Privacy & trust center

Know what you’re sharing.
Know who can see it.

Last updated September 20, 2026. This page describes the controls in the current service and their limits. It is not a certification or a guarantee that any online service is risk-free.

Your personal information

Names, relationship entries, photos, and reflections are encrypted in your browser before upload. Account email addresses are processed to send sign-in codes; the account database stores a keyed hash. We also process account and connection identifiers, timestamps, IP addresses in operational logs, and notification endpoints if enabled.

We do not sell personal information or use advertising trackers. Fonts and website assets are hosted with the service. Essential cookies and browser storage support sign-in, encrypted keys, and your preferences.

Encryption and access

Relationship content uses authenticated encryption on your device. Private records and partner-shared records use different access keys. Passkeys protect sign-in, and a recovery key can restore access when your passkey cannot unlock your data. Keep your recovery key offline in a safe place. We cannot recover it for you.

An important choice when inviting your partner

An invitation key can unlock the shared space for its recipient. Copying the link keeps its secret in the URL fragment, rather than sending it as part of the normal page request. If you choose Email invitation, our server and Microsoft Azure Communication Services process the key and recipient address to send that email. The message and key may remain in email systems. We do not store the raw key or address in the application database; hashed delivery-throttling records expire after a day.

Only send an invite to your intended partner. Protect the email, do not forward it, and cancel an unused invite if sent to the wrong person. Each invitation works once and expires in seven days; creating a replacement invalidates the previous invitation.

Three audiences, explicit choices

Either partner can withdraw a report or revoke the professional connection. This blocks future access through the service. It cannot delete screenshots, downloads, or copies someone already made.

Where data lives and how long it stays

The service is hosted on Microsoft Azure in the United States, East US 2. Azure Communication Services sends account and invitation email. Microsoft 365 handles business mailboxes. Apple, Google, Mozilla, or Microsoft may deliver optional push notifications. Relationship push content is encrypted; generic service notices and delivery metadata are not.

Application request logs are retained for seven days. Availability monitoring is retained for 30 days. Encrypted database backups age out within 35 days. Account deletion removes your application records; a closed shared space has a 30-day grace period for the remaining partner. See the privacy policy for details.

Security access records

We retain pseudonymous access and security records for 365 days to investigate misuse. These include event time, action, response status, and keyed account, client and resource references. They exclude relationship content and message bodies. Sessions expire after 15 minutes without interaction and require a new sign-in at least every 12 hours.

Health information and professional use

Us in Bloom is a consumer relationship reflection tool. We do not advertise HIPAA compliance, offer this as an electronic health record system, or claim an independent security certification. Encryption alone does not establish HIPAA compliance. Do not upload clinical records or regulated patient information under an assumption of compliance.

Professionals should contact professionals@usinbloom.com before using the service in a regulated care workflow. Applicable agreements, including a Business Associate Agreement where required, and a suitability review must be in place first. Read our HIPAA readiness status. See HHS guidance on cloud services and health information.

Limits you should understand

Encryption does not protect against someone using your unlocked device, obtaining an invitation or recovery key, or copying content they can access. Browser code and device security matter. No independent penetration test or compliance certification is currently claimed. Share only what you’re comfortable storing, and use a safe device.

Questions or a security concern?

Privacy requests · Report a vulnerability · Get help. Please do not email recovery keys, invite keys, or private relationship content to support.