Us in Bloom is operated by SARA, 1033 S College St, Winchester, TN 37398. HIPAA readiness status.
Privacy Policy
Last updated September 20, 2026. Us in Bloom is operated by SARA. Contact: privacy@usinbloom.com.
The short version
Everything you write in Us in Bloom — check-ins, messages, journal entries, photos, even your name — is encrypted on your device before it’s sent to us. Relationship content is stored encrypted. If you choose to email an invitation, our server and email provider process its access key, as explained below. We don’t sell data, show ads, or use advertising trackers. We use operational availability monitoring.
What is stored encrypted
- Anything you or your partner write or upload.
- Your name or your partner’s name.
- Your recovery key. Invitation keys are an exception if you choose to send them by email.
What we do store
- Encrypted data you create, and when it was saved.
- Which two accounts share a space.
- Your passkeys’ public keys (these can’t be used to sign in as you).
- If you turn on notifications, the address your browser gives us for delivering them. Relationship notification content is encrypted; generic service notices are not.
- Server logs with IP addresses and page addresses, kept for 7 days for security and troubleshooting.
When you sign up or recover your account, our server and Microsoft Azure Communication Services process the address you enter to send a one-time code. Our account database keeps a keyed hash of the address, rather than the address itself. The email provider processes delivery information. If you email our support, privacy or security addresses, Microsoft 365 stores your message and contact details so we can respond. Please do not send private relationship content or recovery keys by email.
Emailed partner invitations
If you choose Email invitation, our server and Microsoft Azure Communication Services process the recipient’s email address and invitation access key to send the message. Anyone with that key can join your space and read partner-shared content. We do not persist the raw address or key in the application database or request logs. Hashed recipient and sender throttling records are kept for one day. The provider and recipient’s email system may retain the message and delivery metadata. Copying the invitation link instead keeps its secret in the browser’s URL fragment. Protect the link or email and cancel a mistaken invitation before it is accepted.
Who processes data for us
Us in Bloom runs on Microsoft Azure in the United States (East US 2). Microsoft also processes signup email and business mailbox messages. Notifications are delivered through your device’s push service (Apple, Google, Mozilla or Microsoft), which processes delivery metadata and encrypted relationship notification content; generic service notices are not encrypted.
Your partner
Your partner sees only what you choose to share. Private entries are never visible to them. If you unlink, your shared space closes immediately. Your partner can save a copy of your shared history for 30 days, after which it’s permanently deleted.
Deleting your data
You can export your data or delete your account at any time from Me → Sign-in & recovery. Deleting your account permanently erases everything you wrote. Encrypted backups age out within 35 days.
Optional professional sharing
An operator-approved therapist or counselor can invite your couple. Both partners must approve the connection and every report. Reports contain only the sections you choose and preview, encrypted separately for that professional. Private journals are not included. Professionals do not receive the key to your couple’s space.
Either partner can withdraw a report or revoke the connection. This stops access through Us in Bloom, but cannot erase copies already saved by your professional. The server stores connection and approval metadata. Reports are snapshots, not live monitoring.
Health information
This consumer reflection service is not represented as HIPAA-compliant or as a clinical record system. Do not upload regulated patient information assuming those protections apply. Professionals must confirm suitability and any required agreements before a regulated care workflow. See our privacy and trust center.
Optional text notifications
If you enroll, we process your verified mobile number, consent, preferences and delivery metadata. The number is encrypted at rest with a server-managed key, not end-to-end encrypted, and is processed by Azure Communication Services and carriers for delivery. Texts contain only generic notices. We do not sell mobile information or share it with third parties or affiliates for marketing or promotional purposes. Removing your number deletes the active contact; abuse-prevention hashes expire after one day and queue metadata after seven days. Backups age out within 35 days. See text messaging terms and privacy for opt-out and retention details.
Security audit records
We retain pseudonymous security access records for 365 days, including timestamps, action types, response status, and keyed account, client and resource references. These records exclude relationship content and message bodies. They can remain after account deletion for security investigations; backup copies age out within 35 additional days.
Age
Us in Bloom is for adults 18 and over.
Changes
If we change this policy, we’ll update the date above and tell you in the app before the change takes effect.
Contact and security reports
For privacy requests: privacy@usinbloom.com. To report a security problem: security@usinbloom.com. For help: support@usinbloom.com.