Bloom legal
Privacy Policy
Bloom is built so this page can stay short. Your family's records live in a database on your own computer — not on our servers — so most of what a privacy policy usually has to explain simply doesn't apply. What follows is the complete, specific list of what does and doesn't reach us.
The short version
- Your student's records stay home. Grades, essays, activities, journal entries, chat history, and documents are stored in a database on your family's computer. We do not have a copy.
- AI requests pass through us, scrubbed first. Names, contact details, and other direct identifiers are stripped on your computer before any text is sent for AI drafting. We relay it and keep a count of calls — never the content.
- We store very little: usage counts, billing status (through Stripe), consent receipts, feedback you explicitly send, and encrypted share snapshots we cannot read.
- Parents are in control. The software runs on your hardware, under your account, and you can delete all of it at any time.
The details below are written to match how the software actually works, not the other way around.
01Who we are
Who we are
Bloom is made by Taspara Solutions LLC ("we", "us"). Bloom is a self-hosted college-guidance application: the app itself runs on your family's computer, and we operate a small central service that supplies it with configuration, reference data, updates, and a few relays described below. Questions about this policy go to [email protected].
02Data locality
Your family's data lives on your computer, not our servers
When you install Bloom, it sets up its own database on your computer. Everything your family puts into Bloom — the student's grades, test scores, school records like attendance and discipline notes, essays and drafts, activities, college lists, journal entries, chat conversations, uploaded documents, and any financial details you enter — is stored in that local database. That database is not published to the internet; it is reachable only by the Bloom app running on the same computer.
Bloom also makes a nightly backup of that database. Backups are written to a folder on the same computer and older backups are deleted after 14 days by default. Backups are never uploaded to us.
Because of this design, we cannot browse, sell, mine, or lose your student's records: we never hold them. The rest of this policy is the specific list of what our central service does see.
03The data ledger
Exactly what goes where
Every piece of data Bloom touches falls into one of three lanes.
Stays on your computer
Stored only in your local database. We have no copy.
- The student's profile: grades, GPA, test scores, activities, awards
- School records you enter for the On Track guide, like attendance and discipline notes
- Essays, drafts, and the moments journal
- Chat and coaching conversation history
- Uploaded documents (transcripts, score reports)
- Family financial details you enter
- College lists, deadlines, application progress
- Nightly database backups (deleted locally after 14 days)
Passes through, never stored
Transits our relay to do its job, then is gone. Our logs record sizes, timing, and success — not content.
- AI request text — scrubbed of direct identifiers on your computer first, relayed in memory to the AI provider, and returned. We keep a per-call count, the model name, and the response length; never the words. (See section 04.)
- Document scans sent for heavier conversion — sealed end-to-end with encryption keys only your app and our conversion service hold, converted in memory, returned encrypted, and not retained. Filenames travel inside the encrypted payload.
Stored on our server
The complete list of what we keep, and why.
- Your install's key and its activity metadata — a label for your install (for example, a family name you chose), when it last checked in, and how many requests it has made. This is how we know your Bloom is healthy and entitled to updates.
- AI usage records — one row per AI call: which model, the token cap, the response length as a character count, and whether it succeeded. Used for fair daily limits. No prompt or response text is stored.
- Consent receipts — when someone in your family accepts the in-app terms, we store the name and email they typed, their role, the document version and its full text, and a timestamp. These are append-only evidence of agreement.
- Feedback reports you explicitly send — see section 06.
- Encrypted share snapshots — ciphertext only; we cannot decrypt it. See section 05.
- Billing records — Stripe customer and subscription identifiers and status. See section 07.
- Email reminder requests — if your family turns on email reminders, we relay a fixed template to the address you chose. The request can carry only a template name and small counts (for example, "3 deadlines"); the API rejects free text by design.
Configuration and reference data (college data files, settings) flow the other way — from us to your install — and contain nothing about your family.
04AI features
AI features, third-party processing, and PII scrubbing
Bloom's drafting and coaching features use large language models. Your install does not talk to AI companies directly; it sends requests through our relay, and we route them to an AI provider — either a model we operate or a third-party cloud model. That means AI request text is processed by a third-party AI provider under that provider's terms.
Before any text leaves your computer for an AI request, Bloom's sanitizer strips direct identifiers:
- Names and email addresses are removed
- Phone numbers, dates of birth, and government ID patterns are removed
- Exact family income is replaced with a broad bracket
- Your city is replaced with your state
- Citizenship details are reduced to a general category
Be aware of the honest limit of scrubbing: the material the student is actively working on — an essay draft, a chat question — is the point of the request, so that text does go to the AI provider (with the identifiers above stripped). If a student types identifying details into the body of an essay, those travel with it. AI responses are scrubbed again on the way back as a safety net.
Each family's install has a daily cap on AI calls, enforced by our relay. We keep per-call usage records (model, sizes, success) but never the content of prompts or responses.
05Counselor sharing
Counselor sharing is end-to-end encrypted
When a student shares progress with a counselor, their Bloom encrypts a snapshot on the family's computer and pushes only the ciphertext to us. The decryption key travels in the share link itself (in the URL fragment, which browsers do not send to servers), so the counselor's browser decrypts the snapshot locally. Optionally a PIN is folded into the key.
We store the ciphertext and cannot read it. Shares expire, are capped in number and size, and the student can revoke any share with one click, which deletes the ciphertext.
06Feedback
Feedback you choose to send us
If someone in your family presses "Send feedback" in the app, that report does come to us — it is the one moment where content from your install reaches our server, and it happens only on that explicit action. A report can include:
- The message you typed (up to 4,000 characters)
- An optional screenshot (PNG or JPEG, up to 2 MB, verified by content)
- An excerpt of the app's technical log, plus the page, app version, and browser info
The message and log excerpt are scrubbed of emails, phone numbers, and ID patterns on your computer before sending, and scrubbed again on our server. A screenshot shows whatever was on the screen — review it before sending. Reports are rate-limited and used only to fix problems and improve Bloom.
07Billing
Billing runs through Stripe
If your install is on a paid subscription, payment is handled by Stripe, Inc. Your card number goes to Stripe and never touches our servers. We store the identifiers Stripe gives us — a customer ID, a subscription ID, your plan, and its status (active, past due, canceled) — so your install knows it is entitled. Stripe processes your payment details under Stripe's privacy policy.
08Cookies
Cookies and tracking
The Bloom app on your computer sets a session cookie so you stay signed in to your own install; it is marked HTTP-only and never leaves your browser's conversation with the app on your machine. Stripe's checkout and billing pages set their own cookies under Stripe's policy.
This website sets no analytics or advertising cookies, loads no third-party scripts, fonts, or trackers, and keeps no marketing profiles. What you read here stays between you and your browser.
09Children
Children's data and parental control
Bloom is used by high-school students, who are usually minors, and that shaped its architecture. Bloom is licensed to a parent or legal guardian, who installs and operates the software on the family's own computer. The student's records are collected and stored by that family-run installation — under the parent's control, on the parent's hardware — not gathered by us into accounts on our servers. We do not build profiles of children, and the limited server-side data described in section 03 is keyed to the family's install, not to a child.
Parents can review what the app stores, delete individual records in the app, or delete the entire installation and its data at any time (section 10). If you believe our server holds something it shouldn't, contact us at [email protected] and we will investigate and delete it where required.
10Retention & deletion
Data retention and deletion
On your computer
Your local data is yours for as long as you keep it. You can delete individual records in the app, and removing Bloom's installation (its Docker containers and volumes) permanently deletes the database and its local backups. Backups age out on their own after 14 days.
On our server
- Feedback reports and screenshots — kept while useful for fixing the issue; deleted on request.
- AI usage records and operational logs — kept for operating limits, billing fairness, and troubleshooting.
- Consent receipts — retained as append-only evidence that the terms were accepted; this is their purpose.
- Billing records — retained as long as needed for accounting and legal obligations.
- Encrypted share snapshots — deleted when revoked, and unreadable to us at all times.
To ask us to delete what we hold about your install, email [email protected].
11Security
Security
Traffic between your install and our service is encrypted in transit, and every request is authenticated with a per-family key that we store only in hashed form. The most sensitive payloads — counselor shares and document conversions — are additionally end-to-end encrypted so that even our own server (and anything in front of it) sees only ciphertext. Uploads such as feedback screenshots are validated by content, size-capped, and rate-limited. Our operational logs are deliberately content-free.
No system is perfectly secure, but Bloom's first line of defense is architectural: the data that matters most never leaves your house.
12Changes & contact
Changes to this policy, and how to reach us
If we change this policy, we will update this page and its "Last updated" date. If a change means more data would reach our servers, the app will ask for fresh consent before that change applies to your install — consent receipts exist precisely so that what you agreed to is on the record.
Questions, concerns, or deletion requests: [email protected].