Privacy
Last updated 2026-08-21
Your profile is encrypted on your Mac. Signing in creates a Bloom account, but your data isn't in it — there's no Bloom database of your content. Bloom is local-first with cloud processing: the things you act on get processed by third-party services to do the work you asked for. Every AI request is one you triggered, and every outbound request is written to a local audit log you can read.
How it's stored on your Mac
The profile Bloom builds — everything it has learned about you and the people you fill forms for — is kept in a database encrypted on disk, under a key held in your Mac's Keychain. Files you add stay in Bloom's own folder. Bloom's one-button reset deletes all of it: the database, the files, the audit log, and the key.
Your Bloom account
You sign in with Google, or with a six-digit code sent to your email address. That creates an account record holding your email address, which method you used, when you last signed in, and — if you used Google — the display name Google hands back, which the app shows you so you can tell which account you're in. That is the whole of it. Your profile, documents, recipes and history are not in it and never reach it — they stay on your Mac.
The account exists so Bloom's relay can tell that a request came from you rather than from someone who found the URL. It's held by our authentication provider, never sold, never used for advertising, and never used to build a profile of you. Signing out, and Bloom's one-button reset, both delete the session from your Mac — but neither cancels it at the authentication provider, so that token stays valid there until it expires on its own. Ask at[email protected] and we'll delete the account itself.
What leaves your Mac
- Form fills — the selected person's profile and a picture of the form go to our AI provider through Bloom's relay when you trigger a fill. Its commercial terms don't permit training on this data.
- Reading a document you add — when you add a passport, licence or similar, its pages are sent once to the same AI provider to be read into fields. Once only, at the moment you add it: after that Bloom works from the fields, and the images are never sent again.
- Voice and meeting audio — streams from your Mac straight to the speech and transcription providers while a session is active, authorized by a short-lived token. The audio never passes through Bloom's relay. Meeting capture includes other participants' speech.
- Spelling help, when you finish a form by voice — if a fill leaves fields Bloom couldn't answer, it can ask you for them out loud. The first question carries a short list of that person's names, email addresses, phone numbers, and the place names in their address, so the speech model doesn't "correct" an unusual spelling into a common one. That goes to the speech provider over the open voice connection, not through Bloom's relay. Nothing else from the profile goes with it — not dates of birth, not passport or identity numbers, not document contents, not employers or family members.
- Connected services — read to prepare meeting briefs, described below.
Bloom's relay forwards and keeps nothing: no request or response bodies are logged, and nothing is cached.
Connected services
Bloom can read your calendar, email, files and workspace tools to prepare a pre-meeting brief. Before every brief, Bloom shows you a sheet naming exactly which sources it will read. Your Mac digests what it finds on-device into a short summary, and only that summary goes to the AI provider.
- Google Calendar, Gmail and Drive connect through a managed connection provider, which holds the credential — no Google token is stored on your Mac, and Bloom keeps only an opaque identifier. These requests route through Bloom's relay.
- Slack and Notion use tokens held in your Mac's Keychain; Bloom talks to those services directly.
Google user data
What Bloom does. Exactly four read operations, and nothing else is possible: list your calendar events; search Gmail for threads with a meeting's attendees; search Drive for documents relevant to that meeting; open one of those documents. Bloom never sends mail, never creates or edits calendar events, and never modifies or deletes files.
What Google asks you to grant is broader than that, and you should hear it here rather than discover it on the consent screen. Bloom currently connects through a managed connection provider whose shared Google app carries a fixed set of scopes — including full Gmail access and full Drive access. Bloom doesn't use them, but they're what the screen asks for. Google marks most of them optional, so you can decline them and Bloom will still work.
What keeps the gap closed. Two independent allowlists, at different layers, both limited to those four read operations. The connection provider will not execute any other tool even if asked, and Bloom's relay will not ask for one. So the ability to send mail or delete a file is not something Bloom holds and chooses not to use — it is refused twice, in systems that would each have to fail.
- Use — your calendar is read automatically to show upcoming events in the app; this is the one connector read that isn't triggered by a click, and nothing from it goes to an AI provider. Gmail and Drive are read only when you click Prepare on a meeting, to find threads and documents relevant to its attendees.
- Storage — there's no Bloom server holding this data. It stays on your Mac; only the on-device brief summary goes further.
- Sharing — Google user data reaches the managed connection provider that carries the request, and reaches our AI provider only inside that brief summary. It is never sold, never used for advertising, and never read by a human.
- Revoking — disconnect in Bloom's settings, which revokes the grant at Google and requests deletion from the connection provider, which retains its own record Bloom can't purge. You can also revoke in your Google security settings. Bloom's one-button reset revokes every connection and deletes everything held locally.
Bloom's use of information received from Google APIs adheres to theGoogle API Services User Data Policy, including the Limited Use requirements.
What never happens
- No Bloom database of your content — no profile, no documents, no transcripts on our servers.
- No analytics, no trackers, no cookies — in the app or on this site.
- Nothing goes to an AI provider in the background.