1. Who is responsible
Blosm is currently a personal beta project operated from Germany. Contact: support@myblosm.com.
2. Information used by Blosm
Blosm uses account and profile details, including name, email, account identifiers, date of birth, country, preferences and an optional phone number. Depending on the features you use, it also processes routines, products, journal entries, mood, nutrition, fitness and sleep records, images, videos, scan reports and content you include in AI requests.
Social features process profile visibility, follows and connections, posts, reels, messages, interactions and reports. App and device identifiers, permission status and technical diagnostics support authentication, notifications, security and service operation. Private wellbeing records are separate from the content you choose to publish.
3. Why it is used
Data is used to provide authentication, personalization, skin analysis, reports, routines, product tools, journal features, security, recovery, and the Blosm Intelligence experiences you request.
4. Early access and beta interest
If you join the website waitlist or volunteer as a beta tester, Blosm collects your email address, your selected interest, consent status, and confirmation status. This information is used only to manage early access and send related Blosm updates. You can unsubscribe through an email link or contact support at any time.
Brevo processes these sign-ups and delivers confirmation and early-access email on Blosm’s behalf. Double confirmation is used so a place is saved only after the email address is confirmed. The information is retained while early access is relevant or until you unsubscribe or request deletion, subject to legal and security requirements.
5. Infrastructure and connected services
Google Firebase and Google Cloud provide authentication, database and file storage, hosting, notifications and app-integrity services. Microsoft Azure hosts the authenticated Blosm backend, and the configured Azure OpenAI service processes text and images included in requested AI experiences.
When you use maps, OpenStreetMap receives map-tile requests and network information; the requested area can reveal approximate or precise location. Food searches can send the search terms and request metadata to Open Food Facts. These providers process those requests under their own privacy arrangements.
Voice input uses Android speech recognition. Blosm prefers an available on-device recognizer, but can use a connected speech provider when local recognition is unavailable. That provider may receive audio. You can review the resulting text before sending it to Blosm I. If you request read-aloud playback, the response text is passed to your device’s configured text-to-speech engine, which may use connected services depending on the engine and voice selected.
Device services and SDKs, including Google ML Kit, may process technical diagnostics and app or device identifiers. Health Connect access and camera, microphone, location and activity permissions are requested for the features that need them. You can manage permissions in Android; some features will then be limited.
Optional Firebase Crashlytics reports help us find technical failures. Sharing is off by default and requires a separate choice in Data & Privacy for this account on this device. Reports contain technical codes, app and device details, and an installation identifier; photos, messages and wellness records are not attached. Turning sharing off stops new recording and new upload authorizations. Reports already submitted cannot be recalled through this switch. Google processes these reports and may process them outside your country.
6. AI processing
Blosm I uses the authenticated backend for the AI experiences you request. Requests may include your message, supported context you choose to enable, and images you explicitly add or consent to analyse. Personal context is not made public by using these tools.
AI output can be incomplete or incorrect. Cosmetic insights are visual estimates and general wellbeing guidance, not a diagnosis or treatment. Processing is subject to the configured providers and their applicable service arrangements; it is not represented as exclusively on-device.
7. Images and scan information
Before the first scan, Blosm asks for permission to analyze, upload, store, and process scan images. During testing, data may remain while the account is active unless you delete content or request account deletion.
8. Sharing and advertising
Blosm does not sell personal data or use personal data for advertising in this beta. Providers receive information needed for their connected features, and processing may take place outside your country depending on the service.
Your profile and the audience of each publication determine who can see social content. Public posts and reels can have external links and previews. Private wellbeing records are not automatically published to your profile or feed.
Supported chats use encryption tied to device keys. Initial requests, older message formats and reports you submit may also be processed by Blosm; not every message is end-to-end encrypted. Account access alone does not recover lost device keys. Other people may retain copies of content you have shared with them.
9. Deletion and recovery
A deletion request restricts app access immediately. You have 30 days to cancel. If you do not cancel, Blosm removes the Authentication account, Firestore records, public profile, username reservation, and user-owned Storage files. Website early-access information can be removed separately by unsubscribing or contacting support.
10. Age and changes
Blosm is intended for adults aged 18 or older. This policy may be updated as the beta and its supporting services evolve.