Privacy Policy
How we handle information when you use the BLUME app.
This policy describes practices for the BLUME app operated by B.L.U.M.E. Communities (“we,” “us,” or “our”). If you use a different legal entity name for your organization, replace it here after legal review.
Summary
BLUME is a gratitude challenge app with daily prompts, Circles (program editions), and a community feed. We collect the information you provide when you create an account, build your profile, and post in the app—including optional photos you choose to attach. We use service providers to run the app (for example, cloud hosting, sign-in, and error reporting). We do not sell your personal information. You can contact us with questions or requests using the email in the Contact us section.
Information we collect
Account and authentication
When you sign up or sign in, we collect information needed to create and secure your account. Depending on how you register, this may include your email address, an account identifier from our authentication provider, and (if you use social sign-in) basic profile details that the provider shares with us, such as your name or profile image, as permitted by that provider and your settings. We support sign-in with email, Google, and Sign in with Apple where available.
Profile and community content
We store profile information you choose to provide (for example, display name, avatar, or bio) and content you submit through the app, such as responses to daily prompts and messages in the community feed. If you attach images, we process and store those images so they can be shown in the app. Other participants in your Circle or the community may see content you post according to how the product is designed and our access rules.
Photos and media
The app may request access to your photo library so you can select images to share. We only access photos you explicitly choose to upload. We do not access your camera for capture in the current product configuration described in our app permissions.
Usage and product analytics
We may record in-app events tied to your user account (for example, onboarding steps or challenge-related actions) to understand how the product is used and to improve features. These events can include an event type and optional technical or contextual details (“payload”) you do not directly type as a message.
Technical and diagnostic data
When you use the app, certain technical information is generated automatically, such as device or app version details, timestamps, and identifiers needed to maintain your session. If you experience a crash or error, we may receive diagnostic reports through our error-reporting service, which can include stack traces, device type, operating system version, and similar data to help us fix issues.
Information we do not intentionally collect
We do not require you to provide sensitive categories of data (such as health data beyond what you voluntarily write in free-text posts) to use the core app. Please avoid sharing special categories of personal data in public posts unless you choose to do so.
How we use information
We use the information above to:
- Provide, operate, and maintain the BLUME app and its features;
- Authenticate you and protect accounts against abuse;
- Display your profile and content to you and, where applicable, to other users in your Circle or feed;
- Store and deliver images and other content you upload;
- Improve the product, including through aggregated or de-identified insights where appropriate;
- Respond to support requests and enforce our terms and community expectations;
- Detect, prevent, and address technical issues and security incidents;
- Comply with applicable law and respond to lawful requests.
Legal bases (EEA, UK, and similar regions)
If data protection law in your region requires a “legal basis,” we rely on one or more of the following, depending on the activity: performance of a contract with you (providing the app you asked for); our legitimate interests in operating, securing, and improving the service (balanced against your rights); your consent where we ask for it (for example, for optional permissions or marketing, if we offer them); or compliance with legal obligations. You may have additional rights under local law; see Your rights and choices.
Sharing and subprocessors
We share information with service providers that process data on our behalf under appropriate agreements. They may only use your information as instructed by us. Categories of providers include:
- Supabase — cloud infrastructure for authentication, database, file storage, and related APIs that power the app backend.
- Google — if you choose Google sign-in, Google processes authentication according to Google’s policies and shares limited account information with us as part of that flow.
- Apple — if you choose Sign in with Apple, Apple processes authentication according to Apple’s policies and may share limited information with us (for example, a user identifier or relay email, depending on your choices).
- Sentry — error and performance monitoring to diagnose crashes and stability issues.
We may also disclose information if we believe in good faith that disclosure is required by law, regulation, legal process, or governmental request; to enforce our agreements or protect the rights, safety, or property of our users or the public; or in connection with a merger, acquisition, or asset sale, subject to appropriate safeguards.
We do not sell your personal information as that term is commonly understood in U.S. state privacy laws.
Retention
We retain information for as long as your account is active and as needed to provide the service. We may retain certain records longer where required for legal, security, or operational reasons (for example, backups, fraud prevention, or dispute resolution). When retention periods end, we delete or de-identify information in line with our practices and applicable law. Exact retention can depend on the type of data and our infrastructure; you may ask us about deletion as described below.
Security
We implement technical and organizational measures designed to protect your information, including access controls and encryption in transit where supported by our providers. No method of transmission or storage is completely secure; we encourage you to use a strong, unique password and to protect your device.
Your rights and choices
Depending on where you live, you may have the right to:
- Access, correct, or update your personal information;
- Request deletion of your account or certain data;
- Object to or restrict certain processing;
- Withdraw consent where processing is based on consent;
- Lodge a complaint with a data protection authority.
To exercise these rights, contact us at the email below. We may need to verify your request. If you use Google or Apple sign-in, you may also manage certain information through those providers’ account settings. For account deletion specifically, you can use the in-app flow (Profile → Account → Delete account) or our dedicated page: Delete your account.
International transfers
We and our service providers may process information in the United States and other countries where we or they operate. Those countries may have different data protection rules than your own. Where required, we use appropriate safeguards (such as standard contractual clauses approved by regulators) for transfers of personal data from the EEA, UK, or Switzerland, in addition to other lawful transfer mechanisms.
Children
BLUME is not directed to children under 13 (or the minimum age required in your jurisdiction to consent to processing without parental permission). We do not knowingly collect personal information from children below that age. If you believe we have collected information from a child, please contact us and we will take steps to delete it.
Changes to this policy
We may update this Privacy Policy from time to time. We will post the updated version on this page and change the “Last updated” date above. If changes are material, we may provide additional notice (for example, in the app or by email) where required by law. Continued use of the app after the effective date of changes constitutes your acknowledgment of the updated policy, to the extent permitted by law.
Contact us
For privacy questions, requests, or complaints, contact B.L.U.M.E. Communities at tgraubaena@gmail.com.