๐ŸŒธBloom Again

BloomAgain Privacy Policy

Last updated: 10 September 2026 Effective: 10 September 2026


The short version

You are reading this because BloomAgain holds some of the most private information a person can write down.

health readings โ€” is stored under your account only. No other user can see it.

to generate a reply. Nothing else goes with it. You can use most of the app without ever touching an AI feature.

recognise patterns โ€” it does not diagnose anyone.

If you are in immediate danger, stop reading this and call 112. Other helplines are listed in ยง14.

The rest of this policy is the detail. We've tried to write it so you can actually read it.


1. Who we are

BloomAgain is operated by Solvixalabs, registered at Bowrampet, Hyderabad, Telangana, India.

For privacy questions, to exercise your rights, or to complain: privacy@bloomagain.app (see flag L-01 โ€” replace with a domain address)

Our Data Protection Officer / Grievance Officer is Naresh Podichetty, reachable at the same address. Under India's Digital Personal Data Protection Act, we are the Data Fiduciary for your data. Under the GDPR, we are the controller.

Lawyer to confirm the exact titles, statutory contact details, and the response timeline we publish โ€” flag L-02.


2. Who this policy is for

BloomAgain is for adults, 18 and over. We do not knowingly collect data from children. If we learn that a child has created an account, we will delete it. If you believe a child is using BloomAgain, contact us at privacy@bloomagain.app.

If a child is in danger, Childline 1098 is a 24ร—7 helpline for children in distress, including children witnessing abuse at home.


3. What we collect

We've split this by why it exists, because that matters more than a category name.

3.1 Things you have to give us to have an account

WhatWhy
Email addressTo create your account, sign you in, and reset your password
Password (stored only as a cryptographic hash by Firebase Authentication)To sign you in
Display name, if you enter oneSo the app can address you
A user ID we generateTo keep your data separate from everyone else's

Bloom Again offers email sign-in and a guest session only. There is no Google or Apple sign-in, so no third-party identity provider receives anything about you, and we receive nothing from one.

3.2 Things you choose to put in

This is the heart of the app, and it is all optional. You decide what goes in.

Much of this will, by its nature, be sensitive: it may describe your health, your sex life, your religion or caste, your relationships, and criminal conduct by another person. Some of it may identify a third party โ€” the person who harmed you, your children, your family. We treat all of it as sensitive, and ยง5 explains the rules we hold ourselves to.

3.3 Health and wearable data โ€” only if you turn it on

If you connect Apple Health or Health Connect, BloomAgain reads:

We use these to compute a personal anxiety awareness score โ€” a comparison against your own recent baseline, so you can notice when your body is reacting before your mind catches up.

This is wellness information, not a medical measurement. It does not detect, diagnose, monitor, or treat any condition. It is often wrong. Caffeine, illness, exercise, a hot room, and a bad night's sleep all move these numbers. Never make a medical decision based on it.

If the app writes anything back to Apple Health (for example, a sleep log), we only write what you have asked it to write.

You can revoke health access at any time in your phone's system settings, and the app keeps working without it.

3.4 Voice recordings and speech-to-text

Two separate things, and they behave differently:

and stored under your account like any other file in the vault, and you can delete them.

recognition. On iOS and Android this may mean audio is processed by Apple's or Google's speech service under their privacy policies, not ours. If that matters to you, type instead.

The microphone is never on unless you have started a recording or a dictation. BloomAgain does not listen in the background.

3.5 AI features

When you use the AI coach, pattern insights, letter drafting, or the weekly briefing, the app sends the relevant text to our AI provider through our own server. The AI provider's key never sits on your phone.

What is sent: the instruction that shapes the reply, plus the conversation or entry the feature is working on. What is not sent: your email, your name, your account ID, your health readings, your files, or anything from a feature you aren't currently using.

Engineering must confirm this per feature and correct this paragraph if it overstates โ€” flag E-05.

Our AI provider is Anthropic (the Claude models), used under commercial API terms. We rely on those terms for retention limits and for the commitment not to train models on our API inputs. Anthropic deletes API inputs and outputs within 30 days of receipt or generation, except where a longer period is required to enforce their usage policy or comply with law - see privacy.claude.com/en/articles/7996866-how-long-do-you-store-personal-data โ€” do not paraphrase this from memory.

3.6 Self-assessment questionnaires

Your answers are stored under your account and used to produce a reflection back to you.

A score is not a diagnosis. These questionnaires are structured prompts for self-reflection, not clinical instruments, and they say nothing about the mental state of the person who harmed you. Only a qualified professional who has assessed you can diagnose anything.

3.7 Payments

stores, with RevenueCat managing entitlements. We receive an anonymous purchase identifier and your plan status. We never see your card number.

confirmation of the payment and the booking details. We never see your card or UPI credentials. Engineering to confirm the exact fields โ€” flag E-06.

3.8 Technical and diagnostic data

stack trace when the app fails.

features are used, so we know what to fix. We do not send the content of your entries to analytics.

Analytics currently starts automatically. We are adding a setting to turn it off, and until then this policy must not claim otherwise โ€” flag E-02. This section must be rewritten once that toggle ships.

3.9 What we deliberately do not collect


4. Why we're allowed to do this (legal bases)

What we doIndia (DPDP)EU/UK (GDPR)
Run your accountYour consentPerformance of a contract
Store your entries, evidence, recordingsYour consentConsent, and for special-category data, explicit consent
Health and wearable readingsYour separate, specific consentExplicit consent
AI featuresYour separate, specific consentConsent
Payments and subscriptionsConsent / necessary for the serviceContract, and legal obligation for tax records
Crash reporting and securityConsentLegitimate interests โ€” keeping the app working and secure
AnalyticsConsentConsent
Responding to a lawful orderAs required by lawLegal obligation

Every consent can be withdrawn. Withdrawing is as easy as giving it โ€” see ยง9. Withdrawing consent doesn't undo something we already lawfully did, but it stops it going forward.

A lawyer must confirm this mapping, particularly whether consent or contract is the right basis for each, and how it interacts with the DPDP notice requirements โ€” flag L-02.


5. What we will never do

We are writing these as commitments, not aspirations:

  1. We will never sell your personal data. Not under any definition of "sell",

and not under the broader "sell or share" definition used in California.

  1. **We will never use your entries, recordings, or health data to target

advertising** at you or anyone else.

  1. We will never publish or share the content of your entries without your

specific instruction, except where ยง8 (law) forces us to.

  1. We will never read your entries for curiosity. Staff access is limited to

named people, requires a documented reason, and is logged. We will not access your content to "look into" a support request unless you ask us to and tell us what to look at.

  1. We will never use your data to train an AI model, and we require the same

of our AI provider under its commercial terms.


6. Who else touches your data

We keep this list short on purpose. These are processors โ€” they act on our instructions, under contract, and cannot use your data for their own purposes.

WhoWhat they handleWhere
Google (Firebase) โ€” Auth, Firestore, Storage, Cloud Functions, Crashlytics, Analytics, Messaging, Remote Config, App CheckAccount, all stored content, crash and usage dataFirestore: asia-south1 (Mumbai, India). File storage: us-east1 (United States).
AnthropicThe text sent for an AI replyOutside India; the regions listed at trust.anthropic.com/subprocessors
RevenueCatSubscription status, anonymous purchase IDOutside India
Apple / Google PlaySubscription paymentTheir own terms
RazorpayPractitioner booking paymentsIndia
Email forwarding (no third-party helpdesk)Support emails you send usIndia - forwarded to our own mailbox; no helpdesk provider keeps a copy

Practitioners you book through the app are not our processors. When you book a session, that practitioner becomes independently responsible for the information you share with them, under their own professional and privacy obligations. We pass on only what is needed to make the booking. See flag L-04.

If BloomAgain is ever sold, merged, or transferred, your data may move with it. We will tell you before that happens and give you a real opportunity to export and delete first.


7. How your data is protected

We want to be precise here rather than reassuring, because in your situation the difference matters.

What is true:

any request for another user's data โ€” this is enforced on the server, not just hidden in the app.

come from a genuine copy of the app.

your face or fingerprint.

available so the app is less identifiable on your phone.

can't be pulled out of the installed app.

What is not true, and we won't claim it is:

your content sits in. That means a court order, a lawful demand, or a serious breach of our systems could expose it. If that risk is unacceptable for a particular piece of information, don't put it in the app.

The app currently displays "End-to-end encrypted" in the evidence vault. That string is wrong and must be changed before launch โ€” flag E-01. This section is the accurate description.

What you should also know: the biggest risk to you is usually not our servers. It is someone with physical access to your unlocked phone. Turn on the app lock. Turn on a device passcode. Consider whether the person you're documenting can see your notifications.

No system is perfectly secure. If we ever suffer a breach affecting your data, we will notify you and the relevant authority as the law requires we will notify the Data Protection Board of India without delay as the DPDP Act requires, tell affected users directly, and where the GDPR applies notify the supervisory authority within 72 hours.


8. When the law forces our hand

We may have to disclose data if we receive a valid, binding legal order โ€” a court order, a warrant, or a lawful demand from an authority with jurisdiction.

Our commitments:

We disclose data only when the law compels us to, and we refuse or narrow requests that are overbroad. Where we are permitted to tell you about a request, we will. We do not publish a transparency report yet; if that changes we will say so here.


9. Your rights, and how to actually use them

Whatever country you're in, you can:

RightHow
See what we holdSettings โ†’ Export my data. You get a readable file of your content.
Correct somethingEdit it in the app. For account details, email us.
Delete everythingSettings โ†’ Delete account.
Withdraw a consentSettings โ†’ turn off the relevant feature. Health access is revoked in your phone's system settings.
Take your data elsewhereThe export is a machine-readable file.
Object or restrictEmail privacy@bloomagain.app and tell us what you want stopped.
ComplainTo us first, at Naresh Podichetty โ€” we'd rather fix it. Then to your regulator: the Data Protection Board of India, or your national supervisory authority in the EU/UK, or the California Privacy Protection Agency.
Nominate someone (India)You can nominate a person to exercise your rights if you die or become incapacitated. Contact us to record a nomination.

We will not treat you differently for exercising a right. No degraded service, no price change, no nagging.

We aim to respond within 30 days.

Deleting your account removes your entries, records, and files from our live systems. Two honest caveats: (a) encrypted backups roll off on a 30 days cycle, and (b) we keep the minimum transaction records that tax and accounting law requires. Deletion asks for your password to confirm it is really you. If you started with a guest session and never added a password, or cannot complete that step, email us and we will delete the account manually.


10. How long we keep things

DataKept until
Your entries, incidents, evidence, recordingsYou delete them, or you delete your account
Health readingsYou delete your account or disconnect health access
AI conversation historyYou delete the conversation or your account
Account recordYou delete your account
Crash and analytics data14 months, then deleted automatically
Payment and tax recordsThe period Indian tax law requires โ€” currently 8 years, the period Indian tax law requires
Backups30 days

If your account is inactive for 24 months, we will email you before deleting it. Consider carefully whether this is appropriate for this app โ€” a survivor may deliberately not open it for years and still need the evidence.


11. Data leaving India

Some of our processors โ€” Anthropic and RevenueCat in particular โ€” operate outside India, so your data will be processed abroad.

For users in India, transfers are made in line with the DPDP Act and any restrictions the government notifies we do not make the app available where doing so would breach sanctions or export law.

For users in the EU/UK, we rely on the European Commission's Standard Contractual Clauses, together with the UK International Data Transfer Addendum where the UK GDPR applies.


12. If you're in California

You have the right to know, delete, correct, and opt out of "sale" or "sharing" of your personal information, and to limit the use of sensitive personal information. We do not sell or share your personal information, and we use sensitive personal information only to provide the features you asked for โ€” so there is nothing to opt out of. You can still exercise every other right through ยง9, and we will not discriminate against you for doing so.

A US privacy lawyer should confirm this, and confirm whether any other state law applies.


13. This is not therapy, medicine, or legal advice

BloomAgain provides information, structure, and reflection tools. It does not provide healthcare, mental-health treatment, or legal representation.

behaviour. They are recognition, not diagnosis โ€” of you or of anyone else.

about your situation. Laws change and courts interpret them differently. Only a qualified advocate who knows your facts can advise you.

See 03_ai_disclaimer.md for the full detail on the AI features.


14. If you need help right now

BloomAgain is not an emergency service and no one monitors what you write. If you are in danger or thinking about harming yourself, please reach a person:

112Emergency โ€” police, fire, ambulance (all-India)
181Women Helpline โ€” 24ร—7, connects to One Stop Centres, police, counselling
14416Tele-MANAS โ€” Government of India 24ร—7 mental health support, multiple languages
9152987821iCall โ€” free confidential psychosocial counselling (TISS)
1930Cyber Crime Helpline โ€” online harassment, stalking, image abuse
15100NALSA โ€” free legal aid
1098Childline โ€” children in distress
14567Elderline โ€” elder abuse and neglect
7827170170National Commission for Women

Outside India, please use your local emergency number and national helplines.


15. Changes to this policy

If we change something that materially affects you, we will tell you in the app before it takes effect and give you the chance to export your data or close your account. Minor corrections will be reflected in the "Last updated" date at the top.

We will never make a change that turns your data into something we sell.


16. Contact

Solvixalabs Bowrampet, Hyderabad, Telangana India

Privacy and data protection: privacy@bloomagain.app Data Protection Officer / Grievance Officer: Naresh Podichetty

If we haven't resolved your complaint, you can escalate to the Data Protection Board of India, or in the EU/UK to your national data protection authority.


Draft โ€” pending review by a licensed advocate. Contains no statutory section references by design; a lawyer must supply them.