Privacy Policy

Last updated: August 17, 2026

1. Who We Are

Blossom ("Blossom," "we," "us," or "our"), operated from the Republic of Türkiye, provides the Blossom platform — the websites at blossai.com, the Blossom web application, the Blossom mobile applications, the Blossom developer API, and all related features (together, the "Service"). Blossom is the data controller responsible for personal data processed in connection with the Service.

This Privacy Policy explains what we collect, why we collect it, who we share it with, and the rights you have. It applies to account holders, visitors to our websites, and — because Blossom analyzes publicly available social media content — to creators whose public content appears in the Service (see Section 4).

For any privacy question or request, contact privacy@blossai.com. Our registered business details are available on request through the same address.

2. Information We Collect From You

2.1 Account and Profile Information

  • Name, display name, and email address
  • Authentication data (managed via Supabase Auth or Google sign-in; we never see or store your Google password)
  • Avatar image, if you provide one
  • Answers you give during onboarding — including any quiz or questionnaire completed before you create an account (content niche, goals, experience level, platform focus)
  • Language and interface preferences

2.2 Workspaces and Content You Add

  • Brand or client workspaces you create, including their names, categories, and settings
  • Videos, audio, images, and other files you upload for analysis or store in your asset library, plus extracted derivatives (frames, audio tracks, transcripts, waveform features)
  • Social media URLs you submit for analysis
  • Scripts, drafts, notes, briefs, calendar entries, favorites, and production-board items you create
  • Team and organization data: members you invite, their roles, and workspace assignments

2.3 Connected Social Accounts

If you connect an Instagram or TikTok account, we collect and store:

  • OAuth access tokens issued by the platform (stored encrypted; we never receive your platform password)
  • Profile information the platform makes available (username, bio, follower/following counts, avatar)
  • Post data and performance metrics available through the platform's or our data providers' APIs

We do not access your direct messages or private content. If you use publishing features, we transmit the content you explicitly choose to publish, only when you instruct us to. You can disconnect an account at any time in settings, which revokes our access going forward.

2.4 Mentor Conversations and Connected Tools

  • Messages you exchange with the Blossom mentor, and the context the mentor is given to answer them (your workspace data, analyses, and account state)
  • Token-usage metering data (how much AI capacity your conversations consume)
  • If you connect external tools to the mentor (via MCP or similar integrations): the connection credentials you provide (stored encrypted) and the data those tools return when the mentor calls them at your direction

Mentor messages and context are processed by our AI providers (Section 6). Data retrieved from tools you connect is processed only to answer your requests and is subject to the third-party tool's own terms.

2.5 Payment and Subscription Data

Web payments are processed by Paddle, our merchant of record. Paddle collects your payment details directly under its own privacy policy; card numbers and bank details never touch our servers. We receive transaction confirmations, subscription status, plan, country, and billing history. Purchases made through the Apple App Store or Google Play, where offered, are processed by Apple or Google under their terms.

2.6 Usage, Device, and Log Data

  • Features used, analyses run, searches performed, and items saved
  • Pages viewed, referrers, session identifiers, and interaction events (collected by our own first-party analytics)
  • Device type, operating system, browser type, app version, and coarse location (country/region derived from IP)
  • IP address, timestamps, and diagnostic logs (errors, performance measurements)
  • API request logs when you use the developer API (endpoint, token identifier, volume, timing)

2.7 Communications

Support requests, emails you send us, and survey or feedback responses, including their contents and metadata.

3. How We Use Your Information

  • Providing the Service: running AI analyses on content you submit, generating scripts and recommendations, powering the mentor, displaying trends and insights, syncing connected accounts, publishing content at your direction, and operating team workspaces
  • Billing and account management: managing subscriptions, plan limits, credits, and trials
  • Communication: transactional emails (verification, password reset, billing), calendar reminders and push notifications you enable, responses to support requests, and — with your consent where required — product news
  • Improvement and safety: measuring feature usage, monitoring AI output quality, debugging, capacity planning, preventing fraud and abuse, and enforcing our Terms of Service
  • Marketing measurement: understanding which campaigns and landing pages bring visitors who sign up (Section 7)
  • Legal compliance: tax, accounting, and responding to lawful requests

We do not sell your personal data, and we do not use the content you upload to train AI models.

4. Publicly Available Social Media Content

A core part of the Service is analyzing what makes public social media content perform. To do this, we collect publicly available content and metadata from platforms such as Instagram and TikTok through licensed third-party data providers — including public posts, captions, engagement metrics, and public profile information of the creators who published them (usernames, follower counts, bios).

  • We collect only information the creator has made public on the platform; we never access private accounts, private posts, or direct messages
  • We process this data for analytics, trend identification, benchmarking, and educational breakdowns of content technique — not to build marketing profiles of the creators or to contact them
  • Where the GDPR applies, we process this data on the basis of our legitimate interest in providing content-performance analytics (Art. 6(1)(f) GDPR), balanced against the fact that the data was made public by the creator for public consumption
  • Metrics reflect what platforms and providers report and may lag or differ from live values

If you are a creator and would like your public content or profile excluded from Blossom, email privacy@blossai.com from an address or account that lets us verify you control the profile. We will remove the content from our corpus and block future collection of that profile. Creators also have all rights described in Sections 13–15.

5. AI Processing

AI analysis is what the Service does, so content you submit is processed by machine-learning systems:

  • Video and image analysis: uploaded or referenced media is processed to extract frames, audio, and transcripts, which are sent to our AI providers for analysis
  • Audio analysis: beats, energy, and musical structure are computed on our own servers; derived descriptors may be included in AI prompts
  • Text generation: scripts, suggestions, classifications, and mentor answers are generated by large language models using your inputs and workspace context
  • Voice generation: where you use voiceover features, the text you provide is sent to a speech-synthesis provider

Our AI providers currently include Google (Gemini models via Google Cloud Vertex AI), Anthropic (Claude models), OpenAI, and ElevenLabs. We use paid API tiers whose terms prohibit the provider from using our customers' content to train their models. Which provider handles a given operation may change; the no-training commitment is a condition of any provider we use for your content.

5.1 Automated Decision-Making

Scores, classifications, and recommendations produced by the Service are informational outputs, not decisions with legal or similarly significant effects on you (GDPR Art. 22). Plan limits and abuse prevention may use automated rules; if an automated action materially affects your account, you can request human review at privacy@blossai.com.

6. Sharing and Sub-processors

We share personal data only with processors that help us run the Service, and only what each needs:

  • Supabase — authentication, database, and file storage (encrypted at rest and in transit)
  • Google Cloud (Vertex AI), Anthropic, OpenAI, ElevenLabs — AI analysis and generation (Section 5)
  • Paddle — payments and subscription management, as merchant of record
  • Apple and Google — app distribution, in-app purchases where offered, and push-notification delivery (APNs, Firebase Cloud Messaging)
  • Social data providers (including HikerAPI and LamaTok) — retrieval of publicly available platform data; URLs or usernames you submit are passed to them to fetch the public data
  • Analytics and attribution providers — Google Analytics, Meta, and AppsFlyer (Section 7)
  • Hosting, infrastructure, and email delivery providers — servers, content delivery, monitoring, and transactional email

Beyond processors, we disclose personal data only: to comply with law or valid legal process; to protect the rights, safety, or property of Blossom, our users, or the public; in connection with a merger, acquisition, or asset sale (your data remains subject to this policy); with other members of your team or organization as the product's sharing features imply; and as aggregated or de-identified statistics that cannot identify you.

Each processor is bound by a data processing agreement consistent with applicable law.

7. Analytics, Advertising, and Attribution

We use the following measurement technologies:

  • First-party analytics: our own tracker records page views, scroll depth, and product events, sent only to our servers
  • Google Analytics 4: aggregate website usage measurement on our websites and web app
  • Meta Pixel: on our websites, to measure whether our advertising on Meta platforms leads to sign-ups; Meta may associate these events with your Meta account under Meta's own privacy policy
  • AppsFlyer: in our mobile apps, to attribute app installs to the campaign that produced them

These tools may set cookies or use device identifiers and constitute "sharing" for cross-context behavioral advertising as some laws define it. Google Analytics and the Meta Pixel do not load until you accept them in the cookie banner shown on your first visit. Your choices:

  • Choose "Essential only" in the cookie banner — the tools above then stay off; change your choice any time on our Cookie Policy page
  • Opt out at any time by emailing privacy@blossai.com with the subject "Ad tracking opt-out" (see also Section 14 for California)
  • Use browser tracking protection, the Google Analytics opt-out add-on, Meta's ad preferences, and your device's ad-tracking settings (iOS App Tracking Transparency, Android ads personalization)

We do not run third-party ad networks inside the product, and we do not sell your data to data brokers.

8. Cookies and Local Storage

  • Essential: authentication tokens (Supabase Auth), session state, security
  • Preferences: theme, language, layout settings
  • Measurement: first-party analytics session, Google Analytics, and Meta Pixel cookies (Section 7)
  • Payments: cookies Paddle needs to process a transaction
  • Sign-in: cookies Google sets when you use Google sign-in

Blocking essential storage will break sign-in; everything else is optional. The full list of cookies, their durations, and the consent controls are in our Cookie Policy.

9. Legal Bases (GDPR / UK GDPR)

Where the GDPR or UK GDPR applies, we process personal data on these bases:

  • Contract (Art. 6(1)(b)): providing the Service you signed up for — accounts, analyses, mentor, billing, support
  • Legitimate interests (Art. 6(1)(f)): securing the Service, preventing fraud, first-party product analytics, processing publicly available creator content (Section 4), and defending legal claims — you may object at any time (Section 13)
  • Consent (Art. 6(1)(a)): non-essential cookies and pixels, marketing emails, push notifications, and connecting social accounts or external tools — withdrawable at any time without affecting prior processing
  • Legal obligation (Art. 6(1)(c)): tax, accounting, and lawful requests

We do not intentionally process special categories of personal data; please do not submit such data through the Service.

10. Türkiye (KVKK)

For persons in the Republic of Türkiye, personal data is processed in accordance with the Law on the Protection of Personal Data No. 6698 ("KVKK"), with Blossom acting as data controller (veri sorumlusu). Processing rests on the conditions in KVKK Articles 5 and 6, corresponding to the bases in Section 9. Under KVKK Article 11 you have the right to learn whether your data is processed, request information, learn the purpose, know the third parties it is transferred to, request correction or deletion, object to results produced exclusively by automated systems, and claim damages for unlawful processing.

To exercise these rights, apply to privacy@blossai.com in accordance with the Communiqué on Application Procedures. We respond within 30 days. Cross-border transfers described in Section 12 are carried out in accordance with KVKK Article 9.

11. Data Retention

  • Account, workspace, and content data: for the life of your account
  • Uploaded media and analyses: until you delete them or your account
  • Mentor conversations: until you delete them or your account
  • Usage and diagnostic logs: up to 12 months
  • Payment and tax records: as long as tax and commercial law require (typically 6–10 years)
  • Public creator content (Section 4): for as long as it is analytically relevant, subject to removal requests

After account deletion we erase or irreversibly de-identify your personal data within 30 days, except records we must keep by law or need for fraud prevention and the defense of legal claims.

12. International Transfers

Our infrastructure and processors operate in the European Union, the United States, and other countries. Where data moves across borders from the EEA, UK, or Switzerland, we rely on European Commission adequacy decisions (including the EU–U.S. Data Privacy Framework for certified recipients) or Standard Contractual Clauses with supplementary measures (encryption in transit and at rest, access controls). Transfers from Türkiye follow KVKK Article 9. You can request details of the mechanism covering a specific transfer at privacy@blossai.com.

13. Your Rights

Depending on where you live, you may have the right to:

  • Access the personal data we hold about you and receive a copy
  • Correct inaccurate or incomplete data
  • Delete your data ("right to be forgotten") — see also Section 16
  • Receive your data in a portable, machine-readable format
  • Restrict or object to processing, including processing based on legitimate interests
  • Withdraw consent at any time, without affecting prior lawful processing
  • Not be subject to solely automated decisions with legal effect (Section 5.1)

Exercise any right at privacy@blossai.com. We verify requests against your account and respond within 30 days (extendable for complex requests, with notice). If you are in the EEA, UK, or Switzerland you may also lodge a complaint with your supervisory authority; in Türkiye, with the Personal Data Protection Authority (KVKK Kurumu).

14. California Privacy Rights (CCPA / CPRA)

California residents have the rights to know, delete, correct, opt out of sale or sharing, limit use of sensitive personal information, and non-discrimination.

Categories collected (past 12 months): identifiers (name, email, IP); commercial information (subscription history); internet activity (usage logs, analytics events); audio/visual information (uploaded media); professional information (workspace and brand data you provide); inferences (content preferences). Sources: you, your devices, connected platforms, and our data providers. We do not collect government identifiers, precise geolocation, or biometric data.

Sale and sharing: we do not sell personal information for money. Our use of the Meta Pixel and similar tools may constitute "sharing" for cross-context behavioral advertising under the CPRA. To opt out, email privacy@blossai.com with the subject "California opt-out", or use the controls in Section 7. We honor opt-out requests regardless of how they reach us.

You may use an authorized agent; we will require proof of authorization and verify your identity through your account.

15. Security and Breach Notification

  • TLS encryption in transit; AES-256 encryption at rest
  • Row-level access controls isolating each account's and workspace's data
  • OAuth tokens and connection credentials stored encrypted
  • Short-lived, automatically expiring session tokens
  • Production access restricted to authorized personnel
  • Payment data handled entirely by Paddle — it never reaches our servers

If a breach is likely to put your rights and freedoms at risk, we will notify the competent authority within 72 hours of becoming aware and, where the risk to you is high, notify you without undue delay. No internet service can guarantee absolute security.

16. Deleting Your Account and Data

You can delete your account and all associated data from your account settings, or by following the steps at blossai.com/delete-account, or by emailing privacy@blossai.com. Deletion covers your profile, workspaces, uploads, analyses, mentor conversations, and connections, subject to the legal retention exceptions in Section 11.

17. Children

The Service is not directed to children. We do not knowingly collect personal data from anyone under 16 (or under 13 in the United States, per COPPA). If you believe a child has provided us personal data, contact privacy@blossai.com and we will delete it promptly.

18. Third-Party Links and Platforms

The Service links to third-party platforms and websites (Instagram and TikTok profiles, external tools you connect, and others). Their privacy practices are their own; this policy does not cover them. Blossom is not affiliated with, endorsed by, or sponsored by Instagram, Meta, TikTok, or ByteDance.

19. Changes to This Policy

We may update this policy as the Service, technology, or the law changes. For material changes we will give at least 14 days' notice by email or in-app notification before they take effect. The "Last updated" date above reflects the current version. The English version of this policy controls over any translation.

20. Contact

Privacy requests: privacy@blossai.com

General support: support@blossai.com

Legal notices: legal@blossai.com

We aim to answer every privacy inquiry within 30 days.