Privacy Policy
Effective August 5, 2026
Overview
Bloomiro ("Bloomiro," "we," "us") provides a search visibility action platform for businesses. This Privacy Policy explains what personal and project data we collect, how we use it, who we share it with, and what choices you have.
By creating an account or using our website, dashboard, API, or MCP (Model Context Protocol) tools, you agree to this Privacy Policy. If you use Bloomiro on behalf of a company or organization, you confirm that you have authority to accept this policy for that organization.
Who we are
Bloomiro operates the service at bloomiro.com and related subdomains. For privacy questions or requests, reach us at hi@bloomiro.com.
For most customer project data (websites you add, Search Console metrics you connect, competitors you track, tasks, and analysis results), we process data on your instructions to provide the service. For account, billing, security, and service-improvement data described below, we act as the data controller.
Bloomiro does not currently maintain an establishment in the European Economic Area or the United Kingdom. EEA and UK privacy inquiries can be sent to hi@bloomiro.com. If we appoint an EU or UK representative under GDPR Article 27 or UK GDPR Article 27, we will publish their contact details in this policy.
Information we collect
Account and organization data
- Name and email address when you register or are invited to a team
- Authentication data, including password hashes and, if you choose it, Google sign-in identifiers handled through our authentication provider
- Organization name, membership, and role within a workspace
- Preferences and settings you save in the dashboard
Project and visibility data
When you use Bloomiro, you or your team may provide or generate:
- Website URLs, brand names, and competitor names or domains
- Visibility profiles, keyword themes, page analyses, and task lists
- AI prompts you create for presence monitoring
- Comments and status updates on tasks
- Public web content from your site and competitor sites that we fetch during crawls and scans
Google Search Console (optional)
If you connect Google Search Console, we access Search Console data for the properties you authorize, such as queries, pages, clicks, impressions, CTR, average position, and related aggregates. If you use URL indexing requests, we send only the URLs you submit through the Google Indexing API. OAuth tokens are encrypted at rest in our database. We do not receive your Google account password.
Google Analytics (optional)
If you connect Google Analytics (GA4), we access read-only Analytics data for the properties you authorize, such as sessions, users, engagement metrics, countries, and traffic sources. OAuth tokens are encrypted at rest in our database. We do not receive your Google account password.
AI presence and SEO data
When you run features such as AI presence checks, we store:
- Prompt text, run metadata, mention summaries, and answer previews
- Larger result payloads in private object storage linked to your project
- Backlink summaries and related SEO metrics from third-party data providers
MCP and API usage
If you create MCP API keys or authorize MCP clients through OAuth, we store hashed key material, project scope, and an audit log of tool calls (tool name, credits used, latency, and success or error status). MCP tools return data from your connected project to the client you authorized.
Billing data
Paid plans and credit top-ups are processed by Stripe. We receive subscription status, plan identifiers, and billing metadata needed to run your account. Stripe collects payment card details directly; we do not store full card numbers on our servers.
Technical and usage data
- IP address, browser type, device information, and request logs for security
- Essential session cookies and local storage used to keep you signed in and remember basic UI preferences (for example, sidebar state)
- Rate-limit counters and short-lived cache entries in Redis
- Error and performance data needed to operate and debug the service
Cookies and similar technologies
We use only essential cookies and similar technologies needed to authenticate you, keep your session secure, and remember basic interface preferences. We do not use non-essential advertising cookies, and we do not place third-party tracking or analytics cookies on bloomiro.com for our own marketing measurement.
Connecting Google Analytics (GA4) through Bloomirouses Google's APIs to read reporting data for properties you authorize. That is separate from cookies on our marketing site, and it does not install Google Analytics tracking on bloomiro.com.
How we use information
We use the information above to:
- Provide, maintain, and secure the Bloomiro platform
- Crawl and analyze websites, generate visibility insights, tasks, and reports you request
- Sync and display Google Search Console and Google Analytics data you connect
- Run AI presence monitoring and related checks you initiate
- Expose project data through dashboard and MCP tools you authorize
- Process payments, credits, and invoices through Stripe
- Send transactional email, such as organization invites
- Detect abuse, enforce limits, and comply with law
- Improve reliability and fix bugs (using aggregated or de-identified data where possible)
We do not sell your personal information. We do not use your project content to train Bloomiro's own machine learning models.
Google user data and Limited Use
When you connect Google Search Console or Google Analytics, Bloomiro's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
What we access
- Google Search Console: performance and property data for sites you authorize, and indexing requests only when you submit a URL
- Google Analytics (GA4): read-only reporting data for properties you authorize
How we use Google user data
We use Google user data only to provide or improve user-facing features that are prominent in Bloomiro, including:
- Dashboard views for Search Console and Web analytics
- Tasks, insights, and reports derived from your connected project data
- MCP and API responses when you create API keys or authorize OAuth access to your project
We do not use Google user data to serve ads, for retargeting or interest-based advertising, to determine creditworthiness, or to train Bloomiro's own machine learning models.
How we store and share Google user data
OAuth tokens are encrypted at rest. Report summaries and connection metadata are stored in our database. Larger or cached report payloads may be stored in private object storage or short-lived cache tied to your project.
We do not sell Google user data. We do not transfer it to advertising platforms, data brokers, or information resellers. We share it only:
- With infrastructure providers that host Bloomiro (for example, database and object storage) solely to operate the service for you
- With third-party AI model inference when you run features that generate tasks, insights, or similar analysis from your project. We send those requests through OpenRouter to DeepInfra US-hosted AI models. DeepInfra does not use those inputs or outputs for training and does not retain prompt or response logs as a normal practice. Excerpts may include Search Console query and page metrics when those metrics are inputs to the feature you run. Google Analytics report data is used for dashboard and API display; we do not currently send GA4 report payloads into the AI inference pipeline, but if a future feature does, it will be covered by this disclosure and limited to providing the user-facing feature.
- With MCP or API clients you explicitly authorize to access your project
- When required for security, abuse investigation, or legal compliance
- As part of a merger, acquisition, financing, reorganization, or sale of assets, in which case Google user data may be transferred as part of the transaction, subject to this Privacy Policy. We will give notice of such a transfer where required by law.
Human access
Bloomiro employees, contractors, and agents do not read your Google Search Console or Google Analytics data except when you give affirmative agreement for a specific support request, when necessary to investigate security or abuse, or when required by law. Aggregated, de-identified operational metrics may be used internally to improve reliability.
Your controls
You can disconnect Google Search Console or Google Analytics at any time from project settings. Disconnecting removes stored OAuth tokens and stops new syncs. For Search Console, we also delete cached report data we stored for the project (daily metrics, queries, and pages). For Google Analytics, we delete the connection and tokens; short-lived cached report responses expire automatically (typically within hours). Derived items you already created in Bloomiro (for example, tasks that referenced Search Console metrics) may remain until you delete them or delete the project. You can also revoke Bloomiro's access in your Google Account permissions.
AI inference and third-party analysis
Some features send excerpts of your project data (for example, site summaries, page content, task context, and, when connected and relevant to the feature, Search Console query or page metrics) to third-party AI models to generate visibility profiles, task suggestions, and similar analysis.
For those AI model features, we route requests through OpenRouter to DeepInfraUS-hosted AI models. Per DeepInfra's terms and data privacy documentation, DeepInfra does not sell API inputs or outputs, does not use them to train models, and does not retain prompt or response content or logs as a normal practice (requests are processed in memory and discarded after the response). DeepInfra may keep limited data briefly only when needed for debugging or security, and generally logs metadata rather than prompt content. See DeepInfra's data privacy documentation.
Separate services support other product features:
- UI scraping of public consumer AI answer interfaces (for example ChatGPT, Gemini, Perplexity, and Google AI surfaces) for AI presence checks you run
- SEO and backlink data providers used only to deliver features you run
Those vendors process data according to their own terms and privacy policies. Sharing of Google user data with AI model inference is also described in the Google user data section above.
Service providers we use
We rely on infrastructure and subprocessors to run Bloomiro, including:
- Supabase for authentication and primary database storage
- Cloudflare for application hosting, API workers, and private object storage (R2)
- Upstash for caching and rate limiting (not a permanent data store)
- Stripe for payments and subscription billing
- Google for optional Google sign-in, Google Search Console API access, and Google Analytics API access you authorize
- Cloudflare Email Service for transactional email
- OpenRouter routing to DeepInfra US-hosted AI models for inference features you run (no training on your prompts; no prompt or response log retention as a normal practice)
- UI scraping providers used for AI presence checks against public consumer AI answer interfaces you initiate
- SEO and backlink data providers used only to deliver features you run
These providers process data under agreements appropriate to their role. They may store or process data in the United States, the European Union, or other countries where they operate.
MCP and connected AI tools
Bloomiro offers MCP access so tools such as Cursor, Claude, ChatGPT, or other compatible clients can read project data and perform allowed actions on your behalf. You choose which clients to connect and which API keys or OAuth grants to issue.
Data returned through MCP is governed by this policy and by the access scope of the key or token you created. You are responsible for reviewing the privacy practices of any AI client or automation you connect to your project.
Legal bases (EEA, UK, and Switzerland)
If you are in the European Economic Area, the United Kingdom, or Switzerland, we process personal data on these bases:
- Contract: to provide the service you signed up for
- Legitimate interests: to secure the platform, prevent abuse, and improve reliability, balanced against your rights
- Consent: where required, for example when you connect Google Search Console, Google Analytics, or authorize MCP access
- Legal obligation: when we must retain or disclose data by law
How long we keep data
We keep account and project data while your account or project is active. After you close your account or we permanently delete an organization, we delete or anonymize personal and project data within 12 months, except where a longer period is required for billing, tax, fraud prevention, security logs, or legal compliance.
When you delete a project from project settings, related database records are removed. Linked object storage files may take additional time to purge from backups and caches. Ephemeral cache entries in Redis typically expire within minutes to hours.
MCP audit events and security logs are typically retained for up to 24 months. Billing records may be kept for up to 7 years where needed for accounting or legal compliance. Contact us if you need help deleting data tied to a closed account.
Your rights and choices
Depending on where you live, you may have the right to:
- Access a copy of personal data we hold about you
- Correct inaccurate account information in your profile or organization settings
- Delete projects you manage from the dashboard
- Disconnect Google Search Console or Google Analytics at any time
- Revoke MCP API keys or OAuth tokens from project settings
- Object to or restrict certain processing
- Export data where technically feasible
- Withdraw consent where processing is based on consent
- Lodge a complaint with your local data protection authority
To exercise these rights, email hi@bloomiro.com. We may need to verify your identity before responding. We respond to verified data subject requests within one month of receipt (or longer where permitted by applicable law, in which case we will tell you). If you are a team member, your organization owner may need to act on some requests.
Residents of California and other U.S. states with comprehensive privacy laws (including Virginia, Colorado, Connecticut, Utah, and similar statutes) may have additional rights, such as the right to know, access, delete, and correct personal information, and to opt out of sale or targeted advertising as those terms are defined by applicable law. We do not sell personal information, and we do not share personal information for cross-context behavioral advertising. Because we do not engage in those activities, Global Privacy Control (GPC) browser signals do not change our current processing practices; we still honor applicable opt-out and deletion rights when you contact us.
International transfers
Bloomiro is operated from multiple regions through cloud providers. If you access the service from outside the country where our providers host data, your information may be transferred internationally. Where required, we rely on appropriate safeguards such as standard contractual clauses or equivalent mechanisms offered by our vendors.
Security
We use technical and organizational measures designed to protect your data, including encryption in transit (HTTPS), encrypted storage for sensitive tokens, hashed API keys, access controls, and tenant isolation by organization. No method of transmission or storage is completely secure; we cannot guarantee absolute security.
Children
Bloomiro is a business service and is not directed to children under 16. We do not knowingly collect personal information from children. Contact us if you believe a child has provided us data.
Business customers
If your organization uses Bloomiro across a team, your administrator controls invites, projects, and integrations. You are responsible for ensuring you have a lawful basis to submit website URLs, Search Console data, Google Analytics data, competitor information, and any personal data of your colleagues into the platform.
If you need a data processing agreement for your company, reach us at hi@bloomiro.com.
Changes to this policy
We may update this Privacy Policy from time to time. We will post the revised version on this page and update the effective date. Material changes may also be notified by email or in-product notice. Continued use after the effective date means you accept the updated policy.
Related documents
Our Terms of Service govern your use of the platform, including disclaimers about SEO and AI visibility outcomes.
Questions? Reach us at hi@bloomiro.com.