- Bloom uses your account, plant photos, and care information to provide the app.
- Anthropic analyzes photos for identification and health suggestions. Amplitude helps us understand app use, and Sentry helps us diagnose crashes.
- We do not sell personal information or share it for cross-app advertising. Analytics still involves data collection, including approximate location derived from an IP address.
- You can delete your account in the app or contact us about access, correction, and deletion. Some provider, security, and backup records are handled separately.
Who we are and what this covers
Solac Labs LLC operates Bloom Plant Care and bloomsprout.app. This policy covers the iPhone app, our website, and support communications. Contact us at hello@bloomsprout.app.
Information we collect
- Account and profile information: email address, authentication information, display name, an optional username, and your account identifier.
- Plants and care: plant names, photos you take or upload, identification results, symptom descriptions, health suggestions, notes, care history, saved plants, and reminder schedules.
- Preferences: onboarding answers such as plant-care experience and home-light preferences, timezone, and notification settings. These are information you provide, not measurements of your home.
- Purchases: subscription product, purchase and renewal information, trial and entitlement status, and identifiers used to connect purchases to your account. Apple handles payment details; Bloom does not receive your payment-card number.
- App activity and device information: feature and screen-use events, sessions, app opens, plant-add and care-task events, paywall interactions, app and operating-system versions, device information, and an analytics device identifier. Events can be associated with your Bloom account ID when signed in.
- Approximate location: Amplitude receives the IP address of analytics requests and can derive country, region, city, and similar approximate geographic information. Bloom does not request precise GPS location or use IDFA for tracking. The app's Amplitude configuration disables IDFV and carrier collection.
- Diagnostics and security: crash and app-hang reports, stack traces, technical context, server request information, IP addresses, timestamps, and account or request identifiers. If you contact support, we receive your email and whatever information you choose to include.
- Notifications: your device push token when notifications are enabled, and settings needed to deliver reminders.
- Android waitlist: if you sign up on our website, we collect your email address, signup date, the website link or form you used (such as the homepage or FAQ), and a record of your consent to Android-related emails. To limit spam, we temporarily store a coded network identifier derived from your IP address using a secret key. The waitlist database does not store your raw IP address.
Why we use information
We use information to identify plants, provide care and health suggestions, save and sync your collection, deliver reminders, process subscriptions, answer support requests, prevent abuse, and maintain the service. App analytics helps us understand onboarding, feature use, and where people encounter problems. Diagnostics helps us find and fix crashes and hangs.
We use Android waitlist signups to measure interest and, with your consent, send updates about Bloom for Android. Joining does not create a Bloom account or subscribe you to general marketing. There is no promised Android release date.
Where data-protection laws require a legal basis, we process information necessary to provide the features you request to perform our agreement with you; use proportionate security, reliability, and product-improvement information for our legitimate interests; comply with legal obligations; and rely on consent where required. Where we rely on consent, you can withdraw it as described in the rights section below.
Photos and AI analysis
When you choose photo identification or a plant-health check, Bloom uploads the image to our servers and sends it, together with relevant plant or symptom information, to Anthropic, whose Claude models provide the analysis. This is cloud processing, not analysis confined to your iPhone. Avoid including people, documents, or other personal information that is unnecessary for a plant photo.
Under Anthropic's commercial API terms, customer content is not used to train its models by default. Anthropic may retain inputs and outputs under its applicable API retention rules, including for safety, abuse prevention, or legal requirements. Bloom does not promise zero retention by the AI provider. See Anthropic's data usage information.
Our upload processing strips embedded image metadata, including EXIF location, before storage. This does not remove information visible in the picture. Photos are stored using cloud storage. Image URLs can be accessed by anyone who has the exact link, so do not treat a photo URL as a private sharing channel.
An identification photo may become a reference image in Bloom's shared species catalog. Other users can then see that photo without your profile or name. Contact us if you want a reference image removed. Account deletion clears matching catalog references and attempts to remove the underlying stored photos, subject to the deletion limitations below.
Service providers and other disclosures
We use the following providers for the purposes described here:
- Anthropic: plant images and relevant text for AI identification and plant-health analysis.
- Supabase: account authentication and our application database.
- Cloudflare: website delivery, security, storage of Android waitlist entries, and storage and delivery of plant photos. Website requests expose ordinary connection information, including an IP address, to our hosting provider.
- Fly.io: hosting for application servers and related technical logs.
- Apple: App Store distribution, purchases and subscriptions, and push-notification delivery.
- RevenueCat: purchase, entitlement, and subscription processing, using account and purchase identifiers and associated device information.
- Amplitude: product analytics, including app events, account and analytics device identifiers, technical device information, and IP-derived approximate location.
- Sentry: app crash and hang diagnostics and, when configured, backend error monitoring. Reports may include your account ID and technical context.
Providers process information under applicable service agreements and privacy terms. Providers acting on our behalf are engaged to process data for the relevant service with appropriate safeguards. Apple also handles information under its own privacy terms. We may disclose information to comply with law, protect rights and security, or as part of a merger, acquisition, or business transfer, subject to applicable notice and data-protection requirements.
We do not sell personal information or share it for cross-context behavioral advertising.
Analytics, website storage, and tracking choices
In the app: Amplitude records selected product events and session/app-lifecycle activity. We do not configure it to capture your typed search text, plant photos, or symptom notes. Sentry crash and hang reporting is enabled; screenshot attachments, view-hierarchy attachments, performance tracing, and session replay are disabled in the app configuration. These limits do not mean that the app collects no analytics or diagnostics.
Signing out resets the app's Amplitude identity for future events and clears the signed-in Sentry user association. It does not erase previously received events. The app does not currently offer an analytics opt-out switch. Contact us about applicable objection, consent, or deletion rights.
On the website: this website does not include an advertising pixel or a third-party visitor-analytics SDK, and we do not set marketing cookies. Our hosting provider processes requests to deliver and secure the site. App Store download links include fixed campaign labels identifying the page or group of pages where the link appears. These labels do not contain your email, account ID, or a unique visitor identifier. Apple uses these links to provide aggregate campaign reporting, subject to its reporting thresholds. Following an App Store link takes you to Apple's service, which has its own privacy practices. We also use Google Search Console to review aggregate search performance. Any future advertising or additional analytics integration will be evaluated and reflected here before use, with consent or opt-out mechanisms where required.
The website does not change its behavior in response to a browser's Do Not Track signal. We do not sell or share data for cross-context advertising regardless of that signal, and do not use website data to track you across unrelated services for advertising.
Notifications and permissions
You can adjust care-reminder preferences and time slots in Bloom, and control notification permission in iPhone Settings → Notifications → Bloom. Push notifications may mention a plant's name and may also tell you when an identification is ready. A trial-ending reminder may be scheduled locally on your phone if notifications are allowed; delivery is not guaranteed.
The app attempts to deregister its push token on sign-out. The service removes tokens that have not been seen for 90 days. Camera and photo access are used when you choose those features; you can manage system permissions in iPhone Settings.
Retention and account deletion
Android waitlist: we retain your entry while evaluating Android demand and providing the updates you requested. You can leave the waitlist, withdraw consent, or request deletion by emailing hello@bloomsprout.app from the address you signed up with. Waitlist removal is separate from deleting an iPhone app account. Temporary coded network identifiers are valid for a ten-minute rate-limit window and become eligible for removal when it ends; expired entries are removed during subsequent signup attempts or administrative cleanup. Hosting security logs and database backups may persist separately under our provider's retention settings.
We retain account and plant information while needed to provide your account and the features you use. Deleting an individual plant removes it from your collection, but some related records and stored photos remain until account deletion.
To request account deletion in the app, open You → Delete account… and complete the confirmation and any requested reauthentication. Successful deletion removes the sign-in identity and active account records, including saved plants, care records, identification and diagnosis records, and reminder records. It also clears matching shared-catalog photo references. Stored photo removal is attempted during deletion; a storage failure may leave an unreferenced file requiring separate cleanup. Contact us if you need help with a deletion request or a remaining photo link.
A limited record of the deleted account ID and deletion time is retained to prevent an old session from recreating the account. It becomes eligible for cleanup after seven days and is removed when the service next performs its deletion cleanup; seven days is not a guaranteed purge deadline.
Account deletion does not automatically erase all historical Amplitude, Sentry, or RevenueCat records. Provider-held records may require a separate deletion request. Contact us so we can coordinate applicable requests. Apple may retain purchase records under its own policies and legal obligations.
Logs, diagnostics, backups, and security records may persist beyond account deletion. Retention depends on the provider's settings, operational needs, applicable legal obligations, and the time needed to handle requests or disputes. We do not promise a single fixed retention window for all these systems. We restrict retained information to its relevant purpose and handle deletion requests subject to applicable law.
Deleting your account or the app does not cancel a subscription. Manage Bloom Pro separately in your Apple Account subscription settings.
Access, correction, and other rights
You can review and update information available in your account and contact hello@bloomsprout.app to request access, a portable copy, correction, or deletion. We may need to verify your identity before acting. Do not send us your password or payment-card details.
Depending on the law that applies to you, you may also have rights to restrict or object to processing, withdraw consent where processing relies on it, appeal a decision, and complain to your local data-protection authority. Withdrawal does not affect processing that was lawful before withdrawal. We will not discriminate against you for exercising applicable privacy rights. An authorized agent can contact us with appropriate proof of authority where the law permits.
Security and international processing
We use safeguards such as encrypted transport, access controls, and protected authentication storage. No online service can guarantee absolute security, and publicly accessible photo URLs have the limitations described above.
Bloom operates from the United States. Our service providers may process or store information in the United States and other countries where they operate. Where applicable law requires transfer safeguards, we use appropriate contractual or other lawful safeguards. Contact us for information about safeguards relevant to your request.
Children
Bloom is not intended for children under 13, and we do not knowingly collect their personal information. If you believe a child under 13 has provided personal information, contact us so we can investigate and take appropriate action. If your jurisdiction requires an older age or parental permission to use the service, those requirements also apply.
Changes and contact
The date at the top of this policy identifies the latest revision. We will post updates here and provide additional notice of material changes, or obtain consent, where required by applicable law.
For privacy questions or requests, contact hello@bloomsprout.app. The data controller is Solac Labs LLC.