The short version
Bloom Log (“Bloom”) is operated by Frostad Studio in Washington State and is offered only to adults age 18 and older located in the United States.
- Only your trusted devices can read stored session backups. Bloom encrypts session details and heart-rate samples in your browser before backup. Frostad Studio does not receive the key needed to decrypt them.
- We do not sell your information. Frostad Studio does not sell or rent personal information, and does not use intimate session data for advertising.
- We do not build profiles of how you use Bloom. Marketing-site measurement has no persistent visitor identifier, and product error reports are not connected to your account.
- Error reports contain technical details, not your records. Automatic reports exclude intimate records, heart-rate data, user-named devices, account identity, and cryptographic material.
- Marketing is optional. We send promotional email only when you affirmatively opt in. Account, security, support, and billing messages are separate.
Information we handle
Account information
When you create or use a Bloom account, we handle your email address and the identifiers, device labels, and security records needed to sign you in, recognize your trusted devices, and protect encrypted backups. Adding a trusted device also creates temporary security records used to approve the device and transfer encrypted access to it. Those records may include request status and expiration details, public keys, salts, one-way hashes and proofs, and encrypted key-transfer material. Bloom uses one-time codes sent by email instead of asking you to create a password.
Encrypted session backups
Your session content is readable in Bloom only on a trusted device. Session times, ratings, moods, physical states, partner context, desire, comfort, intentions, need fulfillment, and heart-rate samples are encrypted in your browser with AES-256-GCM before backup. The encryption key and recovery code are created on your device; Frostad Studio does not receive their plaintext values and cannot decrypt the stored backup. Any patterns or insights Bloom derives from a session are calculated on your trusted device rather than stored as separate server-side profile fields.
To keep encrypted backups synchronized, Bloom stores a small amount of operational information outside the encrypted record: your account and trusted-device identifiers; a record identifier that includes its date and time; the encrypted record's size and format versions; whether it was deleted; and timestamps and change identifiers used to order updates. This information can show approximately when a record changed and which trusted device sent the change, but it does not contain the session details or heart-rate readings. We use it to operate and secure backup and synchronization—not for advertising, marketing profiles, or product-usage analytics.
Consumer health data
Washington law uses a broad definition of “consumer health data.” The categories Bloom's software processes include the heart-rate, sexual-health, intimate-session, desire, comfort, mood, physical-state, partner-context, and reflection information you choose to record. The legal definition can also cover your use of Bloom and related account, date, and device information.
This does not mean Frostad Studio can read your sessions. You enter session information on a trusted device, and a connected heart-rate device supplies samples only when you direct it to. Bloom uses that information in your browser to provide the features you request, then encrypts it before backup. Frostad Studio and its cloud provider receive the encrypted record and the limited operational information described above, without the plaintext key needed to read the record.
We use encrypted records, operational information, and account information only to provide and secure Bloom, handle billing and support, comply with law, or carry out another purpose with any consent the law requires. Service providers receive only the encrypted records or the limited account, purchase, network, delivery, or support information needed for their roles. A provider receives readable session information only if you choose to put it in a support message or file. Frostad Studio has no affiliates with which it shares consumer health data, and we do not sell consumer health data.
Subscription and payment information
We keep limited subscription records, such as Stripe customer and subscription identifiers, the subscribed plan or price, subscription status, and relevant billing dates. Stripe processes checkout and payment information. Frostad Studio does not receive or store your complete payment-card number.
Website and technical information
Like other online services, Bloom and its hosting, authentication, payment, and security providers process ordinary request information—such as an IP address, browser or device type, request time, referring page, and error or security events—to deliver and protect the service.
On the marketing site, we measure page visits, broad referral sources, campaign tags, and clicks on selected Bloom links. This measurement uses no analytics cookies or persistent visitor identifier, creates no person profile, and is never connected to a Bloom account or intimate session history.
Anonymous product error diagnostics
When the Bloom product app encounters a technical failure, it automatically sends PostHog a sanitized report so we can diagnose and repair the problem. A report may identify the general feature and operation involved, a standardized error category, whether a retry was attempted, the general Bluetooth protocol family involved, Bloom's software version, and a sanitized application stack trace. It uses a random temporary identifier that is not connected to your Bloom account and is not retained for later visits.
Bloom allows only approved diagnostic fields and replaces unrestricted error messages with standardized categories before sending a report. Reports exclude your identity and account identifiers, session content and times, heart-rate readings, user- or manufacturer-assigned device names and Bluetooth identifiers, recovery and pairing codes, cryptographic material, stored encrypted records, raw URLs, network request or response contents, and any diagnostic file.
We use these reports only to diagnose and repair technical failures, not to analyze how you use Bloom, advertise to you, or track you across sites.
Information you choose to send
If you contact us, we receive the information in your message. If you voluntarily attach a diagnostic log or Bloom backup, it may contain device details, timestamps, heart-rate readings, session details, or other sensitive information. Bloom never uploads those files or their contents for support without an action you take yourself. This is separate from the automatic, sanitized error reports described above, which do not include a diagnostic file or its contents.
Encrypted records, trusted devices, and recovery
While you use Bloom on a trusted device, your browser keeps a readable local copy of your history so the app can display and update it. Before any session backup leaves the browser, Bloom encrypts the entire record with a key kept on your trusted device.
When you set up encryption, Bloom gives you a recovery code that we do not receive or store in plaintext. You can authorize another trusted device from one you already use or with that recovery code. This design means Frostad Studio cannot recover your encrypted history if you lose every trusted device and the recovery code. You can also export a readable copy; any exported file is outside Bloom's encryption and should be stored carefully.
You can replace your recovery code or remove a trusted device. Bloom periodically confirms that an online browser is still authorized; if a browser has been removed, Bloom signs it out and attempts to delete its local Bloom records and access credentials. An offline browser cannot receive that instruction until it reconnects, and browser restrictions may prevent automatic cleanup. Exported files and other copies outside Bloom are not affected.
How we use information
We use the limited information we handle to:
- create, authenticate, secure, and support Bloom accounts;
- store, synchronize, restore, and delete browser-encrypted session backups;
- provide trials, subscriptions, checkout, billing, and account management;
- send one-time sign-in codes and necessary account, security, billing, or policy notices;
- respond to support requests and investigate problems;
- receive sanitized, anonymous error reports to detect, diagnose, and repair technical failures;
- understand aggregate marketing-site traffic and campaign effectiveness;
- prevent fraud, abuse, and security incidents; and
- comply with applicable legal, tax, accounting, and regulatory obligations.
If you opt in to marketing, we may also send Bloom news or offers. You can unsubscribe at any time without affecting transactional account messages.
Your choices and control
Records, backups, and trusted devices
You can delete individual records in Bloom, export your history, or add a trusted device. Session changes are backed up automatically when Bloom can connect. If two devices change the same session, Bloom keeps the last write, using the device identifier to break an exact timestamp tie. Exported files remain wherever you saved or shared them until you delete them.
Account deletion
You can delete your account from Bloom after confirming the signed-in email, or request deletion by email. After successful in-app confirmation, Bloom immediately deletes the Bloom account, encrypted session backups, trusted-device and recovery records, and other associated active Bloom server records. If a subscription is active, Bloom tells Stripe not to renew it. The Stripe subscription may remain scheduled through the end of the paid period for billing administration, but it does not keep the Bloom account or encrypted history active. Bloom access ends immediately, and the unused portion of the current period is not refunded unless required by law. Email requests are handled within the response periods described below.
Deletion removes Bloom data from the browser making the request. Other online devices periodically validate the account, lose access, and remove Bloom data when they detect the deletion. An offline device cannot be remotely erased until it reconnects, so you should reconnect it or clear Bloom's site data on that device. Account deletion cannot remove exported backups or files you saved or shared.
We instruct relevant service providers to delete covered data from their active systems. Where deletion from archived or backup systems cannot be completed within the initial response period, it may take up to six months as permitted by Washington law; the data will not be restored to active systems except as needed to complete deletion. We may retain a limited deletion receipt only as reasonably necessary to complete and verify deletion, prevent late billing events from recreating account records, resolve disputes, or meet legal obligations. Stripe and Frostad Studio may retain limited transaction, invoice, subscription, and payment records when reasonably necessary for billing, tax, accounting, dispute, fraud-prevention, or other legal purposes.
Email and analytics choices
You may unsubscribe from marketing email at any time. Marketing-site measurement is limited to the page, referral, campaign, and selected-link information described above. It is configured without analytics cookies, persistent visitor identifiers, person profiles, advertising use, or cross-site behavioral tracking. Because these practices already avoid the tracking addressed by browser “Do Not Track” and Global Privacy Control signals, those signals do not change how Bloom operates. Bloom and its providers still use browser storage where necessary for sign-in, local app data, security, checkout, and subscription management.
Error-diagnostic choices
Sanitized error reporting operates automatically when you use the Bloom product app and is used only to maintain the reliability and security of the service you request. Bloom does not offer an in-app setting to disable these reports. Because Bloom does not connect a report to your account or retain a persistent PostHog identifier, Frostad Studio generally cannot locate a particular report in response to an account-access or deletion request. Reports expire under the retention period below. You may contact us with questions or stop future reports by no longer using the product app.
Privacy requests
You may request access to personal information and consumer health data that Frostad Studio controls; request a list of third parties and affiliates with whom we have shared or sold your consumer health data; request correction or deletion; and withdraw consent for collection or sharing that relies on your consent. To make a request, email hello@bloom-log.app, preferably from the address associated with your account. We may take reasonable steps to verify that the request is yours. Withdrawing consent does not affect processing already performed and may prevent us from providing a feature that requires the data.
We will respond to a Washington consumer-health request within 45 days after receiving it. When reasonably necessary, we may extend the response period once by another 45 days and will tell you within the first 45 days why the extension is needed. If we deny a request, we will explain the decision and how to appeal. You may appeal by emailing hello@bloom-log.app. We will respond to the appeal within 45 days. If the appeal is denied, you may contact the Washington State Attorney General. We do not discriminate against anyone for exercising a privacy right.
Retention and security
We keep account information, encrypted session backups, trusted-device records, and recovery metadata while an account is active and as reasonably necessary to provide Bloom. When you delete an individual session, Bloom may retain a limited deletion marker while the account remains active so another device does not restore the deleted record; that marker can include the session identifier and timing metadata described above. We remove or minimize deletion markers and deletion receipts when they are no longer reasonably necessary for synchronization, deletion completion, security, billing integrity, dispute resolution, or legal compliance, and remove account-associated markers when the account is deleted, subject to the archive and legal-retention limits described above. Support messages and voluntarily supplied files are deleted when they are no longer needed to resolve the request. Sanitized PostHog error reports are retained for no more than 12 months. Aggregate analytics may be retained without information intended to directly identify you.
Encryption protects stored backups from being read without your key. It does not protect records that are open on a compromised trusted browser, or against malicious software delivered to that browser. Keep your devices, email account, and recovery code secure.
Frostad Studio and its providers use reasonable administrative and technical safeguards appropriate to the information they handle. No online service, browser-storage system, or transmission method can be guaranteed completely secure. If a breach triggers the Federal Trade Commission's Health Breach Notification Rule or another notification law, we will notify affected people and government agencies within the time and by the methods the applicable law requires. Where permitted, we will use the email address associated with your account for individual notice; we may also use another legally required form of notice.
Changes to this policy
We may update this policy as Bloom changes. We will revise the effective date above and provide additional notice when a change is material or when applicable law requires it. Changes to how Bloom stores or uses intimate session history will be explained before they take effect when required by law.
Contact Frostad Studio
Questions, account-deletion requests, privacy requests, consent withdrawals, and privacy appeals can be sent by email to hello@bloom-log.app.
Frostad StudioWashington State, United States