Last updated: 10 September 2026 Effective: 10 September 2026
You are reading this because BloomAgain holds some of the most private information a person can write down.
health readings โ is stored under your account only. No other user can see it.
to generate a reply. Nothing else goes with it. You can use most of the app without ever touching an AI feature.
recognise patterns โ it does not diagnose anyone.
If you are in immediate danger, stop reading this and call 112. Other helplines are listed in ยง14.
The rest of this policy is the detail. We've tried to write it so you can actually read it.
BloomAgain is operated by Solvixalabs, registered at Bowrampet, Hyderabad, Telangana, India.
For privacy questions, to exercise your rights, or to complain: privacy@bloomagain.app (see flag L-01 โ replace with a domain address)
Our Data Protection Officer / Grievance Officer is Naresh Podichetty, reachable at the same address. Under India's Digital Personal Data Protection Act, we are the Data Fiduciary for your data. Under the GDPR, we are the controller.
Lawyer to confirm the exact titles, statutory contact details, and the response timeline we publish โ flag L-02.
BloomAgain is for adults, 18 and over. We do not knowingly collect data from children. If we learn that a child has created an account, we will delete it. If you believe a child is using BloomAgain, contact us at privacy@bloomagain.app.
If a child is in danger, Childline 1098 is a 24ร7 helpline for children in distress, including children witnessing abuse at home.
We've split this by why it exists, because that matters more than a category name.
| What | Why |
|---|---|
| Email address | To create your account, sign you in, and reset your password |
| Password (stored only as a cryptographic hash by Firebase Authentication) | To sign you in |
| Display name, if you enter one | So the app can address you |
| A user ID we generate | To keep your data separate from everyone else's |
Bloom Again offers email sign-in and a guest session only. There is no Google or Apple sign-in, so no third-party identity provider receives anything about you, and we receive nothing from one.
This is the heart of the app, and it is all optional. You decide what goes in.
Much of this will, by its nature, be sensitive: it may describe your health, your sex life, your religion or caste, your relationships, and criminal conduct by another person. Some of it may identify a third party โ the person who harmed you, your children, your family. We treat all of it as sensitive, and ยง5 explains the rules we hold ourselves to.
If you connect Apple Health or Health Connect, BloomAgain reads:
We use these to compute a personal anxiety awareness score โ a comparison against your own recent baseline, so you can notice when your body is reacting before your mind catches up.
This is wellness information, not a medical measurement. It does not detect, diagnose, monitor, or treat any condition. It is often wrong. Caffeine, illness, exercise, a hot room, and a bad night's sleep all move these numbers. Never make a medical decision based on it.
If the app writes anything back to Apple Health (for example, a sleep log), we only write what you have asked it to write.
You can revoke health access at any time in your phone's system settings, and the app keeps working without it.
Two separate things, and they behave differently:
and stored under your account like any other file in the vault, and you can delete them.
recognition. On iOS and Android this may mean audio is processed by Apple's or Google's speech service under their privacy policies, not ours. If that matters to you, type instead.
The microphone is never on unless you have started a recording or a dictation. BloomAgain does not listen in the background.
When you use the AI coach, pattern insights, letter drafting, or the weekly briefing, the app sends the relevant text to our AI provider through our own server. The AI provider's key never sits on your phone.
What is sent: the instruction that shapes the reply, plus the conversation or entry the feature is working on. What is not sent: your email, your name, your account ID, your health readings, your files, or anything from a feature you aren't currently using.
Engineering must confirm this per feature and correct this paragraph if it overstates โ flag E-05.
Our AI provider is Anthropic (the Claude models), used under commercial API terms. We rely on those terms for retention limits and for the commitment not to train models on our API inputs. Anthropic deletes API inputs and outputs within 30 days of receipt or generation, except where a longer period is required to enforce their usage policy or comply with law - see privacy.claude.com/en/articles/7996866-how-long-do-you-store-personal-data โ do not paraphrase this from memory.
Your answers are stored under your account and used to produce a reflection back to you.
A score is not a diagnosis. These questionnaires are structured prompts for self-reflection, not clinical instruments, and they say nothing about the mental state of the person who harmed you. Only a qualified professional who has assessed you can diagnose anything.
stores, with RevenueCat managing entitlements. We receive an anonymous purchase identifier and your plan status. We never see your card number.
confirmation of the payment and the booking details. We never see your card or UPI credentials. Engineering to confirm the exact fields โ flag E-06.
stack trace when the app fails.
features are used, so we know what to fix. We do not send the content of your entries to analytics.
Analytics currently starts automatically. We are adding a setting to turn it off, and until then this policy must not claim otherwise โ flag E-02. This section must be rewritten once that toggle ships.
| What we do | India (DPDP) | EU/UK (GDPR) |
|---|---|---|
| Run your account | Your consent | Performance of a contract |
| Store your entries, evidence, recordings | Your consent | Consent, and for special-category data, explicit consent |
| Health and wearable readings | Your separate, specific consent | Explicit consent |
| AI features | Your separate, specific consent | Consent |
| Payments and subscriptions | Consent / necessary for the service | Contract, and legal obligation for tax records |
| Crash reporting and security | Consent | Legitimate interests โ keeping the app working and secure |
| Analytics | Consent | Consent |
| Responding to a lawful order | As required by law | Legal obligation |
Every consent can be withdrawn. Withdrawing is as easy as giving it โ see ยง9. Withdrawing consent doesn't undo something we already lawfully did, but it stops it going forward.
A lawyer must confirm this mapping, particularly whether consent or contract is the right basis for each, and how it interacts with the DPDP notice requirements โ flag L-02.
We are writing these as commitments, not aspirations:
and not under the broader "sell or share" definition used in California.
advertising** at you or anyone else.
specific instruction, except where ยง8 (law) forces us to.
named people, requires a documented reason, and is logged. We will not access your content to "look into" a support request unless you ask us to and tell us what to look at.
of our AI provider under its commercial terms.
We keep this list short on purpose. These are processors โ they act on our instructions, under contract, and cannot use your data for their own purposes.
| Who | What they handle | Where |
|---|---|---|
| Google (Firebase) โ Auth, Firestore, Storage, Cloud Functions, Crashlytics, Analytics, Messaging, Remote Config, App Check | Account, all stored content, crash and usage data | Firestore: asia-south1 (Mumbai, India). File storage: us-east1 (United States). |
| Anthropic | The text sent for an AI reply | Outside India; the regions listed at trust.anthropic.com/subprocessors |
| RevenueCat | Subscription status, anonymous purchase ID | Outside India |
| Apple / Google Play | Subscription payment | Their own terms |
| Razorpay | Practitioner booking payments | India |
| Email forwarding (no third-party helpdesk) | Support emails you send us | India - forwarded to our own mailbox; no helpdesk provider keeps a copy |
Practitioners you book through the app are not our processors. When you book a session, that practitioner becomes independently responsible for the information you share with them, under their own professional and privacy obligations. We pass on only what is needed to make the booking. See flag L-04.
If BloomAgain is ever sold, merged, or transferred, your data may move with it. We will tell you before that happens and give you a real opportunity to export and delete first.
We want to be precise here rather than reassuring, because in your situation the difference matters.
What is true:
any request for another user's data โ this is enforced on the server, not just hidden in the app.
come from a genuine copy of the app.
your face or fingerprint.
available so the app is less identifiable on your phone.
can't be pulled out of the installed app.
What is not true, and we won't claim it is:
your content sits in. That means a court order, a lawful demand, or a serious breach of our systems could expose it. If that risk is unacceptable for a particular piece of information, don't put it in the app.
The app currently displays "End-to-end encrypted" in the evidence vault. That string is wrong and must be changed before launch โ flag E-01. This section is the accurate description.
What you should also know: the biggest risk to you is usually not our servers. It is someone with physical access to your unlocked phone. Turn on the app lock. Turn on a device passcode. Consider whether the person you're documenting can see your notifications.
No system is perfectly secure. If we ever suffer a breach affecting your data, we will notify you and the relevant authority as the law requires we will notify the Data Protection Board of India without delay as the DPDP Act requires, tell affected users directly, and where the GDPR applies notify the supervisory authority within 72 hours.
We may have to disclose data if we receive a valid, binding legal order โ a court order, a warrant, or a lawful demand from an authority with jurisdiction.
Our commitments:
We disclose data only when the law compels us to, and we refuse or narrow requests that are overbroad. Where we are permitted to tell you about a request, we will. We do not publish a transparency report yet; if that changes we will say so here.
Whatever country you're in, you can:
| Right | How |
|---|---|
| See what we hold | Settings โ Export my data. You get a readable file of your content. |
| Correct something | Edit it in the app. For account details, email us. |
| Delete everything | Settings โ Delete account. |
| Withdraw a consent | Settings โ turn off the relevant feature. Health access is revoked in your phone's system settings. |
| Take your data elsewhere | The export is a machine-readable file. |
| Object or restrict | Email privacy@bloomagain.app and tell us what you want stopped. |
| Complain | To us first, at Naresh Podichetty โ we'd rather fix it. Then to your regulator: the Data Protection Board of India, or your national supervisory authority in the EU/UK, or the California Privacy Protection Agency. |
| Nominate someone (India) | You can nominate a person to exercise your rights if you die or become incapacitated. Contact us to record a nomination. |
We will not treat you differently for exercising a right. No degraded service, no price change, no nagging.
We aim to respond within 30 days.
Deleting your account removes your entries, records, and files from our live systems. Two honest caveats: (a) encrypted backups roll off on a 30 days cycle, and (b) we keep the minimum transaction records that tax and accounting law requires. Deletion asks for your password to confirm it is really you. If you started with a guest session and never added a password, or cannot complete that step, email us and we will delete the account manually.
| Data | Kept until |
|---|---|
| Your entries, incidents, evidence, recordings | You delete them, or you delete your account |
| Health readings | You delete your account or disconnect health access |
| AI conversation history | You delete the conversation or your account |
| Account record | You delete your account |
| Crash and analytics data | 14 months, then deleted automatically |
| Payment and tax records | The period Indian tax law requires โ currently 8 years, the period Indian tax law requires |
| Backups | 30 days |
If your account is inactive for 24 months, we will email you before deleting it. Consider carefully whether this is appropriate for this app โ a survivor may deliberately not open it for years and still need the evidence.
Some of our processors โ Anthropic and RevenueCat in particular โ operate outside India, so your data will be processed abroad.
For users in India, transfers are made in line with the DPDP Act and any restrictions the government notifies we do not make the app available where doing so would breach sanctions or export law.
For users in the EU/UK, we rely on the European Commission's Standard Contractual Clauses, together with the UK International Data Transfer Addendum where the UK GDPR applies.
You have the right to know, delete, correct, and opt out of "sale" or "sharing" of your personal information, and to limit the use of sensitive personal information. We do not sell or share your personal information, and we use sensitive personal information only to provide the features you asked for โ so there is nothing to opt out of. You can still exercise every other right through ยง9, and we will not discriminate against you for doing so.
A US privacy lawyer should confirm this, and confirm whether any other state law applies.
BloomAgain provides information, structure, and reflection tools. It does not provide healthcare, mental-health treatment, or legal representation.
behaviour. They are recognition, not diagnosis โ of you or of anyone else.
about your situation. Laws change and courts interpret them differently. Only a qualified advocate who knows your facts can advise you.
See 03_ai_disclaimer.md for the full detail on the AI features.
BloomAgain is not an emergency service and no one monitors what you write. If you are in danger or thinking about harming yourself, please reach a person:
| 112 | Emergency โ police, fire, ambulance (all-India) |
|---|---|
| 181 | Women Helpline โ 24ร7, connects to One Stop Centres, police, counselling |
| 14416 | Tele-MANAS โ Government of India 24ร7 mental health support, multiple languages |
| 9152987821 | iCall โ free confidential psychosocial counselling (TISS) |
| 1930 | Cyber Crime Helpline โ online harassment, stalking, image abuse |
| 15100 | NALSA โ free legal aid |
| 1098 | Childline โ children in distress |
| 14567 | Elderline โ elder abuse and neglect |
| 7827170170 | National Commission for Women |
Outside India, please use your local emergency number and national helplines.
If we change something that materially affects you, we will tell you in the app before it takes effect and give you the chance to export your data or close your account. Minor corrections will be reflected in the "Last updated" date at the top.
We will never make a change that turns your data into something we sell.
Solvixalabs Bowrampet, Hyderabad, Telangana India
Privacy and data protection: privacy@bloomagain.app Data Protection Officer / Grievance Officer: Naresh Podichetty
If we haven't resolved your complaint, you can escalate to the Data Protection Board of India, or in the EU/UK to your national data protection authority.
Draft โ pending review by a licensed advocate. Contains no statutory section references by design; a lawyer must supply them.