Privacy Policy
Clear information about the data behind HelloBLOOM.
This policy explains what personal information HelloBLOOM processes, why it is needed, how education and student records are handled, when service providers receive data, and how people can exercise their privacy rights.
HelloBLOOM does not sell personal information and does not currently use advertising trackers to build behavioural profiles.
Students use organisation-issued tokens or codes. They do not purchase subscriptions or independently control organisation records.
The Level Placement Test uses deterministic rules and teacher confirmation. Generative AI does not mark the test or decide a student's level.
1. Scope and responsibility
This policy applies to the HelloBLOOM website, subscriptions, account and organisation tools, Architect Workspace, Teaching Plans, Lesson Presenter, student preparation and review, Level Placement Test, billing functions, and related support communications.
HelloBLOOM is the service operator. James Caldwell, Founder, is the privacy contact for this policy and can be reached at admin@hellobloom.live.
Organisation and school records
For account administration, billing, platform security and direct communications, HelloBLOOM determines why and how the information is processed. When a school, academy, teacher or organisation enters student, parent, class, progress or placement information, that customer normally decides the educational purpose and acts as the responsible organisation. HelloBLOOM processes those records to provide the contracted service and to follow the customer's authorised instructions.
Korean service note: This English policy is designed around the disclosure structure used under Korea's Personal Information Protection Act (PIPA). The contracting entity, registered address, final production processor schedule and any domestic representative details required for Korean commercial operation will be confirmed in the applicable order terms and reflected here before they become legally necessary.
2. Information we process
We aim to collect only the information needed to operate the service. Some information is required to create or administer an account; other fields, including student email and parent contact details, are optional unless an organisation requires them for its own lawful educational purpose.
| Information category | Examples | How it is obtained |
|---|---|---|
| Account and identity | Name, email address, Firebase user ID, authentication provider, role, email-verification status and account status. | From the user during registration, Google sign-in, an invitation, or account administration. |
| Organisation, teacher and class | Organisation name, memberships, permissions, teacher assignments, class name, class level or age band, and status. | From organisation owners, admins and authorised teachers. |
| Student and parent contact | Student ID or token, display name, optional student email, optional parent or guardian name, phone and email, class membership and enrolment status. | Entered by an authorised organisation or teacher. Students generally use an issued token rather than creating an email account. |
| Learning and placement | Preparation or review progress, activity completion, High/Medium/Low or right/wrong teacher marks, teacher notes, placement responses, skill profile, strengths, development priorities, recommended and teacher-confirmed level, test status and dates. | Created as teachers and students use learning and placement functions. Placement attempts and results are attached to the enrolled student's Firebase record, with limited local browser recovery data on the administering device. |
| Curriculum and generated content | Curriculum selections, plans, prompts, briefs, lesson activities, scripts, uploaded reference files, generated images, audio, music, and teacher edits. | Entered, selected, uploaded or generated by authorised adult users. |
| Subscription and billing | Plan, billing cycle, account email, currency, amount, payment status, Stripe customer, subscription, checkout and payment identifiers, and receipt or invoice details. | From the customer and Stripe. HelloBLOOM does not receive or store complete payment-card numbers. |
| Device, security and operations | IP address, browser and device information, authentication tokens, timestamps, function and storage logs, error details and security events. | Collected automatically when the service is accessed. |
| Communications | Email address, message content, subject, delivery status and support history. | From direct contact, invitations, verification, billing and service emails. |
HelloBLOOM does not request Korean resident registration numbers, passport numbers, health information, biometric identifiers or precise location data as part of ordinary service use. Please do not enter that information into free-text notes, prompts or uploads.
3. Purposes and legal bases
We process personal information for the following purposes:
- create, verify and secure accounts;
- provide subscriptions, organisation tools, classes, student access, curriculum, planning, presentation, print and preparation features;
- administer teacher-directed placement tests and attach results to the relevant student record or local recovery session;
- process subscriptions and BLOOM Credit purchases, reconcile payments and issue receipts;
- generate curriculum and classroom content when an authorised adult requests it;
- deliver invitations, verification, billing, service and support communications;
- prevent abuse, investigate errors, protect accounts and maintain service reliability;
- meet legal, accounting, tax, consumer-protection and privacy obligations; and
- establish, exercise or defend legal claims.
Legal bases
Depending on the relationship and applicable law, processing is based on performance of a subscription or service contract, steps requested before entering that contract, the customer's lawful instructions, consent, compliance with legal obligations, protection of users and the service, or another basis permitted by PIPA or other applicable law. When Korean law requires separate consent, including for particular overseas transfers or processing of a child under 14, that consent must be obtained before the relevant processing begins.
We do not use personal information for an unrelated purpose without a lawful basis and any notice or consent required by law.
4. Students and children
HelloBLOOM is a teacher-directed education service. Students do not purchase subscriptions, choose organisation settings or independently enrol themselves. An authorised adult creates or imports the student record and provides a randomised student code, passcode or QR-based login route.
- Student email is optional in the current organisation and teacher tools.
- Student-facing sessions receive only the information needed to display assigned activities and record permitted progress.
- Teacher notes, marking guidance, answer keys, internal routing and private organisation data are not intended to be sent to the student presentation screen.
- Standard student use does not create facial-recognition data, voiceprints or biometric profiles.
Children under 14 in Korea
The school, academy, teacher or other customer must have a lawful basis for entering a child's information and must obtain verifiable consent from the child's legal representative when Korean law requires it. The customer must also give parents or guardians the information needed to understand the educational processing.
If HelloBLOOM learns that a child's information was entered without the required authority or consent, we may restrict the record and work with the responsible organisation to correct or delete it.
5. AI and automated decisions
Content generation
Authorised adult users can request language, lesson, image, audio or music generation. The relevant prompt, script, reference material and technical instructions may be sent to a configured generation service. HelloBLOOM's design rule is that student names, student or parent email addresses, phone numbers, school identities, voice profiles, facial data and identifying student records must not be included in external AI requests.
Teachers and admins must not place identifying student information in prompts, scripts, notes or reference images. Generated content must be reviewed by a teacher or authorised adult before classroom use.
Placement and student decisions
The HelloBLOOM Level Placement Test is teacher-directed. Its recommendation is calculated by deterministic, testable rules from teacher-selected responses. Generative AI does not assign marks, calculate the level or make a final decision. The teacher reviews the skill profile and confirms or overrides the recommendation.
HelloBLOOM does not currently make a solely automated decision that produces legal or similarly significant effects for a student.
6. Service providers and overseas processing
HelloBLOOM uses specialist providers to host the service, authenticate users, process payments, deliver email and generate content. Data is disclosed only for the service purpose, under the applicable contract and security settings. Provider entities, sub-processors and exact processing locations can depend on production configuration and the customer's location.
| Provider or service | Purpose and information | Countries, transfer method and timing | Retention |
|---|---|---|---|
| Google Cloud and Firebase | Hosting, authentication, database, file storage, cloud functions, security logs and optional Google sign-in. This can include account, organisation, teacher, class, student, learning and content records. | Encrypted online transfer when the service is used. Current callable functions operate in the United States; designated HelloBLOOM generation engines operate in Google Cloud's Seoul region. Google may use other disclosed infrastructure locations. | For the service relationship and backup or log periods under the configured Google Cloud terms, then deleted or de-identified according to those controls. |
| Stripe | Secure subscription and BLOOM Credit checkout, payment confirmation, receipts, refunds and fraud prevention. Stripe receives checkout identity, email, plan, amount and payment details directly. | Encrypted online transfer to Stripe in the United States and other Stripe processing locations when checkout or billing is used. | Under Stripe's service terms and financial, fraud-prevention and legal retention requirements. |
| HelloBLOOM generation engines and Google AI services | Language, speech, audio and music generation requested by an authorised adult. Instructional prompts, scripts and generation settings are processed; identifying student records are not intended to be sent. | Encrypted online transfer when generation is requested. HelloBLOOM engines are currently deployed in Seoul, South Korea; supporting Google services may process in other disclosed Google locations. | For generation delivery, reliability, abuse prevention and the configured provider retention period; resulting assets may remain in the customer's HelloBLOOM workspace. |
| OpenAI | Image generation or editing requested by an authorised adult. Prompt and selected reference media may be sent; identifying student data must not be included. | Encrypted API transfer to the United States and other OpenAI processing locations when image generation is requested. | According to the configured business API terms and settings; generated assets may remain in the customer's HelloBLOOM workspace. |
| Google Workspace/Gmail or Resend | Account verification, invitations, reminders, billing receipts and service email. Recipient name or email, message content and delivery metadata may be processed. | Encrypted online transfer to the United States and other provider processing locations when an email is sent. | For delivery, support, abuse prevention and provider log periods under the applicable email-service terms. |
Where PIPA requires separate consent for an overseas transfer, HelloBLOOM or the responsible organisation will obtain it before transfer. Where another PIPA basis permits a transfer needed to provide the contracted service, the required notice will identify the recipient, country, items, purpose, transfer method and timing, and retention period.
We do not provide personal information to unrelated third parties for their own advertising. We may disclose information when a person has consented, when required by law or a valid legal process, to protect life or safety, or in connection with a business reorganisation subject to appropriate notice and safeguards.
7. Retention and deletion
We keep personal information only for the period needed for the purpose described above, the active service relationship, the responsible organisation's instructions, and applicable legal obligations.
- Unverified registrations: current account-lifecycle controls remove unverified authentication access after approximately one day. Limited lifecycle records may remain to document the action and prevent abuse.
- Verified but unpaid registrations: current controls send limited reminders and remove authentication access after approximately 14 days if subscription setup is not completed.
- Active accounts and organisation records: retained while the account or subscription is active and for the period needed to close, export, secure or lawfully retain the account after termination.
- Student, class, progress and placement records: retained in Firebase while required by the responsible organisation or until deletion, account closure or expiry of an agreed retention period. Limited placement recovery data stored in browser local storage remains on that device until it is cleared or removed.
- Billing and transaction records: retained for accounting, tax, fraud prevention, payment disputes and the periods required by applicable electronic-commerce and financial law.
- Security and service logs: retained for the period reasonably needed to investigate incidents, maintain reliability and meet legal obligations.
When retention is no longer required, electronic records are deleted, overwritten or de-identified using methods intended to prevent ordinary reconstruction. Provider backups are removed through the provider's backup-expiry process. Paper records, if any, are securely shredded.
8. Cookies and browser storage
HelloBLOOM and its essential service providers use browser storage, authentication state and limited cookies to keep users signed in, protect sessions, remember language and interface choices, recover work, connect student sessions and complete secure checkout.
- Firebase Authentication and Google sign-in may store essential authentication information.
- HelloBLOOM stores the selected interface language and limited application preferences.
- Placement-test attempts and results are stored in Firebase against the stable student ID. A local recovery copy, including timer state, can also remain in the administering teacher's browser.
- Student access uses session storage for the issued session ID and limited session summary.
- Stripe may use its own essential security and fraud-prevention cookies on hosted checkout pages.
HelloBLOOM does not currently deploy advertising cookies or third-party behavioural analytics on its public pages. A user can clear cookies and site storage through browser settings, but doing so may sign the user out or remove unsynchronised recovery data.
9. Security and incidents
HelloBLOOM uses administrative and technical measures appropriate to the service, including role-based access, Firebase security rules, authentication and email verification, restricted callable functions, encrypted network connections, managed secret storage, access separation between student and teacher surfaces, security logging, and data minimisation for external generation requests.
No online service can guarantee absolute security. Account holders must protect passwords, student tokens and authorised devices, remove access when staff leave, and report suspected misuse promptly.
If a personal-information incident occurs, HelloBLOOM will investigate, contain and document it, assist affected organisations, and notify affected people and the appropriate authority within the period and in the manner required by applicable law.
10. Your rights
Subject to applicable law, a person or authorised legal representative may request:
- confirmation of whether personal information is processed and access to it;
- correction of inaccurate or incomplete information;
- deletion of information that is no longer lawfully required;
- suspension or restriction of processing;
- withdrawal of consent where consent is the legal basis; and
- information about overseas transfers, recipients and processing purposes.
Send a request to admin@hellobloom.live. We may ask for information needed to verify identity, authority and the relevant account or organisation. We will respond within the period required by applicable law and explain any lawful reason a request cannot be completed in full.
For a student record controlled by a school, academy or teacher, the request should normally be made to that organisation first. HelloBLOOM will assist the responsible organisation with a valid request.
11. Contact and complaints
Privacy contact: James Caldwell, Founder
Email: admin@hellobloom.live
General contact page: hellobloom.live/contact.html
If a concern is not resolved, people in South Korea can also contact:
12. Policy changes
We may update this policy when the service, providers, law or processing practices change. The current version will remain available on this page with its effective and last-updated dates. Where a change materially affects people's rights or requires consent, we will provide additional notice or obtain consent as required before the change takes effect.