Platform
Privacy Policy
How Bloosh collects, uses, discloses, and processes personal information across its platforms and services.
Last updated on 1 October 2026
#Overview
This Privacy Policy describes how Bloosh Limited (“Bloosh,” “we,” “our” or “us”) collects, uses, discloses, and otherwise processes information in connection with a customer’s or user’s use of or access to our websites (“Sites”), platforms, applications, services, and solutions (collectively, “Services”), including bloosh.ai (marketing, account and billing) and app.bloosh.ai (the product), or any other disclosure by an individual of information to Bloosh through other means (for example, through email).
When you access or use our Services or otherwise provide information to Bloosh, we process your information in accordance with this Privacy Policy. By using any of our Services or otherwise providing information to Bloosh, you acknowledge that you have read, understood, and agree to this Privacy Policy and our Terms of Service.
We recommend that you read this Privacy Policy in full to ensure you are fully informed. If you have any questions about this Privacy Policy or our privacy practices, please contact us at [email protected].
#Scope of This Privacy Policy
This Privacy Policy applies to personal data that Bloosh processes as a controller. It does not apply to the extent Bloosh processes personal data solely as a processor or service provider on behalf of its customers.
“Customer Data” means data processed by Bloosh on behalf of a customer in connection with that customer’s use of the Services, including tasks, calendar events, chats and AI prompts, uploaded documents, connected email and calendar data, connected WhatsApp or other third-party integrations you enable, and the organisation’s workspace data (including its relationship graph). Each customer acts as the controller of such data and is responsible for the collection, use, and disclosure of its Customer Data. If your organisation administers seats for you, that organisation’s policies also apply.
Where we provide an account directly to you, Bloosh is the controller of your account data, billing data, and the technical data we collect to operate the Sites and Services.
#1. Information We Collect, Purposes, and Legal Bases
We collect information you provide directly to us when you, for example:
- interact with Bloosh through our Sites;
- register for an account;
- use the product (chat, tasks, calendar, documents, automations);
- connect email, calendar, or messaging accounts;
- request customer support; or
- otherwise communicate with us.
We may combine this information with information collected automatically or obtained from other lawful sources.
Our legal basis for collecting and using personal data depends on the context and the type of information involved. We generally rely on one or more of the following:
- Contractual necessity (GDPR Article 6(1)(b)), such as providing Services pursuant to our Terms;
- Legitimate interests (GDPR Article 6(1)(f)), such as operating, improving, and securing our Services, provided those interests are not overridden by your rights;
- Consent (GDPR Article 6(1)(a)), where required by law, including optional connections; or
- Legal obligation (GDPR Article 6(1)(c)).
For transparency, the table below sets out the information we collect, the purposes, and the legal bases for such processing.
| Information We Collect | Purpose for Processing | Legal Basis for Processing |
|---|---|---|
Account Registration When you create an account, we may collect contact and identity information, including your name, email address, password (hashed by our authentication provider), profile fields you provide (for example job role or bio), organisation and workspace details, and authentication identifiers from Google Sign-In if you use it. | To create, administer, and manage your account, authenticate you, isolate workspaces, and provide the Services. | GDPR Article 6(1)(b) — performance of a contract. |
Payment Information We collect information related to Services you purchase, including subscription status, plan, renewal dates, and Stripe customer and subscription identifiers. Payment card details are processed directly by Stripe; Bloosh does not store full payment card numbers. | To manage accounts, process transactions, invoices, trials, and provide paid Services. | GDPR Article 6(1)(b) — performance of a contract. GDPR Article 6(1)(f) — legitimate interests in operating billing and preventing payment abuse, provided such interests are not overridden by your fundamental rights and freedoms. |
Communications If you contact us, we may collect your name, contact details, message contents, any attachments, and any other information you choose to provide. | To respond to inquiries, provide support, and communicate with you about the Services. | GDPR Article 6(1)(f) — legitimate interest in customer communications, provided such interests are not overridden by your fundamental rights and freedoms. |
Workspace Content (Customer Data) We process the content you and your organisation put into the Services, including tasks, calendar events, chats and messages with the assistant, contacts and relationship-graph data derived from your content, uploaded documents and extracted text or metadata, assistant configuration (for example name and persona), automations, and settings you choose. | To provide and operate the Services you signed up for. To run the assistant and related features (indexing, recall, drafting, day planning) by sending relevant excerpts to model providers as described in section 7. To maintain a private relational graph for your organisation. | GDPR Article 6(1)(b) — performance of a contract, where we provide the account directly. Where an organisation administers your workspace, we typically process this content as a processor on that organisation’s instructions. |
Connected Services If you link a third-party account, we may collect OAuth tokens (stored encrypted in a secrets vault), mailbox metadata and message content we ingest, calendar event data we sync, WhatsApp message content you send to or receive from the assistant, and send activity when you confirm outbound mail. Current connections may include Google (Sign-In, Gmail, Calendar), Microsoft (mail and calendar), and WhatsApp. | To keep the assistant current with your inbox and calendar, draft and send messages you confirm, and operate connected features you enable. Disconnecting a provider stops new ingest and destroys the stored credential. | GDPR Article 6(1)(b) — performance of a contract for features you enable. GDPR Article 6(1)(a) — consent, where required for optional OAuth scopes; you can withdraw consent by disconnecting the integration. |
Cookies, Tokens and Other Tracking Technologies We use session cookies required to keep you signed in (including across bloosh.ai and app.bloosh.ai when configured) and preference storage such as theme. We do not use third-party advertising cookies on the product. This Privacy Policy applies to Bloosh’s use of cookies and does not cover cookies placed by third parties you choose to connect. | To authenticate you and keep the Services working. To remember preferences such as theme. | Strictly necessary cookies are processed based on our legitimate interests and are exempt from consent requirements under EU ePrivacy rules (GDPR Article 6(1)(f)). GDPR Article 6(1)(a) — consent, where required for any non-essential cookies. Preference storage can be cleared in your browser. |
Usage, Log, and Device Information We may automatically collect:
| To operate, secure, maintain, analyse, and improve the Services, and to prevent abuse. | GDPR Article 6(1)(f) — legitimate interest in operating, improving and securing our Services, provided such interests are not overridden by your fundamental rights and freedoms. |
In addition to the above-mentioned purposes, and depending on the specific circumstances, we may also process your personal data to:
- provide you with updates and other information relating to the Services;
- protect the rights and property of Bloosh and others;
- perform operational functions in connection with our business;
- carry out any other purpose described to you at the time the information was collected;
- maintain appropriate records for internal administrative purposes;
- comply with legal and regulatory requirements, required disclosures, and choices and controls that may be available;
- find and prevent fraud, abuse, and other illegal activity; and
- for compliance purposes, including enforcing our Terms of Service, or other legal rights, or as may be required by applicable laws and regulations or requested by any judicial process or governmental agency.
We do not sell your personal data. We do not use your workspace content, documents, or connected-inbox content to train foundation models for Bloosh or for the public, and we select model providers under terms that restrict use of API inputs for training where such options exist.
We also may use aggregated or de-identified information, which cannot reasonably be used to identify you. Once de-identified and aggregated so that data does not personally identify you, it is no longer personal data. Such de-identified and/or aggregated information which does not identify individuals is not subject to this Privacy Policy.
#Information We Receive from Third Parties
We may receive information that third parties provide to us, which may include information about you — for example from Google if you use Sign-In or connect mail and calendar, from Microsoft if you connect mail and calendar, from Stripe in connection with billing, or from WhatsApp if you use that integration. If you have questions about those parties’ privacy practices, you should review their privacy policies.
#2. How We Share Information
We may share personal data with:
- Vendors and Service Providers. We share personal data with processors that help us run Bloosh, including Supabase (authentication, Postgres with row-level security isolating organisations, file storage, realtime, and an encrypted secrets vault for OAuth tokens); Railway (application hosting for bloosh.ai and app.bloosh.ai); Stripe (payment processing and customer portal); and model / AI providers as described in section 7 (for example Anthropic, Google, OpenAI, OpenRouter and their underlying model hosts).
- Connected account providers. If you use Google Sign-In or connect Gmail, Calendar, Microsoft, or WhatsApp, data flows according to the scopes you approve and those providers’ terms. They may act as independent controllers of your account with them.
- Aggregated or Anonymized Information. Where legally permissible, we may use and share aggregated or anonymized information. This information cannot reasonably be used to identify you.
- Business Transfers. We may disclose or transfer personal data to a potential acquirer, successor, or assignee as part of any proposed or actual merger, acquisition, sale of assets, or similar transaction, or in connection with bankruptcy, insolvency, or receivership, where personal data is transferred as a business asset.
- Legal Obligations and Protection. We may share information as necessary to: (i) comply with applicable laws, regulations, legal processes, or governmental requests; (ii) enforce this Privacy Policy or any agreement we may have with you, including our Terms; (iii) detect, prevent, or address fraud, security, or technical issues; (iv) respond to your requests; or (v) protect our rights, property, or safety, as well as those of our users or the public.
- With Your Consent. We may share information with your consent.
We require processors to protect personal data and use it only on our instructions, except where they act as independent controllers (for example Google for your Google Account). We do not sell personal data.
#3. Cookie Notice
We use cookies and other related technologies (including local storage and tokens) when you visit our Sites or use the Services. Cookies are small text files placed on a user’s device. They enable the collection of information that allows a website to recognize a session, support functionality and security, and remember preferences.
Types of cookies we use:
- Strictly Necessary Cookies: required for the operation, security, and accessibility of the Sites and Services (for example authentication and keeping you signed in). These cookies cannot be disabled without breaking sign-in, and do not require consent under EU ePrivacy laws.
- Functional Cookies / storage: enable preferences such as theme. You can clear these in your browser.
We do not currently use third-party analytics or marketing cookies on the product. You may manage cookies through your browser settings; disabling strictly necessary cookies will affect sign-in and other core functionality.
This Cookie Notice applies only to Bloosh’s use of cookies and does not cover cookies placed by third-party services you choose to access or connect.
#4. Third-party Services
You may access other third-party services through our Sites or your use of the Services, for example by clicking on links or by connecting Google, Microsoft, WhatsApp, Stripe, or a model provider.
Bloosh is not responsible for the privacy policies or practices of third-party services, and this Privacy Policy does not apply to information collected by those parties in their capacity as independent controllers. We encourage you to review the privacy policies of any third-party services you access. Links or integrations with third-party services do not constitute an endorsement, affiliation, or representation regarding their privacy or information security practices.
#5. Security
Bloosh is committed to protecting your information. We employ administrative, technical, and organisational security measures designed to protect personal data from unauthorised access, use, alteration, or disclosure, including encrypted transport (HTTPS), authentication with hashed passwords or single sign-on, organisation-scoped access control in the database (row-level security), encrypted storage of OAuth refresh tokens in a secrets vault, and least-privilege access for service credentials.
We follow industry-recognised information security standards appropriate to the nature and risk of the processing involved. However, no system or method of transmission over the Internet is completely secure, and we cannot guarantee absolute security of your personal data. Please use a strong unique password and protect devices that stay signed in.
#6. Data Retention
We retain personal data only for as long as necessary to fulfill the purposes described in this Privacy Policy, unless a longer retention period is required or permitted by law.
We retain account and workspace data for as long as your account or organisation remains active. You can delete documents and much workspace content in-product. After account or organisation deletion (or a verified deletion request), we delete or irreversibly anonymise personal data within a reasonable period, except where we must retain it for legal, tax, dispute, or security reasons (for example billing records or abuse logs).
Connected mail, calendar, and messaging data follows your connection: disconnecting a provider stops new ingest and destroys the stored credential; previously ingested copies in Bloosh remain until you delete them or we delete the workspace, unless a shorter retention is configured for your plan.
When we no longer have a legitimate business need or legal obligation to process personal data, we will delete, anonymise, or securely isolate such data. If deletion is not immediately possible (for example, due to backup systems), the data will be securely stored and isolated until deletion is feasible.
If you have questions about data retention, please contact [email protected].
#7. Use of Emerging Tech Such as Artificial Intelligence and Machine Learning
Bloosh uses large language models and related machine-learning systems to operate the assistant and related features (including document indexing, data extraction, day planning, and drafting).
When you chat with the assistant or trigger AI features, Bloosh sends the relevant context to one or more model or embedding providers you or we configure (for example Anthropic, Google, OpenAI, or models reached via OpenRouter). That context may include chat history, task and calendar snippets, document excerpts, email or thread content you have connected, WhatsApp message content, and tool results needed to complete the turn.
Providers process that data to return model outputs. Processing is typically transient for API inference, subject to each provider’s data-processing terms. Outputs and the workspace records they produce (messages, proposed cards, summaries, embeddings) are stored in your organisation’s Bloosh workspace.
We do not use Customer Data to train foundation models for Bloosh or for the public, and we select providers under terms that restrict use of API inputs for training where such options exist.
AI outputs can be incorrect or incomplete. You remain responsible for reviewing confirmed actions. The assistant proposes; outbound messages, calendar changes, and deletions require your confirmation before they are carried out, except for automations you have explicitly switched on.
#8. International Data Transfers
We and our processors may process data in the United States and other countries that may not provide the same level of data protection as your country of residence. Where required, we use appropriate safeguards, such as Standard Contractual Clauses, or rely on an adequacy decision. Details for a specific processor are available on request at [email protected].
#9. EEA and UK Residents Data Protection Rights
Data protection laws distinguish between a “controller” and a “processor.” Customers are controllers of Customer Data uploaded to the Services. Bloosh is the controller of personal data collected directly through the Sites or outside of Customer Data.
If you are located in the European Economic Area (EEA) or the United Kingdom, you have the right to:
- Access, correct, or delete your personal data
- Object to or restrict certain processing
- Request data portability
- Withdraw consent, where processing is based on consent
- Lodge a complaint with a supervisory authority
Requests may be submitted to [email protected], and we will respond in accordance with applicable law. We may need to verify your identity. Where Bloosh processes personal data on behalf of a customer, requests should be directed to the relevant customer as data controller (for example your organisation’s admin).
#10. Consumer Data Protection Rights
The law of your jurisdiction may provide you with certain rights regarding our use of your personal data. Subject to any exceptions and/or exemptions under applicable law, you may, for example, have the following rights with respect to your personal data collected by us.
#I. Categories of Personal Data
We may collect and share the following categories of personal data:
- Identifiers (for example name, email address, IP address, account identifiers)
- Customer records information (for example contact details and billing identifiers)
- Commercial information (for example subscription plan and transaction history)
- Internet or network activity (for example usage data and log data)
- Approximate geolocation data derived from IP, used for security and service operation
- Professional information you choose to provide in your profile (for example job role)
- Customer content you submit to the Services (workspace content, documents, connected mail, calendar, and messages), processed as described in this policy
Personal data may be collected directly from you, automatically through your use of the Services, or from third-party sources you connect.
We may disclose the foregoing categories of personal data to the service providers listed in section 2 for one or more of the business purposes set forth in this Privacy Policy.
#II. Consumer Privacy Rights
Subject to certain exceptions, you may have the right to:
- Know the categories and specific pieces of personal data we collect, use, disclose, or share
- Delete personal data we have collected
- Correct inaccurate personal data
- Portability of your personal data that we collected
- Limit the use and disclosure of sensitive personal data
- Opt out of the sale or sharing of your personal data
- Withdraw your consent to our processing of certain personal data
- Not be discriminated against for exercising your privacy rights
The scope of these rights and their applicability vary by jurisdiction. There may also be exceptions where we may not have an obligation to fulfill your request.
#III. Exercising Your Rights
You may submit a verifiable consumer request by emailing [email protected]. We will verify your identity before responding and may request additional information as permitted by law.
You may designate an authorized agent to make a request on your behalf. We may require proof of authorization and verification of your identity. Bloosh cannot respond to a request or provide personal data if we cannot verify the identity or authority to make the request.
If Bloosh receives data through a customer of its Services, Bloosh may have no direct relationship with the individual whose personal data it processes as Customer Data. An individual who seeks access, correction, or deletion of that data should direct their query to the Bloosh customer within whose workspace such data exists (the data controller). If we deny a request, we will explain the reasons we cannot comply, if applicable.
#IV. Sale and Sharing of Personal Data
Bloosh does not sell personal data and does not share personal data for cross-context behavioral advertising.
#V. Global Privacy Control and Do Not Track
Because we do not sell or share personal data for targeted advertising, we do not operate a “Do Not Sell or Share” preference center. The Services do not currently respond to “Do Not Track” (“DNT”) or Global Privacy Control (“GPC”) browser signals. Our practices regarding data collection and use are described in this Privacy Policy.
#11. Other Disclosures
We do not use your sensitive personal information for the purpose of inferring characteristics about you.
We do not perform processing of your information which constitutes automated decision-making or profiling in furtherance of decisions that produce legal effects or similarly significant effects concerning you. The assistant proposes actions; you remain responsible for what you confirm.
#12. Email Opt Out
You may opt out of receiving general emails from Bloosh by following the unsubscribe instructions in any marketing email we send you. You will still receive transactional messages needed to operate your account (for example security, billing, and service notices).
#13. Children’s Privacy
Bloosh is not directed at children under 16 (or the minimum age required in your jurisdiction), and we do not knowingly collect personal data from children. If you learn that a child has provided us with personal data in violation of this Privacy Policy, you can alert us at [email protected]. If we become aware that such data has been collected, we will take appropriate steps to delete it.
#14. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. We will revise the “Last updated” date and, for material changes, provide additional notice as required by law (for example by email or an in-product banner). To the extent permitted under applicable law, changes are effective upon posting. Continued use after the effective date means you accept the updated policy, except where consent is required.
#15. Accessibility
We are committed to facilitating the accessibility of our Services. To access this Privacy Policy or any other portion of the Services in an alternative format, please contact us at [email protected].
#16. Contact Us
If you have questions or concerns about this Privacy Policy or our data practices, please email us at [email protected].
General: [email protected].