Trust & Legal
Privacy Policy
Last updated June 27, 2026
This policy explains what Bloom Intelligence Labs collects, how it is used, and the choices you have. It is written to be read, not to be hidden behind.
Who we are
Bloom is an AI-native Voice of the Customer product, operated by Bloom Intelligence Labs, Inc. ("Bloom," "we," "us," or "our"), a company incorporated in Ontario, Canada. This policy covers Bloom's websites and the Bloom service. Bloom runs on Appriana, a multi-tenant platform built and maintained by our team, with full access to operate, extend, and improve it.
For questions about this policy or your data, contact us at privacy@withbloom.ai.
Two roles, two sets of rules
Bloom handles personal data in two distinct capacities, and which one applies determines how your rights work. The distinction matters, so we state it plainly up front.
As a processor. When a business customer uses Bloom to analyze their own customer signal, reviews, support tickets, transcripts, and similar, that data may contain personal information belonging to the customer's own users. Some of this signal is supplied by the customer; some Bloom gathers from public sources at the customer's direction, when they tell us which brands or sources to watch. In both cases the customer is the controller: they decide what is collected and why, and Bloom processes it on their instructions under a Data Processing Addendum. If your data is in a Bloom workspace because you are a customer of one of our customers, that customer is responsible for it, and requests about it should go to them.
As a controller. When you interact with Bloom directly, by visiting our website, joining the waitlist, requesting access to a paper, contacting us, holding a Bloom account, or submitting feedback or other content to us directly, we decide how that information is used. Here Bloom is the controller, and the rights described below apply to us directly.
The rest of this policy is primarily about the second role, the information we collect and control directly. For data we process on a customer's behalf, the governing terms are in the customer's agreement and our Data Processing Addendum, which we provide on request.
What we collect
When you interact with Bloom directly, we collect:
- Account and contact details you give us: name, work email, company name, phone number, and similar information provided when you create an account, join the waitlist, request a paper, or contact us.
- Usage information from the website and product: pages viewed, features used, approximate location derived from IP, browser and device type, and the date and time of requests.
- Communications and content you send us, including support requests, feedback, and any content you submit directly through a Bloom account.
- Cookies and similar technologies, described in the cookies section below.
We do not ask for, and ask that you not send us, sensitive personal information (such as government identifiers, health, or financial account numbers) outside the secure channels built for it.
How we use it
We use the information we control to:
- provide, operate, and secure the Bloom service and website;
- respond to your requests, support you, and communicate about your account;
- understand how the product and site are used, so we can improve them;
- send service messages, and, where permitted, occasional product updates you can opt out of;
- meet legal, tax, and regulatory obligations, and enforce our terms.
We rely on a lawful basis for each use: performing our contract with you, your consent where required, our legitimate interests in operating and improving Bloom, and compliance with law.
AI, models, and training
Bloom is an AI product, so we are explicit about this: we do not use customer data to train or improve our models. The signal a customer brings into Bloom is analyzed to provide the service to that customer, and for that customer alone. That account-specific analysis is the product working as intended; it is not model training, and it does not feed a shared model.
If we ever offer a capability that would use a customer's data beyond providing the service to them, it will be on an opt-in basis, with that customer's explicit authorization, and never as a default.
Where data is processed
Bloom operates from Canada and uses infrastructure that may process data in multiple regions. Where personal data moves across borders, we rely on appropriate safeguards, including standard contractual clauses where they apply, to protect it in transit and at its destination. For customer data processed under a DPA, data location is addressed in that agreement and can be part of the deployment discussion.
How long we keep it
We keep personal information we control for as long as needed to provide the service, maintain your account, meet legal obligations, and resolve disputes. When it is no longer needed, we delete or de-identify it. Customer data we process is retained and deleted according to the customer's agreement; on request, customer data can be deleted, while certain access-control records are retained for audit integrity.
How we protect it
Protecting data is a priority area for our team, and Bloom is built accordingly. Data is encrypted in transit and at rest, access is governed by our access-control system Fortress, and we apply controls across the platform and our operations. No method of transmission or storage is ever completely secure, but the measures we take, and the controls available for review, reflect a serious standard. You can read the detail on our Enterprise Security page.
Your rights
Depending on where you live, you have rights over your personal information. For data Bloom controls, you can exercise these by contacting privacy@withbloom.ai. For data held in a customer's workspace, contact that customer, who is the controller; we will support them in responding.
If you are in the EU, EEA, or UK (GDPR)
You have the right to:
- access the personal data we hold about you;
- correct data that is inaccurate or incomplete;
- erase your data, where there is no overriding reason to keep it;
- restrict or object to certain processing;
- data portability, to receive your data in a usable format;
- withdraw consent at any time, where processing relies on consent;
- lodge a complaint with your local supervisory authority.
If you are in California (CCPA / CPRA)
You have the right to:
- know what personal information we collect, use, and disclose;
- access and delete your personal information;
- correct inaccurate personal information;
- opt out of the sale or sharing of personal information, though we do not sell or share it in the sense those terms are defined;
- limit the use of sensitive personal information;
- be free from discrimination for exercising these rights.
We will not charge you or degrade your service for exercising any of these rights, and we verify requests before acting on them to protect your data.
Children
Bloom is a business product and is not directed to children. We do not knowingly collect personal information from anyone under the age of majority in their jurisdiction. If you believe a child has provided us information, contact us and we will remove it.
Changes to this policy
We may update this policy as Bloom evolves or the law changes. When we do, we will revise the date at the top, and for material changes we will give clearer notice. Continuing to use Bloom after an update means you accept the revised policy.
Contact
Bloom Intelligence Labs, Inc.
Ontario, Canada
Privacy: privacy@withbloom.ai
Legal notices: legal@withbloom.ai