Cookie Policy

Last updated: August 17, 2026

This policy explains the cookies and similar technologies (localStorage, pixels, SDK identifiers) used by Blossom — the websites at blossai.com, the Blossom web application, and the Blossom mobile applications. It supplements our Privacy Policy.

"Cookies" here covers both browser cookies and browser storage such as localStorage; the same rules apply to both.

1. How Consent Works

On your first visit a banner asks whether we may use non-essential cookies. Nothing non-essential loads before you answer:

  • Accept all — analytics and advertising-measurement cookies (Sections 4 and 5) are enabled
  • Essential only — only the cookies in Sections 2 and 3 are used; Google Analytics and the Meta Pixel never load

Your choice is stored on your device (in the blossom_consent entry) so we don't ask again. Change it any time:

2. Essential Cookies and Storage

Required for the Service to function; they cannot be switched off. Blocking them in your browser will break sign-in.

  • Authentication session (Supabase Auth, sb-* keys) — keeps you signed in; for the life of your session
  • Consent record (blossom_consent) — remembers your banner choice; until you clear it
  • Preferences (blossom_theme, language, layout) — remembers how you set up the interface; until you clear them
  • Landing assignment (blsm_lp_variant) — keeps the landing-page version you first saw consistent across visits; up to 90 days, permanent after sign-up
  • Payment cookies (Paddle) — set during checkout to process the transaction, under Paddle's own policy
  • Sign-in cookies (Google) — set when you use Google sign-in, under Google's own policy

3. First-Party Analytics

Our own tracker (blsm_analytics_session) records page views, scroll depth, and product events, and sends them only to our servers — no third party receives them and no cross-site tracking is involved. We use this on the basis of our legitimate interest in understanding how the product is used; Section 13 of the Privacy Policy explains how to object.

4. Analytics Cookies (Consent-Gated)

Loaded only after you choose "Accept all":

  • Google Analytics 4 (_ga, _ga_*) — aggregate usage measurement of our websites and web app; persists up to 2 years. Google's processing is described in Google's cookie policy

5. Advertising-Measurement Cookies (Consent-Gated)

Loaded only after you choose "Accept all":

  • Meta Pixel (_fbp) — measures whether our advertising on Meta platforms (Facebook, Instagram) leads to visits and sign-ups; persists up to 90 days. Meta may associate these events with your Meta account under Meta's privacy policy; manage this in Meta's ad preferences

We do not run third-party ad networks inside the product, and we do not sell your data.

6. Mobile Apps

The mobile apps do not use browser cookies, but use equivalent technologies:

  • AppsFlyer — attributes app installs to the campaign that produced them, using device identifiers where your OS settings allow
  • Push notifications (Apple APNs, Firebase Cloud Messaging) — device tokens used only to deliver notifications you enable

Control these through your device: on iOS, App Tracking Transparency (Settings → Privacy → Tracking) and notification settings; on Android, "Delete advertising ID" / ads personalization and notification settings.

7. Browser Controls

Beyond our banner, every browser lets you block or delete cookies in its settings, and tracking-protection features (and the Google Analytics opt-out add-on) work independently of our controls. Blocking essential storage will prevent sign-in from working.

8. Changes and Contact

If we add or change a cookie category, we will update this page and, where the change requires it, ask for your consent again. Questions: privacy@blossai.com.