Privacy Policy — BloomReads
Effective date: 3 September 2026
Last updated: 3 September 2026
Replaces: the version of 28 August 2026
BloomReads ("the app") is made by its developer ("we", "us"). This policy explains what the app does with information, and what it does not do.
The short version. Your library lives on your phone and we have no server that holds it. We collect anonymous statistics about how the app is used. The app records the screens you move through during setup and the guided tour, which means things you type there can appear in a recording we can watch (section 3). The app also measures which advertisement brought you to it, and asks your permission before doing so (section 5). If you write to us in the support chat, that message reaches us (section 6). Photographs you take of your own books are saved on your phone and never sent to us (section 8).
1. What changed in this version
Three things changed on 3 September 2026. All three are corrections to this page rather than changes to the app: nothing about what BloomReads does changed on this date, only what this page says about it.
- Photographs of your own books are now described (sections 2, 8 and 11). The app has always let you photograph the spine, edge or cover of a book you own, or pick a picture for it from your photo library, and keep that image on your shelf. The previous version of this page said, under Camera, that no photo is ever taken or saved. That was wrong. Photographs are taken, they are saved on your device, and they travel inside a backup file if you export one. What has never happened, and still does not, is any of them reaching us.
- The statistics section claimed more than the app collects (sections 4, 8 and 10). It described screens opened, buttons tapped, reading sessions started and finished, the size of your library, barcode scans and reminders opened. Measurement was narrowed to setup and the guided tour before that version was published, and none of those things has left your device since. Claiming more collection than happens is still an inaccurate privacy policy, so the list is now cut back to what the app actually sends.
- Your streak, and a short profile of your installation, are now named (sections 2, 4 and 7). A handful of figures — the length of your current streak, how many days you have opened the app, which session number you are on, when you installed it, whether you finished setup, whether you have a subscription — are kept against your installation's record and reach Amplitude, and most of them Superwall. Section 2 listed the streak among the things that never leave the phone. The number does leave, and it is now described where it belongs.
The version of 28 August 2026 made two corrections:
- Approximate location is now named (section 4). It was always happening and was never described. Our analytics provider works out a country, region and city from the internet address your device connects from. The app does not use your iPhone's location services and has never asked for location permission — but a country worked out this way is still information about you, so it belongs on this page under its own name.
- The app no longer asks for your first name (sections 3, 4 and 11). The field was removed from setup, and nothing sends a name anywhere. The previous version of this page still described it as an optional question. Those passages are gone rather than reworded, because the question itself is gone.
And the version of 25 August 2026 made four. All of them are kept here so the record of what changed is not lost:
- Advertising measurement was added (section 5). The previous policy said this app does not track you and does not ask for tracking permission. That is no longer true. The app now asks for permission through Apple's App Tracking Transparency prompt, and — only if you allow it — reads Apple's advertising identifier so we can tell which advertisement brought you here. The previous wording is corrected rather than quietly deleted, because it said the opposite of what the app now does.
- The support chat is described (section 6). It existed before and was not mentioned. What you type into it reaches us.
- Screen recording is narrower than we said (section 3). The previous policy said every session is recorded. That is no longer the case: recording now runs only during setup and the guided tour, and stops when they end. The rest of your time in the app is not recorded.
- Two more processors are named (section 7): Singular, which handles the advertising measurement, and Supabase, which hosts the support chat.
2. What stays on your device
All of the following is stored only on your iPhone. There is no account, no sign-in, and no server of ours that holds any of it:
- The books in your library — titles, authors, covers, page counts, ISBNs
- Photographs you take of a book you own — its spine, its edge or its cover — and any picture you choose from your photo library for a book (see section 8)
- Your reading sessions, including dates, durations and pages read
- Your notes, ratings and collections
- Your daily goal, reading challenge and reminder times
- The name you give your library, and how you have decorated the shelf
- Your theme, app icon and other settings
- Your Screen Time app selection (see section 9)
One exception, so the list above is not misleading. The length of your current streak leaves your device as a number, on your installation's record — see section 4. The reading behind it does not: no session, no book, no page count and no date goes with it.
The only way the rest of this leaves your device as data — your books, your sessions, your notes and the photographs you took of your own copies — is if you export a backup file and share it yourself. We never receive that file. (A screen recording is a different matter, and is covered in the next section.)
If you import your library from Goodreads, you choose the export file yourself and it is read on your device only. The file is not uploaded, and we never see it or anything in it.
The Home Screen widget reads a small snapshot file that the app writes on your device. The widget makes no network connections of any kind.
If you delete the app, all of it is deleted with it. You can also erase your library, sessions, collections and reminders at any time from Profile → Erase all data.
3. Screen recording
To find out where people get stuck, the app records the screens you move through and sends the recording to our analytics provider, Amplitude. We watch these to fix things that do not work.
Being specific about it:
- When it records. Only during two stretches: setting the app up for the first time, and the guided tour that points out where things are. Recording starts when one of those begins and stops when it ends. Ordinary use of the app — your library, your reading sessions, your notes, your statistics — is not recorded.
- How much is recorded. In App Store and TestFlight builds, every run of those two stretches is recorded. There is no sampling at present.
- What is hidden automatically. Passwords, email addresses, card numbers and telephone numbers are always masked by the recorder and never appear. Text you type into a field during setup — including the name you give your library — is also masked.
- What is not hidden. Everything else that is on screen during those two stretches. That includes the covers and titles of any books shown during the tour, the first book you add during setup, and a photograph of your own copy if the shelf on screen is showing one. If you can see it, a recording of that moment can show it.
- What is never recorded. Anything you do outside this app. The recorder captures this app's own screens and nothing else — not other apps, not the Home Screen, not anything you type elsewhere.
- What it is tied to. The same random installation identifier as our other statistics (section 4). It is not tied to your name or your Apple Account.
- What it is not used for. Recordings are used to improve the app. They are not sold, not shared with advertisers, and not used to build a profile of you.
If you would rather not be recorded, the app has no separate switch for it: deleting the app stops all recording and all statistics. We would rather say that than imply a control that does not exist. If you want a recording associated with your installation deleted, write to us at the address in section 18 and we will delete what we can identify.
4. The statistics we collect
Alongside the recordings, we collect anonymous usage events so we can count what the recordings only show one case of:
- Product interaction, during setup and the guided tour only — how far you get through setup, which step you left on, whether you added a first book, whether you set reminders, and the same for the guided tour that follows. When those two are over the app stops sending this. The screens you open, the buttons you tap, the books you add and the reading sessions you run afterwards are recorded nowhere but your own phone.
- Diagnostics — when an operation fails during those same two stretches, and why. An error that happens later is dealt with on your phone and reported nowhere
- Subscription events — whether a subscription screen appeared, whether a purchase, trial or restore succeeded, which plan was bought, and its price and currency
- Device and app context — app version, build, iOS version, device model, language, time zone
- Approximate location — the country, region and city that our analytics provider works out from the internet address your device connects from. This is not read from your iPhone: the app does not use location services and never asks for location permission. It is worked out from the connection itself, the way it is for any website you visit. We use it to know which countries our readers are in, and which countries an advertisement actually reached. It is not a street address, cannot locate you within a city, and is never used to build a profile of you or shown to anyone else.
This data is attached to a random identifier generated by the app on first launch and stored on your device. It identifies an installation, not a person. That identifier is neither Apple's Identifier for Vendors (IDFV) nor the Identifier for Advertisers (IDFA); it is a value the app makes up for itself. The separate question of the advertising identifier is dealt with in section 5.
These events carry no content. Where a statistic needs to know whether you typed something, the app records how long what you typed was, or simply that a field was filled in — never the characters themselves. A search sends us the length of your query and how many results came back; it does not send the query.
Your installation's profile. Separately from the events above, a short list of figures is kept against your installation's record and updated when it changes. This is the one measurement that continues after setup and the tour are over, and it is here because section 2 would otherwise be wrong:
- the length of your current reading streak, as a number — never the sessions, books, pages or dates behind it;
- how many days you have opened the app, and which session number you are on;
- the day, week and month you installed it, and how long ago that was;
- whether you finished setup, and whether you currently have a subscription;
- your answer to the tracking prompt in section 5;
- the device and app context listed above.
All of it goes to Amplitude. Six of these figures — your streak, the days you have been active, your session number, the week you installed, how long ago that was, and whether you finished setup — also go to Superwall, where they decide which subscription offer you are shown. Both are attached to the same random installation identifier and to nothing else.
Your setup answers. Separately again, the answers you give while setting the app up leave your device and go to our subscription provider, Superwall, which uses them to decide which subscription offer to show you and to write it in your own terms — the name you gave your library in the headline, for example. Those answers are:
- how many books you read a year, and the totals the app works out from that;
- how many hours you say you spend on your phone, and how many minutes a day you want to read;
- the name you gave your library, and the theme, backdrop, material and ornament you chose for it;
- whether you added a first book and what status you gave it — not which book;
- whether you turned reading reminders on.
None of these answers is published, sold, or used to identify you.
5. Advertising measurement, and the permission we ask for
This section replaces a passage in the previous policy that said the opposite. That version said the app did not read the advertising identifier, did not track you, and did not ask for tracking permission. Since advertising measurement was added, none of those three statements is correct, and the honest thing is to say so plainly rather than edit them out.
What we do. We advertise the app. To know whether an advertisement was worth running, we need to be able to tell that an install, and a later subscription, came from a particular advertisement. Our attribution provider, Singular, does that measurement for us.
The permission. Shortly after you first open the app, iOS shows Apple's App Tracking Transparency prompt, asking whether the app may track you across apps and websites owned by other companies. Your answer decides what follows:
- If you allow it, the app may read Apple's Identifier for Advertisers (IDFA) and pass it to Singular, which uses it to match your install to an advertisement you saw in another app. Under Apple's definition, this is tracking, and it is why the prompt is shown.
- If you decline, no advertising identifier is read and none is sent. iOS additionally blocks the app from contacting Singular's servers, and we have declared Singular's domains to Apple so that this blocking works as intended.
You can change your answer at any time in the iPhone Settings app, under Privacy & Security → Tracking.
What is measured either way. Separately from the prompt, Apple operates its own privacy-preserving measurement system, SKAdNetwork. Apple's servers — not your phone — send our advertising partners an anonymous, aggregated report saying that an install or a purchase happened. It contains no identifier for you and we cannot connect it to a person. This works whether or not you allowed tracking, because Apple designed it to.
What is never sent for advertising. Nothing about your library, your reading, your notes, your goals or your setup answers is sent to Singular or to any advertising partner. What travels is that an install happened, that a subscription or trial began, and the identifiers described above.
We do not sell personal information, and we do not share it with data brokers. Some privacy laws, California's among them, use the word share broadly enough to cover what is described above — handing an advertising identifier to a measurement partner. To be exact rather than reassuring: that is the only sharing that happens, it happens only if you allowed the tracking prompt, and turning this app off under Privacy & Security → Tracking stops it.
6. The support chat
The app has a support chat, reachable from Home and from Profile. It is the one place in the app where words you write leave your phone.
- What is sent. The message you type, and — attached to it — your app version, iOS version, device model and language. Nothing about your library travels with it: not a title, not an author, not a note. You choose every word that goes.
- Where it goes. To a database we run on Supabase, and to us. It is not passed to any other processor.
- How a conversation is identified. By a random device identifier and a secret, both created on your phone the first time you write to us and kept in the iPhone Keychain. We store only a hash of the secret, so the copy on your phone is the only one that exists — which is what stops anyone else reading your thread. There is no account and no name attached.
- Why it survives a reinstall. That identifier is deliberately kept in the Keychain, which normally outlives deleting and reinstalling the app, so that somebody who reinstalls to fix the very problem they wrote in about comes back to their conversation rather than to a blank one. It is used for nothing else, and it never leaves your device except to name your thread.
- How long it is kept. Until you ask us to delete it, or until we close and clear the conversation. To have a thread deleted, write to the address in section 18 from the app, or tell us roughly when you wrote and what about.
7. Who else receives data
We use a small number of processors. Each receives only what it needs.
| Service | What it receives | Why | Their policy |
|---|---|---|---|
| Amplitude | The anonymous usage events in section 4 and the screen recordings in section 3 | Product analytics and session replay | amplitude.com/privacy |
| Superwall | Subscription screen views, purchase, trial and restore events, the setup answers in section 4, and part of the installation profile in section 4 — your streak, days active, session number, install week and whether you finished setup | Runs the subscription screens and remembers whether you are subscribed | superwall.com/privacy |
| Singular | That an install, trial or subscription happened; and, only if you allowed tracking, Apple's advertising identifier | Measures which advertisement brought you to the app | singular.net/privacy-policy |
| Supabase | The support messages you write and the app, iOS, device and language strings that ride with them (section 6) | Hosts the database behind the support chat | supabase.com/privacy |
| Apple | Your purchase; and, when you search for a book, that search term and your store region | Apple processes all payments — we never see your payment details — and its iTunes Search API is one of the book catalogues | apple.com/legal/privacy |
| Open Library (Internet Archive) | The title, author or barcode you are searching for | Book details and cover art | archive.org/about/terms |
| Google Books | The title, author or barcode you are searching for | Book details and cover art | policies.google.com/privacy |
| NeoDB | The title, author or barcode you are searching for | Book details and cover art | neodb.social |
How book searches work. The four catalogues are asked at the same time rather than one after another, and whichever answers first is what you see. So a single search sends your search term to all four. Each receives that one term and nothing else: no identifier of yours, no part of your existing library, and no account, because the app has none. Apple's catalogue is additionally told your store region, so that a reader in Spain is offered the Spanish edition. The catalogues are contacted only when you actively search, scan or add a book, and when a cover image is fetched.
8. Camera and photographs
The camera is used for two different things, and the app asks for camera permission the first time you reach either one.
Scanning a barcode. You can add a book by scanning the barcode on its back cover.
- The camera feed is used to read the barcode and nothing else. It is processed live on your device.
- No photo is taken or kept by the scanner. What it produces is a number — the ISBN — which is sent to the book catalogues in section 7 to look the book up.
Photographing your own copy. You can also photograph the spine, the edge or the cover of a book you own, so that the shelf shows your copy rather than a stock jacket. You can choose a picture from your photo library for the same purpose instead.
- A photograph is taken, and it is saved. It is straightened, scaled down to the size the shelf draws it at, and stored on your device alongside the book.
- It is never sent to us. There is no upload and no server of ours holds a copy. It leaves your device only inside a backup file that you export and share yourself — or if it happens to be on screen during setup or the guided tour, which is what section 3 is about.
- When you choose from your photo library, the app uses Apple's picker, which hands over the one picture you picked. The app cannot see the rest of your photos and never asks for access to them.
- You can remove a photograph at any time from the book's own page, and deleting the app deletes every one of them.
Camera permission is optional for both. You can still add books by searching or by typing them in, a book without a photograph simply shows its catalogue cover, and you can withdraw the permission at any time in the iPhone Settings app.
9. Screen Time and app blocking
If you turn on app blocking, the app asks for Screen Time (Family Controls) permission so it can hold back the apps you choose while you are reading.
This is handled entirely by Apple's own system:
- You pick the apps in Apple's picker, not ours.
- What we receive back are opaque tokens. The app never learns which apps you chose, which apps you have installed, or how long you spend in any of them.
- The selection is stored on your device only. It is never sent to us or to anyone else.
- It is used for one thing: applying a shield while a reading session is running, and lifting it when the session ends.
Screen Time permission is optional. Everything else in the app works without it, and you can withdraw it at any time in the iPhone Settings app.
10. Notifications
If you allow notifications, reminders are scheduled on your device by iOS. We do not operate a push server and cannot send you anything remotely. Whether you turned reminders on during setup, and the times you picked there, are part of the setup answers in section 4. After setup, nothing about your reminders is sent anywhere at all — not that one was scheduled, not that one was delivered, not that one was opened, and never its contents.
11. What we deliberately do not collect
- Your library, as data. No book title, author, ISBN, note, rating or search query is ever sent to us as an event or a record, and neither is any photograph you took of a book. We hold no copy of your library and could not reconstruct it. The one exception is what a screen recording happens to show during setup or the tour, which is why section 3 exists.
- Your identity. No email address, phone number, contacts, and no location from your iPhone — the app does not use location services and has never asked for location permission. (The approximate country and city worked out from your internet address are a different thing, and are described in section 4.) The app does not ask your name. The only things you tell us about yourself are whatever you choose to write in the support chat, and the name you give your library — which is yours to invent. We never receive a photograph either: the pictures you take or choose for your books stay on your device (section 8).
- Your reading, for advertising. Nothing about what or how you read is ever sent to an advertising partner. See section 5.
12. Children
BloomReads is not directed at children under 13, and we do not knowingly collect information from them. There is no account, no profile and no way to communicate with anyone else through the app apart from writing to us. If you believe a child has provided us with information, contact us and we will delete it.
13. How long we keep things
Anonymous usage events, screen recordings and attribution records are retained by our providers for as long as the product needs them, and are deleted on request. Support conversations are kept until deleted, as described in section 6. Everything else lives on your device for as long as you keep the app.
14. Your rights
Depending on where you live, you may have the right to access, correct, delete or export your personal information, to object to or restrict processing, to opt out of the sale or sharing of personal information, and to lodge a complaint with a supervisory authority.
Because the app has no account, our records are tied to a random installation identifier rather than to you, so in most cases we have no way to connect a request to a specific person. In practice:
- To delete everything on your device: Profile → Erase all data, or delete the app. Note that Erase all data clears your library, sessions, collections and reminders; it does not reach statistics or recordings already sent.
- To stop any further data being sent, including recordings: delete the app. A later reinstall starts a new identifier that is not connected to the old one.
- To stop advertising measurement without deleting the app: turn this app off under iPhone Settings → Privacy & Security → Tracking.
- To have an analytics record, a recording or an attribution record deleted: email us at the address below with whatever you can tell us about the installation and roughly when you used the app, and we will delete what we can identify.
- To have a support conversation deleted: email us, ideally from the same device, and say roughly when you wrote.
Our legal basis for processing under the GDPR is our legitimate interest in understanding how the app is used and in keeping it working, your consent where the App Tracking Transparency prompt has been allowed, and the performance of our contract with you for the subscription itself.
15. Security
Data in transit is encrypted with HTTPS. Data on your device is protected by iOS's own file protection. The support chat's secret is held in the iPhone Keychain and never leaves the device. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
16. International transfers
Our providers, including Amplitude, Superwall, Singular and Supabase, process data in the United States. Where required, transfers rely on the European Commission's Standard Contractual Clauses.
17. Changes
If we change this policy we will update the date at the top and, for anything significant, tell you in the app.
18. Contact
Questions, requests or complaints:
Email: abeto.studio@gmail.com