Privacy Policy

Last updated: 5 August 2026

This Privacy Policy explains how your personal data is processed when you use Bluumme — both the mobile app (iOS, Android) and the website at https://bluumme.com. We comply with the EU General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (BDSG).

1. Controller

Emir Atay Metzer Str. 62 40476 Düsseldorf Germany Email: hello@bluumme.com

A Data Protection Officer is not required by law (Art. 37 GDPR, § 38 BDSG).

2. Data we process

2.1 Account data

When you sign up, we collect: email address, username, password (hashed), optional display name, optional profile picture.

A profile or cover picture may be taken with the camera or chosen from your device's photo library. Only the picture you pick is uploaded — the app does not read, index or scan the rest of your library, and posts themselves can only be captured live with the camera.

For "Sign in with Apple": an anonymised Apple identifier, optional email (including Apple's private relay). For "Sign in with Google": email, name, profile picture URL if available.

2.2 Content

Photos, videos, captions, comments, likes, saved challenges, streak data and ranking data.

2.3 Location data (only with consent)

If you choose to attach a location to a post, we store the approximate coordinates of that post. You can revoke location access at any time in your device settings or in the app's settings.

2.4 Device and usage data

IP address (truncated in logs), device type, OS version, app version, language setting, crash reports, performance metrics, and pseudonymous product analytics events (e.g. "app opened", "post created" — see section 4.6).

2.5 Push notifications (only with consent)

If you enable notifications, we store a device-specific token in order to send you notifications. These cover activity on your account (likes, comments, follows, follow requests, messages), the daily and weekly challenges, changes in your ranking, new posts from accounts on the platform, and occasional reminders when you have been away. You can turn notifications off entirely in your device settings, or per type in the app's settings.

2.6 Moderation and safety data

When you use the safety tools in the app we store the minimum data needed to act on them:

2.7 Automated content filtering

At post creation we run a small profanity filter over captions and usernames that blocks universally recognised slurs in the languages we ship. No content is logged; only the rejection event is surfaced to you in the app.

Automated image screening. When you publish a photo, and when you set a profile or cover picture, the image is checked automatically for adult and violent content before it can circulate. The check is performed on our behalf by Google Cloud Vision (SafeSearch, see section 4.1): the image is transmitted for analysis, classified, and not retained by that service or used to train any model. What we keep is the resulting classification (a likelihood value such as "very unlikely" for adult content), stored alongside the post.

Videos and message contents are not screened. Nobody looks at your photos as part of this check unless the classification flags them — see section 10 for what happens then, and our Content Moderation Policy for the standards applied.

2.8 Direct messages

If you choose to send a direct message (DM) to another Bluumme user, we store the following so the conversation can be delivered and shown to both participants:

DMs are transmitted over TLS (HTTPS) and stored encrypted at rest by our processor (Google Cloud / Firestore, AES-256 server-side encryption). They are not end-to-end encrypted — Bluumme staff can in principle access message contents in order to respond to lawful requests, abuse reports, or court orders. We do not read DMs for advertising, profiling, or model training, and we do not share their contents with third parties.

When you create an account, the official @bluumme account automatically follows you and sends you one welcome message. It is stored like any other conversation, and you can delete it.

You can delete an individual message or an entire conversation at any time from within the app. Deleting your account also deletes all DMs you sent; DMs you received are removed from your view but remain in the recipient's inbox until they delete them (this mirrors how email works).

2.9 Communities

If you join or run a community, we store the community's public profile (name, handle, description, images) and, for each membership, the community id, your user id, your role in it (member or owner) and the time you joined. If a community requires approval, we store the join request and any text you submit with it until it is approved or declined. Communities keep their own internal activity score and their owners can grant members community-specific badges; both are stored against your membership. Community membership is visible to other members, and to anyone viewing a public community.

2.10 Invites and referrals

If you invite someone with your personal invite link or code and they use it, we store a referral record containing both user ids, both public handles, the status of the referral, and timestamps. Your own profile stores which account referred you. We use this only to award the one-time invite bonus once, to prevent the same invite being redeemed twice, and to detect abuse (for example self-referral or accounts created only to farm rewards).

2.11 App integrity

The app attests to our backend that it is a genuine, untampered copy of Bluumme, using Apple's App Attest on iOS and Google's Play Integrity on Android via Firebase App Check. This exchanges device-level integrity signals with Apple / Google and produces a short-lived token. It contains no personal data about you and is not used to identify or track you — its only purpose is to keep scripts, bots and modified clients away from the service.

3. Purposes and legal bases

Purpose Legal basis
Providing the service (account, feed, posts, ranking) Art. 6(1)(b) GDPR — performance of a contract
Direct messages between users Art. 6(1)(b) GDPR — performance of a contract
Community membership, join requests and community rankings Art. 6(1)(b) GDPR — performance of a contract
Invites and referral rewards Art. 6(1)(b) GDPR — performance of a contract
App integrity / attestation (App Check), and abuse detection on referrals Art. 6(1)(f) GDPR — legitimate interest
Location attached to posts Art. 6(1)(a) GDPR — consent
Push notifications Art. 6(1)(a) GDPR — consent
Security, abuse prevention, moderation Art. 6(1)(f) GDPR — legitimate interest
Automated screening of images for adult or violent content (section 2.7) Art. 6(1)(f) GDPR — legitimate interest in a safe service, and Art. 6(1)(c) GDPR in view of our obligations as a hosting provider under the Digital Services Act
Crash reports and performance analysis Art. 6(1)(f) GDPR — legitimate interest
First-party analytics — understanding how features are used (sign-ups, activation, retention) to improve the app Art. 6(1)(f) GDPR — legitimate interest
Compliance with legal obligations (e.g. deletion requests) Art. 6(1)(c) GDPR

4. Recipients and international data transfers

We use the following processors:

4.1 Google (Firebase)

Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (with data processing also in the United States by Google LLC). Services used: Firebase Authentication, Firestore (database), Cloud Storage, Cloud Functions, Firebase Hosting, Firebase App Check (with Google Play Integrity on Android), and Cloud Vision (SafeSearch) for the automated image screening described in section 2.7. Images sent to Cloud Vision are processed transiently for classification; Google does not retain them and does not use them to train its models. Legal basis for US transfer: EU-US Data Privacy Framework (DPF). Google is certified under the DPF. Privacy Policy: https://policies.google.com/privacy DPF entry: https://www.dataprivacyframework.gov

4.2 Apple (Sign in with Apple, App Store, Push, App Attest)

Apple Distribution International Ltd., Hollyhill Industrial Estate, Hollyhill, Cork, Ireland. On iOS, app-integrity attestation (section 2.11) is performed by Apple's App Attest service. Privacy Policy: https://www.apple.com/legal/privacy/

4.3 Website hosting

Firebase Hosting (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland)

4.4 Internal moderation alerting

New reports trigger an internal notification to the operator via a private Discord webhook so we can meet the 24-hour review commitment. The webhook receives the report id, reason category, and the public handle of the reported account — never private account information, post content beyond the public caption, or any personal data of the reporter beyond their public display name.

The same webhook also receives an alert whenever the automated image screening (section 2.7) hides or removes something, so that a human can review it inside the 24-hour commitment. That alert contains the post id, the internal user id of the author and the classification values — not the image itself.

The same webhook also receives a daily operating summary. That message contains only aggregate counts (new sign-ups, new posts, how many people posted, totals, and the size of the moderation queue) — no names, handles, user ids or content.

4.5 Crash reporting (Sentry)

Functional Software, Inc. (Sentry), 45 Fremont Street, 8th Floor, San Francisco, CA 94105, USA. We use Sentry to collect crash reports and performance data so we can find and fix errors. Our Sentry project is configured for EU data residency — crash data is ingested and stored in the European Union (Germany). Crash reports may contain your internal user id, device information, and the app state at the time of the error — never your password or message contents. Legal basis for any residual US transfer: EU-US Data Privacy Framework (DPF); Sentry is certified under the DPF. Privacy Policy: https://sentry.io/privacy/

4.6 Product analytics (PostHog)

PostHog, Inc., 2261 Market Street #4008, San Francisco, CA 94114, USA. We use PostHog Cloud EU to understand how Bluumme is used (e.g. how many users open the app, create posts, or come back after signing up) so we can improve the product. Events are stored on servers in the European Union (Frankfurt, Germany) and are linked only to a pseudonymous identifier — a random device id, or your internal user id once you are signed in. They are never linked to your name, email address, photos, or message contents, and we do not use this data for advertising or share it with third parties for their own purposes. You can object to this processing at any time (Art. 21 GDPR) via hello@bluumme.com; we will then delete your analytics profile. Legal basis for any residual US transfer: EU-US Data Privacy Framework (DPF); PostHog is certified under the DPF. Privacy Policy: https://posthog.com/privacy

We do not sell data to third parties. We do not share data with advertising networks.

5. Retention

Data Retention period
Active account data As long as your account exists
Posts, comments, likes As long as your account exists or until you delete them
Direct messages Until you delete the message/conversation, or until either participant deletes their account
EULA acceptance timestamp + version As long as your account exists
Block records Until you unblock the user or your account is deleted
Community membership and role Until you leave the community, the community is deleted, or your account is deleted
Community join requests Until approved or declined, then up to 12 months
Referral records 12 months after the referral completes, for abuse prevention
Reports (post or user) 12 months for abuse prevention
Content hidden pending review Until reviewed — restored, or deleted and then treated as the row below
Content removed for a rules violation (copy kept as proof the action was justified, so it can be explained or appealed) 12 months, then deleted
Image classification values (section 2.7) With the post they belong to
Data after account deletion Up to 30 days in backups, then irrevocably deleted
Server logs (truncated IP) 14 days
Crash reports 90 days
Product analytics events (pseudonymous) Up to 24 months, or until you object / request deletion

6. Your rights

Under the GDPR you have the right to:

To exercise these rights, contact hello@bluumme.com or use the in-app controls.

Right to lodge a complaint with a supervisory authority

You have the right to lodge a complaint with a data protection authority, in particular:

State Commissioner for Data Protection and Freedom of Information North Rhine-Westphalia (LDI NRW) Kavalleriestraße 2-4, 40213 Düsseldorf, Germany https://www.ldi.nrw.de

7. Minors

Bluumme is intended for users aged 13 and over. In Germany, persons under 16 require parental consent under Art. 8 GDPR. We do not knowingly register children under 13.

8. Security

We use TLS for data in transit, Firebase default encryption for data at rest, hashed passwords (bcrypt via Firebase Auth), and restrict access to production data to the controller. Requests from the app are attested with Firebase App Check (section 2.11) so the backend can reject scripts and tampered clients.

Private conversations and other people's private profiles are additionally protected against screen capture: on Android the system blocks screenshots and screen recording on those screens, and on iOS — where the operating system does not allow blocking — the app detects a screenshot and warns you. This is a device-side protection only; no screenshot event is transmitted to us or to the other person.

9. Cookies and tracking

The Bluumme app itself does not set cookies. The website uses only strictly necessary cookies (session, language preference). No advertising or analytics cookies are set without your explicit consent.

10. Automated decisions

We use one automated process that can act on your content: the image screening described in section 2.7. Its possible outcomes are:

You are told in the app when either of the last two happens, including that the decision was reached by automated means, and you can have it reviewed by a human by replying to that message or writing to hello@bluumme.com. Because a human review and reversal is available on request, this is not a decision "based solely on automated processing" within the meaning of Art. 22(1) GDPR; the right to obtain human intervention, to express your point of view and to contest the decision applies in any case.

We do not otherwise use automated decision-making or profiling within the meaning of Art. 22 GDPR. The ranking system is based on published posts and interactions but has no legal or similarly significant effect on you.

11. Apple Privacy Nutrition Label & Google Data Safety

The following summary corresponds to our declarations on the App Store and Google Play.

Data linked to your identity: email, username, photos, videos, profile information, community memberships, invite/referral records, location (if opted in). Data used for app functionality: all of the above plus crash data and performance data. Data used for first-party analytics: usage and interaction data (e.g. app opens, posts, follows, challenge participation) is processed on our behalf by PostHog on EU servers (see section 4.6), linked only to a pseudonymous identifier, to understand how features are used and to improve Bluumme. This data is never used for advertising and is never shared with third parties for their own purposes. Data used for advertising or cross-app tracking: none. Data sold or shared with brokers: none. Data retention: see section 5.

12. Changes to this Privacy Policy

We may update this Privacy Policy to reflect new legal requirements or changes to the service. We will announce material changes in the app and by email at least 14 days before they take effect.