Bloom
Privacy Policy · 隐私政策

Bloom 隐私政策

适用于 Bloom iOS 应用及其配套 watchOS 应用(Bundle ID:com.gengguangyao.bloom)
生效日期:2026 年 9 月 2 日 · 最后更新:2026 年 9 月 2 日

我们的核心承诺:您在 Bloom 中记录的健康数据只保存在您自己的设备上,绝不上传到任何服务器——包括我们的。我们也没有服务器。账户信息仅在您本人的 iCloud 私有空间内同步,开发者无法读取。唯一的例外是姐妹社区:当您主动发布帖子或回复时,该内容会按第 2.4 节所述存储于苹果 CloudKit 公共数据库——健康数据永远不会随社区内容一同上传。

01引言

Bloom(下称"本应用")是一款个人健康记录应用,由个人开发者(下称"开发者"、"我们")独立开发和运营。我们深知经期与健康信息的私密性,因此本应用在架构设计上遵循一条基本原则:您的数据归您所有,并尽可能留在您的设备上。

本隐私政策说明本应用收集哪些信息、如何使用这些信息、信息存储在哪里,以及您如何访问、管理或删除这些信息。使用本应用即表示您同意本政策所述的数据处理方式。

本应用的核心功能(记录与查看健康数据)无需注册账户即可使用。仅当您主动创建账户以启用多设备登录时,才会涉及第 2.2 节所述的账户信息。

02我们收集哪些信息

2.1 健康数据 —— 仅存储在您的设备上

您在应用中记录的经期、症状、备注等健康信息,全部以本地文件形式存储在您的设备上。这些数据:

  • 永不上传到任何服务器(我们没有任何服务器);
  • 不与您的账户、广告标识符或任何第三方标识关联;
  • 不用于广告、数据分析或任何形式的用户跟踪。

2.2 账户信息 —— 仅当您注册账户时

当您选择创建账户(通过"通过 Apple 登录"、"通过 Google 登录"或邮箱密码注册)时,我们会处理以下信息:

  • 电子邮箱地址:用于注册、登录及账户识别;
  • 显示名称:来自您 Apple / Google 账户中的姓名,或您注册时自行填写;
  • 密码:仅以 PBKDF2 单向哈希(含随机盐值)形式存储,我们无法还原明文;
  • 登录状态标识:用于在您更换或重装设备后恢复登录状态。
数据类型用途存储位置是否离开您的设备
健康记录(经期、症状、备注等) 提供应用核心功能 仅设备本地 否
电子邮箱地址 账户注册与登录 设备本地 + 您本人的 iCloud 私有数据库* 是,仅同步至您本人的 iCloud
显示名称 个性化问候 设备本地 + 您本人的 iCloud 私有数据库* 是,仅同步至您本人的 iCloud
密码哈希(PBKDF2) 验证您的登录 设备本地 + 您本人的 iCloud 私有数据库* 是,仅同步至您本人的 iCloud
社区帖子与回复(昵称、文字内容) 姐妹社区交流(仅当您主动发布) 苹果 CloudKit 公共数据库(见 2.4 / 4.3 节) 是,公开发布给其他社区用户
举报记录(原因 + 内容片段) 社区内容审核 苹果 CloudKit 公共数据库(开发者可读) 是,仅当您主动提交举报时

* iCloud 私有数据库(CloudKit Private Database)属于您本人的 iCloud 账户空间,仅您本人可访问,开发者无法读取。详见第 4.2 节。

2.3 我们不收集的信息

为清晰起见,本应用不收集或使用:

  • 广告标识符(IDFA)或任何跨应用追踪标识;
  • 任何分析 SDK、崩溃收集服务或第三方数据收集 SDK*;
  • 精确位置信息、通讯录、照片、浏览历史;
  • 您的健康数据与账户之间的关联档案。
* 除"通过 Google 登录"功能所必需的 Google 登录 SDK 外,本应用不含任何第三方数据收集组件。Google 登录 SDK 自带符合苹果要求的隐私清单(PrivacyInfo.xcprivacy)。

2.4 社区内容(姐妹社区)—— 仅当您主动发布时

应用内置可选的"姐妹社区",供用户交流与互助。若您从未发布帖子或回复,本节不适用于您。当您发布内容时,以下信息会通过苹果 CloudKit公共数据库存储,并可被其他开启社区功能的用户看到:

  • 社区昵称(与您的账户、邮箱无关联,可在个人资料页随时修改)或您选择的"匿名"标识;
  • 您主动发布的文字内容(帖子标题、正文与回复);
  • 帖子所属分类(如"鼓励""心得")与发布时间;
  • 苹果 CloudKit 为公共记录自动附加的匿名化作者标识(creatorUserRecordID)——一串无法直接对应到您真实身份的随机代号,仅用于"拥抱"计数与举报/屏蔽功能;
  • 当您举报某条内容时:举报原因及该内容的片段(最多 200 字符),存储于供开发者审核的记录中。

社区内容绝不包含:您的邮箱地址、健康数据(经期、症状、体温、饮食记录等)、账户信息,或任何可用于联系或识别您本人的信息。健康数据与社区内容在技术上完全隔离,互不关联。

您对社区内容的控制:您可以在设备上随时隐藏(屏蔽)任意作者;如需删除您已发布的帖子或回复,请通过第 11 节的邮箱联系我们,我们会在数个工作日内处理。被举报内容经核实后会由开发者从公共数据库中移除。

03信息的使用

我们处理上述信息的目的仅限于:

  • 提供应用的核心功能(本地记录与管理健康数据);
  • 在您注册后维护账户与登录状态;
  • 在您更换或重装设备后,帮您恢复登录状态;
  • 在您主动发布时,将您的帖子与回复同步至社区,并向您展示其他用户发布的公开内容;
  • 处理举报与屏蔽请求,以维护社区安全(依法履行内容审核义务);
  • 回复您通过邮件发来的咨询或支持请求。

我们不会将您的任何信息用于定向广告、用户画像、数据挖掘,或出售给任何第三方。

04数据的存储与安全

4.1 本地存储

您的健康数据与账户信息均在设备本地留有副本。本地数据随应用沙盒隔离,受 iOS 系统级数据保护机制保护。

4.2 iCloud 私有数据库同步(可选)

当您登录了 iCloud 且创建了 Bloom 账户时,账户信息(邮箱、显示名称、密码哈希、登录状态标识)会通过苹果的 CloudKit 私有数据库在您的设备之间同步,以便您在新设备上恢复登录。需要特别说明:

  • 私有数据库中的数据存储在您本人的 iCloud 账户空间内,受您的 iCloud 账户密码保护;
  • 开发者无法访问、读取或解密私有数据库中的任何数据;
  • 若您未登录 iCloud 或选择关闭同步,应用将以纯本地模式运行,核心功能不受任何影响;
  • 健康数据本身不参与 iCloud 同步——即使开启同步,也仅有账户信息会同步。

4.3 社区内容与 CloudKit 公共数据库

您主动发布的社区帖子与回复存储在苹果 CloudKit 公共数据库中,由苹果托管(详见第 5.1 节)。需要说明:

  • 公共数据库不与您的邮箱、健康数据或账户关联——它只包含您发布时主动提供的昵称与文字内容,以及系统生成的匿名化作者标识;
  • "匿名"发布的帖子仅显示"Anonymous",不展示昵称;
  • 开发者可能通过 CloudKit 管理控制台访问公共记录内容,仅用于处理举报、移除违规内容等社区审核目的;
  • 屏蔽名单与"已举报"标记仅保存在您的设备本地,不上传。

4.4 密码保护

邮箱密码采用 PBKDF2 算法(配合随机盐值与多轮迭代)进行单向哈希后存储。我们没有任何途径查看您的密码明文。若忘记密码,只能删除账户后重新注册。

05第三方服务

本应用仅在与登录相关的环节与以下第三方服务交互:

5.1 Apple

"通过 Apple 登录"与 iCloud(CloudKit)服务由 Apple 提供,其数据处理受 Apple 隐私政策 及 iCloud 条款与条件约束。Apple 仅向我们提供您的姓名与邮箱(通过 Apple 登录时),不包含其他数据。此外,社区功能使用 CloudKit 公共数据库托管您发布的帖子与回复;该部分内容的存储与传输由苹果按上述条款处理,开发者仅在处理举报、移除违规内容等社区审核需要时访问公共记录(见第 4.3 节)。

5.2 Google

"通过 Google 登录"的认证过程由 Google 处理。Google 会向我们提供您的姓名与邮箱地址,其余数据不发生传输。Google 的数据处理受 Google 隐私政策约束,其登录 SDK 的数据实践见 Google 身份服务数据披露。我们不会向 Google 发送您的健康数据。

小结:本应用不包含广告网络、分析平台或数据经纪类 SDK。与第三方的交互仅限登录认证本身。

06数据的共享与出售

我们不出售、不出租、不交易您的任何个人数据,也不出于广告或跟踪目的与任何第三方共享数据。您的健康数据从未离开您的设备,因此无从共享;账户数据仅存在于您的设备与您本人的 iCloud 私有空间中。社区帖子与回复属于您主动选择公开发布的内容,仅面向其他社区用户可见——除此之外,我们不向任何第三方共享任何信息。

在法律法规要求或政府主管部门依法定程序强制要求的范围内,我们可能需要依法配合,但以最低必要为限。

07数据的保留与删除

  • 健康数据:保留在设备本地,直至您在应用内手动删除相应记录,或卸载应用(卸载即清除全部本地数据)。
  • 账户数据:您可以随时在应用内删除账户(个人资料页 → 账户设置 → 删除账户)。删除账户会移除您 iCloud 私有数据库中的账户记录;设备上的健康数据默认保留,您可自行决定是否删除。
  • 社区内容:帖子与回复保存在 CloudKit 公共数据库中,直至您请求删除。您可随时通过第 11 节的邮箱联系我们,删除您发布的任何帖子、回复或举报记录,我们会在数个工作日内处理。
  • 屏蔽与举报:屏蔽名单与"已举报"标记仅保存在设备本地,卸载应用或清除数据即消失;您主动提交的举报(原因 + 内容片段)保存在公共数据库中供审核,处理完毕后删除。
  • 退出登录:仅结束当前设备的登录状态,不影响其他设备。
  • 卸载应用:清除设备上的所有本地数据(健康数据与账户本地副本)。iCloud 私有数据库中的账户记录需通过"删除账户"操作移除;您已发布的社区内容需按上文方式请求删除。

由于健康数据仅存在于您的设备上,我们无法、也不会替您保留或备份这些数据——请自行留意设备备份。

08您的权利

由于您的数据保存在您自己的设备与您本人的 iCloud 账户中,您对数据拥有完全、直接的控制权。您有权:

  • 访问:随时在应用内查看您的全部健康记录与账户信息;
  • 更正:直接在应用内编辑任何记录;
  • 删除:删除单条记录、删除账户,或卸载应用以清除全部本地数据;
  • 撤回同意:删除账户即视为撤回对账户数据处理的同意;不注册账户则本政策仅涉及本地数据处理;
  • 投诉与咨询:通过第 11 节的联系方式向我们提出。

09儿童隐私

本应用不面向 13 周岁以下的儿童,我们不会在知情的情况下收集儿童的个人信息。如您认为有儿童未经监护人同意向我们提供了个人信息,请通过第 11 节的联系方式告知我们,我们将及时删除相关数据。

10政策的更新

若本政策发生实质变更,我们会更新本页面顶部的"最后更新"日期。重大变更将通过应用内提示或其他合理方式通知您。在本政策更新后继续使用本应用,即表示您接受更新后的政策。

联系我们

对本政策或本应用的数据处理有任何疑问、建议或请求,请发送邮件至:

1992gengguangyao@gmail.com

我们通常会在数个工作日内回复。

Privacy Policy

Bloom Privacy Policy

Applies to the Bloom iOS app and its companion watchOS app (Bundle ID: com.gengguangyao.bloom)
Effective date: September 2, 2026 · Last updated: September 2, 2026

Our core promise: the health data you record in Bloom stays on your device — it is never uploaded to any server, including ours (we don't have one). Account information syncs only through your own iCloud private storage, which the developer cannot read. The one exception is the Sisters community: when you choose to publish a post or reply, that content is stored in Apple's CloudKit public database as described in Section 2.4 — your health data never travels with community content.

01Introduction

Bloom (the "App") is a personal health tracking app developed and operated by an independent developer (the "Developer", "we", "us"). We understand how intimate period and health information is, so the App is built on one foundational principle: your data belongs to you and stays on your device wherever possible.

This Privacy Policy explains what information the App collects, how it is used, where it is stored, and how you can access, manage, or delete it. By using the App, you agree to the practices described in this policy.

The App's core features (recording and viewing health data) do not require an account. Account information (Section 2.2) is only involved if you choose to create an account to enable sign-in across devices.

02Information We Collect

2.1 Health Data — stored on your device only

Health information you record in the App (period entries, symptoms, notes) is stored as local files on your device. This data:

  • is never uploaded to any server (we operate none);
  • is never linked to your account, advertising identifiers, or any third-party identifier;
  • is never used for advertising, analytics, or tracking of any kind.

2.2 Account Information — only if you create an account

If you choose to create an account (via Sign in with Apple, Sign in with Google, or email and password), we process:

  • Email address — used for registration, sign-in, and account identification;
  • Display name — taken from your Apple / Google profile, or entered by you at registration;
  • Password — stored only as a salted, one-way PBKDF2 hash; we cannot recover the plaintext;
  • Sign-in session identifier — used to restore your session on a new or reinstalled device.
Data typePurposeWhere it is storedLeaves your device?
Health records (periods, symptoms, notes) Core app functionality Device only No
Email address Account registration and sign-in Device + your own iCloud private database* Yes — synced to your own iCloud only
Display name Personalized greeting Device + your own iCloud private database* Yes — synced to your own iCloud only
Password hash (PBKDF2) Verifying your sign-in Device + your own iCloud private database* Yes — synced to your own iCloud only
Community posts & replies (nickname, text) Sisters community (only when you publish) Apple CloudKit public database (see 2.4 / 4.3) Yes — published to other community users
Reports (reason + content snippet) Community content moderation Apple CloudKit public database (developer-readable) Yes — only when you submit a report

* The iCloud private database (CloudKit Private Database) belongs to your own iCloud account. Only you can access it; the Developer cannot read it. See Section 4.2.

2.3 Information we do NOT collect

For clarity, the App does not collect or use:

  • advertising identifiers (IDFA) or any cross-app tracking identifier;
  • any analytics SDK, crash-reporting service, or third-party data-collection SDK*;
  • precise location, contacts, photos, or browsing history;
  • any profile linking your health data to your account.
* Apart from the Google Sign-In SDK required for the "Sign in with Google" feature, the App contains no third-party data-collection components. The Google Sign-In SDK ships with a privacy manifest (PrivacyInfo.xcprivacy) compliant with Apple's requirements.

2.4 Community content (Sisters community) — only when you publish

The App includes an optional "Sisters" community for peer support. If you never post or reply, this section does not apply to you. When you publish content, the following is stored via Apple's CloudKit public database and may be seen by other users who have the community feature enabled:

  • Community nickname (unrelated to your account or email; editable anytime in your profile) or the "Anonymous" label if you choose it;
  • the text you publish (post titles, bodies, and replies);
  • the post's category (e.g. "Encouragement", "Wins") and its timestamp;
  • a pseudonymous author identifier (creatorUserRecordID) that Apple's CloudKit attaches to every public record — a random token that cannot be mapped back to your real identity, used only for hug counts and the report/block features;
  • when you report content: the reason you selected and a snippet of the reported content (up to 200 characters), stored in a developer-reviewable report record.

Community content never includes: your email address, health data (periods, symptoms, temperature, nutrition logs), account information, or anything that could identify or contact you. Health data and community content are technically isolated and never linked.

Your control over community content: you can hide (block) any author on your device at any time; to delete a post or reply you have published, contact us via the email in Section 11 and we will process it within a few business days. Reported content, once verified, is removed from the public database by the developer.

03How We Use Information

We process the information above solely to:

  • provide the App's core functionality (locally recording and managing health data);
  • maintain your account and sign-in state after you register;
  • restore your sign-in state on a new or reinstalled device;
  • sync your posts and replies to the community when you publish, and show you public content from other users;
  • handle reports and blocks to keep the community safe (fulfilling our content-moderation obligations);
  • respond to inquiries or support requests you send us by email.

We do not use any of your information for targeted advertising, profiling, data mining, or sale to third parties.

04Data Storage & Security

4.1 Local storage

Both your health data and your account information exist as local copies on your device. Local data lives inside the app sandbox and is protected by iOS system-level data protection.

4.2 iCloud private database sync (optional)

If you are signed in to iCloud and have created a Bloom account, your account information (email, display name, password hash, session identifier) syncs across your devices via Apple's CloudKit private database, allowing you to restore your session on a new device. Specifically:

  • data in the private database resides in your own iCloud account space, protected by your iCloud credentials;
  • the Developer cannot access, read, or decrypt anything in your private database;
  • if you are not signed in to iCloud or sync is unavailable, the App runs in fully local mode with no impact on core functionality;
  • health data itself never syncs — even with sync enabled, only account information is synced.

4.3 Community content and the CloudKit public database

Community posts and replies you choose to publish are stored in Apple's CloudKit public database, hosted by Apple (see Section 5.1). Notably:

  • the public database is never linked to your email, health data, or account — it contains only the nickname and text you knowingly provide when posting, plus a system-generated pseudonymous author identifier;
  • posts marked "Anonymous" display no nickname at all;
  • the developer may access public records through the CloudKit Console solely to handle reports and remove content that violates community guidelines;
  • your block list and "reported" markers stay on your device and are never uploaded.

4.4 Password protection

Email passwords are stored only as one-way PBKDF2 hashes (with a random salt and multiple iterations). There is no way for us to view your plaintext password. If you forget it, the only option is to delete the account and register again.

05Third-Party Services

The App interacts with the following third-party services only as part of the sign-in flow:

5.1 Apple

Sign in with Apple and iCloud (CloudKit) are provided by Apple and governed by the Apple Privacy Policy and iCloud Terms and Conditions. When you use Sign in with Apple, Apple shares only your name and email with us. In addition, the community feature uses the CloudKit public database to host the posts and replies you publish; that content is stored and transmitted by Apple under the terms above, and the developer accesses public records only for community-moderation needs such as handling reports and removing violating content (see Section 4.3).

5.2 Google

The authentication flow for Sign in with Google is handled by Google. Google provides us with your name and email address; no other data is transmitted. Google's data practices are governed by the Google Privacy Policy, and its sign-in SDK disclosures are available at Google Identity data disclosure. We never send your health data to Google.

In short: the App contains no ad networks, analytics platforms, or data-broker SDKs. Third-party interaction is limited to the sign-in authentication itself.

06Data Sharing & Selling

We do not sell, rent, or trade any of your personal data, and we do not share data with third parties for advertising or tracking purposes. Your health data never leaves your device, so it cannot be shared; your account data exists only on your device and in your own iCloud private storage. Community posts and replies are content you chose to publish publicly and are visible only to other community users — beyond that, we share nothing with anyone.

We may be required to disclose information to the minimum extent necessary where legally mandated by law or lawful government process.

07Data Retention & Deletion

  • Health data — retained on your device until you delete the records in the App or uninstall the App (uninstalling erases all local data).
  • Account data — you can delete your account at any time inside the App (Profile → Account settings → Delete account). Deleting your account removes the account records from your iCloud private database; health data on the device is retained by default and is yours to delete.
  • Community content — posts and replies remain in the CloudKit public database until you request deletion. You can contact us anytime via the email in Section 11 to delete any post, reply, or report you have submitted; we process such requests within a few business days.
  • Blocks and reports — your block list and "reported" markers stay on your device and disappear when you uninstall the app or erase its data; reports you actively submit (reason + content snippet) are kept in the public database for review and deleted once handled.
  • Signing out — ends the session on the current device only, without affecting other devices.
  • Uninstalling the App — erases all local data (health data and the local account copy). Account records in the iCloud private database are removed via the "delete account" action; community content you have published is removed by request as described above.

Because your health data exists only on your device, we cannot — and never will — retain or back it up for you. Please manage your own device backups.

08Your Rights

Since your data lives on your own device and in your own iCloud account, you have complete, direct control over it. You have the right to:

  • Access — view all your health records and account information in the App at any time;
  • Correct — edit any record directly in the App;
  • Delete — delete individual records, delete your account, or uninstall the App to erase all local data;
  • Withdraw consent — deleting your account withdraws consent to processing of account data; without an account, this policy concerns only local data processing;
  • Complain or inquire — contact us using the details in Section 11.

09Children's Privacy

The App is not directed at children under 13, and we do not knowingly collect personal information from children. If you believe a child has provided us personal information without a guardian's consent, please notify us via the contact details in Section 11 and we will promptly delete it.

10Changes to This Policy

If this policy changes materially, we will update the "Last updated" date at the top of this page. Significant changes will be announced through in-app notices or other reasonable means. Continued use of the App after an update constitutes acceptance of the revised policy.