Privacy
Last updated 2026-08-11
Your profile and your documents stay encrypted on your Mac. Signing in creates a Bloom account, but your data isn't in it — there's no Bloom database of your content. Bloom is local-first with cloud processing: the things you act on get processed by third-party services to do the work you asked for. Every AI request is one you triggered, and every outbound request is written to a local audit log you can read.
Your Bloom account
You sign in with Google, or with a six-digit code sent to your email address. That creates an account record holding your email address, which method you used, and when you last signed in. That is the whole of it. Your profile, documents, recipes and history are not in it and never reach it — they stay on your Mac.
The account exists so Bloom's relay can tell that a request came from you rather than from someone who found the URL. It's held by our authentication provider, never sold, never used for advertising, and never used to build a profile of you. Ask at [email protected] and we'll delete it.
What leaves your Mac
- Form fills and document extraction — the selected person's profile and a picture of the form go to our AI provider through Bloom's relay when you trigger a fill. Its commercial terms don't permit training on this data.
- Voice and meeting audio — streams from your Mac straight to the speech and transcription providers while a session is active, authorized by a short-lived token. The audio never passes through Bloom's relay. Meeting capture includes other participants' speech.
- Connected services — read to prepare meeting briefs, described below.
Bloom's relay forwards and keeps nothing: no request or response bodies are logged, and nothing is cached.
Connected services
Bloom can read your calendar, email, files and workspace tools to prepare a pre-meeting brief. Before every brief, Bloom shows you a sheet naming exactly which sources it will read. Your Mac digests what it finds on-device into a short summary, and only that summary goes to the AI provider.
- Google Calendar, Gmail and Drive connect through a managed connection provider, which holds the credential — no Google token is stored on your Mac, and Bloom keeps only an opaque identifier. These requests route through Bloom's relay.
- Slack and Notion use tokens held in your Mac's Keychain; Bloom talks to those services directly.
Google user data
What Bloom does. Exactly four read operations, and nothing else is possible: list your calendar events; search Gmail for threads with a meeting's attendees; search Drive for documents relevant to that meeting; open one of those documents. Bloom never sends mail, never creates or edits calendar events, and never modifies or deletes files.
What Google asks you to grant is broader than that, and you should hear it here rather than discover it on the consent screen. Bloom currently connects through a managed connection provider whose shared Google app carries a fixed set of scopes — including full Gmail access and full Drive access. Bloom doesn't use them, but they're what the screen asks for. Google marks most of them optional, so you can decline them and Bloom will still work.
What keeps the gap closed. Two independent allowlists, at different layers, both limited to those four read operations. The connection provider will not execute any other tool even if asked, and Bloom's relay will not ask for one. So the ability to send mail or delete a file is not something Bloom holds and chooses not to use — it is refused twice, in systems that would each have to fail.
- Use — your calendar is read automatically to show upcoming events in the app; this is the one connector read that isn't triggered by a click, and nothing from it goes to an AI provider. Gmail and Drive are read only when you click Prepare on a meeting, to find threads and documents relevant to its attendees.
- Storage — there's no Bloom server holding this data. It stays on your Mac; only the on-device brief summary goes further.
- Sharing — Google user data reaches the managed connection provider that carries the request, and reaches our AI provider only inside that brief summary. It is never sold, never used for advertising, and never read by a human.
- Revoking — disconnect in Bloom's settings, which revokes the grant at Google and requests deletion from the connection provider, which retains its own record Bloom can't purge. You can also revoke in your Google security settings. Bloom's one-button reset revokes every connection and deletes everything held locally.
Bloom's use of information received from Google APIs adheres to theGoogle API Services User Data Policy, including the Limited Use requirements.
What never happens
- No Bloom database of your content — no profile, no documents, no transcripts on our servers.
- No analytics, no trackers, no cookies — in the app or on this site.
- Nothing goes to an AI provider in the background.