Privacy Policy for Bloom
Last Updated: 2026-09-08
This Privacy Policy describes how Frostskull AB ("we", "our", or "us") handles information in connection with Bloom — Divorce Recovery (the "App"), a self-guided divorce-recovery companion for iOS and Android.
The short version. Bloom has no account system and no server of ours. Everything you write — Vault messages, reflections, checklist items, the dates you enter, your name — is stored only on your device and is never transmitted to us or anyone else. The App does send a limited stream of anonymous usage events to Google Analytics for Firebase, and purchase records to RevenueCat and the app stores. Those are described in full below.
1. There is no account and no cloud copy
You do not create an account to use the App. There is no email address, no password, no sign-in, and no cloud sync. We do not operate a database of user records, and we cannot look up, read, or recover anything you have entered.
The practical consequence is worth stating plainly: your data lives on one device. If you lose that device, uninstall the App, or use "Start over", the data is gone and we cannot restore it.
2. What stays on your device
The following is stored in the App's private storage on your phone and is never transmitted:
- Your first name.
- Your separation date, and any anniversary, birthday, finalisation date or custom date you add.
- Your setup answers — where you are in the process, who ended the relationship, your contact level, what has been hardest lately, your 30-day goal, and whether you have children and their age bracket.
- Vault messages. The free-text messages you write instead of sending. These are the most sensitive thing in the App and they never leave your device under any circumstances.
- Session reflections and any other free text you write in the program.
- Your checklist items, including the text of any item you add yourself.
- Your streak history, urge events, milestone state, and dating-readiness answers and scores.
- App settings, such as your onboarding progress and notification preference.
Text you type on a ritual screen is not stored at all — it stays on screen and is discarded.
3. What the App does send, and to whom
Four external services are involved. There are no others: no advertising network, no attribution SDK, no social login, and no analytics beyond the one named here.
Google Analytics for Firebase
Active in the released version of the App. It receives usage events — which setup step you reached, paywall and purchase events, taps on the urge button, completed sessions, checklist and milestone completions, your dating-readiness bucket, and whether you allowed notifications — together with six general properties: your current stage, your situation, your goal, whether you have children (yes/no), whether you subscribe, and your streak length.
It never receives your name, your dates, or any text you write. Custom checklist items are counted by their identifier only, never by their text.
Separately, Google's own SDK collects a standard set by default, which we do not choose or control: a random app-instance identifier, your device model, operating system version, language, and an approximate location derived from your IP address (typically country- or region-level).
Firebase Crashlytics & Anonymous Authentication
When the App crashes, Crashlytics receives the crash report — a stack trace and device state — so we can fix it. Crash reports are grouped using a random identifier created on first launch. That identifier is not an account: it has no email, no password, no sign-in, and it is not shared with any other service. Crash reporting is active in the released version of the App only.
RevenueCat
Manages your subscription entitlement. It receives purchase and receipt data from the store, plus standard device and SDK information. The App does not give RevenueCat a user ID of any kind, so it identifies your purchase under its own anonymous identifier, which is not connected to the crash-reporting identifier above. RevenueCat receives none of your name, dates, answers or written content.
Apple App Store & Google Play
Process your payment and hold your subscription and billing records under their own privacy policies. We never receive or store your payment card details. All the App learns back from them is whether your subscription is active.
We do not sell your personal information, and we do not share it for cross-context behavioural advertising. We may disclose information where required by law or valid legal process, and records could transfer as part of a merger, acquisition or asset sale — but note that in the App's case there is no store of your written content for any of this to reach.
4. Sensitive information
We recognise that even reduced to categories, this information describes your marital status, family situation and emotional state. We treat it as sensitive: it is why the free-text areas of the App are kept entirely on-device, why the analytics stream is limited to the categories listed above, and why the App asks for no permissions it does not need.
5. Notifications
Reminders are scheduled and delivered locally by your device. There is no push service, no server sending them, and no device push token collected by us. Notifications are optional and the App works without them.
One thing to be aware of: these notifications can include your first name and refer to an upcoming date, and — like any notification — they appear on your lock screen. If you share your phone or leave it where others can see it, consider leaving notifications off, or hiding notification previews in your device settings.
6. Sharing a milestone card
When you share a milestone card, the App hands the image to your phone's share sheet and you choose where it goes. We do not upload it anywhere. Your first name appears on the card only if you switch that on — it is off by default. Once you share the image, what happens to it is governed by the app or service you sent it to.
7. Permissions
The App requests permission to send you notifications, and on Android declares permissions needed to reschedule those local reminders after a restart and to use vibration.
It does not request access to your location, camera, microphone, contacts, calendar or photo library, and it does not use an advertising identifier or ask to track you across other apps and websites.
8. Data retention and deletion
- On your device: your data stays until you remove it. Settings → Start over erases the entire database, all settings, and every scheduled notification. It is immediate and cannot be undone. Uninstalling the App also removes its data.
- With Google (Analytics and Crashlytics): anonymous usage and crash records are retained according to the settings in our Firebase project and Google's own retention policies. These records are not linked to your name or to anything you wrote.
- With RevenueCat and the app stores: purchase and subscription records are retained under their policies, typically for accounting, tax and fraud-prevention purposes.
Erasing your data in the App does not cancel your subscription, and cancelling your subscription does not erase your data. See Delete Your Data for both.
9. Your rights
Depending on where you live, you may have rights to access, correct, export, restrict, object to the processing of, or erase your personal data, and to lodge a complaint with your data protection authority.
For anything held on your device, you can exercise these rights directly and immediately: it is all visible in the App, and "Start over" erases it. For the anonymous analytics, crash and purchase records described in Section 3, contact us at info@frostskull.com. Please understand that because those records carry no name, email or account, we may be unable to identify which records are yours; where that is the case we will say so rather than act on the wrong data.
If you are in the EU or UK and are not satisfied with our response, you may complain to your national supervisory authority; in Sweden this is Integritetsskyddsmyndigheten (IMY).
10. Children's privacy
The App is intended for adults aged 18 and over and is not directed at children. We do not knowingly collect personal information from minors. The App records only whether you have children and their age bracket — used solely to decide whether to show one additional checklist — and never any identifying detail about them.
11. International transfers
The third-party services in Section 3 are operated by companies that may process data outside your country of residence, including in the United States. They act under their own terms and safeguards. Your on-device data is not transferred anywhere.
12. Security
An honest account rather than a reassuring one:
- Your data is held in the App's private storage area, isolated from other apps by your operating system and protected by your device passcode or biometric lock.
- The App does not apply its own separate encryption to its database, and it does not currently offer an in-app PIN or biometric lock on the Vault.
- Because there is no server and no account, there is no online store of your data to be breached — but equally, an unlocked or lost phone is the whole risk, and we have no way to wipe the App remotely.
- We recommend keeping a device passcode or biometric lock enabled.
13. Changes to this policy
We may update this Privacy Policy. Material changes will be communicated through an in-app notice or an updated "Last Updated" date at the top of this page. Continued use of the App after changes are posted constitutes acceptance of the updated policy.
14. Contact
For privacy questions, data requests or concerns, contact us at: info@frostskull.com
Frostskull AB
Martingalgatan 8
18374 TÄBY
Sweden