Privacy Policy
Last updated: September 1, 2026
We take the protection of your data seriously. In this privacy policy we explain transparently what data we process, what we use it for, and what rights you have. If you have any questions, reach out to us at any time.
1. Data controller
The data controller responsible for the processing of personal data within the meaning of Art. 4(7) GDPR is:
bloomnow (in the process of incorporation as bloomnow FlexCo)
represented by Anna Christine Enzinger
Unter Bregarten 22/1
2482 Münchendorf, Austria
Email: ace@bloomnow.app
As soon as bloomnow FlexCo is registered in the Austrian commercial register, responsibility will transfer to the FlexCo. We will update this policy accordingly.
2. Data protection contact
Roxane Hunot, co-founder of bloomnow, is the internal point of contact for all data protection matters.
Email: rh@bloomnow.app
You can address any question about the processing of your data directly to her.
3. General principles
We only process personal data to the extent necessary to provide our website and services and to fulfil legal obligations. Processing is carried out only on one of the following legal bases under Art. 6(1) GDPR:
- (a) consent
- (b) performance of a contract or pre-contractual measures
- (c) compliance with a legal obligation
- (f) legitimate interests
For special categories of personal data within the meaning of Art. 9 GDPR (e.g. health data) we process data exclusively on the basis of your explicit consent pursuant to Art. 9(2)(a) GDPR.
4. Processing activities in detail
4.1 Visiting the website (server logs)
When you visit our website, our hosting provider automatically records technical data that your browser transmits:
- IP address (shortened or anonymized where technically possible)
- date and time of the request
- page or file requested
- browser and operating system used
- referrer URL
This data is processed to provide the website technically, to ensure its stability and security and to defend against attacks. The legal basis is Art. 6(1)(f) GDPR (legitimate interest). Server logs are deleted after a maximum of 30 days.
4.2 Cookies and consent management
We use cookies on our website, small text files stored in your browser. We distinguish between:
- Strictly necessary cookies required for the website to function. Legal basis: Art. 6(1)(f) GDPR.
- Optional cookies (e.g. for web analytics or embedded content) that are only set with your consent. Legal basis: Art. 6(1)(a) GDPR.
Optional cookies (in particular for web analytics and audience measurement, and for measuring advertising performance) are only set after you have consented via our cookie banner. We do not use a third-party tool for this, but a lightweight in-house consent solution combined with Google Consent Mode v2. Until you consent, analytics- and advertising-related storage access (in particular cookies) remains disabled; in this state Google services run without cookies and without recognising you.
We store your choice locally in your browser (localStorage) so the banner does not reappear on every visit. You can withdraw or adjust any consent given at any time, with effect for the future, via the "Cookie settings" link in the footer of every page. Withdrawing is as easy as giving consent.
4.3 Web analytics and marketing (Google services)
On the basis of your consent (Art. 6(1)(a) GDPR) we use the following services provided by Google Ireland Ltd. (Gordon House, Barrow Street, Dublin 4, Ireland; parent company Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA). You can withdraw your consent at any time via "Cookie settings" in the footer.
Google Tag Manager. We use Google Tag Manager to deliver the tags (scripts) below in a managed way. Tag Manager itself does not set cookies and does not collect personal data for analytics purposes; it only controls the consent-based loading of the other services.
Google Analytics 4. We use Google Analytics 4 to understand how our website is used (e.g. pages visited, time on page, approximate location, device and browser information). A pseudonymous identifier (client ID) and your truncated IP address are processed; we do not directly attribute this to you. We operate Google Analytics with IP truncation enabled and without combining it with other data sources.
Google Ads (conversion tracking and remarketing). We measure the performance of our ads (e.g. whether a sign-up follows an ad click) and may serve advertising on that basis. Google may set cookies for this purpose if you have consented.
The data collected by these services may be transferred to the USA. For this we rely on the EU-US Data Privacy Framework (Google LLC is certified) and additionally on standard contractual clauses pursuant to Art. 46 GDPR. For more information, see Google's privacy policy at policies.google.com/privacy.
4.4 Launch pre-registration
The bloomnow app is in a closed beta. When you pre-register for the launch, we process the following data in order to inform you about the public launch of bloomnow and to send you a confirmation:
- name (optional)
- email address
- language preference (German or English)
- time of sign-up
After pre-registering you receive a confirmation email. The legal basis is your consent under Art. 6(1)(a) GDPR. You can withdraw your pre-registration at any time by sending a message to rh@bloomnow.app. After you withdraw, we delete your data within 30 days, unless a statutory retention obligation applies.
To manage pre-registrations we store the data in our database at Supabase (servers in Frankfurt, EU); the confirmation email is sent via our processor Resend Inc. (USA). You can find more about both providers in section 6.
In addition, for each pre-registration we record how it came about (such as the category of the referring site or an anonymous campaign code from a tracking link) and the approximate country of origin (only the two-letter country code, without storing the IP address). We evaluate this only in aggregate, to understand which channels work. The legal basis is our legitimate interest in effective reach measurement under Art. 6(1)(f) GDPR.
4.5 Embedded videos and social embeds
Our website contains embedded YouTube videos (e.g. introduction videos and voices from our advisory board). When you click the video thumbnail we load the YouTube player and your browser establishes a connection to YouTube's servers, transmitting at least your IP address.
Providers and possible transfers to third countries:
- YouTube: Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland; parent company Google LLC, USA
The legal basis is your consent under Art. 6(1)(a) GDPR, which you give by clicking the thumbnail. For transfers to the United States we rely on the EU-US Data Privacy Framework, provided the respective provider is certified under it, and additionally on standard contractual clauses pursuant to Art. 46 GDPR.
4.6 Email communication
If you write to us by email, for instance to beta@bloomnow.app, ace@bloomnow.app or rh@bloomnow.app, we process the personal data contained in your message in order to handle your request.
To handle requests faster, incoming support enquiries (email and in-app messages) are pre-sorted with AI assistance and reply drafts are prepared for our team. For this purpose the subject, a preview and the most recent messages of your enquiry are transmitted to our processor Mistral AI (France, processing within the EU; see section 6.2), processed transiently, not stored there and not used to train AI models. The classification only orders our internal work queue; every reply is read, checked and sent by a person on our team (no automated decision within the meaning of Art. 22 GDPR). Below every support reply sent by email you will also find two links that let you tell us with one click whether the reply was helpful. This feedback serves to measure our service quality (Art. 6(1)(f) GDPR), is stored only with the respective support case and is deleted with it; the confirmation page works without cookies and without tracking.
We process public reviews of our app in the app stores (Google Play, Apple App Store) with display name, star rating and text in order to respond to them and to assure the quality of our app. The source are the stores themselves; the legal basis is our legitimate interest in support and quality assurance (Art. 6(1)(f) GDPR). Changes and deletions in the store are mirrored when we synchronize; we also honour deletion requests directly.
The legal basis is Art. 6(1)(b) GDPR (pre-contractual measures or performance of a contract) or Art. 6(1)(f) GDPR (legitimate interest in responding).
Emails are deleted once the reason for the communication no longer applies and no statutory retention obligations stand in the way.
4.7 Own cookieless reach measurement
To understand how many people visit our website and which channels bring them to us, we run our own lightweight reach measurement. On each page view we store an anonymous record in our database at Supabase (servers in Frankfurt, EU): the page visited, the category of the referring source (e.g. a search engine, a social network, or an anonymous campaign code from a tracking link) and the approximate country of origin.
This measurement works without cookies and without recognising you across visits. We set no identifiers, build no user profiles and store no IP address: the country is derived from the IP address by our hosting provider (Vercel) and passed to us only as a two-letter country code; we do not otherwise process the IP address for this. Only anonymous aggregate statistics result, and no conclusions about you as a person are possible. The legal basis is our legitimate interest in privacy-friendly reach measurement under Art. 6(1)(f) GDPR.
4.8 bloomie chat on the website
Through the bloomie window on our website you can ask questions about bloomnow. Your chat input is transmitted to our processor Mistral AI (France, processing within the EU; see section 6.2) to generate responses and is stored together with the responses in our database at Supabase (servers in Frankfurt, EU), so an ongoing conversation can be continued. Your input is not used to train AI models. bloomie is labelled as AI, answers only questions about bloomnow, does not provide diagnoses and makes no automated decisions with legal effect (Art. 22 GDPR). To protect against abuse we store, per chat session, only a salted check value (hash) that cannot be traced back to you, instead of your IP address. If you voluntarily leave your name and email address to be contacted by our team, we process these to answer your enquiry. Please do not enter health data or other particularly sensitive information in the chat.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in answering your enquiry and secure operation); where you actively contact us, Art. 6(1)(b) GDPR.
5. Data processing in the bloomnow app
The following processing activities relate to the bloomnow app (iOS, Android, web app). All app data is stored in our database at Supabase, with servers located in Frankfurt (AWS eu-central-1), within the EU.
5.1 Account and profile
When you register, we process your email address, your name and, optionally, a profile picture. You can sign in with email/password or via Google OAuth (Google LLC, USA); when you sign in with Google we receive the email address and name stored with Google. For the community you can use an alias and a separate community avatar, so your real name does not have to be visible there.
Legal basis: Art. 6(1)(b) GDPR (performance of a contract).
Retention period: until you delete your account.
5.2 App settings
We store your settings (e.g. color mode, language, text size, notification preferences) to make them available across your devices.
Legal basis: Art. 6(1)(b) GDPR.
5.3 Self-care features (health data)
If you use features such as the mood diary (mood, sleep quality, tags, notes), wins, or saved tools, we process the content you enter. This information can allow conclusions about your health and therefore constitutes special categories of personal data (Art. 9 GDPR).
Legal basis: your explicit consent (Art. 9(2)(a) GDPR), which you can withdraw at any time with effect for the future, by deleting the content or your account in the app.
5.4 Questionnaires and self-assessments
The app offers questionnaires (e.g. about your family situation) and an ADHD-oriented self-screening. We store your answers and the results calculated from them in order to recommend suitable content and display your results. The tests are not diagnostic instruments and do not replace professional assessment. Information you provide may also relate to your child; it is entered exclusively by you as the parent or legal guardian; children do not have their own access to the app.
Legal basis: your explicit consent (Art. 9(2)(a) GDPR), which you give before your first questionnaire and can withdraw at any time.
5.5 bloomie (AI assistant)
bloomie is an AI-powered assistant. Your chat input is transmitted to our processor Mistral AI (France, processing within the EU) to generate responses and is stored together with the responses as a conversation history in your account, so you can continue earlier conversations. Your input is not used to train AI models. bloomie is expressly labelled as AI in the app, does not provide diagnoses and does not make automated decisions with legal effect (Art. 22 GDPR). You can delete conversation histories in the app; when you delete your account they are removed entirely.
So that the answers fit your situation, we pass a small extract from your profile along with your question: indications of the neurotype as they emerged from your questionnaires, and the topics you have shown an interest in so far. These details go to the same processor as the question itself. They are the difference between a generic answer and a fitting one, and because they come from the questionnaires, they rest on the same explicit consent as those (see section 5.4).
Legal basis: Art. 6(1)(b) GDPR; insofar as you enter health-related content, and for the personalisation described above, your explicit consent (Art. 9(2)(a) GDPR).
5.6 Community and direct messages
Posts, comments and reactions in the community are visible to other signed-in users (under your community alias, if set). In public communities your membership is additionally visible publicly, including to visitors who are not signed in: only your chosen alias and your community avatar are shown, never your real name or email address. The member lists of private or hidden groups remain restricted to signed-in, authorised users. Direct messages are visible only to you and the respective recipient. We store this content until you delete it or your account.
Legal basis: Art. 6(1)(b) GDPR.
5.7 Push notifications
If you enable push notifications, we store a device token and send messages via Firebase Cloud Messaging (Google LLC, USA; transfer based on the EU-US Data Privacy Framework and standard contractual clauses). You can disable push at any time in the app or in your system settings; the token is removed when you delete your account.
Legal basis: Art. 6(1)(a) GDPR (consent).
5.8 Appointments, reminders and travel time
The appointments feature lets you create appointments and reminders, including by dictating them with your voice or having them recognized from a photo or screenshot, and shows you a daily overview ("Now & Next"). We store the content you enter (title, date, time, location, notes) in your account. We process voice and image recognition solely to create an appointment from it. Processing takes place on our EU infrastructure (Supabase, Frankfurt); the text recognition in a photo is handled by the vision model of our processor Mistral AI (France, processing within the EU, see section 5.5). The photo is processed for that single step only and is stored neither by us nor by Mistral. What remains is the appointment it produced.
When you ask for the travel time for an appointment, we transmit the appointment's location to two European map services: Photon (operated by Komoot GmbH, Germany) for geocoding, i.e. converting the address into coordinates, and Valhalla (provided by FOSSGIS e. V. based on OpenStreetMap, Germany) for route and travel-time calculation. Only the location data needed for the calculation is transmitted, without any user identifier and without any link to your account. Processing takes place within the EU; no transfer to a third country occurs.
Legal basis: Art. 6(1)(b) GDPR (performance of a contract); the travel-time calculation only happens at your request.
5.9 Usage statistics and crash reports (self-operated)
So that we know which features are used and where the app runs into errors, we collect two technical records. Both stay exclusively on our own infrastructure in the EU (Supabase, servers in Frankfurt). Since 6 August 2026 no third-party analytics and no third-party crash provider is involved: PostHog and Firebase Crashlytics have been removed from the app. We now use Firebase for push notifications only (see section 5.7).
- Usage events. When you open a feature or complete a step, we store the name of the event, the corresponding area of the app, the app version, the build number and the platform (iOS, Android, web), linked to your account identifier. The content of your entries, tests or conversations is not transmitted, nor are advertising IDs or identifiers that would make you recognizable across other apps. There is no session replay, so your screen content is not recorded.
- Crash reports. When the app hits an error, we store the error message, the technical call history (stack trace), the library affected, the app version, the build number, the platform and the time. If a session was active at that moment, your account identifier is attached to the report, otherwise it is stored without any account reference. Content you entered is not part of the report.
Legal basis: Art. 6(1)(f) GDPR. Our legitimate interest is a stable app whose errors we can find and fix. The data stays with us, no processor is involved and no transfer to a third country takes place.
Objection: you can switch crash reports off at any time in the app, in the privacy and legal section of your profile, with the crash reports toggle (on by default). No further reports are collected after that. You can object to the usage statistics under Art. 21 GDPR with an informal email to rh@bloomnow.app.
Retention: both records are deleted together with your account. Crash reports without an account reference carry no identifier and cannot be attributed to you.
Until 6 August 2026 we based usage and crash analytics on your consent (Art. 6(1)(a) GDPR). Consents already given are kept unchanged, solely as a record pursuant to Art. 7(1) GDPR. They no longer serve as a basis for any processing.
5.10 Beta testing
During the beta phase we additionally process: (a) your beta feedback (content, time, app version) in order to improve the app, and (b) your acceptance of the beta participation terms (time and text version) in order to be able to demonstrate that consent was given (Art. 7(1) GDPR).
Legal basis: Art. 6(1)(b) and (f) GDPR (interest in record-keeping and improvement).
5.11 Consent for email and notifications
At the end of setup, and at any time later in your profile, you decide yourself how we may reach you. The decision is separate by channel (email or a notification on your device) and by occasion: a reminder if everyday life gets in the way; what is new in bloomnow; curated suggestions on your topics. There is deliberately no blanket "yes to everything", because that would not be informed consent.
We keep a record of this. We store your account identifier, the channel, the occasion, whether you consented or withdrew, where in the app it happened, the identifier of the text you were shown at that moment, and the time. Every consent and every withdrawal is its own entry; we never change an existing one. Only that way can we later show what exactly you said yes to, and what was on the screen when you did.
Legal basis: for the sending itself your consent (Art. 6(1)(a) GDPR, and for promotional email additionally § 174 TKG 2021, the Austrian implementation of Art. 13 of Directive 2002/58/EC); for the record our accountability obligation under Art. 7(1) GDPR (Art. 6(1)(c) GDPR).
Withdrawal: at any time in your profile or via the unsubscribe link in every email, with effect for the future. Unsubscribing via the link takes effect immediately and overrides everything in the record.
Retention: until you delete your account.
5.12 Surveys in the app
Now and then we show a short question, for example whether you would recommend bloomnow to someone else. You can answer it or dismiss it with "Later". Both are voluntary and have no consequences for how you use the app.
For each question we store one row: your account identifier, which question it was, whether it was shown, dismissed or answered, your answer (a value on the scale or a chosen option), your voluntary free-text comment, plus language, app version, build number, platform and the times. That row is also how we remember not to ask you again. Without it, the same question would be waiting the next time you open the app.
Legal basis: Art. 6(1)(f) GDPR. Our legitimate interest is to learn whether the app actually helps, without bothering you repeatedly with the same question.
Objection: at any time with an informal email to rh@bloomnow.app under Art. 21 GDPR.
Retention: until you delete your account.
5.13 Sharing bloomnow (referral link)
Your profile contains a personal link under "Weitersagen". If someone pre-registers for the launch through your link, we credit you with points in the community. You send the link yourself; we never write to anyone on your behalf and we store no contacts of yours.
For this we store your personal code together with your account identifier, and one entry per credited pre-registration containing the code, an internal identifier of the pre-registration and the time. You only ever see numbers, that is how many pre-registrations and how many points have come in. You never get to see the names or email addresses of the people who followed your link. The pre-registration itself is handled like any other (see section 4.4).
Legal basis: Art. 6(1)(b) GDPR insofar as you use the feature; otherwise Art. 6(1)(f) GDPR (traceable crediting that resists abuse).
Retention: until you delete your account.
5.14 Data export and account deletion
You can exercise both rights directly in the app (Profile → "Export data" or "Delete account"). The export is sent to your verified account email address as a machine-readable file (sent via our processor Resend Inc., USA). Account deletion immediately and irreversibly removes all your data from our database, including your profile, diary and test data, conversation histories, community content and direct messages. Residual copies in encrypted backups expire automatically after the backup retention period. As proof of deletion we store only an anonymous check value (hash) with a timestamp that cannot be traced back to you.
The export contains all data held under your account, explicitly including data you did not write yourself. Alongside your profile, settings, diary and test data, conversations with bloomie, community content and direct messages, that means your usage events, the crash reports attributed to you, your entries in the consent record, your survey answers and your credited referral points. For the right of access under Art. 15 GDPR it does not matter who produced the data: observed and inferred data are included too, as long as they relate to you.
Before we delete, we optionally ask you for the reason, with a fixed set of choices and a voluntary free-text field. We store that answer without any personal reference: only the chosen reason, your free text, the language of the interface and the date to the day. No account identifier, no email address, no time of day, and we link it to nothing, not even to the deletion record. It cannot be attributed to you afterwards, and that is exactly why it may outlive the deletion. You can skip the question; it has no effect on the deletion.
Legal basis for that question: Art. 6(1)(f) GDPR (understanding why people leave). Since the stored answer carries no personal reference, it is no longer personal data once recorded.
5.15 Moments
With "Moments" you record what was going on in a particular situation: the situation itself, what led up to it, how it showed, how intense it was, what helped, plus an optional note and, if you like, the sleep quality of the night before. Over time a pattern becomes visible in there that a single day hides.
Each moment also carries environmental data for that point in time. They sit there so that you can see for yourself whether there is a connection; we do not evaluate them beyond that. The two lunar values, moon phase and illumination, are calculated by the app on your device. Nothing leaves the device for those.
Weather conditions, air pressure and temperature are different, which is why it is spelled out here: the app fetches those from a weather service, Open-Meteo GmbH, based in Bürglen (canton of Uri, Switzerland). All that is transmitted is your approximate location, rounded to two decimal places, which is roughly one kilometre. No account identifier goes with it, no device identifier and no name. Because the request comes from your device, Open-Meteo sees your IP address; according to them, IP addresses are recorded for technical and security purposes only, are not linked to individuals, and are deleted after 90 days.
This only happens when you have switched on the weather permission in the "Weather-sensitive" tool, and for moments only for the current day. The same service also provides the weekly weather outlook. Switch the permission off and nothing is requested any more, and moments manage without weather values. The search for professionals near you is not affected: there your position stays on the device and the distance is calculated there.
Legal basis: your explicit consent (Art. 9(2)(a) GDPR), because these entries allow conclusions about health. You can withdraw it at any time with effect for the future by deleting the entries or your account. For the weather lookup the legal basis is your consent (Art. 6(1)(a) GDPR), which you give with the weather permission and withdraw with it.
Retention: until you delete the entry, at the latest until you delete your account.
5.16 Tests you have started
If you break off a questionnaire or self-screening halfway through, we remember where you stopped: which test it was, for whom in the family, how many questions are answered, how many there are in total, where you are, and when you started and last continued. Your answers are not part of this marker, and no result is derived from it.
It is the reason you can resume a test instead of starting over. If you delete the started test in the app, the marker goes with it.
Legal basis: Art. 6(1)(b) GDPR (performance of a contract). Even which test you started can be health-related, so we additionally base storing it on the same explicit consent you give before the first questionnaire (Art. 9(2)(a) GDPR, see section 5.4).
Retention: until the test is completed or deleted, at the latest until you delete your account.
5.17 Game progress
For the games in the app we store one save per game: which game it is, the save slots with the progress reached, and when it was last saved. That way a game continues at the same point on another device. Content from other areas of the app is not part of it.
Legal basis: Art. 6(1)(b) GDPR.
Retention: until you delete your account.
5.18 Family and sharing
You can set up a family in the app and invite people to it. For this we store the family itself and who created it, and for each invited person the invitation with email address, role and status, the invitation key and the time it was accepted. Added to that is the profile you create for each family member: display name, kind of member, year of birth or age band, colour, avatar and interests. As a rule these details concern other people, usually your child, and you enter them as the person with parental responsibility.
What becomes visible inside the family is your decision and nobody else’s: per member, whether it is shared with the family, and per account, whether moments are shared. You can also share individual content deliberately. For this we store what it concerns, who the share went to, which rights it covers, the share key, the status and the timestamps. You can revoke a share at any time.
Legal basis: Art. 6(1)(b) GDPR; insofar as health-related content is shared, your explicit consent (Art. 9(2)(a) GDPR), which lies in the deliberate act of sharing.
Retention: until you delete the family, the member or the share, at the latest until you delete your account.
5.19 Entitlement check and request starter
The entitlement check shows you what support exists in your country, what it provides, where it is applied for, which deadlines are running and who to turn to, plus cards on legal remedies, for example when an application has been refused. This content is the same for everyone, it is not a statement about you. Which country it is based on is set in your profile.
The request starter assembles a text from it that you send yourself, to an authority, a school or any other place you choose. The wording is produced by an AI model, so the details you provide for it go to our processor Mistral AI (France, processing within the EU, see section 5.5): what the request is about, which body it is addressed to, and which country it concerns.
Three further details are yours to add or leave out: your child's first name, your own name, and a short description of your everyday life. They make the letter more personal and are then sent to Mistral as well. We name them individually here because the first two are details about another person and the description can be health-related. The tool works without all three.
No row of our own about you is stored for this tool: not your details, not the text produced, and not who you send it to. Nothing stays at Mistral either. That you opened the tool may be recorded as a usage event under section 5.9.
Legal basis: Art. 6(1)(b) GDPR; for the three optional details your consent (Art. 6(1)(a) GDPR), and where the description is health-related, your explicit consent under Art. 9(2)(a) GDPR. It lies in your filling those fields in; left empty, none of it is transmitted.
5.20 A reminder after a longer break
If you have not been in the app for a while, we send you at most one friendly reminder. For this we store one row per reminder: your account identifier, which stage it was, when it was sent and whether it was suppressed. That row is also the brake. Without it you would get the same reminder several times over.
Whether such a reminder reaches you at all is something you decided at the end of setup and can change at any time in your profile (see section 5.11).
Legal basis: for sending, your consent (Art. 6(1)(a) GDPR); for the record, our legitimate interest in not writing to you repeatedly (Art. 6(1)(f) GDPR).
Withdrawal: at any time in your profile or via the unsubscribe link, with effect for the future.
Retention: until you delete your account.
5.21 Listed professionals and experience reports about them
The app and this website carry a directory of professionals: name, title, profession, practice address, how to reach them, languages, areas of focus and a short description. These details come from publicly accessible sources, from submissions by users, or from the professional themselves. So in part we do not collect them from the person concerned but via third parties; this section is at the same time the information required under Art. 14 GDPR.
Purpose and legal basis: families should be able to find professional help near them. The legal basis is Art. 6(1)(f) GDPR: the interest of searching families in a findable directory of people acting in a professional capacity, and our interest in offering them one. Only data from the professional sphere is processed, no private addresses and no health data about the professional.
Experience reports. Users can recommend a professional and write about how they experienced the support. Those are statements about a named person, which is why we look at them before they are published. Until then nobody sees them except the person who wrote them, and us. Anything that breaches our rules, or makes a factual claim we cannot verify, is not published. Reported entries are looked at again and taken down where the report is justified.
If you are listed yourself: you have the right to information about the data stored about you, to rectification, to erasure and to object under Art. 21 GDPR. You do not need to give reasons for objecting to being listed; we then remove the entry from the app and the website, together with the experience reports attached to it. An email to rh@bloomnow.app is enough, and we answer within a month. The same applies if you consider an individual report to be inaccurate.
Retention: until an objection is made or the entry ceases to exist for another reason; experience reports for no longer than the entry they belong to.
5.22 Subscriptions and purchases
You take out subscriptions through the app store of your device. Your payment details (card number, bank account) are seen only by Apple or Google; they do not reach us. To unlock your access and restore it on another device, we process for a purchase: the identifier of your account, an anonymous buyer identifier issued by the store, the product identifier of the chosen package, the term, start and end of the current period, whether it is a trial period, the status (active, cancelled, expired) and, to verify the purchase, the store's purchase receipt.
To manage subscriptions we use RevenueCat (RevenueCat, Inc., 633 Taraval St., Suite 101, San Francisco, CA 94116, USA). RevenueCat verifies the purchase receipts with Apple and Google and reports the state of your subscription to us. What goes there is the purchase data named above, the identifier of your account and the technical data of the call (IP address, device type, operating system and app version, country and currency of the store). No content from the app, no name and no email address.
From the subscription events (purchase, renewal, cancellation, refund) we also store one row in our usage statistics without payment data (section 5.9), so we know how many families use which package. How much of a limited allowance you have already used in the current week (for example minutes in the Klangraum) we count per account and week, so the app can tell you what is still open.
Legal basis: Art. 6(1)(b) GDPR (performance of the contract); for the statistics Art. 6(1)(f) GDPR.
Retention: the subscription state until the subscription ends and thereafter for the duration of statutory retention obligations (seven years for accounting records in Austria); the weekly counters until the end of the respective week, at the longest until your account is deleted.
6. Hosting and sub-processors
6.1 Hosting
Our website is delivered through Vercel Inc. (340 S Lemon Ave #4133, Walnut, CA 91789, USA) via its European edge locations. We have entered into a data processing agreement with Vercel pursuant to Art. 28 GDPR. As Vercel is a US-based company, we additionally rely on the EU-US Data Privacy Framework as well as standard contractual clauses pursuant to Art. 46 GDPR for any data transfer.
The backend infrastructure of our app (database, authentication, storage) runs on Supabase (Supabase Inc., 970 Toa Payoh North, Singapore), with servers located in Frankfurt in the AWS eu-central-1 region. Personal data of our app users is stored exclusively within the EU. We have entered into a data processing agreement with Supabase pursuant to Art. 28 GDPR. As Supabase has a US parent company, we additionally rely on the EU-US Data Privacy Framework and on standard contractual clauses pursuant to Art. 46 GDPR.
6.2 Overview of sub-processors
We use the following processors:
- Vercel Inc. (USA): website hosting and delivery via European edge locations
- Supabase Inc. (Singapore; servers in EU/Frankfurt): database, authentication and storage for the app, and for the website's launch pre-registrations
- Google Ireland Ltd. (Ireland): Google Tag Manager, Google Analytics 4 and Google Ads for web analytics and advertising performance measurement (only after consent)
- Mistral AI (France, processing within the EU): AI model for bloomie, the AI assistant in the app, including the personalisation of its answers based on profile details (see section 5.5); text recognition in photos in the appointments tool, where the image is not stored (see section 5.8); and the AI-assisted pre-sorting and reply drafts in our support (see section 4.6). Processing is transient, nothing is stored at Mistral.
- Komoot GmbH / Photon (Germany): geocoding of location data for the app's travel-time feature (only at your request; see section 5.8)
- FOSSGIS e. V. / Valhalla (Germany, based on OpenStreetMap): route and travel-time calculation for the app's travel-time feature (only at your request; see section 5.8)
- Open-Meteo GmbH (Bürglen, Switzerland): weather conditions, air pressure and temperature for the "Weather-sensitive" tool, the weather outlook and the environmental data on a moment (only when the weather permission is on; see section 5.15). All that is transmitted is the location rounded to roughly one kilometre, without any identifier.
- Dynatrace (EU region): technical monitoring and error diagnosis of our server functions (observability/tracing) to ensure stability and performance; only technical telemetry metadata is processed (function name, request method, response status, error messages), no content of your input, no health data and no IP address
- Resend Inc. (USA): transactional emails from the app and confirmation emails for the launch pre-registration
- Firebase / Google LLC (USA): push notifications (Cloud Messaging) for the app
- Google LLC (USA): Google OAuth for optional sign-in to the app
- RevenueCat, Inc. (USA): management of the app's subscriptions and verification of purchase receipts with Apple and Google (see section 5.22); processed are the account identifier and the purchase data, no payment details and no content
We have entered into data processing agreements pursuant to Art. 28 GDPR with every processor that stores or processes data on our behalf. Photon, Valhalla and Open-Meteo, by contrast, we call as open map and weather services: all that goes there is the location data needed for the calculation, without any identifier and without any link to your account.
For the app's usage statistics and crash reports we use no processor at all; both run on our own EU infrastructure (see section 5.9).
7. Transfers to third countries
Your data is only transferred to third countries (outside the EU or EEA) where this is necessary to provide the requested service, for example for embedded content from US providers, and where you have consented or another legal basis applies.
In such cases we rely on:
- the EU-US Data Privacy Framework (for US providers that are certified under it), or
- standard contractual clauses pursuant to Art. 46 GDPR together with supplementary technical and organizational measures.
For RevenueCat (USA, section 5.22) we rely on standard contractual clauses pursuant to Art. 46 GDPR, which form part of the data processing agreement; only the account identifier and the purchase data are transferred.
One special case is the weather service Open-Meteo, based in Switzerland (section 5.15). The European Commission has found Switzerland to provide an adequate level of data protection (adequacy decision under Art. 45 GDPR). Standard contractual clauses are not needed for it, but the transfer is still one to a third country and is therefore named here.
8. Retention periods
We store personal data only for as long as required for the respective processing or as required by law:
- Launch pre-registration: until the public app launch and up to 6 months thereafter if no account is created; withdrawal possible at any time, followed by deletion within 30 days
- App data: as long as your account exists; when you delete your account, all your data is deleted immediately and cascadingly from our database; residual copies remain only in encrypted backups until our hosting provider's backup retention period expires
- App usage events and crash reports: until you delete your account; crash reports without an account reference carry no identifier and cannot be attributed to anyone
- The app's consent record, survey answers and referral entries: until you delete your account
- Moments, started tests, game progress, family and sharing entries and the reminder record: until you delete the respective entry, at the latest until you delete your account
- Entries in the professionals directory together with the experience reports attached to them: until the professional objects or the entry ceases to exist for another reason
- The reason given for an account deletion: kept indefinitely, because it carries no personal reference and cannot be attributed to anyone
- Server logs: maximum of 30 days
- Email communication: until the matter is resolved, maximum 3 years thereafter
- Accounting and tax-relevant data: in line with statutory retention obligations (typically 7 years in Austria)
9. Your rights
You have the following rights against us at any time:
- Right of access under Art. 15 GDPR: we will tell you what data we hold about you.
- Right to rectification under Art. 16 GDPR: you can have incorrect data corrected.
- Right to erasure under Art. 17 GDPR: you can request deletion of your data, unless statutory retention obligations apply. You can delete your account and all associated data yourself at any time, even without the app, at bloomnow.ai/en/delete-account.
- Right to restriction of processing under Art. 18 GDPR
- Right to data portability under Art. 20 GDPR: you will receive your data in a structured, commonly used, machine-readable format.
- Right to object under Art. 21 GDPR: you can object at any time to processing based on legitimate interest.
- Right to withdraw consent under Art. 7(3) GDPR: you can withdraw any consent at any time with effect for the future.
You can also exercise access or data portability and erasure directly in the app: Profile → "Export data" or "Delete account" (see section 5.14).
A short email to rh@bloomnow.app is enough. We will respond within the statutory deadline of one month.
10. Right to lodge a complaint
You have the right to lodge a complaint with a data protection supervisory authority if you believe that the processing of your data infringes the GDPR. The supervisory authority competent for us is:
Austrian Data Protection Authority (Datenschutzbehörde)
Barichgasse 40 to 42, 1030 Vienna, Austria
www.dsb.gv.at
You can also contact the supervisory authority of your place of residence or workplace.
11. Data security
We use technical and organizational measures to protect your data, in particular encryption in transit (TLS) and at rest, access restrictions within the team, contractual confidentiality obligations, and regular security reviews.
12. Automated decision-making
Our app includes bloomie, an AI-powered assistant (see section 5.5). However, no automated decisions with legal effect or similarly significant impact within the meaning of Art. 22 GDPR take place, neither through bloomie nor anywhere else in the app. Recommendations and content serve solely to inform and support you.
13. Processing of special categories of data (health data)
bloomnow is aimed at families of neurodivergent children. Health-related data falls within the special categories of personal data under Art. 9 GDPR and is subject to special protection.
We process such data exclusively on the basis of your explicit consent under Art. 9(2)(a) GDPR. This applies in particular to the self-care features (e.g. the mood diary), questionnaires and self-assessments, and health-related content you share with bloomie; see sections 5.3 to 5.5 for details. You can withdraw your consent at any time with effect for the future, for example by deleting the respective content or your account in the app.
14. Additional information for users in Switzerland
If you use bloomnow from Switzerland, the revised Swiss Federal Act on Data Protection (revFADP) applies to you in addition. What we process, why and for how long is unchanged from the sections above; the following points come on top.
- Controller and contact: bloomnow e. U., Unter Bregarten 22/1, 2482 Münchendorf, Austria. The contact point for anything to do with data protection is rh@bloomnow.app.
- Sensitive personal data: data about health counts as sensitive under Art. 5(c) revFADP. We process it only with your explicit consent, exactly as described in sections 5.3, 5.4, 5.5, 5.15 and 5.18.
- Your rights: access (Art. 25 revFADP), rectification (Art. 32 revFADP), release and transfer of your data (Art. 28 revFADP), erasure, and objection to a processing operation. In substance these match the rights in section 9, and you exercise them the same way.
- Disclosure abroad: our servers are in the EU (Frankfurt). Switzerland and the EU each recognise the other side’s level of data protection as adequate. For the processors based in the USA named in section 6.2 we additionally rely on standard contractual clauses.
- Supervisory authority: you can contact the Federal Data Protection and Information Commissioner (FDPIC), Feldeggweg 1, 3003 Bern, at any time.
15. Changes to this privacy policy
We may update this privacy policy, for example when we introduce new features or when the legal situation or tools we use change. We will actively inform you of material changes, e.g. by email to registered users. The current version is always available at bloomnow.ai.
16. Contact
You can reach out to us with any privacy question at any time:
Roxane Hunot
Data Protection Contact
rh@bloomnow.app
General enquiries: beta@bloomnow.app