Privacy Policy — BloomReads

Effective date: 3 September 2026
Last updated: 3 September 2026
Replaces: the version of 28 August 2026

BloomReads ("the app") is made by its developer ("we", "us"). This policy explains what the app does with information, and what it does not do.

The short version. Your library lives on your phone and we have no server that holds it. We collect anonymous statistics about how the app is used. The app records the screens you move through during setup and the guided tour, which means things you type there can appear in a recording we can watch (section 3). The app also measures which advertisement brought you to it, and asks your permission before doing so (section 5). If you write to us in the support chat, that message reaches us (section 6). Photographs you take of your own books are saved on your phone and never sent to us (section 8).


1. What changed in this version

Three things changed on 3 September 2026. All three are corrections to this page rather than changes to the app: nothing about what BloomReads does changed on this date, only what this page says about it.

The version of 28 August 2026 made two corrections:

And the version of 25 August 2026 made four. All of them are kept here so the record of what changed is not lost:

2. What stays on your device

All of the following is stored only on your iPhone. There is no account, no sign-in, and no server of ours that holds any of it:

One exception, so the list above is not misleading. The length of your current streak leaves your device as a number, on your installation's record — see section 4. The reading behind it does not: no session, no book, no page count and no date goes with it.

The only way the rest of this leaves your device as data — your books, your sessions, your notes and the photographs you took of your own copies — is if you export a backup file and share it yourself. We never receive that file. (A screen recording is a different matter, and is covered in the next section.)

If you import your library from Goodreads, you choose the export file yourself and it is read on your device only. The file is not uploaded, and we never see it or anything in it.

The Home Screen widget reads a small snapshot file that the app writes on your device. The widget makes no network connections of any kind.

If you delete the app, all of it is deleted with it. You can also erase your library, sessions, collections and reminders at any time from Profile → Erase all data.

3. Screen recording

To find out where people get stuck, the app records the screens you move through and sends the recording to our analytics provider, Amplitude. We watch these to fix things that do not work.

Being specific about it:

If you would rather not be recorded, the app has no separate switch for it: deleting the app stops all recording and all statistics. We would rather say that than imply a control that does not exist. If you want a recording associated with your installation deleted, write to us at the address in section 18 and we will delete what we can identify.

4. The statistics we collect

Alongside the recordings, we collect anonymous usage events so we can count what the recordings only show one case of:

This data is attached to a random identifier generated by the app on first launch and stored on your device. It identifies an installation, not a person. That identifier is neither Apple's Identifier for Vendors (IDFV) nor the Identifier for Advertisers (IDFA); it is a value the app makes up for itself. The separate question of the advertising identifier is dealt with in section 5.

These events carry no content. Where a statistic needs to know whether you typed something, the app records how long what you typed was, or simply that a field was filled in — never the characters themselves. A search sends us the length of your query and how many results came back; it does not send the query.

Your installation's profile. Separately from the events above, a short list of figures is kept against your installation's record and updated when it changes. This is the one measurement that continues after setup and the tour are over, and it is here because section 2 would otherwise be wrong:

All of it goes to Amplitude. Six of these figures — your streak, the days you have been active, your session number, the week you installed, how long ago that was, and whether you finished setup — also go to Superwall, where they decide which subscription offer you are shown. Both are attached to the same random installation identifier and to nothing else.

Your setup answers. Separately again, the answers you give while setting the app up leave your device and go to our subscription provider, Superwall, which uses them to decide which subscription offer to show you and to write it in your own terms — the name you gave your library in the headline, for example. Those answers are:

None of these answers is published, sold, or used to identify you.

5. Advertising measurement, and the permission we ask for

This section replaces a passage in the previous policy that said the opposite. That version said the app did not read the advertising identifier, did not track you, and did not ask for tracking permission. Since advertising measurement was added, none of those three statements is correct, and the honest thing is to say so plainly rather than edit them out.

What we do. We advertise the app. To know whether an advertisement was worth running, we need to be able to tell that an install, and a later subscription, came from a particular advertisement. Our attribution provider, Singular, does that measurement for us.

The permission. Shortly after you first open the app, iOS shows Apple's App Tracking Transparency prompt, asking whether the app may track you across apps and websites owned by other companies. Your answer decides what follows:

You can change your answer at any time in the iPhone Settings app, under Privacy & Security → Tracking.

What is measured either way. Separately from the prompt, Apple operates its own privacy-preserving measurement system, SKAdNetwork. Apple's servers — not your phone — send our advertising partners an anonymous, aggregated report saying that an install or a purchase happened. It contains no identifier for you and we cannot connect it to a person. This works whether or not you allowed tracking, because Apple designed it to.

What is never sent for advertising. Nothing about your library, your reading, your notes, your goals or your setup answers is sent to Singular or to any advertising partner. What travels is that an install happened, that a subscription or trial began, and the identifiers described above.

We do not sell personal information, and we do not share it with data brokers. Some privacy laws, California's among them, use the word share broadly enough to cover what is described above — handing an advertising identifier to a measurement partner. To be exact rather than reassuring: that is the only sharing that happens, it happens only if you allowed the tracking prompt, and turning this app off under Privacy & Security → Tracking stops it.

6. The support chat

The app has a support chat, reachable from Home and from Profile. It is the one place in the app where words you write leave your phone.

7. Who else receives data

We use a small number of processors. Each receives only what it needs.

Service What it receives Why Their policy
Amplitude The anonymous usage events in section 4 and the screen recordings in section 3 Product analytics and session replay amplitude.com/privacy
Superwall Subscription screen views, purchase, trial and restore events, the setup answers in section 4, and part of the installation profile in section 4 — your streak, days active, session number, install week and whether you finished setup Runs the subscription screens and remembers whether you are subscribed superwall.com/privacy
Singular That an install, trial or subscription happened; and, only if you allowed tracking, Apple's advertising identifier Measures which advertisement brought you to the app singular.net/privacy-policy
Supabase The support messages you write and the app, iOS, device and language strings that ride with them (section 6) Hosts the database behind the support chat supabase.com/privacy
Apple Your purchase; and, when you search for a book, that search term and your store region Apple processes all payments — we never see your payment details — and its iTunes Search API is one of the book catalogues apple.com/legal/privacy
Open Library (Internet Archive) The title, author or barcode you are searching for Book details and cover art archive.org/about/terms
Google Books The title, author or barcode you are searching for Book details and cover art policies.google.com/privacy
NeoDB The title, author or barcode you are searching for Book details and cover art neodb.social

How book searches work. The four catalogues are asked at the same time rather than one after another, and whichever answers first is what you see. So a single search sends your search term to all four. Each receives that one term and nothing else: no identifier of yours, no part of your existing library, and no account, because the app has none. Apple's catalogue is additionally told your store region, so that a reader in Spain is offered the Spanish edition. The catalogues are contacted only when you actively search, scan or add a book, and when a cover image is fetched.

8. Camera and photographs

The camera is used for two different things, and the app asks for camera permission the first time you reach either one.

Scanning a barcode. You can add a book by scanning the barcode on its back cover.

Photographing your own copy. You can also photograph the spine, the edge or the cover of a book you own, so that the shelf shows your copy rather than a stock jacket. You can choose a picture from your photo library for the same purpose instead.

Camera permission is optional for both. You can still add books by searching or by typing them in, a book without a photograph simply shows its catalogue cover, and you can withdraw the permission at any time in the iPhone Settings app.

9. Screen Time and app blocking

If you turn on app blocking, the app asks for Screen Time (Family Controls) permission so it can hold back the apps you choose while you are reading.

This is handled entirely by Apple's own system:

Screen Time permission is optional. Everything else in the app works without it, and you can withdraw it at any time in the iPhone Settings app.

10. Notifications

If you allow notifications, reminders are scheduled on your device by iOS. We do not operate a push server and cannot send you anything remotely. Whether you turned reminders on during setup, and the times you picked there, are part of the setup answers in section 4. After setup, nothing about your reminders is sent anywhere at all — not that one was scheduled, not that one was delivered, not that one was opened, and never its contents.

11. What we deliberately do not collect

12. Children

BloomReads is not directed at children under 13, and we do not knowingly collect information from them. There is no account, no profile and no way to communicate with anyone else through the app apart from writing to us. If you believe a child has provided us with information, contact us and we will delete it.

13. How long we keep things

Anonymous usage events, screen recordings and attribution records are retained by our providers for as long as the product needs them, and are deleted on request. Support conversations are kept until deleted, as described in section 6. Everything else lives on your device for as long as you keep the app.

14. Your rights

Depending on where you live, you may have the right to access, correct, delete or export your personal information, to object to or restrict processing, to opt out of the sale or sharing of personal information, and to lodge a complaint with a supervisory authority.

Because the app has no account, our records are tied to a random installation identifier rather than to you, so in most cases we have no way to connect a request to a specific person. In practice:

Our legal basis for processing under the GDPR is our legitimate interest in understanding how the app is used and in keeping it working, your consent where the App Tracking Transparency prompt has been allowed, and the performance of our contract with you for the subscription itself.

15. Security

Data in transit is encrypted with HTTPS. Data on your device is protected by iOS's own file protection. The support chat's secret is held in the iPhone Keychain and never leaves the device. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

16. International transfers

Our providers, including Amplitude, Superwall, Singular and Supabase, process data in the United States. Where required, transfers rely on the European Commission's Standard Contractual Clauses.

17. Changes

If we change this policy we will update the date at the top and, for anything significant, tell you in the app.

18. Contact

Questions, requests or complaints:

Email: abeto.studio@gmail.com