Trust & Legal
How Bloom Uses Data
Last updated June 27, 2026
A plain-language account of what Bloom does with data: what it touches, what it never does, who can see it, and how long it stays. The formal detail lives in our Privacy Policy and agreements; this page is the readable version.
The short version
- Bloom analyzes the customer signal you bring in, to give you back insight. That is the whole job.
- We do not train our models on your data. Your data is used to serve you, and you alone.
- Your data is isolated from every other customer's, enforced in the system, not by policy alone.
- We do not sell data, and we do not run advertising on it.
- You can export the data you supply and the outputs we generate for you, and have your data deleted, on request.
The sections below explain each of these, and where the formal terms live.
What Bloom does with your data
Bloom is a Voice of the Customer product. It takes unstructured customer signal, reviews, support tickets, transcripts, public review sources, and similar, and turns it into a small set of calibrated instruments you can act on. To do that, Bloom collects the signal you direct it to, organizes it, analyzes it, and surfaces what matters to the people who can act.
Some of that signal you supply directly. Some Bloom gathers from public sources, at your direction, when you tell it which brands or sources to watch. In both cases, Bloom is processing it to serve you. The result is yours.
What Bloom does not do: train on your data
Bloom does not use customer data to train or improve its models. The signal you bring in is analyzed to provide the service to you, and to you alone. That account-specific analysis is the product working as intended; it is not model training, and it does not feed a shared model that other customers benefit from.
This is the question every serious buyer of an AI product asks, so we answer it plainly and put it first. If we ever offer a capability that would use your data beyond serving you, it will be opt-in, with your explicit authorization, and never a default. Until you choose otherwise, your data trains nothing.
How your data stays separate
By default, Bloom is multi-tenant, which means many customers run on the same platform. Keeping each customer's data fully separated is therefore foundational, not an afterthought. Isolation is enforced at the point every query runs: one customer's data and another's are never within reach of the same query. This is a property of how the system is built, not a rule someone has to remember to apply. Where a customer runs Bloom in their own cloud, a dedicated environment, or on their own premises, isolation goes further still, there are no other tenants in the picture, and the deployment is theirs alone.
Access by our own team is held to the same standard. Staff reach a customer's data only when required, through the same access controls that govern everyone else, under least privilege. You can read how this works on our Enterprise Security page and in the detail of our access system, Fortress.
Who can see your data
Within your organization, you decide who sees what. Bloom's access controls let your administrators grant access by role and scope, so an executive, an operator, and a contractor can each be given exactly the access they should have.
Outside your organization, the answer is narrow. Bloom staff access customer data only when required to operate or support the service, under least-privilege controls. We use a small set of subprocessors to run the service, each under contract and bound to protect the data; they are listed on our subprocessors page. We do not sell or rent data, and we do not share it for anyone else's advertising.
How long data stays, and getting it out
We keep your data for as long as you use the service and need it there. The specifics for a given account are set in your agreement.
Getting your data out
The data you supply, and the analysis and outputs Bloom generates for you, are yours to export, to the extent the relevant export tools exist for your plan. Separately, Bloom also collects public information at your direction to power the service. That collected source material is part of how the service runs rather than a self-serve export; we are glad to discuss broader extracts where it makes sense, but they are not something the product hands back automatically.
Deleting your data
On request, we delete the data you supplied and the outputs we generated on your behalf. Public information Bloom has collected may be retained as part of operating the service, with one important exception: where an individual exercises a valid right to erasure of their personal data, that request is handled under our Privacy Policy and applicable law, regardless of where the data came from. Certain access-control records are retained for audit integrity, and backups age out on their ordinary cycle.
AI and third-party models
Bloom uses AI to analyze signal. Where parts of that analysis rely on third-party model providers, those providers process data to return a result to Bloom and are bound by contract not to use it for their own purposes, including their own model training. The providers Bloom relies on are part of the subprocessor list we maintain. As above, none of this is used to train Bloom's own models on your data.
Where the formal terms live
This page is the readable version. The binding detail lives in a few places:
- our Privacy Policy, which covers personal data in full, including your rights under laws like GDPR and CCPA;
- our Terms of Service, which govern use of Bloom;
- our subprocessors list, kept current;
- and, for business customers, a Data Processing Addendum that sets out how Bloom processes data on your behalf. We provide it during procurement; contact us to request a copy.
Questions about your data
Bloom Intelligence Labs, Inc.
Ontario, Canada
Data protection: privacy@withbloom.ai