is stored encrypted at rest on EU servers, with per-account access rules enforced by the database itself, so that even a bug in the App could not expose one person's garden to another. No secret keys are shipped inside the App. No method of storage or transmission is perfectly secure, but we keep the most sensitive information — your voice and your setup answers — off our servers entirely. If a personal-data breach ever affects you in a way that creates a high risk to your rights, we will inform you and the supervisory authority as the GDPR requires.
13. Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you and receive a copy;
- rectify inaccurate data;
- erase your data ("right to be forgotten");
- restrict processing in certain circumstances;
- port the data you gave us to another service in a machine-readable format;
- object to processing based on our legitimate interests, including the anonymous statistics;
- withdraw consent at any time where processing is based on consent — including tracking permission — without affecting processing that already happened;
- lodge a complaint with a supervisory authority.
You can exercise most of these rights directly in the App: everything synced is visible in the App, Settings → Account lets you sign out or delete the account, Settings → Privacy lets you switch statistics off or erase all local data, and Settings → Account → Export lets you download your synced data as a file. For anything else, email jp@upularstudio.com; we respond within one month (extendable by two further months for complex requests, in which case we will tell you). We may ask you to confirm your request from the email address linked to your account so that we do not hand your data to someone else. Anonymous statistics cannot be linked to you and therefore cannot be looked up, corrected, or extracted for an individual.
The supervisory authority for Lithuania is the State Data Protection Inspectorate (Valstybinė duomenų apsaugos inspekcija, L. Sapiegos g. 17, LT-10312 Vilnius, https://vdai.lrv.lt). You may also complain to the authority in the EU country where you live or work.
United Kingdom. If you are in the UK, the UK GDPR gives you the same rights; the supervisory authority is the Information Commissioner's Office (https://ico.org.uk).
United States (including California). The categories of personal information we collect are those listed in section 2 (identifiers, commercial information, internet and app activity, and inferences limited to commercial milestones), collected from you, your sign-in provider, Apple, and advertising platforms, for the purposes listed there. With your tracking permission we "share" identifiers and app activity with advertising platforms for cross-context behavioural advertising (section 8.6); we do not sell personal information for money. California residents have the rights to know, delete, correct, opt out of sale or sharing, and not be discriminated against for exercising their rights; use Settings → Privacy in the App, the "Do Not Sell or Share My Personal Information" link on the Website, or email jp@upularstudio.com. We honour Global Privacy Control signals on the Website. We do not knowingly sell or share the personal information of anyone under 16.
14. Changes to this policy
If we change this policy, we will update the version number and effective date at the top. Material changes — new categories of data, new service providers, new purposes, or changes to your rights — will be announced inside the App before they take effect; where the law requires your consent to a change, we will ask for it. Minor clarifications may be posted without an in-app notice.
15. Contact
MB Upular Company code: 308114012 Registered address: Pamėnkalnio g. 1-26, LT-01116 Vilnius, Lithuania Email: jp@upularstudio.com