Privacy Policy
The short version
- Everything you log lives in an encrypted database on your iPhone. We don’t have a copy. We can’t have a copy.
- No account, no cloud, no tracking. The app makes no network calls of its own — the only network activity is Apple’s own subscription system.
- Data leaves your phone only when you share it — a doctor report or an export, through the iOS share sheet, to a destination you pick.
- Erasing your data is final. There’s no cloud copy to restore from — and that’s the point.
What Bloomkind stores — on your device
Bloomkind keeps what you give it, and nothing else:
- Symptom entries — the symptom, its severity, the time, and any note you add.
- Mood check-ins — a 1–5 rating, the time, and any note.
- HRT and supplement logs — name, dose, schedule, start and end dates, notes.
- Cycle and sleep data — dates and flow you log yourself, plus anything you choose to import from Apple Health.
- App settings — things like your reminder preference and quick-log button layout. Settings never contain health data.
All health data lives in a database inside the app’s private container, protected with Apple’s strongest file-protection class — it’s encrypted on disk and readable only while your iPhone is unlocked.
What Bloomkind never does
- No account, no sign-in, no user identifier. There is nothing to sign up for, so there is nothing to leak.
- No server, no upload path. The app contains no code that can send your health data anywhere. The only network activity possible is Apple’s own StoreKit machinery that processes subscriptions.
- No third-party SDKs, no ads, no trackers. Bloomkind is built with first-party Apple frameworks only.
- No cloud sync. This version has zero sync. If sync ever ships, it will be opt-in and end-to-end encrypted — and this policy will be updated first.
Usage statistics: off by default, and local-only
Bloomkind has an optional usage-statistics toggle in Settings. It is off by default. If you turn it on, the app records bare event names with timestamps (for example, report_generated) — no parameters, no content, and nothing from your health data. These events are stored in a file on your device, you can view and clear them in Settings at any time, and they are never uploaded anywhere. They exist so you can see which features you use — not so we can.
Apple Health
Connecting Apple Health is optional and read-only. Bloomkind asks for access only when you tap to connect, and it reads just two things: menstrual flow and sleep, to enrich your charts. The app works fully if you decline.
Imported data lands in the same encrypted on-device store, labeled as coming from Health, and you can remove all of it in one tap (Settings → Remove imported Health data). Bloomkind never writes anything to Apple Health.
The only ways data leaves your phone
Both are actions you take yourself:
- Doctor report (PDF) — generated on your device and handed to the iOS share sheet. You choose where it goes; the app never uploads it.
- Data export (JSON) — a complete export of everything you’ve logged, through the same share sheet, under the same rules.
There is no third path.
Erasing your data
Settings → Erase everything deletes all of your entries from the on-device store and clears the local usage-statistics log. Because no cloud copy exists, erasure is genuinely final.
Subscriptions
Bloomkind Pro is billed by Apple through your Apple account. Apple handles the payment — we never see your payment details, and buying Pro creates no account with us. Pro unlocks features, never data collection.
Changes to this policy
If Bloomkind’s privacy behavior ever changes, this policy and its effective date will be updated before the change ships. The promise above — on-device, no account, nothing leaves without you — is the product, not a version note.
Contact
Questions about privacy? Email bookbondar@gmail.com.
Bloomkind is made by OB Data LLC. It is a symptom-tracking and education tool — it does not diagnose, treat, or provide medical advice.