โ† Bloom

Privacy

How the pilot handles your data

Effective July 12, 2026 ยท Pilot version

Information the portal uses

  • Google account identity, email, authentication session, and workspace membership.
  • Business profile details and the modules enabled for your workspace.
  • Portal records such as contacts, calls, documents, approvals, support, usage, and billing history.
  • Connected-account metadata and encrypted credentials only when you choose to connect a service.
  • Security and audit records needed to operate and troubleshoot the portal.

How Bloom uses it

Bloom uses this information to provide your workspace, deliver the services you selected, respond to support requests, secure the portal, and improve the pilot. Bloom does not sell pilot participant data or use advertising cookies in the Client Portal.

Service providers

The pilot uses Supabase for database and authentication, Vercel for hosting, Stripe for billing when enabled, Resend for operational email, Google for sign-in and optional connections, and the AI or phone providers attached to modules you choose. Provider access is limited to operating those functions.

Workspace separation and security

Portal access is checked against workspace membership and enabled modules. Bloom uses authenticated sessions, tenant-scoped database rules, restricted service credentials, and audit records. No online system is risk-free; report suspected access issues to support@thaliabloom.com.

Retention and deletion

Workspace data is retained while the pilot or service is active and as needed to provide support. Phone Desk transcript text is automatically removed after 12 months; call summaries and operational history may remain. The portal does not currently store raw call recordings. Email Bloom to request an export, correction, workspace closure, or deletion. Limited billing, security, and legal records may be retained.

Cookies

The portal uses essential authentication and security cookies. It does not currently use advertising cookies.