Skip to content
bloom

Privacy Policy

Last updated: 2026-08-16

This page explains what data Bloom collects when you use our platform, why, and what choices you have about it.

1. Who we are

Bloom (https://bloommilestone.com) is the data controller for the information described in this policy. You can reach us at contact@bloommilestone.com for any question about this policy or your data.

2. What we collect

  • Account data — full name, email address, a hashed (never plaintext) password, and the organization/workspace name you provide at signup.
  • Business/project data — whatever you submit through a Guided Brief (business description, target audience, contact details, style preferences) so Bloom can generate a website for you.
  • Generated content — the websites, copy, and images Bloom generates on your behalf, and any assets you upload.
  • Usage data — server-side structured logs (timestamps, route, status code, error details) for operating and debugging the platform. We do not log full request bodies or full user objects in these logs.
  • Contact-form submissions — name, email, and message, if you use the contact form.
  • Session cookies — see the Cookie Policy.
  • IP address — used only transiently, in memory, to rate-limit requests and prevent abuse. Never written to a database or log file.
  • Payment records — when you make a purchase, we keep a record of the amount, date, and a reference number for the transaction. We do not receive or store your card number or payment-account credentials.
  • Purchaser information from our payment processor — for a purchase made without an existing Bloom account, our payment processor Paddle may provide us with the purchaser's email address so we can create and provision the corresponding Bloom account. We don't request or receive anything beyond that email address from Paddle for this purpose.

Creating an account requires your full name, email address, password, and workspace name — all four are required. When submitting a Guided Brief, your business name, description, goals, target audience, and requested pages are required; style preferences, opening hours, location, business contact details, and additional notes are optional. If you leave an optional field blank, the generated website simply omits that content rather than inventing something in its place.

Business contact information you submit for your project — such as a business email, phone number, or address — may be incorporated directly into the website Bloom generates for you, and becomes publicly visible once that website is published. This is separate from your own Bloom account credentials (login email, password), which are never published anywhere.

3. Why we collect it

To create and operate your account, to generate and publish the website(s) you request, to respond to support/contact requests, to keep the platform secure (rate limiting, abuse prevention, error diagnosis), and to process payment for the Bloom Website and any optional Care plan you choose to add (see Pricing). The Bloom Website is a one-time purchase; Care plans are optional, separately billed, recurring subscriptions — renewal, cancellation, and failed-payment handling for those are managed by our payment processor, Paddle, not by manual invoicing.

The business/project data you submit through a Guided Brief is sent to our AI providers (see below) solely to generate your website's copy and images from that brief. We don't use this AI process to make any decision about you as an account holder, and it doesn't involve profiling or automated decision-making about you personally — it generates content for the website you asked for, nothing else.

4. Who we share it with

Bloom uses the following real, named third-party processors to operate the platform today. We do not sell your data, and we do not share it with anyone beyond what's listed here:

  • A managed Postgres database provider, to store account and project data.
  • Cloudflare R2, to store generated and uploaded website assets.
  • Anthropic (Claude) and OpenAI, to generate website copy and images from your brief.
  • Vercel, to host and publish this platform and the websites it generates.
  • Resend, to send password-reset, contact-form, and purchase-confirmation emails.
  • Paddle, our payment processor and merchant of record, to process payment for the Bloom Website and any Care plan. Bloom does not store your card or payment-account details — payment happens on Paddle's own page, and Paddle acts as an independent controller for the data it collects during that process, under its own privacy terms.

Several of these providers are based outside the European Economic Area (for example, in the United States) — where that applies, the data described above may be processed there as part of that provider's service to us.

We don't currently use an error-tracking service in production — if that changes, this list will be updated at the same time.

5. How long we keep it

Account and project data is retained for as long as your account is active. If you'd like your account and its data deleted, email contact@bloommilestone.com and we'll process the request directly — there isn't a self-service deletion button in the product yet.

6. Your rights

Depending on where you're located, applicable law (such as GDPR or CCPA) may give you rights to access, correct, export, or delete your personal data, and to object to certain processing. To exercise any of these, email contact@bloommilestone.com — we handle these requests directly through that address today.

7. Security

Passwords are hashed (never stored in plaintext). Sessions use httpOnly cookies. All tenant data is isolated at the database level. Administrative routes are protected by a timing-safe secret comparison.

8. Changes to this policy

We may update this policy as the platform evolves. Material changes will be reflected by an updated "Last updated" date on this page.

9. Contact

Questions about this policy, or requests regarding your data, can be sent to contact@bloommilestone.com.

Questions about this page? Contact us.