"通过 Apple 登录"与 iCloud(CloudKit)服务由 Apple 提供,其数据处理受 Apple 隐私政策 及 iCloud 条款与条件约束。Apple 仅向我们提供您的姓名与邮箱(通过 Apple 登录时),不包含其他数据。此外,社区功能使用 CloudKit 公共数据库托管您发布的帖子与回复;该部分内容的存储与传输由苹果按上述条款处理,开发者仅在处理举报、移除违规内容等社区审核需要时访问公共记录(见第 4.3 节)。
5.2 Google
"通过 Google 登录"的认证过程由 Google 处理。Google 会向我们提供您的姓名与邮箱地址,其余数据不发生传输。Google 的数据处理受 Google 隐私政策约束,其登录 SDK 的数据实践见 Google 身份服务数据披露。我们不会向 Google 发送您的健康数据。
Applies to the Bloom iOS app and its companion watchOS app (Bundle ID: com.gengguangyao.bloom)
Effective date: September 2, 2026 · Last updated: September 2, 2026
Our core promise: the health data you record in Bloom stays on your device — it is never uploaded to any server, including ours (we don't have one). Account information syncs only through your own iCloud private storage, which the developer cannot read. The one exception is the Sisters community: when you choose to publish a post or reply, that content is stored in Apple's CloudKit public database as described in Section 2.4 — your health data never travels with community content.
01Introduction
Bloom (the "App") is a personal health tracking app developed and operated by an independent developer (the "Developer", "we", "us"). We understand how intimate period and health information is, so the App is built on one foundational principle: your data belongs to you and stays on your device wherever possible.
This Privacy Policy explains what information the App collects, how it is used, where it is stored, and how you can access, manage, or delete it. By using the App, you agree to the practices described in this policy.
The App's core features (recording and viewing health data) do not require an account. Account information (Section 2.2) is only involved if you choose to create an account to enable sign-in across devices.
02Information We Collect
2.1 Health Data — stored on your device only
Health information you record in the App (period entries, symptoms, notes) is stored as local files on your device. This data:
is never uploaded to any server (we operate none);
is never linked to your account, advertising identifiers, or any third-party identifier;
is never used for advertising, analytics, or tracking of any kind.
2.2 Account Information — only if you create an account
If you choose to create an account (via Sign in with Apple, Sign in with Google, or email and password), we process:
Email address — used for registration, sign-in, and account identification;
Display name — taken from your Apple / Google profile, or entered by you at registration;
Password — stored only as a salted, one-way PBKDF2 hash; we cannot recover the plaintext;
Sign-in session identifier — used to restore your session on a new or reinstalled device.
Data type
Purpose
Where it is stored
Leaves your device?
Health records (periods, symptoms, notes)
Core app functionality
Device only
No
Email address
Account registration and sign-in
Device + your own iCloud private database*
Yes — synced to your own iCloud only
Display name
Personalized greeting
Device + your own iCloud private database*
Yes — synced to your own iCloud only
Password hash (PBKDF2)
Verifying your sign-in
Device + your own iCloud private database*
Yes — synced to your own iCloud only
Community posts & replies (nickname, text)
Sisters community (only when you publish)
Apple CloudKit public database (see 2.4 / 4.3)
Yes — published to other community users
Reports (reason + content snippet)
Community content moderation
Apple CloudKit public database (developer-readable)
Yes — only when you submit a report
* The iCloud private database (CloudKit Private Database) belongs to your own iCloud account. Only you can access it; the Developer cannot read it. See Section 4.2.
2.3 Information we do NOT collect
For clarity, the App does not collect or use:
advertising identifiers (IDFA) or any cross-app tracking identifier;
any analytics SDK, crash-reporting service, or third-party data-collection SDK*;
precise location, contacts, photos, or browsing history;
any profile linking your health data to your account.
* Apart from the Google Sign-In SDK required for the "Sign in with Google" feature, the App contains no third-party data-collection components. The Google Sign-In SDK ships with a privacy manifest (PrivacyInfo.xcprivacy) compliant with Apple's requirements.
2.4 Community content (Sisters community) — only when you publish
The App includes an optional "Sisters" community for peer support. If you never post or reply, this section does not apply to you. When you publish content, the following is stored via Apple's CloudKit public database and may be seen by other users who have the community feature enabled:
Community nickname (unrelated to your account or email; editable anytime in your profile) or the "Anonymous" label if you choose it;
the text you publish (post titles, bodies, and replies);
the post's category (e.g. "Encouragement", "Wins") and its timestamp;
a pseudonymous author identifier (creatorUserRecordID) that Apple's CloudKit attaches to every public record — a random token that cannot be mapped back to your real identity, used only for hug counts and the report/block features;
when you report content: the reason you selected and a snippet of the reported content (up to 200 characters), stored in a developer-reviewable report record.
Community content never includes: your email address, health data (periods, symptoms, temperature, nutrition logs), account information, or anything that could identify or contact you. Health data and community content are technically isolated and never linked.
Your control over community content: you can hide (block) any author on your device at any time; to delete a post or reply you have published, contact us via the email in Section 11 and we will process it within a few business days. Reported content, once verified, is removed from the public database by the developer.
03How We Use Information
We process the information above solely to:
provide the App's core functionality (locally recording and managing health data);
maintain your account and sign-in state after you register;
restore your sign-in state on a new or reinstalled device;
sync your posts and replies to the community when you publish, and show you public content from other users;
handle reports and blocks to keep the community safe (fulfilling our content-moderation obligations);
respond to inquiries or support requests you send us by email.
We do not use any of your information for targeted advertising, profiling, data mining, or sale to third parties.
04Data Storage & Security
4.1 Local storage
Both your health data and your account information exist as local copies on your device. Local data lives inside the app sandbox and is protected by iOS system-level data protection.
4.2 iCloud private database sync (optional)
If you are signed in to iCloud and have created a Bloom account, your account information (email, display name, password hash, session identifier) syncs across your devices via Apple's CloudKit private database, allowing you to restore your session on a new device. Specifically:
data in the private database resides in your own iCloud account space, protected by your iCloud credentials;
the Developer cannot access, read, or decrypt anything in your private database;
if you are not signed in to iCloud or sync is unavailable, the App runs in fully local mode with no impact on core functionality;
health data itself never syncs — even with sync enabled, only account information is synced.
4.3 Community content and the CloudKit public database
Community posts and replies you choose to publish are stored in Apple's CloudKit public database, hosted by Apple (see Section 5.1). Notably:
the public database is never linked to your email, health data, or account — it contains only the nickname and text you knowingly provide when posting, plus a system-generated pseudonymous author identifier;
posts marked "Anonymous" display no nickname at all;
the developer may access public records through the CloudKit Console solely to handle reports and remove content that violates community guidelines;
your block list and "reported" markers stay on your device and are never uploaded.
4.4 Password protection
Email passwords are stored only as one-way PBKDF2 hashes (with a random salt and multiple iterations). There is no way for us to view your plaintext password. If you forget it, the only option is to delete the account and register again.
05Third-Party Services
The App interacts with the following third-party services only as part of the sign-in flow:
5.1 Apple
Sign in with Apple and iCloud (CloudKit) are provided by Apple and governed by the Apple Privacy Policy and iCloud Terms and Conditions. When you use Sign in with Apple, Apple shares only your name and email with us. In addition, the community feature uses the CloudKit public database to host the posts and replies you publish; that content is stored and transmitted by Apple under the terms above, and the developer accesses public records only for community-moderation needs such as handling reports and removing violating content (see Section 4.3).
5.2 Google
The authentication flow for Sign in with Google is handled by Google. Google provides us with your name and email address; no other data is transmitted. Google's data practices are governed by the Google Privacy Policy, and its sign-in SDK disclosures are available at Google Identity data disclosure. We never send your health data to Google.
In short: the App contains no ad networks, analytics platforms, or data-broker SDKs. Third-party interaction is limited to the sign-in authentication itself.
06Data Sharing & Selling
We do not sell, rent, or trade any of your personal data, and we do not share data with third parties for advertising or tracking purposes. Your health data never leaves your device, so it cannot be shared; your account data exists only on your device and in your own iCloud private storage. Community posts and replies are content you chose to publish publicly and are visible only to other community users — beyond that, we share nothing with anyone.
We may be required to disclose information to the minimum extent necessary where legally mandated by law or lawful government process.
07Data Retention & Deletion
Health data — retained on your device until you delete the records in the App or uninstall the App (uninstalling erases all local data).
Account data — you can delete your account at any time inside the App (Profile → Account settings → Delete account). Deleting your account removes the account records from your iCloud private database; health data on the device is retained by default and is yours to delete.
Community content — posts and replies remain in the CloudKit public database until you request deletion. You can contact us anytime via the email in Section 11 to delete any post, reply, or report you have submitted; we process such requests within a few business days.
Blocks and reports — your block list and "reported" markers stay on your device and disappear when you uninstall the app or erase its data; reports you actively submit (reason + content snippet) are kept in the public database for review and deleted once handled.
Signing out — ends the session on the current device only, without affecting other devices.
Uninstalling the App — erases all local data (health data and the local account copy). Account records in the iCloud private database are removed via the "delete account" action; community content you have published is removed by request as described above.
Because your health data exists only on your device, we cannot — and never will — retain or back it up for you. Please manage your own device backups.
08Your Rights
Since your data lives on your own device and in your own iCloud account, you have complete, direct control over it. You have the right to:
Access — view all your health records and account information in the App at any time;
Correct — edit any record directly in the App;
Delete — delete individual records, delete your account, or uninstall the App to erase all local data;
Withdraw consent — deleting your account withdraws consent to processing of account data; without an account, this policy concerns only local data processing;
Complain or inquire — contact us using the details in Section 11.
09Children's Privacy
The App is not directed at children under 13, and we do not knowingly collect personal information from children. If you believe a child has provided us personal information without a guardian's consent, please notify us via the contact details in Section 11 and we will promptly delete it.
10Changes to This Policy
If this policy changes materially, we will update the "Last updated" date at the top of this page. Significant changes will be announced through in-app notices or other reasonable means. Continued use of the App after an update constitutes acceptance of the revised policy.