Privacy Policy
Last updated: May 19, 2026
[REPLACE: Full legal entity name, e.g., "Blossom Technologies Inc."] ("Blossom," "we," "us," or "our") is the data controller responsible for personal information processed in connection with the Blossom platform (the "Service"). Our registered office is at [REPLACE: Full business address].
This Privacy Policy explains how we collect, use, store, and share your personal information when you use the Service. By using the Service, you acknowledge the practices described here. For privacy questions or requests, contact us at privacy@blossai.com.
1. Information We Collect
1.1 Account Information
When you create an account, we collect:
- Full name and display name
- Email address
- Profile avatar (if provided)
- Authentication credentials (managed securely via Supabase Auth or Google OAuth)
- Onboarding preferences (content niche, goals, experience level)
1.2 Content You Upload
When you use our content analysis features, we process:
- Video files uploaded for analysis
- Audio extracted from video content for beat, energy, and music analysis
- Social media URLs submitted for analysis
- Metadata associated with uploaded content (file type, duration, dimensions)
1.3 Connected Social Accounts
If you connect your Instagram or TikTok accounts, we may access:
- Public profile information (username, bio, follower/following counts)
- Public post data (captions, engagement metrics, timestamps)
- Content performance metrics available through public APIs
We never access your direct messages, private posts, or platform credentials. You can disconnect accounts at any time from your account settings.
1.4 Usage Data
We automatically collect:
- Features used and analysis history
- Search queries within the platform
- Interaction patterns (formats saved, content viewed)
- Device type, browser type, and general location (country level)
- Timestamps of activity and session duration
1.5 Payment Information
Payment processing is handled entirely by Paddle, our merchant of record. We do not store your credit card numbers, bank account details, or other sensitive financial data on our servers. We only receive transaction confirmations, subscription status, and billing history from Paddle.
2. How We Use Your Information
We use your information for the following purposes:
2.1 Providing the Service
- Performing AI-powered content analysis (visual, audio, narrative, engagement, strategic)
- Generating personalized content scripts and recommendations
- Displaying trending content, viral formats, hooks, and tactics
- Providing influencer discovery and performance insights
- Managing your subscription and feature access
2.2 Improving the Service
- Analyzing usage patterns to improve features and user experience
- Monitoring AI analysis quality and accuracy
- Identifying and fixing bugs or performance issues
- Developing new features based on aggregated user behavior
2.3 Communication
- Sending account-related notifications (verification, password reset, subscription changes)
- Responding to support requests
- Notifying you of material changes to our terms or policies
2.4 Security and Compliance
- Detecting and preventing fraudulent or unauthorized access
- Enforcing our Terms of Use
- Complying with legal obligations
3. Legal Basis for Processing (EEA / UK Users)
If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, we rely on the following legal bases under the GDPR / UK GDPR to process your personal data:
- Performance of a contract (Art. 6(1)(b)): To provide the Service you have signed up for — account management, AI analysis of content you submit, subscription billing, and customer support.
- Legitimate interests (Art. 6(1)(f)): To secure the Service, prevent fraud, improve features through aggregated usage analytics, and communicate with you about Service updates. You may object to processing based on legitimate interests at any time (see Section 9).
- Consent (Art. 6(1)(a)): For optional features such as connecting social media accounts, marketing emails (where applicable), and any non-essential cookies. You may withdraw consent at any time without affecting prior lawful processing.
- Legal obligation (Art. 6(1)(c)): To comply with applicable laws, tax/accounting rules, lawful requests by public authorities, and to respond to legal claims.
We do not process special categories of personal data (such as health, biometric, or political data) intentionally. Please do not submit such data through the Service.
4. AI Processing and Automated Decision-Making
A core part of our Service involves AI-powered analysis. Here is how your data flows through our AI systems:
- Video analysis: Uploaded videos are processed to extract visual frames, which are sent to Google Gemini for AI analysis under Google's paid API terms applicable to our account.
- Audio analysis: Audio is extracted from videos and analyzed on our servers for beats, energy patterns, drops, and musical sections. Audio metadata may be included in AI prompts for contextual analysis.
- Text analysis: Captions, hooks, and narrative content are processed through AI models to generate insights on storytelling, engagement strategy, and viral potential.
- Batch processing: Multiple analysis dimensions may be processed in parallel to deliver comprehensive results efficiently.
We instruct our AI providers not to use your content to train their models, in accordance with the API tier under which we operate. We do not share your uploaded content with other users.
4.1 Automated Decision-Making
The Service uses automated processing to generate scores, classifications, and recommendations (e.g., virality scores, hook classifications, format matches). These outputs are informational suggestions only. They do not produce legal or similarly significant effects on you within the meaning of GDPR Article 22. If you would like a human review of any automated output that materially affects your account, contact privacy@blossai.com.
5. Third-Party Services (Sub-processors)
We rely on the following third-party services ("sub-processors") to operate the platform:
- Supabase: Authentication, database storage, and real-time services. Your account data and analysis results are stored in Supabase with encryption at rest and in transit.
- Google Gemini (Google LLC): AI-powered content analysis. Video frames and text content are sent to Google's API for processing under Google's API terms.
- Paddle: Payment processing and subscription management. Paddle acts as our merchant of record and handles all financial transactions. Paddle's privacy policy governs payment data.
- Instagram & TikTok data providers (HikerAPI, LamaTok): We use authorized third-party APIs to retrieve publicly available social media data for trending content, influencer insights, and content analysis.
- Hosting and infrastructure providers: Cloud hosting, content delivery, and logging providers used to run and monitor the Service.
Each sub-processor is bound by data processing agreements consistent with applicable law. We encourage you to review each provider's privacy policy for a complete understanding of how your data may be processed.
6. Data Storage, Security, and Breach Notification
We implement industry-standard security measures to protect your data:
- All data is encrypted in transit using TLS/SSL
- Data at rest is encrypted using AES-256 encryption via Supabase
- Authentication tokens are securely managed and expire automatically
- Access to production systems is restricted to authorized personnel
- Uploaded video files are stored securely and access-controlled
- Payment data is handled entirely by Paddle and never touches our servers
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of it (as required by GDPR Art. 33) and, where the breach is likely to result in a high risk to you, we will notify you without undue delay.
While we take all reasonable precautions, no method of transmission over the Internet or electronic storage is 100% secure, and we cannot guarantee absolute security.
7. Data Sharing
We do not sell, rent, or trade your personal information. We may share your data only in the following circumstances:
- Service providers: With third-party sub-processors listed above, solely for the purpose of operating the Service
- Legal requirements: When required by law, regulation, legal process, or governmental request
- Safety: To protect the rights, property, or safety of Blossom, our users, or the public
- Business transfers: In connection with a merger, acquisition, or sale of assets, in which case your data would remain subject to this Privacy Policy
- Aggregated data: We may share anonymized, aggregated statistics that cannot be used to identify individual users
8. Data Retention
- Account data: Retained for the duration of your active account
- Uploaded content: Stored for analysis purposes and available for deletion upon your request
- Analysis results: Retained in your analysis history as long as your account is active
- Usage logs: Retained for up to 12 months for service improvement and security purposes
- Payment records: Retained as required by tax and financial regulations (typically 6–10 years depending on jurisdiction)
After account deletion, we remove your personal data within 30 days, except where retention is required by law or for legitimate business purposes (such as fraud prevention or financial record-keeping).
9. Your Rights
Depending on your jurisdiction, you may have the following rights regarding your personal data:
- Access: Request a copy of the personal data we hold about you
- Correction: Request correction of inaccurate or incomplete data
- Deletion ("right to be forgotten"): Request deletion of your personal data and account
- Portability: Request your data in a structured, commonly used, machine-readable format
- Restriction: Request restriction of processing in certain circumstances
- Objection: Object to processing based on legitimate interests
- Withdrawal of consent: Withdraw your consent at any time where processing is based on consent, without affecting prior lawful processing
- Right not to be subject to solely automated decisions: See Section 4.1
To exercise any of these rights, contact us at privacy@blossai.com. We will respond within 30 days (extendable by an additional 60 days for complex requests, with notice to you).
Right to lodge a complaint: If you are in the EEA, UK, or Switzerland and believe we have not addressed your concern adequately, you have the right to lodge a complaint with your local data protection supervisory authority. A list of EEA supervisory authorities is available at edpb.europa.eu.
10. California Privacy Rights (CCPA / CPRA)
If you are a California resident, the California Consumer Privacy Act (as amended by the CPRA) gives you the following rights regarding your personal information:
- Right to know: Categories and specific pieces of personal information we collect, the sources, the business purpose, and the categories of recipients
- Right to delete: Request deletion of personal information we have collected from you
- Right to correct: Request correction of inaccurate personal information
- Right to opt out of sale or sharing: See below
- Right to limit use of sensitive personal information
- Right to non-discrimination for exercising any of these rights
Do Not Sell or Share My Personal Information: Blossom does not sell your personal information for money, and does not share your personal information for cross-context behavioral advertising as those terms are defined under the CCPA/CPRA. We do not use third-party advertising cookies or trackers.
Categories collected in the past 12 months: Identifiers (name, email, IP); commercial information (subscription history); internet activity (usage logs, search queries); audio/visual information (uploaded videos and audio); inferences (content preferences). We do not collect Social Security numbers, government IDs, precise geolocation, biometric data, or other categories of sensitive personal information.
How to exercise California rights: Email privacy@blossai.com with the subject line "California Privacy Request." We will verify your request using information associated with your account. You may use an authorized agent — written permission and verification of your identity will be required.
11. Cookies and Local Storage
We use minimal browser storage for essential functionality:
- Authentication tokens: Stored securely to maintain your logged-in session (Supabase Auth)
- User preferences: Theme, layout, and interface settings
- Payment widget: Paddle may set cookies necessary to process your transaction
- OAuth providers: Google may set cookies when you sign in via Google
- Session data: Temporary data required for the Service to function
We do not use third-party advertising cookies, behavioral advertising trackers, or cross-site tracking technologies. We do not participate in ad networks.
12. International Data Transfers
Our Service infrastructure and our sub-processors (including Google, Supabase, and Paddle) may process data in the United States and other countries outside your country of residence. When personal data is transferred outside the EEA, UK, or Switzerland, we rely on one or more of the following safeguards required by Chapter V of the GDPR:
- Adequacy decisions of the European Commission where available (e.g., the EU–U.S. Data Privacy Framework for certified U.S. recipients)
- Standard Contractual Clauses (SCCs) approved by the European Commission, and the UK International Data Transfer Addendum where applicable
- Supplementary technical and organizational measures such as encryption in transit and at rest, access controls, and pseudonymization where appropriate
You may request a copy of the transfer mechanisms used by contacting privacy@blossai.com.
13. Children's Privacy
The Service is not directed to children. We do not knowingly collect personal information from children under 16 (or under 13 in the United States, as defined by the Children's Online Privacy Protection Act, "COPPA"). If we become aware that we have collected personal data from a child under the applicable age without verified parental consent, we will take steps to delete that information promptly. If you believe a child has provided us with personal information, please contact privacy@blossai.com immediately.
14. Third-Party Links
The Service may contain links to third-party websites or social media platforms (such as Instagram and TikTok profiles, trending content, etc.). We are not responsible for the privacy practices of these external sites. We encourage you to review the privacy policies of any third-party sites you visit through links on our platform.
15. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. Material changes will be communicated via email or in-app notification at least 14 days before taking effect (or such longer period as required by applicable law). The "Last updated" date at the top of this page indicates when the policy was last revised.
16. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact us at:
Privacy inquiries: privacy@blossai.com
Mailing address: [REPLACE: Full mailing address]
EU / UK Representative (where applicable): [REPLACE: Name, address, and email of your appointed Article 27 GDPR / UK GDPR representative — required if you are not established in the EU/UK but offer services to data subjects there].
We aim to respond to all privacy-related inquiries within 30 days.