Privacy Policy
Last updated: August 26, 2026
Bloomary is operated by DailyMind LTD, a company registered in Cyprus under registration number HE 439959. This policy explains how we handle personal data when you use Bloomary at https://bloomary.life/.
DailyMind LTD is the data controller for personal data processed by Bloomary. Service providers listed below act as processors or independent providers depending on the feature.
1. Data We Collect
Content You Create
Draft posts are saved locally in your browser storage or iOS app storage. DailyMind LTD does not receive or store draft writing content on a server unless you choose to publish it to LinkedIn or send it to us as feedback.
LinkedIn Authorization Data
If you choose to connect LinkedIn, Bloomary processes your LinkedIn member ID, name, email address, profile picture URL, OAuth scope, connection time, and token expiry time. Access tokens are stored on your device where possible, including the iOS Keychain in the iOS app. The backend does not retain LinkedIn access tokens or raw OAuth payloads after completing authorization.
Temporary OAuth state and PKCE verifier values are stored only for completing the authorization flow.
LinkedIn processes the authorization request under LinkedIn's own terms and privacy policy. Bloomary is not affiliated with, endorsed by, or sponsored by LinkedIn.
Feedback
If you send feedback, Bloomary processes the title, message, attached images, and your LinkedIn name, member ID, and email address if you are connected. We use this data to receive your message at info@vigilcom.dev and send a confirmation copy to your email address.
Do not include passwords, payment data, client secrets, employer secrets, health data, or other sensitive personal data in feedback messages or screenshots.
Technical Data
The website is served through Cloudflare. Cloudflare may process standard technical logs such as IP address, user agent, request URL, timestamps, and security events for delivery, security, and performance.
The iOS app uses Sentry for crash, app hang, watchdog termination, and performance diagnostics. The iOS app also uses TelemetryDeck for privacy-first product analytics. TelemetryDeck events are anonymous funnel events and do not include your name, email address, LinkedIn member ID, post content, feedback text, or attached images.
2. How We Use Data
- To let you write, preview, save, reopen, and copy LinkedIn-ready drafts in your browser.
- To start and complete a LinkedIn OAuth authorization flow if you choose to connect LinkedIn.
- To show your connected LinkedIn identity in the app and send feedback confirmations to your email address.
- To receive and respond to feedback, bug reports, screenshots, and product ideas.
- To understand anonymous product funnel usage, such as app opens, editor starts, draft saves, LinkedIn connection events, posting success or failure, and feedback submission.
- To detect crashes, app hangs, watchdog terminations, performance problems, and reliability issues.
- To keep the site available, secure, and performant.
3. Legal Basis
- Contract performance — to provide the writing tool you choose to use.
- Consent — when you choose to start LinkedIn authorization or provide information voluntarily.
- Legitimate interest — for security, debugging, abuse prevention, and service reliability.
- Legal obligation — where we must keep or disclose information to comply with law.
4. Sharing
We do not sell personal data and do not use personal data for ad monetization. We share data only when necessary with:
- Cloudflare for hosting, CDN, and security.
- LinkedIn when you initiate LinkedIn authorization.
- Resend for sending feedback emails and confirmation emails.
- Sentry for iOS crash, hang, watchdog, performance, and reliability diagnostics.
- TelemetryDeck for anonymous iOS product analytics.
- Authorities or professional advisers if required for legal compliance, security, or dispute handling.
We do not use Bloomary data to track you across apps or websites owned by other companies for advertising, advertising measurement, or data broker purposes.
Where a service provider processes personal data for us, we rely on appropriate data processing terms, contractual safeguards, and provider security commitments. If personal data is transferred outside the EEA, we use legally available transfer mechanisms such as standard contractual clauses where required.
LinkedIn account connection data is required only if you choose to connect LinkedIn. Feedback contact data is required only if you choose to send feedback and want us to respond or send a confirmation.
5. Local Storage and Device Storage
Bloomary uses localStorage and sessionStorage in the browser and app storage on iOS. The iOS app stores LinkedIn token data in the iOS Keychain. You can delete local data by using app controls, disconnecting LinkedIn, clearing site data for platform.bloomary.life in your browser, or removing the app.
6. Retention
- Drafts remain on your device until you delete them or clear local storage.
- LinkedIn profile/auth metadata remains until you disconnect LinkedIn, the token expires, or the data is no longer needed to provide the service.
- When you disconnect LinkedIn, Bloomary deletes the matching backend LinkedIn auth/profile row and clears the local token where the app can do so.
- Feedback messages and attached images are kept for up to 12 months unless a longer period is needed for security, legal, or business record reasons.
- Sentry diagnostic events and TelemetryDeck analytics events are retained according to those providers' operational policies and our product reliability needs.
- Cloudflare logs are retained according to Cloudflare's operational policies.
7. Security
We use HTTPS, minimize server-side token storage, and store iOS access tokens in Keychain. Personal data may be accessible only to people who need it to operate, debug, secure, and support Bloomary. Browser storage is controlled by your browser and device. Do not use Bloomary on a shared device if you do not want drafts or tokens to remain available in that browser profile.
If we become aware of a personal data breach, we will investigate, mitigate it, and notify affected users or regulators where required by applicable law.
8. Your Rights
Under GDPR, you may have rights to access, rectify, erase, restrict, port, or object to processing of your personal data. You may also withdraw consent where processing is based on consent.
For data stored only on your device, DailyMind LTD cannot access it directly. You can remove it locally by clearing browser storage for platform.bloomary.life, deleting drafts in the app, disconnecting LinkedIn, or removing the iOS app.
You may request access, correction, deletion, restriction, portability, or objection by contacting us.
You may also have the right to lodge a complaint with a data protection supervisory authority.
9. Children
Bloomary is not directed to children under 16, and we do not knowingly collect personal data from children.
10. Changes
We may update this policy from time to time. The updated date above shows the current version.
11. Contact
DailyMind LTD
Registration number: HE 439959
VAT: CY10439959M
Email: info@dailymind.eu