Trust & Privacy

Your information, handled with care.

This page explains, in plain language, how Bloom looks after the information you share with us — what we collect, where it lives, who can see it, and how to reach us with questions. It's maintained by Bloom with Britt & Co. and updated as our practices evolve.

The short version

A relationship-first approach to your data.

Bloom is a small, relationship-based practice. We only collect what we need to work with you well — your contact details, the notes from our conversations, and the materials you choose to share inside your account.

We don’t sell your information. We don’t share it with third parties for marketing. And we don’t use it for anything other than supporting your work with Bloom.

What we collect

The information you share with us.

Depending on how you interact with Bloom, we may hold things like your name, email address, the answers you provide on the Let’s Talk form, meeting notes, files you upload to your client portal, and the email correspondence between you and Britt.

If you have a client account, your portal also stores the roadmap, priorities, and session history we build together so we can pick up where we left off.

Where it lives

Trusted infrastructure, behind the scenes.

Bloom is built on Lovable Cloud, which uses Supabase for the database and authentication layer. Account passwords are hashed by the auth provider — Britt never sees them. Data is transmitted over encrypted connections (HTTPS/TLS) and stored on managed cloud infrastructure.

We rely on a small number of trusted services to make Bloom work: email delivery (Mailgun), calendar & video for sessions, and AI providers used inside the HQ workspace to help summarize notes. These providers process information on our behalf and are not given access for their own purposes.

Lovable Cloud provides the underlying platform features described here. This page is not a third-party certification — it describes the controls Bloom has enabled and the practices we follow.

Who can see it

Access stays small and intentional.

Inside Bloom’s admin workspace (“HQ”), Britt is the only person with access to client information. Database access is restricted by row-level security so clients can only see their own portal data, and only authenticated admin accounts can reach HQ.

We never share your information with other clients, prospects, or outside parties without your permission.

How long we keep it

Kept on file, until you tell us otherwise.

By default, we keep client records on file indefinitely so we can pick back up if you return to Bloom in the future. If you’d like your information deleted — fully or partially — just ask, and we’ll take care of it.

Records tied to invoices, contracts, or other obligations may be retained as long as required to meet legal or accounting requirements.

Your choices

You’re always in the driver’s seat.

You can ask, at any time, to see what information we hold about you, correct something that’s wrong, export your records, or have your account and data deleted. We’ll honor reasonable requests promptly.

Bloom is a small practice and not formally certified under frameworks like SOC 2, HIPAA, or GDPR. That said, we try to follow the same common-sense principles those frameworks reflect: collect only what we need, protect it carefully, and respect your right to control it.

Cookies & analytics

Light-touch, no tracking for ads.

The public Bloom site uses minimal cookies — primarily the ones needed to keep you signed in to your client portal. We don’t run advertising trackers or sell behavioral data.

Questions or requests

Reach out anytime.

If you have a privacy or security question, want a copy of your data, or want it removed, the best way to reach Bloom is through the contact page. We’ll respond personally.

Last updated: June 2026. We’ll revise this page as our practices evolve.