← Back to Blossom
Legal

Privacy Policy

Last updated 25 August 2026

This describes Blossom exactly as it works today. One thing is still outstanding and is marked where it appears: the exact retention periods for support cases, logs and backups. This policy has not yet been reviewed by a solicitor.

The short version

Blossom is local-first. You can use it without an account, and most of the more sensitive things you write stay on your own device. Signing in and sync are optional. We do not sell your data, show ads, or use third-party behavioural tracking. There is no analytics or advertising code in Blossom at all - not a reduced amount, none.

Who this applies to

Blossom is for transgender, nonbinary, and questioning adults aged 18 and over. We ask you to confirm your age during setup, and that confirmation is all we keep - we never ask for or store a date of birth. We do not ask for ID, a legal name, sex assigned at birth, or a diagnosis.

Who is responsible for your data

Blossom is a project of Grey Studios, and Grey Studios is responsible for the personal data handled through the app. Where this policy says “we”, that means Grey Studios. It is also why some of what follows describes data being handled by Grey Studios rather than by Blossom itself: the people who run Blossom and the people who would see a support message or a crash report are the same small team, working in the same company.

For anything to do with your data, including asking for a copy of it, correcting it, or asking us to delete it, email support@projectblossom.net. You can also use the support route inside the app, which reaches the same people. You do not need an account to email us, and you do not have to explain why you are asking. If what you want is your account gone, you no longer have to ask us at all: Account & sync deletes it there and then, and Retention and deletion below sets out exactly what that reaches.

Grey Studios does not yet have a published postal address. If you need one, for a complaint or a formal request, ask at the address above and we will provide it directly.

What stays on your device

The following never syncs and is never sent to Blossom's servers, no exceptions, whether you're signed out, signed in, or have sync turned on: all photos(presentation and body/progress tracking) and all voice recordings (voice practice sessions). These only ever exist on the device you took or recorded them on.

The following also stays on the device where you create it: your gender-euphoria entries, including any you have sealed as a Time Capsule to reopen later; any leftover history from the Aurora AI chat that was removed in August 2026; any trips you plan in Travel Mode, including where you are going and when; unsaved drafts of journal entries and check-in notes, which Blossom keeps as you type so a crash or a restart can't lose them; your app lock PIN, biometric credential reference, accessibility choices, and Home layout choices. To be exact about the app lock: the PIN itself and the biometric reference never leave the device, but the fact that you have an app lock switched on does travel with your account, so a new device knows to ask for it.

Because Blossom is built to work without a signal, your device also keeps a copy of the app itself - its pages, images and fonts - so it can open on a train or anywhere else offline. That cache holds the app, not your entries, and clearing your browser or app storage removes it.

Blossom does not receive your biometric data. Your device handles that itself; Blossom only keeps a local reference that lets it ask the device to unlock the app.

If you use Blossom without signing in, or sign in but leave sync off, nothing you record in the app is sent to Blossom's servers - everything above stays local, and so does everything listed as syncable below. The one exception is anything you deliberately send us: if you open a support ticket, post feedback or apply to join the team, that is stored on our servers whether or not sync is on, because there is no other way for it to reach us.

What can sync when you choose it

If you sign in and turn on sync, we store selected data in Supabase so it can follow you between your signed-in devices. This can include your profile and preferences; journey milestones and timeline; medications, schedules, dose logs, medication supplies and care supplies; appointments, including the questions and details you prepare for an appointment in advance and any private notes you add afterwards; check-in ratings and notes; goals; the minimal record of which Aurora suggestions you have already been shown, to avoid repeating the same nudge; journal entries; blood-test records; voice practice goals and session notes (never the recording itself); presentation and body/progress tracking data such as category, rating and measurements (never the photo itself); weight and food/calorie logs; budget entries and goals; Intimacy & wellbeing entries; safety check-ins; your saved private links; your Personal Support Map (private contacts and approximate locations you've saved); your waiting list referrals and the updates you log against them, including the service, your reference number and what you were told when you chased; and your self-directed care record, which includes whether anyone is monitoring you, when you started and how often you mean to check bloods. The last two were missing from this list until 25 August 2026, which was an error on our part rather than a change in what syncs.

None of this is currently visible to Blossom staff through the support-access system described below, even while synced - staff support access only reaches the smaller set of categories it already covered before this list expanded. Photos, voice recordings, gender-euphoria and Time Capsule entries, and Travel Mode trips never sync at all, as described above.

You control this category by category. In Account & sync, “Choose what syncs” lets you keep any of the groups above on your devices only while the rest still syncs. Turning a category off stops it being uploaded from then on, and offers to delete what was already uploaded. Nothing is ever removed from your own devices when you do that.

Your account and device storage

We use Supabase Auth for passwordless email sign-in. Your email address is used to create and secure your account. Blossom also uses essential browser storage, such as IndexedDB, local storage and authentication cookies, to keep your local data, session and settings working. We do not use advertising cookies.

Notifications and reminders

If you enable notifications, we store a technical push subscription for that device and process the synced reminder schedule needed to send a reminder. By default notifications are discreet. If you choose detailed notifications, a medication name or appointment title may be included in the notification sent through your browser or operating system's push service. You can turn notifications off in Blossom or in your device settings.

Sharing you choose

Blossom never shares your information automatically. Trusted Circle lets you grant a signed-in person read-only access to only the categories you choose. Blossom Bridge lets you create a temporary, read-only link for someone without an account. Both are optional, category-by-category, and revocable. We keep an in-app access history for these shares.

A Bridge recipient needs the link itself, so treat it like sensitive information. Revoking a link or Trusted Circle grant stops future Blossom access, but cannot remove something a recipient has already read, copied, saved or screenshotted.

The access history records that a link was opened and when. It deliberately does not record who opened it - no name, no IP address, nothing about their device - so it can tell you your link has been used without turning into a log of the person you shared it with.

One thing worth knowing about that history now that account deletion exists: where an entry belongs to somebody who has a Blossom account of their own, deleting their account takes their entries with it. A share history can therefore end up with fewer lines in it than it once had.

Exports

You can create exports, including selected Blossom Passport PDFs and structured data files. These are created for you to download and share. Once an export has left Blossom, you control where it goes and who receives it.

Support access

If you ask for help with a synced account, you can give a staff member a code that grants them time-limited access. While that access is live, authorised staff can see the synced profile, medication, appointment, goal, journey and check-in information needed to help. Being straight about the extent of it: that access can also change and delete those records, not only read them, because fixing something usually means editing it. Each normal in-app access is logged. It expires on its own, and if you want it stopped sooner, ask us and we will end it, since at present only staff can end it from their side. We are changing that so you can revoke it yourself. Journal text, blood-test records, voice practice notes, presentation and body/progress tracking, weight and food/calorie logs, budget entries, Intimacy & wellbeing entries, safety check-ins, private links, and your Personal Support Map cannot currently be reached through support access - not because they don't sync, but because we have deliberately not extended staff access to reach them. Photos, voice recordings, and gender-euphoria and Time Capsule entries cannot be reached either way, since they never sync at all.

When you write to support

A support message is not covered by any of the choices above. When you open a support ticket, the category you pick and everything you type into it are stored on our servers as ordinary text, and they stay there whether or not you use sync and whether or not a support case is ever opened on your account. Authorised Blossom staff can read them. This is the one place in Blossom where something you write is visible to us by default, so it is worth knowing before you write it.

Staff read and reply to tickets through Grey Studios' own internal system rather than through Blossom, so your message and the display name and email on your account are visible there too. It is the same company and the same small team described at the top of this policy, and tickets are not shared outside it. There is one copy of a ticket rather than two, so if you delete your Blossom account, your tickets and everything written on them, staff replies included, are deleted along with it.

You do not have to put anything sensitive in a ticket for us to help. If something is easier to describe without the detail, describe it without the detail.

Feedback and applications

Feature requests submitted to the public ideas board are visible publicly. Bug reports, contact emails and staff applications are visible only to authorised Blossom staff. Please do not put medical or other highly sensitive information into a public idea.

None of these are attached to your account. The only thread back to you is an email address you typed in yourself, if you gave one, so deleting your Blossom account does not remove them and we would be guessing if we matched them up on that address alone. If you want an idea, a bug report or an application removed, email us and we will do it.

Blossom used to have a closed beta with a shared chat for testers. That was closed in August 2026 and the messages have been deleted.

When Blossom breaks

When something in Blossom fails, the app sends a report to Grey Studios so we find out rather than waiting for someone to tell us. A report carries the shape of the failure and nothing else: which part of the app was doing what, a short code for the kind of error, and whether it happened on the live site or our test one.

It never carries anything you have written. Not journal text, notes, moods, search terms or email addresses. It also never carries the raw error message, because databases sometimes quote the offending record back inside one, and a message about a journal entry could otherwise contain the entry.

If you are signed in, the report includes your account reference so we can tell one person hitting a problem repeatedly from a hundred people hitting it once. That reference is the same identifier your account uses, so we can connect a report back to an account if we need to. It is not published, and it is not shared outside Grey Studios.

These reports are kept in Grey Studios' own error log rather than in your account, so deleting your account does not remove ones already sent. They still hold nothing you have written, and the reference in them stops pointing at an account that exists.

Donations

Blossom is free. If you choose to give something, payment happens entirely on Stripe's own page. Blossom never sees or stores your card details, and we deliberately keep no record of who has donated: there is no supporter marker on your account and no donor list.

Stripe holds the payment information and sends you a receipt, under its own privacy policy. If you set up a monthly donation you can stop it at any time from that receipt. Because we hold no link between a donation and a Blossom account, we cannot look up your payments for you, and you would need to contact Stripe or use your receipt.

Where Blossom shows how much a month has raised towards its running costs, our server works that out by asking Stripe for the payments made through Blossom's donation link that month and adding them up. Stripe's reply is read for two things only: what each payment was worth, and which payment it was, so a refund can be matched to the payment it reverses. Nothing about the person who paid is read or kept, and the only thing that survives is the monthly total. That is what lets the paragraph above stay true.

How we use information

We use information to provide the features you choose, keep your account and data secure, deliver reminders you enable, respond to support requests, and improve the service. Staff can view aggregate operational statistics for synced accounts, such as total account numbers, broad regions and module uptake. These statistics are not used for advertising, and local-only use leaves no server-side analytics trail.

How we protect synced data

Synced data is protected by row-level security so a signed-in account can access its own records, with the limited sharing and support exceptions described above. Our providers encrypt stored data. Synced data is not currently end-to-end encrypted, so authorised service administrators could theoretically access it where necessary to operate or secure the service. We treat that as a real limitation, not a hidden footnote.

Providers and external links

We currently use Supabase for authentication and synced data, Vercel to host Blossom, Stripe if you choose to donate, and your browser or operating system's push service if you enable notifications. Those services process data only to provide their services to us.

Where this happens today: synced data is stored in Ireland, and as of 13 August 2026 the server code that reads and writes it runs in Ireland as well. Until that date the server code ran in the United States, so synced data crossed the Atlantic in the course of ordinary use. It no longer does.

There are now no exceptions to that. Until August 2026 there was one: the optional Aurora AI chat sent what you typed to Anthropic, which processed it outside the UK and EU, and this page said openly that the safeguards for that transfer had not been reviewed. That feature has been removed, so none of your data leaves the UK and the EU any more.

Supabase and Vercel keep their own short-term technical logs of the requests made to Blossom, and those logs include IP addresses, the same as they would for any website. We do not use our providers' logs to work out who you are or what you looked at. They exist so the service can be kept running and secure.

Blossom's own code touches two things about your device, and this paragraph used to say it touched neither. When you make a request that we rate-limit, the server reads the forwarded IP address to count requests against; it is used as a counter in memory and is not written to a database. When something goes wrong and an error is reported to us, that report includes a broad browser and platform name worked out from your browser's user agent, for example a browser family and whether you are on Android, so we can tell whether a bug affects everybody or only one kind of device. Neither is used to identify you, and neither is combined with your account.

Regional resources are curated by Blossom's team. Opening a resource may take you to an external organisation's website, which has its own privacy policy. Blossom is not affiliated with every organisation listed.

Retention and deletion

You can delete your whole Blossom account from inside the app. It is in Account & sync, under Delete your account. It takes two steps and asks you to type the word delete, so it cannot happen by a mistaken tap, and that is the whole of it: we do not ask why you are going, and there is nothing offered to make you stay.

What it removes. Your account, and everything synced under it, meaning everything listed under “What can sync when you choose it” above. That includes records you had already deleted and which the server was still holding as marked deleted. Your notification subscriptions go too, so reminders stop reaching your devices. Any Trusted Circle grants and Bridge links you created stop working, because the records behind them no longer exist. So do any support tickets you opened, including the replies staff sent you. One part of it sits outside your own account and goes anyway: the entries recording that you opened something another person shared with you, which live in their access history rather than yours.

It also clears Blossom's data from the device you do it on, and signs you out. There is one exception, and the app tells you when it applies: if the Blossom data on that device belongs to a different account, it is left alone, because deleting your account must never take someone else's entries off a shared device. If any part of the deletion fails, nothing on your device is touched and Blossom says plainly that your account still exists.

What it does not reach, said here rather than left for you to find out. Anything you posted to the public ideas board, and any bug report, contact email or staff application you sent, is not attached to your account at all, so it stays; email us if you want one removed. Error reports from when Blossom broke stay as well, in the error log described above. Blossom on your other devices keeps its own local copy until you clear it there. Exports you have downloaded are yours. And nothing can pull back something a share recipient has already read, copied or saved.

Three things that account deletion does not change, because they are separate and are all still true. Switching sync off leaves whatever was already uploaded in place. Deleting all data in Settings clears that device and does not touch a synced account. And when you delete a single record while sync is on, the server marks it deleted and stops serving it rather than erasing the text straight away. The one route that removes data from the server without removing your account is turning off an individual category under Choose what syncs, which offers to purge that category and really does delete those rows.

Deletion from the live database happens when you press the button, not on a queue. Our providers keep their own backups and short-term technical logs on their own timers, so a copy can survive there for a while afterwards. We are still setting the precise retention periods for support cases, access logs, feedback, applications and backups. Those periods will be published before wider public release.

Your rights and choices

Depending on the law that applies to you, you may have rights to access, correct, erase, restrict, object to, or receive a copy of your personal data, and to complain to the UK Information Commissioner's Office. You can already export, pause sync, sign out, manage sharing, delete this device's data and delete your account outright through Blossom's own settings, without asking us for any of it. A final reviewed policy will state the legal bases and special-category health-data condition used for each processing purpose.

Aurora

Aurora is the name of Blossom's gentle suggestions: the occasional card on Home saying something like “one of your supplies could use a look”. It is rule-based and it runs entirely on your device. It reads what is already stored there, works out whether anything is worth mentioning, and says at most one thing. No part of it sends anything anywhere, and you can set how often it speaks up, or switch it off, in Settings.

The only thing that leaves your device is a small record of which suggestions you have already been shown, and only if you have sync switched on, so a second device does not repeat one you have seen. It contains no words you wrote.

There used to be a second, separate feature also called Aurora: an optional AI chat that sent what you typed to Anthropic. It was removed in August 2026, along with the closed beta it was part of. Nothing in Blossom now sends your data outside the UK and the EU. If you used that chat, its history was only ever stored on your own device, and deleting all data in Settings clears it.

Separately from the above, most of Blossom's code is written with the help of AI. That is a fact about how the app is built rather than about your data, so it is not part of this policy, but it is declared in full on How Blossom is made.

Changes to this policy

If we make a meaningful change, we will update the date on this page and, where appropriate, tell signed-in users in the app.

Contact

Email support@projectblossom.net for anything at all, including data requests, complaints, or just to ask what we hold. Inside the app, Settings then Contact support reaches the same inbox.

If you are in the UK and you are not happy with how we have handled something, you can complain to the Information Commissioner's Office at ico.org.uk. You are welcome to go to them directly, though we would rather have the chance to put it right first.

Also see our Terms of Service.