Privacy

Last updated 2026-08-11

Your profile and your documents stay encrypted on your Mac. Signing in creates a Bloom account, but your data isn't in it — there's no Bloom database of your content. Bloom is local-first with cloud processing: the things you act on get processed by third-party services to do the work you asked for. Every AI request is one you triggered, and every outbound request is written to a local audit log you can read.

Your Bloom account

You sign in with Google, or with a six-digit code sent to your email address. That creates an account record holding your email address, which method you used, and when you last signed in. That is the whole of it. Your profile, documents, recipes and history are not in it and never reach it — they stay on your Mac.

The account exists so Bloom's relay can tell that a request came from you rather than from someone who found the URL. It's held by our authentication provider, never sold, never used for advertising, and never used to build a profile of you. Ask at [email protected] and we'll delete it.

What leaves your Mac

Bloom's relay forwards and keeps nothing: no request or response bodies are logged, and nothing is cached.

Connected services

Bloom can read your calendar, email, files and workspace tools to prepare a pre-meeting brief. Before every brief, Bloom shows you a sheet naming exactly which sources it will read. Your Mac digests what it finds on-device into a short summary, and only that summary goes to the AI provider.

Google user data

What Bloom does. Exactly four read operations, and nothing else is possible: list your calendar events; search Gmail for threads with a meeting's attendees; search Drive for documents relevant to that meeting; open one of those documents. Bloom never sends mail, never creates or edits calendar events, and never modifies or deletes files.

What Google asks you to grant is broader than that, and you should hear it here rather than discover it on the consent screen. Bloom currently connects through a managed connection provider whose shared Google app carries a fixed set of scopes — including full Gmail access and full Drive access. Bloom doesn't use them, but they're what the screen asks for. Google marks most of them optional, so you can decline them and Bloom will still work.

What keeps the gap closed. Two independent allowlists, at different layers, both limited to those four read operations. The connection provider will not execute any other tool even if asked, and Bloom's relay will not ask for one. So the ability to send mail or delete a file is not something Bloom holds and chooses not to use — it is refused twice, in systems that would each have to fail.

Bloom's use of information received from Google APIs adheres to theGoogle API Services User Data Policy, including the Limited Use requirements.

What never happens