1. Who this policy is from
Bloom is a social publishing tool: you connect the accounts you already own, and Bloom plans, schedules and publishes posts to them on your behalf. Bloom is operated by Gigde (operating Autocloz and Bloom), Bengaluru, Karnataka, India, who is the data controller for the purposes of the GDPR, India’s DPDP Act and the equivalent operator under other privacy laws.
Questions, access requests and complaints: privacy@autocloz.com.
2. What Bloom collects
Three kinds of data, and nothing else:
- Account data— your email address, a hashed password, your workspace and brand names, and your team’s roles. Given by you when you sign up or accept an invitation.
- Content you create — drafts, captions, images and video you upload, schedules, campaigns and notes.
- Platform Data — the access token for each account you connect, the id and name of that Page, profile or channel, the posts Bloom published through it, and the public engagement counts on those posts (likes, comments, shares, views, follower totals). Obtained from the network you connected, and only after you authorise it.
Bloom does notcollect your friends list, your contacts, your location, your private messages beyond the conversations you explicitly manage in Bloom’s inbox, or any special-category data. Bloom does not buy data about you from anyone.
3. Data obtained from Meta
When you connect a Facebook Page, an Instagram Business or Creator account, or a Threads profile, Meta asks you to authorise Bloom and then issues an access token. From that point Bloom holds:
- the access token itself, encrypted at rest;
- your app-scoped user id — an identifier unique to Bloom, which cannot be used to identify you on any other app;
- the id and name of each Page, account or profile you chose to connect;
- the posts Bloom published on your instruction, and the public engagement metrics Meta reports for them.
That data is used for exactly one purpose: doing what you asked Bloom to do — publish your posts on schedule, show you how they performed, and let you reply to comments and messages from inside Bloom. It is not used to build a profile of you, is not used to train any model, and is not sold, rented or shared for anyone else’s marketing.
Bloom’s use of information received from Meta APIs adheres to the Meta Platform Terms and Developer Policies, including their restrictions on use, retention and onward transfer.
Revoking Bloom’s access in your Facebook settings takes effect immediately: Meta notifies Bloom, and Bloom switches the affected connections off and stops using the token. To have the data erased as well, see Data Deletion.
4. Why Bloom is allowed to hold it
- Performance of a contract — account data and content, without which there is no product to provide.
- Your consent— every connection to a social network, given in that network’s own authorisation screen and withdrawable there or in Bloom at any time.
- Legitimate interests — keeping the service secure and working (error logs, rate limiting, abuse prevention), balanced against your rights and limited to what that requires.
5. Who Bloom shares it with
The social networks you connect, because that is where your posts are being published. Beyond that, only the infrastructure Bloom runs on — hosting, and, where you have enabled them, an AI provider for caption generation and an email provider for notifications — each acting on our instructions and receiving no more than the request requires.
Bloom does not sell personal data, does not share it for cross-context behavioural advertising, and has no advertising business of its own.
6. How long it is kept
- Access tokens — until you disconnect the account, revoke access on the network, or ask for deletion. Then removed, not archived.
- Content and analytics — for as long as your workspace exists, so your history stays useful. Deleted with the workspace.
- Deletion records — the confirmation code and outcome of a deletion request are kept so you can check what happened. They contain no personal data beyond the app-scoped id that was asked about.
7. How it is protected
Credentials and access tokens are encrypted at rest with a key held outside the database. Passwords are stored only as salted hashes. Each workspace is scoped so one customer’s data is not reachable from another’s session, and administrative access is separated from customer access. No system is perfect; if a breach ever affects you, you will be told, and the relevant regulator notified where the law requires it.
8. Your rights
Depending on where you live, you may have the right to access your data, correct it, delete it, restrict or object to its processing, take it elsewhere in a portable form, and complain to a supervisory authority. Bloom does not discriminate against anyone for exercising them.
The fastest route to most of these is inside the product: Settings for account data, Accounts to disconnect a network. For erasure, see Data Deletion. Anything else, email privacy@autocloz.com and expect a reply within 30 days.
9. Cookies
Bloom sets one cookie, which holds your sign-in session. It is strictly necessary — the product cannot keep you logged in without it — so no consent banner is shown. Bloom sets no advertising cookies and no third-party trackers.
10. Children
Bloom is a business tool and is not directed at children. Accounts are not knowingly created for anyone under 16 (or the minimum age in your country, if higher). If you believe a child has an account, write to privacy@autocloz.com and it will be removed.
11. Changes to this policy
Material changes are announced in the product before they take effect, and the date at the top of this page always reflects the current version. Continuing to use Bloom after a change means accepting it; if you would rather not, you can delete your data on the Data Deletion page.
12. Contact
privacy@autocloz.com · Bengaluru, Karnataka, India
See also Bloom’s Terms of Service. This policy covers Bloom only; Autocloz has its own privacy policy.