Your student's story is yours. We do not sell family data, build advertising profiles from it, or use it to train AI models — and the parts of this page that sound like promises are enforced in the product, not in a slogan.
1. The promises, and what keeps them
| Promise | What keeps it |
|---|---|
| No selling, no ad profiles, no AI training on family data | There are no advertising or analytics scripts anywhere on this site — our tests refuse to let a public page ship any script at all — and the usage records behind AI features count requests without storing their content. |
| Honesty about the limits | Bloom is not a zero-knowledge service. Our systems must read your data to show your plan, run a feature, support the account, export it, or delete it. We say so rather than implying otherwise. |
| Each household lives in its own database | One database per family, not one shared table with a family column in it. |
| Export and deletion never need an active plan | Neither gesture is behind the paywall — today or in ten years. Both are offered on the expired-plan screen itself. |
| If Bloom ever ends, you get out with everything | Our Terms promise at least 90 days' notice, free export through that whole window, a 12-month archive, then deletion — and family data is never sold as an asset. That clause is hash-checked by a test, so it cannot be quietly edited away. |
| The parent and student wall runs both ways | A student's journal and Rewind are the student's. A parent sees counts and progress, never the words, and a parent's export of those private records is refused. |
| Fair use is stated, not hidden | 400 AI requests per family per day, published on the pricing page and in the Terms, and enforced as written. |
2. What we collect
These are the categories a family's account can hold. Which ones actually fill up depends on the features you use:
- Profile — names, contact details, city and state, citizenship status, optional demographics, grade level and graduation year. No date of birth: Bloom does not collect one anywhere.
- Academics — transcripts and term records (grades 9–12 on the planning grid; grades 5–8 kept only as historical rows), test scores, course plans, school history.
- Applications and essays — the college list, deadlines, checklists, essays with their full version history, recommendations, scholarships.
- Household financial planning — parent-entered income, household size, and the asset details the federal aid formula counts. Blank means “not told,” never zero, and the aid index is calculated rather than stored. A student's own export masks every one of these fields.
- Conversations and AI memory — Ask Bloom threads, plus the short durable conclusions Bloom draws about the journey. Where the surface is student-private, so are they.
- Documents — files the family uploads, such as transcripts, score reports, and aid letters. What Bloom reads out of a document is a proposal: it stays inert until someone presses Apply.
- Calendars — school and family events. A personal calendar you connect is imported busy-only: we keep the time and drop the event's title at the moment it arrives.
- Voice — dictation is transcribed and discarded on our own machine; it is never stored. The one exception is a meeting recording: a family — or their counselor, once that family has given the separate recording consent — may upload the audio of a counseling meeting so it can be turned into a transcript. That transcription runs on our own server and is never sent to an AI vendor. The audio is deleted a week after the transcript is ready; the transcript stays readable by the family and is deleted with the student. Read-aloud and dictation keep no recording at all.
- Feedback — the text you send is scrubbed of personal details before it is stored. A screenshot cannot be scrubbed, so an attached one is kept exactly as you sent it; the form says so and asks you to crop first.
3. Where it lives
One database per family on a managed database cluster, and uploaded files under a namespace belonging to that family alone — so a leaked key cannot even name another family's file. Backups run daily with roughly a week of point-in-time recovery, and practising a restore is part of how we run the service.
4. Who sees what
Students and parents. Journal, Rewind, and each person's own chats belong to the person who wrote them. Parents see counts and progress, not transcripts. A student who has claimed their own login can turn on privacy mode for essay drafts — and only that student can turn it off again, because a switch a parent can flip is not privacy.
Counselors. Access is granted per student by the family and versioned, so a consent can only narrow, never silently widen. One money fence closes every financial surface to a counselor — including the AI's view of it. A counselor cannot export a student, and counselor notes stay parent-only in the export. Revoking access ends live counselor sessions immediately rather than at the next sign-in.
The family can watch us. A household-readable access log records who looked at what: a parent sees the household's rows, a student sees the rows about themselves, and a counselor is refused. The log is deliberately content-light — no payloads, no IP addresses.
5. AI processing
The app itself holds no AI provider credentials; every model call travels through a gateway Bloom operates.
Before anything reaches a model, a sanitizer removes what is never sent: names, email addresses, dates of birth, government identifiers, exact income, street address and city, phone numbers. Income becomes a bracket; location becomes a state. The same scrub runs over the model's answer on the way back.
What the model gateway is told about who is asking is a random identifier for the household — no name, no email. The usage ledger behind the scenes records counts and status codes, never content, and a response body survives no longer than a 24-hour cache used to avoid double-charging a repeated request.
Two lanes are zero-retention by construction. Document extraction is encrypted end to end with modern public-key encryption, so no intermediary between your upload and the extractor ever sees the page in plaintext — and neither the bytes nor the text are logged or cached. Voice recognition runs on our own machine and never leaves it; there is no cloud lane for it at all.
Cloud AI requests travel through an AI request gateway to leading AI models: one for chat, essay coaching, and research, and a hosted voice for read-aloud. The default tier is served by a small model running locally.
Provider-side Zero Data Retention is on. As of August 19, 2026, our account routes requests only to provider endpoints that do not store them, and we verified the routing live. One honest caveat: that guarantee does not cover plugins, and our web-research feature uses a web-search tool that sits outside it — so the search query path is not covered.
6. The companies that help run Bloom
| Provider | Job | What it receives |
|---|---|---|
| Our cloud infrastructure provider | Hosting: servers, managed databases, file storage, backups | All hosted data, at rest on managed infrastructure |
| An AI request gateway | Routing AI requests to the model provider | Sanitized prompts and completions (section 5); a random household identifier for attribution |
| Stripe | Subscription billing | Buyer email, plan, and account identifiers; no student records; card numbers never touch Bloom |
| Our email delivery service | Account and notification email | The recipient's address and the message sent |
| Sign-in | The sign-in token's claims: account identifier, email, whether the email is verified | |
| An edge security service | The human-check on the public Ask Bloom page | That page's interaction |
| College Scorecard (ed.gov) | Public college data | Nothing about your student ever leaves with the request |
| On our own machine | Speech recognition, read-aloud fallback, and the local default model | Never leaves our server, and not a third party at all |
The complete, named list of our service providers is available to any family or reviewer on request — the names are kept off this page to avoid advertising our internals, not to hide who we work with.
Integrations a family points at its own services — your calendar feed, your notes app — talk to the service you chose, with the credentials you gave.
7. Retention and deletion
Canceling stops the renewal; it does not erase the records, so a family has time to export before closing the account. There is no scheduled deletion of family content — the household decides, and both gestures are free and unpaywalled, permanently:
- Take everything. A whole-family archive: every student's records, every uploaded file, and a manifest that lists what was withheld and why. Per-student exports are available as JSON, CSV, or PDF.
- Delete everything. A verified erasure in four steps — stop serving the family, purge the file namespace and check it is gone, drop the family database, and remove the routing records last. A failure at any step is reported as a failure, never as success.
- Per-child delete and per-child reset also exist, each behind a typed-name confirmation.
The operational data that does expire on a clock: job-execution history after 30 days, abandoned signup reservations after 7 days, and the AI request cache after 24 hours.
If Bloom itself winds down, the clause in our Terms applies: notice, a free export window, an archive, then deletion — and no sale of family data as an asset.
8. Security measures
A separate database per family; file storage namespaced per family; sessions that can be revoked in bulk, so one action invalidates every outstanding sign-in for an account; cross-site request forgery protection on every form and background request; end-to-end sealed document extraction; salted, keyed PIN hashing with throttling on share links; busy-only calendar import; signup rate limiting that counts attempts without storing the address alongside the account it creates; a firewall that exposes only the ports the service needs; and managed backups with practised restores.
No online service can promise perfect security, and we do not.
9. Children under 13
Accounts are created by parents, the product serves grades 9–12, and a child under 13 may not independently create or manage a household. A student login exists only after a parent sends the invite. The full picture is on our children's privacy page.
10. A safety floor for minors
Every finished AI answer passes a fixed, rule-based screen — not another model. When it matches signs of distress, Bloom appends the 988 Suicide & Crisis Lifeline details to the answer; it never blocks, refuses, or rewrites what the student was told. A crisis line is also permanently visible in the product, not conditional on anything. When that screen fires, the record we keep stores which rule matched, never the student's words.
11. What this page does not claim
No SOC 2 report, no COPPA safe-harbor seal, no FERPA “certification” — the last of which does not exist as a thing to hold. Bloom does not claim any certification it has not earned. When a third-party attestation is earned, it will be listed here with its scope, and not one day before.
See also our Privacy Policy, Terms of Service, and Data & Disclaimers.