← Back to Bloom Care

Bloom Care — Privacy Policy

How we handle your data and your patients' data

Last updated: April 18, 2026

Bloom Care is a provider-facing platform. This policy covers two categories of data: your data (as a healthcare provider) and patient data (accessed through the platform).

1. Provider Data We Collect

When you create a Bloom Care account, we collect and store:

DataPurposeStorage
Email addressAccount identity & loginCloudflare D1
Full nameDisplayed to patients in consent modalCloudflare D1
NPI numberProvider verification via NPPESCloudflare D1
NPPES registry dataName, credential, taxonomy, state (public data)Cloudflare D1
Role & clinic nameDisplayed to patientsCloudflare D1
Password hashAuthentication (SHA-256, salted)Cloudflare D1
Subscription statusPlan & patient limitsCloudflare D1

We do not collect your location, device fingerprint, browsing history, or any data beyond what is listed above.

2. Patient Data — How It Works

This is the most important section of this policy. Please read it carefully.

Bloom Care does NOT store patient health data

Patient health data lives in the patient's Bloom account (encrypted in Cloudflare KV, controlled by the patient). When you view a patient's data through Bloom Care, you are reading it in real time through a secure API. The data is:

Patient consent governs all access

7 data scopes

ScopeWhat it includes
CyclePeriod dates, flow, mood, cycle length
PregnancyWeek, due date, LMP, kick counts
SymptomsDaily symptom logs, pain levels
MedicationsPrescriptions & supplements
AppointmentsScheduled visits
JournalPersonal reflections & notes
VitalsBBT, blood pressure, weight

Audit logging

Every time you access patient data, the following is recorded:

This audit log is visible to the patient at all times in their Bloom app. It cannot be deleted or modified by the provider.

3. What We Do NOT Collect or Do

4. Third-Party Services

Bloom Care uses the following third-party services:

ServicePurposeData shared
CloudflareInfrastructure (Workers, D1, KV)Provider account data, API requests
NPPESNPI verificationNPI number (public registry lookup)
ResendEmail deliveryPatient email (for invite only)
OpenRouterAI features (optional)Patient data only when provider requests AI summary
Polar.shPayment processingProvider email, payment info (not stored by us)

Each service operates under its own privacy policy. We select services that offer strong privacy protections and, where available, HIPAA-compatible options.

5. Data Security

6. Your Rights as a Provider

7. Patient Rights (as enforced by Bloom Care)

Bloom Care enforces the following patient rights on behalf of Bloom app users:

8. HIPAA Considerations

Bloom Care is built with HIPAA-aligned technical safeguards:

However, Bloom Care does not currently have Business Associate Agreements (BAAs) in place with all infrastructure providers. HIPAA-covered entities should conduct their own risk assessment before using Bloom Care with protected health information (PHI).

For enterprise BAA inquiries, contact ibloom.care.app@gmail.com.

9. Data Retention

Data typeRetention
Provider accountUntil you delete it
Patient linksUntil patient revokes or you delete account
Audit logsRolling 1,000 entries per patient (to be extended to 6 years for HIPAA)
Invite tokens7 days (auto-expire)
Payment recordsManaged by Polar.sh per their retention policy

10. Children's Privacy

Bloom Care is for licensed healthcare providers who are at least 18 years old. It is not intended for use by minors. Patient data shared through Bloom Care may include data from patients under 18 — in such cases, parental/guardian consent and applicable pediatric privacy laws apply.

11. Changes to This Policy

We may update this privacy policy from time to time. Material changes will be communicated via email. Continued use of Bloom Care after changes constitutes acceptance.

12. Contact

Questions about privacy or data handling?

Email: ibloom.care.app@gmail.com