Floom Try for free

Privacy Policy

Last updated: October 1, 2026

This Privacy Policy describes Our policies and procedures on the collection, use and disclosure of Your information when You use the Service and tells You about Your privacy rights and how the law protects You.

We use Your Personal Data to provide and improve the Service. By using the Service, You agree to the collection and use of information in accordance with this Privacy Policy.

What Changed in Floom 2.0

Earlier versions of Floom kept Your content on Your device. Starting with Floom 2.0, when You sign in and use Our cloud features, Your content, quiz answers and settings are stored on Our servers so that they can be shared with Your Partner, synchronized across Your devices and restored if You reinstall the Application or change devices.

This is a material change to how We handle Your information, and We have rewritten this Privacy Policy accordingly. The sections most relevant to the change are:

Interpretation and Definitions

Interpretation

The words whose initial letters are capitalized have meanings defined under the following conditions. The following definitions shall have the same meaning regardless of whether they appear in singular or in plural.

Definitions

For the purposes of this Privacy Policy:

Collecting and Using Your Personal Data

Categories of Personal Data We Collect

The table below describes the categories of Personal Data We collect and the reason We collect each category.

Category of Personal Data Examples of Personal Data We Collect
Identity and Account Data Account identifier received from Sign in with Apple; email address (including an Apple private relay address, if You choose to hide Your email); display name and avatar, if You set them; birthday, if You add it; subscription status
User Content Custom quizzes and their photos, drawings, notes, photo statuses and captions You create with or upload to the Application
Project and Settings Data Quiz answers and results, streaks, anniversary date and countdowns, Application preferences and settings synchronized to Your Account
Location Data Precise location of Your Device, only if You allow it and only while the Application is open, used for the distance widget. We keep only Your most recent location, not a history
Purchase and Transaction Data Purchase history, subscription plan and status, transaction amounts and dates. Payment card details are processed by Apple and are never received or stored by Us
Usage and Analytics Data Feature usage, in-app events, session information, performance metrics
Device and Technical Data IP address, device model and type, operating system, Application version, unique device identifiers, browser type where applicable, diagnostic and crash logs
Customer Support Data Support inquiries, correspondence with Us, feedback and reviews You submit

What We Do Not Collect

To be explicit about the limits of Our collection, We do not:

Cloud Storage and Synchronization

This section describes the server-side storage introduced in Floom 2.0.

What We store. When You are signed in to Your Account and use Our cloud features, We store Your User Content, Project Data and Account information on Our servers.

Why We store it. We store this information to synchronize Your work across Your devices, to let You restore Your content after reinstalling the Application or moving to a new device, to give You access to Your project history, and to apply the storage and feature limits associated with Your plan.

Your content is private to You and Your Partner. User Content stored in Cloud Storage is associated with Your Account and is accessible only to You and, once You connect with a Partner, to that Partner as described in Sharing with Your Partner. It is not published, is not made available to any other users, and is not used for advertising. Our personnel do not access the substance of Your User Content, except in narrow circumstances: when You ask Us to do so in order to resolve a support issue, when We are required to by law or valid legal process, or when it is necessary to investigate a suspected violation of Our terms or a threat to the safety of any person.

How it is protected. Data is encrypted in transit using TLS and encrypted at rest by Our infrastructure providers. Storage is logically isolated per Account. See Security of Your Personal Data for more detail.

Your control. You can delete individual files and projects from within the Application, and You can delete Your Account and the associated content entirely. See Delete Your Personal Data.

Sharing with Your Partner

Floom is made for two. To use most features, You connect Your Account with another Floom user, Your Partner, by sharing an invite code or link. Both of You must accept the connection, and You can be connected to only one Partner at a time.

What Your Partner can see. While You are connected, Your Partner can see:

Your Partner can view, screenshot or save anything You share with them. We cannot control what Your Partner does with content once they have seen it, so please share only what You are comfortable sharing.

Unpairing. Either of You can unpair at any time in the Application. When You unpair, We delete the location, photo status and countdown data of that connection, and You and Your former Partner no longer see each other’s new activity.

Deleting an Account while connected. If You or Your Partner deletes their Account, the content You created together as a couple, including shared quiz results, widgets, drawings, notes and countdowns, is permanently deleted for both of You.

Signing In with Apple

Floom uses Sign in with Apple for authentication. We do not create or store passwords for Your Floom Account.

When You sign in, We receive:

We do not receive Your Apple ID password, Your contacts, Your social connections, Your profile photo, or the contents of Your mailbox. We do not automatically populate Your Floom profile from these services.

You can revoke Floom’s access at any time in Your Apple ID settings. Revoking access prevents You from signing in again; it does not by itself delete Your Floom Account or the content stored in it. To delete Your data, follow the steps in Delete Your Personal Data.

Usage Data

Usage Data is collected automatically when using the Service.

Usage Data may include information such as Your Device’s Internet Protocol address (e.g. IP address), browser type, browser version, the pages of our Service that You visit, the time and date of Your visit, the time spent on those pages, unique device identifiers and other diagnostic data.

When You access the Service by or through a mobile device, We may collect certain information automatically, including, but not limited to, the type of mobile device You use, Your mobile device’s unique ID, the IP address of Your mobile device, Your mobile operating system, the type of mobile Internet browser You use, unique device identifiers and other diagnostic data.

We may also collect information that Your browser sends whenever You visit Our Service or when You access the Service by or through a mobile device.

Information Collected while Using the Application

While using Our Application, in order to provide features of Our Application, We may request Your permission to access:

Photos You select or capture are used to provide the features of the Service. They are uploaded to and stored in Cloud Storage as described in Cloud Storage and Synchronization and shared with Your Partner as described in Sharing with Your Partner. We do not scan Your photo library, and We access only the items You select.

You can enable or disable access to Your camera, photo library, location and notifications at any time through Your Device settings. If You disable access, some features of the Application will not function.

App Tracking Transparency. The Application may ask for Your permission under Apple’s App Tracking Transparency framework. Whatever You choose, We do not currently access Your Device’s advertising identifier (IDFA) or use advertising attribution SDKs. If this changes, We will do so only with Your permission and after updating this Privacy Policy.

Sharing outside Floom. If You choose to share a quiz result to Instagram Stories or save it to Your photo library, this happens only at Your request, and the shared content is then subject to the terms and privacy policies of Instagram or Apple.

Location Data

The distance widget shows how far apart You and Your Partner are. It works only if You allow location access, and only while the Application is open. We do not collect Your location in the background.

AI and Your Content

Floom processes Your User Content on Our own infrastructure.

If this ever changes, We will update this Privacy Policy and notify You in advance in accordance with the Changes to this Privacy Policy section, and where consent is required by law, We will ask for it first.

Use of Your Personal Data

The Company may use Personal Data for the following purposes:

How We Share Your Personal Data

We share Personal Data only in the situations described below.

We do not share Your User Content or Project Data with advertising partners, marketing partners, data brokers, or third-party artificial intelligence providers.

Third-Party Service Providers

We use the following third parties to operate the Service. Each processes Personal Data on Our behalf and under contract.

Sub-processor Purpose Categories of data processed
Railway Hosting of Our backend services, databases and storage of User Content and Project Data. Data is encrypted in transit and at rest. Identity and Account Data, User Content, Project and Settings Data, Device and Technical Data
PostHog Product analytics: understanding how features are used, measuring performance and diagnosing errors, including session replays in which text input and images are masked. Usage and Analytics Data, Device and Technical Data, Account identifier
Sentry Crash reporting and error monitoring. Device and Technical Data, Account identifier
RevenueCat Managing subscriptions and purchase status across Your devices and with Your Partner. Purchase and Transaction Data, Account identifier, Device and Technical Data
Apple Authentication through Sign in with Apple; processing of purchases and subscriptions through the App Store; delivery of push notifications. Identity and Account Data, Purchase and Transaction Data

These providers have their own privacy policies governing their handling of Personal Data.

Floom does not use advertising SDKs, advertising pixels, or mobile attribution trackers. We do not embed tools such as advertising network pixels or attribution SDKs in the Application, and We do not send Your data to advertising platforms.

No Data Selling

We do not sell Your Personal Data, and We do not share Your Personal Data for cross-context behavioral advertising, as those terms are defined under the California Consumer Privacy Act and similar state privacy laws. We have not sold or shared Personal Data for those purposes in the preceding 12 months.

If Our practices change materially, We will update this Privacy Policy and notify You in accordance with applicable law before the change takes effect.

Aggregated and Anonymous Data

We may create aggregated, de-identified or anonymized data from the Personal Data We collect, including by removing information that makes the data personally identifiable to a particular user. We may use such data, and share it with third parties, for lawful business purposes including analyzing and improving the Service. We do not attempt to re-identify data that has been de-identified.

If You are located in the European Economic Area (“EEA”), the United Kingdom, or Switzerland, We process Your Personal Data on the following legal grounds under applicable data protection law:

Purpose of Processing Legal Basis Categories of Data
Providing and maintaining the Service, including creating Your Account and enabling core features Performance of our contract with You Identity and Account, User Content, Project and Settings, Device and Technical
Storing and synchronizing Your content in Cloud Storage, and backing it up Performance of our contract with You User Content, Project and Settings, Identity and Account
Connecting You with Your Partner and sharing content with them Performance of our contract with You Identity and Account, User Content, Project and Settings
Showing the distance between You and Your Partner Consent (location permission) Location
Authenticating You and protecting Your Account Performance of our contract with You; Legitimate interests (account security) Identity and Account, Device and Technical
Processing payments, subscriptions and refunds Performance of our contract with You; Compliance with legal obligations (tax and accounting) Identity and Account, Purchase and Transaction
Responding to Your inquiries and providing customer support Performance of our contract with You; Legitimate interests (providing quality service) Identity and Account, Customer Support, Usage
Analyzing usage and improving the Service Legitimate interests (improving the Service); Consent where required by applicable law Usage and Analytics, Device and Technical
Ensuring safety, security and fraud prevention Legitimate interests (protecting our users and the Service); Compliance with legal obligations Identity and Account, Usage and Analytics, Device and Technical
Sending marketing communications Consent (for electronic marketing); Legitimate interests (promoting Our Service) where permitted Identity and Account, Usage and Analytics
Complying with legal obligations Compliance with legal obligations All categories as required
Establishing, exercising or defending legal claims Legitimate interests (protecting Our legal rights) All categories as relevant to the claim

Where We rely on legitimate interests, We have balanced Our interests against Your fundamental rights and freedoms.

Where We rely on consent, You have the right to withdraw Your consent at any time by contacting Us or adjusting Your settings. Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.

Retention of Your Personal Data

The Company will retain Your Personal Data only for as long as is necessary for the purposes set out in this Privacy Policy. We will retain and use Your Personal Data to the extent necessary to comply with our legal obligations (for example, if We are required to retain Your data to comply with applicable laws), resolve disputes, and enforce our legal agreements and policies.

Where possible, We apply shorter retention periods and reduce identifiability by deleting, aggregating, or anonymizing data. Unless otherwise stated, the retention periods below are maximum periods (“up to”) and We may delete or anonymize data sooner when it is no longer needed for the relevant purpose.

Data Category Retention Period Rationale
Account and Profile Data Duration of Your Account + 30 days after deletion To provide the Service and allow a short recovery window in case of accidental deletion
User Content and Project Data Duration of Your Account; deleted within 30 days of Account deletion Core service functionality; prompt deletion once You leave
Location Data Most recent location only; replaced on each update and deleted when You unpair or delete Your Account Distance widget
Purchase and Billing Records 7 years after the transaction Tax, accounting and legal compliance requirements
Usage and Analytics Data Up to 24 months Understanding feature adoption and improving the Service
Server and Security Logs Up to 12 months Security monitoring, incident investigation and troubleshooting
Customer Support Records 3 years after the inquiry is resolved Support quality, dispute resolution and legal claims
Backups Rotating backups retained up to 90 days Disaster recovery and data integrity
Aggregated / De-identified Data Indefinitely No longer identifiable; used for analytics and service improvement

We may retain Personal Data beyond the periods stated above for the following reasons:

You may request information about how long We will retain Your Personal Data by contacting Us.

When retention periods expire, We securely delete or anonymize Personal Data:

Delete Your Personal Data

You have the right to delete or request that We assist in deleting the Personal Data that We have collected about You.

Deleting individual content. You can delete individual files and projects from within the Application at any time.

Deleting Your Account. You can delete Your entire Account and its associated content from within the Application, in the account settings section. You may also contact Us at capsmol@gmail.com to request deletion.

How deletion works. Floom uses a two-layer deletion process:

Complete deletion requests. If You require destruction of all copies of Your data, including backups, contact Us at capsmol@gmail.com and We will accommodate Your request to the extent technically feasible and legally permissible.

What We keep after deletion. We may retain limited information after Account deletion where We have a legal obligation or lawful basis to do so — for example, billing records required for tax purposes, records needed to establish or defend legal claims, and limited data needed to prevent fraud and abuse of the Service.

You may also update, amend, or correct Your information at any time by signing in to Your Account and visiting the account settings section, or by contacting Us.

Disclosure of Your Personal Data

Business Transactions

If the Company is involved in a merger, acquisition or asset sale, Your Personal Data may be transferred. We will provide notice before Your Personal Data is transferred and becomes subject to a different Privacy Policy.

Law enforcement and government requests

Under certain circumstances, the Company may be required to disclose Your Personal Data if required to do so by law or in response to valid requests by public authorities (for example, a subpoena, court order, search warrant, or a request from a government agency).

The Company may disclose Your Personal Data in the good faith belief that such action is necessary to:

Security of Your Personal Data

The security of Your Personal Data is important to Us. We implement technical and organizational measures designed to protect Personal Data against unauthorized access, use, disclosure, alteration and destruction, including:

You can help protect Your data by:

Breach notification. If We become aware of a security breach affecting Your Personal Data, We will notify You and the relevant supervisory authorities where and within the timeframes required by applicable law.

Please remember that no method of transmission over the Internet, or method of electronic storage, is 100% secure. While We strive to use commercially reasonable means to protect Your Personal Data, We cannot guarantee its absolute security.

International Data Transfers

We operate from the United States, and Our servers and those of Our Sub-processors are located in the United States. Your information, including Personal Data, may therefore be transferred to — and maintained on — computers located outside of Your state, province, country or other governmental jurisdiction, where data protection laws may differ from those in Your jurisdiction.

Transfers from the EEA, UK and Switzerland

Where We transfer Personal Data from the European Economic Area, the United Kingdom or Switzerland to a country that has not been recognized as providing an adequate level of data protection, We implement appropriate safeguards, including:

The Company will take all steps reasonably necessary to ensure that Your data is treated securely and in accordance with this Privacy Policy.

Your Privacy Choices

You have choices about how We collect and use Your data:

Your Privacy Rights

Depending on where You live, You may have the following rights regarding Your Personal Data.

Your Right How to Exercise It
Access or Know — confirm whether We process Your Personal Data and receive a copy of it Much of Your data is visible in the Application. For a complete copy, email capsmol@gmail.com
Correction or Rectification — correct inaccurate or incomplete Personal Data Update Your information in the account settings section of the Application, or contact Us at capsmol@gmail.com
Deletion or Erasure — request deletion of Your Personal Data Delete individual content or Your entire Account in the Application, or contact Us at capsmol@gmail.com
Portability — receive Your data in a structured, commonly used format Email capsmol@gmail.com to request an export of Your Account data, User Content and Project Data
Opt-Out — opt out of targeted advertising, “sales” or “sharing” of Personal Data We do not sell or share Personal Data for cross-context behavioral advertising, so there is nothing to opt out of. You can still opt out of analytics in the Application’s privacy settings
Restrict or Object — object to or restrict certain processing Contact Us at capsmol@gmail.com describing the processing You object to
Withdraw Consent — withdraw consent previously given Adjust Your settings in the Application or Device, or contact Us at capsmol@gmail.com. Withdrawal does not affect prior lawful processing
Non-Discrimination — not be discriminated against for exercising Your rights We will not deny You the Service, charge different prices, or provide a different quality of service because You exercised Your privacy rights

How to Exercise Your Rights

To exercise any of Your privacy rights, email Us at capsmol@gmail.com with “Privacy Request” in the subject line.

Verification. To protect Your privacy, We will verify Your identity before fulfilling Your request. We may ask You to confirm information that matches what We have on file, such as the email address associated with Your Account.

Authorized agents. You may designate an authorized agent to submit requests on Your behalf. We may require proof of authorization and may still verify Your identity directly.

Response time. We will respond to Your request within the timeframes required by applicable law.

State Law Privacy Rights

California Resident Rights

If You are a California resident, the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), provides You with specific rights:

To exercise these rights, contact Us at capsmol@gmail.com. We will respond to verifiable requests within the timeframes required by applicable law.

Nevada Resident Rights

If You are a resident of Nevada, You have the right to opt out of the sale of certain Personal Data to third parties who intend to license or sell that Personal Data. We do not engage in such sales. You may still submit a request by emailing capsmol@gmail.com with the subject line “Nevada Do Not Sell Request”, including Your name and the email address associated with Your Account.

Other U.S. State Privacy Rights

If You are a resident of Texas, California, Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Utah, Virginia, or another state with a comprehensive privacy law, You may have the following rights:

To exercise these rights, contact Us at capsmol@gmail.com.

Right to Appeal

If You are a resident of a state that provides an appeal right — including Colorado, Connecticut, Delaware, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, or Virginia — and We deny Your privacy request, You may appeal Our decision. To appeal, email capsmol@gmail.com with “Privacy Request Appeal” in the subject line and include:

We will respond to Your appeal within the timeframe required by applicable law. If You are not satisfied with Our response, You may contact Your state’s attorney general to file a complaint.

Consumer Health Data

We do not collect, process or infer consumer health data as defined by the Washington My Health My Data Act, Nevada SB 370, or similar laws. We do not use Your location to identify visits to health care services, and We do not derive health-related inferences from Your User Content.

EEA, UK and Switzerland Resident Rights

If You are located in the European Economic Area, the United Kingdom, or Switzerland, You have the rights described in Your Privacy Rights under the General Data Protection Regulation (GDPR) or equivalent law, as well as the right to lodge a complaint with Your local data protection authority if You believe We have not complied with applicable data protection law.

You can find Your local data protection authority here:

The authority You may contact is typically that of Your habitual residence, Your place of work, or the location where the alleged infringement occurred.

Brazil Resident Rights (LGPD)

If You are located in Brazil, You have rights under the Lei Geral de Proteção de Dados (LGPD), including the rights to access, correct, delete and port Your Personal Data, to obtain information about the sharing of Your data, and to revoke consent.

To exercise these rights, contact Us at capsmol@gmail.com. You also have the right to file a complaint with the Autoridade Nacional de Proteção de Dados (ANPD).

Data Controller Information

The controller responsible for Your Personal Data under this Privacy Policy is Aleksei Smolygin, an individual developer doing business as Floom, located in the State of Texas, United States. You can reach Us regarding any privacy matter at capsmol@gmail.com.

Children’s Privacy

Our Service does not address anyone under the age of 18. We do not knowingly collect personally identifiable information from anyone under the age of 18, and We do not knowingly collect personal information from children under 13 as defined by the U.S. Children’s Online Privacy Protection Act (COPPA).

If You are a parent or guardian and You are aware that Your child has provided Us with Personal Data, please contact Us at capsmol@gmail.com and We will delete that information. If We become aware that We have collected Personal Data from anyone under the age of 18 without verification of parental consent, We take steps to remove that information from Our servers.

If We need to rely on consent as a legal basis for processing Your information and Your country requires consent from a parent, We may require Your parent’s consent before We collect and use that information.

Our Service may contain links to other websites that are not operated by Us. If You click on a third party link, You will be directed to that third party’s site. We strongly advise You to review the Privacy Policy of every site You visit.

We have no control over and assume no responsibility for the content, privacy policies or practices of any third party sites or services.

Changes to this Privacy Policy

We may update Our Privacy Policy from time to time. We will notify You of any changes by posting the new Privacy Policy on this page and updating the “Last updated” date at the top.

Where the change is material — as with the introduction of server-side storage in Floom 2.0 — We will let You know in advance by email and/or a prominent notice in the Application, before the change becomes effective. Where applicable law requires Your consent for a change, We will obtain it before the change applies to You.

You are advised to review this Privacy Policy periodically for any changes. Changes to this Privacy Policy are effective when they are posted on this page.

Contact Us

If you have any questions about this Privacy Policy, You can contact us:

© Floom 2026