Last updated: 4 August 2026
Privacy policy
This policy explains what personal data Bloow collects when you use bloow.app, why we process it, and the choices you have. Bloow is a SaaS-native Product OS for founders — we do not sell your data.
Who we are
Bloow ("we", "us") operates the SaaS product available at bloow.app. For privacy questions or requests, contact privacy@bloow.app.
When you use Bloow on behalf of a company, that company is the controller of workspace data. Bloow acts as a processor for customer content stored in your workspace, as described in your agreement with us.
Data we collect
Account data: email address, name, avatar, authentication identifiers, and workspace membership.
Product data you provide: projects, roadmaps, execution cycles, metrics configuration, integration settings, competitive intelligence inputs (including product URLs you submit), tracking/SDK events you send, and team invitations.
Competitive watch data: public pages Bloow crawls for rivals you track (landing, pricing, social, careers), optional Meta Ad Library samples, and derived estimates. This is public web content, not the rival’s private account data.
Usage and technical data: log events, device/browser metadata, IP address (short retention), and product analytics when enabled.
Billing data: plan, subscription status, and billing identifiers processed by Stripe. We do not store full payment card numbers on our servers.
Marketing site: email if you join the newsletter, and cookie preferences on the public site.
How we use data
We process data to provide and secure the service, authenticate users, sync integrations you connect, operate billing, send transactional emails, improve reliability, and comply with law.
We do not use your workspace content to train third-party AI models. Core product analytics in Bloow are rules-based — not LLM-based.
When competitive intelligence enrichment is enabled on the Bloow server, crawled public text from rival pages you track may be sent to Google Gemini to fill empty analysis fields and to rewrite narratives in your UI locale. That is optional, scoped to competitive intel, and is not used for your KPI dashboard.
Legal basis (GDPR)
If you are in the European Economic Area or UK, we rely on: contract performance (providing the service you signed up for), legitimate interests (security, fraud prevention, product improvement with appropriate safeguards), consent (optional analytics cookies on the marketing site), and legal obligation where applicable.
You may withdraw consent for optional cookies at any time without affecting essential service features.
Sub-processors and sharing
We use trusted infrastructure providers to run Bloow, including Supabase (database and authentication), Vercel (hosting and web analytics), Stripe (payments), Resend (transactional email), and PostHog (in-product analytics when configured). When competitive intelligence enrichment is enabled, Google (Gemini / Generative Language API) may process public rival page text for that feature only. They process data only on our instructions and under appropriate agreements.
We may disclose data if required by law or to protect rights, safety, and integrity of the service.
Retention
We keep account and workspace data while your account is active and as needed to provide the service. After cancellation, data is deleted or anonymized within a reasonable period unless law requires longer retention.
Bloow SDK product analytics events are retained for up to 90 days, then automatically deleted.
Backups may persist for a limited time before rotation. Billing records may be kept for statutory accounting periods.
Your rights
Depending on your location, you may have rights to access, rectify, erase, restrict, or port your personal data, and to object to certain processing. You may also lodge a complaint with your local data protection authority.
To exercise your rights, email privacy@bloow.app from the address linked to your account. We may need to verify your identity before responding.
Security
We apply technical and organizational measures including encryption in transit, row-level security in Postgres, role-based access, and server-side authorization checks. No method of transmission or storage is 100% secure; we work continuously to reduce risk.
Cookies
We use essential cookies and similar storage for authentication and product preferences, and optional analytics on bloow.app only after consent (PostHog EU, Vercel Analytics, Bloow product analytics). We do not use advertising or marketing pixels. Details and controls are in our Cookie policy.
International transfers
Your data may be processed in the EU and, where our providers operate elsewhere, with appropriate safeguards such as Standard Contractual Clauses or equivalent mechanisms required by applicable law.
Children
Bloow is a business product not directed at children under 16. We do not knowingly collect personal data from children. Contact us if you believe a child has provided data and we will delete it.
Changes to this policy
We may update this policy when our practices or legal requirements change. We will post the new version on this page and update the date above. Material changes may be notified by email or in-app notice where appropriate.
Contact
privacy@bloow.app
For general support: support@bloow.app