Privacy Policy
Bloomword, by Such Software LLC · Last updated July 14, 2026
We keep data collection focused on running the game, keeping the Daily fair, understanding stability, and supporting optional ads and purchases. We do not sell your personal information, and you can delete your pseudonymous server data yourself from inside the app at any time.
What we collect
- Device-first progress: your settings, your Lexicon (the words you have found), your streak, which biomes you have unlocked, Bestiary discoveries, and gameplay preferences live in the app's local storage. Settings, Lexicon words, streaks, and biome progress stay on your device. Bestiary discoveries are also backed up as described below.
- Service identity and synced Bestiary: Bloomword uses a random, pseudonymous device-install identifier to fetch public game configuration and back up your Bestiary. A discovery record contains the creature identifier, first discovery day, discovery route, an idempotency event identifier, and catalog version. It does not contain the word you typed, a name, email address, contacts, photos, or precise location.
- Leaderboard data (only if you join and finish a ranked Daily): the pseudonymous install identifier, your chosen display handle, the Daily date, score, rank-related stats, submitted words and timestamps for that Daily, and coarse device context such as platform and form factor. The server uses this to replay and verify the score. We do not collect your name, email, contacts, photos, or precise location for leaderboard play.
- Purchases: Bloomword Premium is sold through the Apple App Store and Google Play. Those stores handle the payment; we receive only confirmation that a purchase is valid, never your card or billing details.
- Ads: Bloomword may show rewarded ads through Google AdMob. AdMob may process device, app, and advertising information to show and measure ads according to Google's policies and your device settings. Bloomword does not ask for Apple's App Tracking Transparency permission.
- Analytics and crash diagnostics: we use Firebase Analytics and Firebase Crashlytics for aggregate product events and crash diagnostics. Events may include app start, screen views, Daily start/finish, ranked qualification, share taps, Practice/ad/premium flow, biome picks, purchase events, config health, app version, device model, operating system, and crash logs. Analytics events do not include raw typed words, leaderboard handles, contacts, photos, or precise location.
- Website analytics: we use self-hosted Umami to understand aggregate traffic and store-link clicks, such as which pages are visited, which store link was selected, and where visits arrive from. Umami is cookieless, does not build cross-site profiles, and does not store your IP address. Analytics stays on infrastructure we control rather than being sent to an advertising network.
- Sharing: PNG result cards are generated on your device. If you tap share, your device's native share sheet sends the image and result text only to the app or person you choose.
- Ratings and reviews: after meaningful play, Bloomword may ask Apple or Google to present their official in-app review prompt. The store controls whether it appears and handles any rating or text you submit. Bloomword is not told whether you saw the prompt or left a review.
- Server and website logs: our servers and hosting providers may keep standard operational logs, such as IP address, request time, and error information, for security, debugging, and reliability.
Why
- Local data makes the game work — your progress, settings, and collection. Pseudonymous Bestiary backup lets discoveries survive a session and gives us aggregate collection-health counts.
- Leaderboard data powers the shared Daily competition and lets our server verify every score by replaying it, so nobody can fake their way up the board. Money never buys a higher score.
- Purchases and ads support the free-to-play model.
- Analytics and crash reports help us understand whether Bloomword is fun, stable, fair, and working correctly across devices without reading your personal word list.
- Website analytics helps us understand which pages and store links are useful.
How long we keep it
Local data stays on your device until you delete it or uninstall the app. Leaderboard scores are tied to each day's board. You can remove your pseudonymous server data at any time in the app (Settings → Privacy & data → Delete my data; also linked from Leaderboard), which permanently deletes your leaderboard account, scores, handle, synced Bestiary, and Bestiary activity denominator from our servers. Bestiary discoveries on that device are also cleared so they are not uploaded again under a new identity. Operational logs, analytics, and crash diagnostics are kept only as long as reasonably needed for security, debugging, analytics, and app improvement.
Your choices
- Delete your data: Settings → Privacy & data → Delete my data, in-app, any time. The confirmation explains exactly which server and local Bestiary records will be removed.
- Play without the leaderboard: your Daily and Practice puzzles work offline. Scores are submitted only after you explicitly join the leaderboard; choosing private stops future score submissions. Public configuration and pseudonymous Bestiary backup can still use the Bloomword server.
- Control ads: use your iOS or Android privacy settings to reset or limit advertising identifiers and ad personalization.
- Depending on where you live (e.g. the EEA/UK under GDPR, or California under CCPA), you may have rights to access or delete your data. Because leaderboard data is pseudonymous, the in-app delete is the most direct way to do this; you can also email us.
Service providers
We use service providers to operate Bloomword, including Apple and Google for app distribution and purchases, Google AdMob for rewarded ads, Firebase for analytics and crash diagnostics, and hosting providers for the website and leaderboard servers. Website analytics is self-hosted with Umami. These external providers process data under their own terms and privacy policies.
Children
Bloomword is for general audiences and is not directed at children under 13. We don't knowingly collect personal information from children.
Changes
If this policy changes, we'll update the date above and post the new version here.
Contact
Questions about privacy? Email support@such.software.