Privacy Policy
Last updated: October 1, 2026
This Privacy Policy describes Our policies and procedures on the collection, use and disclosure of Your information when You use the Service and tells You about Your privacy rights and how the law protects You.
We use Your Personal Data to provide and improve the Service. By using the Service, You agree to the collection and use of information in accordance with this Privacy Policy.
What Changed in Floom 2.0
Earlier versions of Floom kept Your content on Your device. Starting with Floom 2.0, when You sign in and use Our cloud features, Your content, quiz answers and settings are stored on Our servers so that they can be shared with Your Partner, synchronized across Your devices and restored if You reinstall the Application or change devices.
This is a material change to how We handle Your information, and We have rewritten this Privacy Policy accordingly. The sections most relevant to the change are:
- Categories of Personal Data We Collect
- Cloud Storage and Synchronization
- Sharing with Your Partner
- Signing In with Apple
- Location Data
- AI and Your Content
- Third-Party Service Providers
- Retention of Your Personal Data
- Delete Your Personal Data
- Security of Your Personal Data
Interpretation and Definitions
Interpretation
The words whose initial letters are capitalized have meanings defined under the following conditions. The following definitions shall have the same meaning regardless of whether they appear in singular or in plural.
Definitions
For the purposes of this Privacy Policy:
-
Account means a unique account created for You to access our Service or parts of our Service.
-
Affiliate means an entity that controls, is controlled by, or is under common control with a party, where “control” means ownership of 50% or more of the shares, equity interest or other securities entitled to vote for election of directors or other managing authority.
-
Application refers to Floom, the software program provided by the Company.
-
Cloud Storage means the storage of Your User Content, Project Data and Account information on servers operated by Us or by Our Service Providers on Our behalf, so that this information is available to You across devices and can be restored.
-
Company (referred to as either “the Company”, “We”, “Us” or “Our” in this Privacy Policy) refers to Aleksei Smolygin, an individual developer doing business as Floom.
-
Country refers to: United States (State of Texas).
-
Device means any device that can access the Service such as a computer, a cell phone or a digital tablet.
-
Partner means the other Floom user whose Account You have connected to Yours using an invite code or link.
-
Personal Data (or “Personal Information”) is any information that relates to an identified or identifiable individual.
We use “Personal Data” and “Personal Information” interchangeably unless a law uses a specific term.
-
Project Data means the information associated with Your use of the Application, such as Your quiz answers and results, streaks, Your anniversary date and countdowns, and Application settings and preferences.
-
Service refers to the Application, including the server-side storage, synchronization, partner and account features introduced in Floom 2.0.
-
Service Provider means any natural or legal person who processes the data on behalf of the Company. It refers to third-party companies or individuals employed by the Company to facilitate the Service, to provide the Service on behalf of the Company, to perform services related to the Service or to assist the Company in analyzing how the Service is used.
-
Sub-processor means a Service Provider that processes Personal Data on Our behalf under Our instructions. The Sub-processors We use are listed in the Third-Party Service Providers section.
-
Third-Party Sign-In Service means an authentication service operated by a third party that You may use to sign in to the Service, specifically Sign in with Apple.
-
Usage Data refers to data collected automatically, either generated by the use of the Service or from the Service infrastructure itself (for example, the duration of a page visit).
-
User Content means the content You create with or upload to the Application that is saved to Cloud Storage, such as custom quizzes and their photos, drawings, notes, photo statuses and captions, and Your profile name and avatar.
-
You means the individual accessing or using the Service, or the company, or other legal entity on behalf of which such individual is accessing or using the Service, as applicable.
Collecting and Using Your Personal Data
Categories of Personal Data We Collect
The table below describes the categories of Personal Data We collect and the reason We collect each category.
| Category of Personal Data | Examples of Personal Data We Collect |
|---|---|
| Identity and Account Data | Account identifier received from Sign in with Apple; email address (including an Apple private relay address, if You choose to hide Your email); display name and avatar, if You set them; birthday, if You add it; subscription status |
| User Content | Custom quizzes and their photos, drawings, notes, photo statuses and captions You create with or upload to the Application |
| Project and Settings Data | Quiz answers and results, streaks, anniversary date and countdowns, Application preferences and settings synchronized to Your Account |
| Location Data | Precise location of Your Device, only if You allow it and only while the Application is open, used for the distance widget. We keep only Your most recent location, not a history |
| Purchase and Transaction Data | Purchase history, subscription plan and status, transaction amounts and dates. Payment card details are processed by Apple and are never received or stored by Us |
| Usage and Analytics Data | Feature usage, in-app events, session information, performance metrics |
| Device and Technical Data | IP address, device model and type, operating system, Application version, unique device identifiers, browser type where applicable, diagnostic and crash logs |
| Customer Support Data | Support inquiries, correspondence with Us, feedback and reviews You submit |
What We Do Not Collect
To be explicit about the limits of Our collection, We do not:
- Collect Your location in the background or keep a history of Your locations
- Extract, derive or store biometric templates, and We do not use facial recognition technology to identify individuals in Your User Content
- Access Your contacts, address book or calendar
- Collect government-issued identity documents
- Receive data about You from advertising networks, data brokers or attribution partners
- Embed advertising SDKs or advertising pixels in the Application
Cloud Storage and Synchronization
This section describes the server-side storage introduced in Floom 2.0.
What We store. When You are signed in to Your Account and use Our cloud features, We store Your User Content, Project Data and Account information on Our servers.
Why We store it. We store this information to synchronize Your work across Your devices, to let You restore Your content after reinstalling the Application or moving to a new device, to give You access to Your project history, and to apply the storage and feature limits associated with Your plan.
Your content is private to You and Your Partner. User Content stored in Cloud Storage is associated with Your Account and is accessible only to You and, once You connect with a Partner, to that Partner as described in Sharing with Your Partner. It is not published, is not made available to any other users, and is not used for advertising. Our personnel do not access the substance of Your User Content, except in narrow circumstances: when You ask Us to do so in order to resolve a support issue, when We are required to by law or valid legal process, or when it is necessary to investigate a suspected violation of Our terms or a threat to the safety of any person.
How it is protected. Data is encrypted in transit using TLS and encrypted at rest by Our infrastructure providers. Storage is logically isolated per Account. See Security of Your Personal Data for more detail.
Your control. You can delete individual files and projects from within the Application, and You can delete Your Account and the associated content entirely. See Delete Your Personal Data.
Sharing with Your Partner
Floom is made for two. To use most features, You connect Your Account with another Floom user, Your Partner, by sharing an invite code or link. Both of You must accept the connection, and You can be connected to only one Partner at a time.
What Your Partner can see. While You are connected, Your Partner can see:
- Your profile name, avatar and birthday, and the anniversary and countdowns You set up together
- Your answers to quizzes and daily questions, and the results and match rates You get together
- Custom quizzes You create, including their photos
- Drawings, notes, and photo statuses with captions You add to shared widgets
- Your location, if You allow location access for the distance widget (see Location Data)
- Whether You have Floom Pro, because a subscription unlocks Floom Pro for both of You
Your Partner can view, screenshot or save anything You share with them. We cannot control what Your Partner does with content once they have seen it, so please share only what You are comfortable sharing.
Unpairing. Either of You can unpair at any time in the Application. When You unpair, We delete the location, photo status and countdown data of that connection, and You and Your former Partner no longer see each other’s new activity.
Deleting an Account while connected. If You or Your Partner deletes their Account, the content You created together as a couple, including shared quiz results, widgets, drawings, notes and countdowns, is permanently deleted for both of You.
Signing In with Apple
Floom uses Sign in with Apple for authentication. We do not create or store passwords for Your Floom Account.
When You sign in, We receive:
- A unique account identifier for You from Apple
- Your email address, or the private relay address Apple generates on Your behalf if You choose to hide Your email
- Authentication tokens needed to keep You signed in
We do not receive Your Apple ID password, Your contacts, Your social connections, Your profile photo, or the contents of Your mailbox. We do not automatically populate Your Floom profile from these services.
You can revoke Floom’s access at any time in Your Apple ID settings. Revoking access prevents You from signing in again; it does not by itself delete Your Floom Account or the content stored in it. To delete Your data, follow the steps in Delete Your Personal Data.
Usage Data
Usage Data is collected automatically when using the Service.
Usage Data may include information such as Your Device’s Internet Protocol address (e.g. IP address), browser type, browser version, the pages of our Service that You visit, the time and date of Your visit, the time spent on those pages, unique device identifiers and other diagnostic data.
When You access the Service by or through a mobile device, We may collect certain information automatically, including, but not limited to, the type of mobile device You use, Your mobile device’s unique ID, the IP address of Your mobile device, Your mobile operating system, the type of mobile Internet browser You use, unique device identifiers and other diagnostic data.
We may also collect information that Your browser sends whenever You visit Our Service or when You access the Service by or through a mobile device.
Information Collected while Using the Application
While using Our Application, in order to provide features of Our Application, We may request Your permission to access:
- Your Device’s camera and photo library, so that You can take or select photos for custom quizzes, photo statuses and Your avatar
- Your Device’s location, so that the distance widget can show how far apart You and Your Partner are (see Location Data)
- Notifications, so that We can let You know about Your Partner’s activity and updates to the Service
Photos You select or capture are used to provide the features of the Service. They are uploaded to and stored in Cloud Storage as described in Cloud Storage and Synchronization and shared with Your Partner as described in Sharing with Your Partner. We do not scan Your photo library, and We access only the items You select.
You can enable or disable access to Your camera, photo library, location and notifications at any time through Your Device settings. If You disable access, some features of the Application will not function.
App Tracking Transparency. The Application may ask for Your permission under Apple’s App Tracking Transparency framework. Whatever You choose, We do not currently access Your Device’s advertising identifier (IDFA) or use advertising attribution SDKs. If this changes, We will do so only with Your permission and after updating this Privacy Policy.
Sharing outside Floom. If You choose to share a quiz result to Instagram Stories or save it to Your photo library, this happens only at Your request, and the shared content is then subject to the terms and privacy policies of Instagram or Apple.
Location Data
The distance widget shows how far apart You and Your Partner are. It works only if You allow location access, and only while the Application is open. We do not collect Your location in the background.
- What We store: Your most recent precise location (latitude, longitude and accuracy) and the time it was updated. We do not keep a history of Your locations.
- Who can see it: You and Your Partner. Your Partner’s Application receives Your location in order to show the distance between You.
- How long We keep it: Your stored location is replaced each time it updates and is deleted when You unpair or delete Your Account.
- How to stop: Turn off location access for Floom in Your Device settings at any time. The distance widget will then stop updating.
AI and Your Content
Floom processes Your User Content on Our own infrastructure.
- We do not send Your User Content to third-party artificial intelligence providers for processing.
- We do not use Your User Content to train artificial intelligence or machine learning models.
- We do not sell, license or otherwise make Your User Content available to third parties for their own model training.
If this ever changes, We will update this Privacy Policy and notify You in advance in accordance with the Changes to this Privacy Policy section, and where consent is required by law, We will ask for it first.
Use of Your Personal Data
The Company may use Personal Data for the following purposes:
- To provide and maintain our Service, including to monitor the usage of our Service.
- To store and synchronize Your content: to save Your User Content and Project Data to Cloud Storage, keep it synchronized across Your devices, and make it available to You again after reinstalling the Application or switching devices.
- To connect You with Your Partner: to pair Your Account with Your Partner’s, show each of You the content You share, and calculate shared results, match rates and the distance between You.
- To back up and restore Your data: to maintain backups so that Your content can be recovered after a technical failure, and to restore Your Account when You request it.
- To authenticate You and secure Your Account: to verify Your identity through Sign in with Apple, keep You signed in, detect unauthorized access, and help You recover access to Your Account.
- To manage Your Account: to manage Your registration as a user of the Service. The Personal Data You provide can give You access to different functionalities of the Service that are available to You as a registered user.
- To administer plans and storage limits: to determine Your subscription entitlements and apply the storage and feature limits associated with Your plan.
- For the performance of a contract: the development, compliance and undertaking of the purchase contract for the products, items or services You have purchased or of any other contract with Us through the Service.
- To prevent fraud and abuse: to detect, investigate and prevent fraudulent transactions, abuse of the Service, and activity that violates Our terms or the law.
- To monitor stability and debug: to diagnose crashes and errors, measure performance, and keep the Service reliable.
- To contact You: To contact You by email, telephone calls, SMS, or other equivalent forms of electronic communication, such as a mobile application’s push notifications regarding updates or informative communications related to the functionalities, products or contracted services, including the security updates, when necessary or reasonable for their implementation.
- To provide You with news, special offers, and general information about other goods, services and events which We offer that are similar to those that you have already purchased or inquired about unless You have opted not to receive such information.
- To manage Your requests: To attend and manage Your requests to Us.
- For business transfers: We may use Your Personal Data to evaluate or conduct a merger, divestiture, restructuring, reorganization, dissolution, or other sale or transfer of some or all of Our assets, whether as a going concern or as part of bankruptcy, liquidation, or similar proceeding, in which Personal Data held by Us about our Service users is among the assets transferred.
- For other purposes: We may use Your information for other purposes, such as data analysis, identifying usage trends, determining the effectiveness of our promotional campaigns and to evaluate and improve our Service, products, services, marketing and your experience.
How We Share Your Personal Data
We share Personal Data only in the situations described below.
- With Your Partner: We share the content and information described in Sharing with Your Partner with the Partner You connect with.
- With Service Providers: We share Personal Data with the Sub-processors listed in Third-Party Service Providers so that they can host Our infrastructure, store data on Our behalf, process payments, provide analytics, and help Us support You. Service Providers may process Personal Data only on Our instructions and for the purposes We specify.
- With Affiliates: We may share Your Personal Data with Our affiliates, in which case we will require those affiliates to honor this Privacy Policy. Affiliates include Our parent company and any other subsidiaries, joint venture partners or other companies that We control or that are under common control with Us.
- For legal reasons: We may disclose Personal Data where necessary to comply with a legal obligation or in the circumstances described in Disclosure of Your Personal Data.
- For business transfers: We may share or transfer Your Personal Data in connection with, or during negotiations of, any merger, sale of Company assets, financing, or acquisition of all or a portion of Our business to another company.
- With Your consent: We may disclose Your Personal Data for any other purpose with Your consent.
We do not share Your User Content or Project Data with advertising partners, marketing partners, data brokers, or third-party artificial intelligence providers.
Third-Party Service Providers
We use the following third parties to operate the Service. Each processes Personal Data on Our behalf and under contract.
| Sub-processor | Purpose | Categories of data processed |
|---|---|---|
| Railway | Hosting of Our backend services, databases and storage of User Content and Project Data. Data is encrypted in transit and at rest. | Identity and Account Data, User Content, Project and Settings Data, Device and Technical Data |
| PostHog | Product analytics: understanding how features are used, measuring performance and diagnosing errors, including session replays in which text input and images are masked. | Usage and Analytics Data, Device and Technical Data, Account identifier |
| Sentry | Crash reporting and error monitoring. | Device and Technical Data, Account identifier |
| RevenueCat | Managing subscriptions and purchase status across Your devices and with Your Partner. | Purchase and Transaction Data, Account identifier, Device and Technical Data |
| Apple | Authentication through Sign in with Apple; processing of purchases and subscriptions through the App Store; delivery of push notifications. | Identity and Account Data, Purchase and Transaction Data |
These providers have their own privacy policies governing their handling of Personal Data.
Floom does not use advertising SDKs, advertising pixels, or mobile attribution trackers. We do not embed tools such as advertising network pixels or attribution SDKs in the Application, and We do not send Your data to advertising platforms.
No Data Selling
We do not sell Your Personal Data, and We do not share Your Personal Data for cross-context behavioral advertising, as those terms are defined under the California Consumer Privacy Act and similar state privacy laws. We have not sold or shared Personal Data for those purposes in the preceding 12 months.
If Our practices change materially, We will update this Privacy Policy and notify You in accordance with applicable law before the change takes effect.
Aggregated and Anonymous Data
We may create aggregated, de-identified or anonymized data from the Personal Data We collect, including by removing information that makes the data personally identifiable to a particular user. We may use such data, and share it with third parties, for lawful business purposes including analyzing and improving the Service. We do not attempt to re-identify data that has been de-identified.
Legal Basis for Processing
If You are located in the European Economic Area (“EEA”), the United Kingdom, or Switzerland, We process Your Personal Data on the following legal grounds under applicable data protection law:
| Purpose of Processing | Legal Basis | Categories of Data |
|---|---|---|
| Providing and maintaining the Service, including creating Your Account and enabling core features | Performance of our contract with You | Identity and Account, User Content, Project and Settings, Device and Technical |
| Storing and synchronizing Your content in Cloud Storage, and backing it up | Performance of our contract with You | User Content, Project and Settings, Identity and Account |
| Connecting You with Your Partner and sharing content with them | Performance of our contract with You | Identity and Account, User Content, Project and Settings |
| Showing the distance between You and Your Partner | Consent (location permission) | Location |
| Authenticating You and protecting Your Account | Performance of our contract with You; Legitimate interests (account security) | Identity and Account, Device and Technical |
| Processing payments, subscriptions and refunds | Performance of our contract with You; Compliance with legal obligations (tax and accounting) | Identity and Account, Purchase and Transaction |
| Responding to Your inquiries and providing customer support | Performance of our contract with You; Legitimate interests (providing quality service) | Identity and Account, Customer Support, Usage |
| Analyzing usage and improving the Service | Legitimate interests (improving the Service); Consent where required by applicable law | Usage and Analytics, Device and Technical |
| Ensuring safety, security and fraud prevention | Legitimate interests (protecting our users and the Service); Compliance with legal obligations | Identity and Account, Usage and Analytics, Device and Technical |
| Sending marketing communications | Consent (for electronic marketing); Legitimate interests (promoting Our Service) where permitted | Identity and Account, Usage and Analytics |
| Complying with legal obligations | Compliance with legal obligations | All categories as required |
| Establishing, exercising or defending legal claims | Legitimate interests (protecting Our legal rights) | All categories as relevant to the claim |
Where We rely on legitimate interests, We have balanced Our interests against Your fundamental rights and freedoms.
Where We rely on consent, You have the right to withdraw Your consent at any time by contacting Us or adjusting Your settings. Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.
Retention of Your Personal Data
The Company will retain Your Personal Data only for as long as is necessary for the purposes set out in this Privacy Policy. We will retain and use Your Personal Data to the extent necessary to comply with our legal obligations (for example, if We are required to retain Your data to comply with applicable laws), resolve disputes, and enforce our legal agreements and policies.
Where possible, We apply shorter retention periods and reduce identifiability by deleting, aggregating, or anonymizing data. Unless otherwise stated, the retention periods below are maximum periods (“up to”) and We may delete or anonymize data sooner when it is no longer needed for the relevant purpose.
| Data Category | Retention Period | Rationale |
|---|---|---|
| Account and Profile Data | Duration of Your Account + 30 days after deletion | To provide the Service and allow a short recovery window in case of accidental deletion |
| User Content and Project Data | Duration of Your Account; deleted within 30 days of Account deletion | Core service functionality; prompt deletion once You leave |
| Location Data | Most recent location only; replaced on each update and deleted when You unpair or delete Your Account | Distance widget |
| Purchase and Billing Records | 7 years after the transaction | Tax, accounting and legal compliance requirements |
| Usage and Analytics Data | Up to 24 months | Understanding feature adoption and improving the Service |
| Server and Security Logs | Up to 12 months | Security monitoring, incident investigation and troubleshooting |
| Customer Support Records | 3 years after the inquiry is resolved | Support quality, dispute resolution and legal claims |
| Backups | Rotating backups retained up to 90 days | Disaster recovery and data integrity |
| Aggregated / De-identified Data | Indefinitely | No longer identifiable; used for analytics and service improvement |
We may retain Personal Data beyond the periods stated above for the following reasons:
- Legal obligation: We are required by law to retain specific data (for example, financial records for tax authorities).
- Legal claims: Data is necessary to establish, exercise, or defend legal claims.
- Safety and abuse prevention: Limited data may be retained to investigate unlawful or harmful conduct and to prevent users who violate Our terms from creating new accounts.
- Your explicit request: You ask Us to retain specific information.
- Technical limitations: Data exists in backup systems that are scheduled for routine deletion.
You may request information about how long We will retain Your Personal Data by contacting Us.
When retention periods expire, We securely delete or anonymize Personal Data:
- Deletion: Personal Data is removed from Our systems and no longer actively processed.
- Backup retention: Residual copies may remain in encrypted backups for a limited period consistent with our backup retention schedule and are not restored except where necessary for security, disaster recovery, or legal compliance.
- Anonymization: In some cases, We convert Personal Data into anonymous statistical data that cannot be linked back to You. This anonymized data may be retained indefinitely for research and analytics.
Delete Your Personal Data
You have the right to delete or request that We assist in deleting the Personal Data that We have collected about You.
Deleting individual content. You can delete individual files and projects from within the Application at any time.
Deleting Your Account. You can delete Your entire Account and its associated content from within the Application, in the account settings section. You may also contact Us at capsmol@gmail.com to request deletion.
How deletion works. Floom uses a two-layer deletion process:
- Layer 1 — Active systems: When You delete content or Your Account, We remove Your access immediately and remove the data from Our active systems within 30 days, so that it is no longer accessible or processed.
- Layer 2 — Backups: Deleted data may persist in encrypted backups and disaster recovery systems until those backups age out of Our rotation (up to 90 days). Backup data is not accessible in normal operations and is not used to restore deleted accounts, but it has not yet been permanently destroyed.
Complete deletion requests. If You require destruction of all copies of Your data, including backups, contact Us at capsmol@gmail.com and We will accommodate Your request to the extent technically feasible and legally permissible.
What We keep after deletion. We may retain limited information after Account deletion where We have a legal obligation or lawful basis to do so — for example, billing records required for tax purposes, records needed to establish or defend legal claims, and limited data needed to prevent fraud and abuse of the Service.
You may also update, amend, or correct Your information at any time by signing in to Your Account and visiting the account settings section, or by contacting Us.
Disclosure of Your Personal Data
Business Transactions
If the Company is involved in a merger, acquisition or asset sale, Your Personal Data may be transferred. We will provide notice before Your Personal Data is transferred and becomes subject to a different Privacy Policy.
Law enforcement and government requests
Under certain circumstances, the Company may be required to disclose Your Personal Data if required to do so by law or in response to valid requests by public authorities (for example, a subpoena, court order, search warrant, or a request from a government agency).
Other legal requirements
The Company may disclose Your Personal Data in the good faith belief that such action is necessary to:
- Comply with a legal obligation
- Protect and defend the rights or property of the Company
- Prevent or investigate possible wrongdoing in connection with the Service
- Protect the personal safety of Users of the Service or the public
- Protect against legal liability
Security of Your Personal Data
The security of Your Personal Data is important to Us. We implement technical and organizational measures designed to protect Personal Data against unauthorized access, use, disclosure, alteration and destruction, including:
- Encryption in transit: All communication between the Application and Our servers is encrypted using TLS.
- Encryption at rest: Data stored on Our servers, including User Content, is encrypted at rest by Our infrastructure providers.
- Account isolation: Stored content is logically isolated per Account, so that content is accessible only through Your authenticated Account.
- No password storage: Authentication is handled through Sign in with Apple. We do not create, receive or store passwords for Your Floom Account.
- Access controls: Access to production systems and Personal Data is limited to personnel who need it to perform their duties, and is subject to authentication and access logging.
- Monitoring: We monitor Our systems for errors, anomalies and unauthorized access.
You can help protect Your data by:
- Securing the Apple ID You use to sign in, including enabling two-factor authentication
- Signing out after using a shared device
- Promptly reporting any suspected unauthorized access to capsmol@gmail.com
Breach notification. If We become aware of a security breach affecting Your Personal Data, We will notify You and the relevant supervisory authorities where and within the timeframes required by applicable law.
Please remember that no method of transmission over the Internet, or method of electronic storage, is 100% secure. While We strive to use commercially reasonable means to protect Your Personal Data, We cannot guarantee its absolute security.
International Data Transfers
We operate from the United States, and Our servers and those of Our Sub-processors are located in the United States. Your information, including Personal Data, may therefore be transferred to — and maintained on — computers located outside of Your state, province, country or other governmental jurisdiction, where data protection laws may differ from those in Your jurisdiction.
Transfers from the EEA, UK and Switzerland
Where We transfer Personal Data from the European Economic Area, the United Kingdom or Switzerland to a country that has not been recognized as providing an adequate level of data protection, We implement appropriate safeguards, including:
- Standard Contractual Clauses: We rely on standard contractual clauses approved by the European Commission, or the UK International Data Transfer Agreement or Addendum as applicable, which contractually require the recipient to protect Your Personal Data to European standards.
- Adequacy decisions: Where available, We rely on decisions recognizing a country as providing an adequate level of protection.
- Other safeguards: We may rely on other transfer mechanisms permitted under applicable law.
The Company will take all steps reasonably necessary to ensure that Your data is treated securely and in accordance with this Privacy Policy.
Your Privacy Choices
You have choices about how We collect and use Your data:
- Analytics: You can opt out of product analytics collection in the Application’s privacy settings. Opting out does not affect the Service’s core functionality.
- Marketing communications: You can opt out of marketing emails by using the unsubscribe link in any marketing email or by contacting Us at capsmol@gmail.com. Even if You opt out, We may still send transactional messages about Your Account, purchases or security.
- Push notifications: You can disable push notifications in Your Device settings or in the Application.
- Device permissions: You can grant or revoke access to Your camera, photo library, location and notifications at any time in Your Device settings.
- Partner connection: You can unpair from Your Partner at any time in the Application.
- Cloud Storage: You can delete individual files, projects, or Your entire Account as described in Delete Your Personal Data.
- Authentication: You can revoke Floom’s access in Your Apple ID settings.
Your Privacy Rights
Depending on where You live, You may have the following rights regarding Your Personal Data.
| Your Right | How to Exercise It |
|---|---|
| Access or Know — confirm whether We process Your Personal Data and receive a copy of it | Much of Your data is visible in the Application. For a complete copy, email capsmol@gmail.com |
| Correction or Rectification — correct inaccurate or incomplete Personal Data | Update Your information in the account settings section of the Application, or contact Us at capsmol@gmail.com |
| Deletion or Erasure — request deletion of Your Personal Data | Delete individual content or Your entire Account in the Application, or contact Us at capsmol@gmail.com |
| Portability — receive Your data in a structured, commonly used format | Email capsmol@gmail.com to request an export of Your Account data, User Content and Project Data |
| Opt-Out — opt out of targeted advertising, “sales” or “sharing” of Personal Data | We do not sell or share Personal Data for cross-context behavioral advertising, so there is nothing to opt out of. You can still opt out of analytics in the Application’s privacy settings |
| Restrict or Object — object to or restrict certain processing | Contact Us at capsmol@gmail.com describing the processing You object to |
| Withdraw Consent — withdraw consent previously given | Adjust Your settings in the Application or Device, or contact Us at capsmol@gmail.com. Withdrawal does not affect prior lawful processing |
| Non-Discrimination — not be discriminated against for exercising Your rights | We will not deny You the Service, charge different prices, or provide a different quality of service because You exercised Your privacy rights |
How to Exercise Your Rights
To exercise any of Your privacy rights, email Us at capsmol@gmail.com with “Privacy Request” in the subject line.
Verification. To protect Your privacy, We will verify Your identity before fulfilling Your request. We may ask You to confirm information that matches what We have on file, such as the email address associated with Your Account.
Authorized agents. You may designate an authorized agent to submit requests on Your behalf. We may require proof of authorization and may still verify Your identity directly.
Response time. We will respond to Your request within the timeframes required by applicable law.
State Law Privacy Rights
California Resident Rights
If You are a California resident, the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), provides You with specific rights:
- Right to Know: You may request information about the categories and specific pieces of Personal Data We have collected about You, the sources of that data, the purposes for collecting it, and the third parties with whom We share it.
- Right to Delete: You may request that We delete Your Personal Data, subject to certain exceptions (such as data needed to complete a transaction or comply with legal obligations).
- Right to Correct: You may request that We correct inaccurate Personal Data We maintain about You.
- Right to Opt Out of Sale or Sharing: We do not sell Personal Data and We do not share Personal Data for cross-context behavioral advertising. We do not use advertising pixels or attribution SDKs.
- Right to Limit Use of Sensitive Personal Information: We use precise geolocation, which is sensitive personal information under the CCPA, only to provide the distance widget You request, which does not give rise to a limitation right. We do not use sensitive personal information to infer characteristics about You.
- Right to Non-Discrimination: We will not discriminate against You for exercising any of Your privacy rights.
To exercise these rights, contact Us at capsmol@gmail.com. We will respond to verifiable requests within the timeframes required by applicable law.
Nevada Resident Rights
If You are a resident of Nevada, You have the right to opt out of the sale of certain Personal Data to third parties who intend to license or sell that Personal Data. We do not engage in such sales. You may still submit a request by emailing capsmol@gmail.com with the subject line “Nevada Do Not Sell Request”, including Your name and the email address associated with Your Account.
Other U.S. State Privacy Rights
If You are a resident of Texas, California, Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Utah, Virginia, or another state with a comprehensive privacy law, You may have the following rights:
- Right to Access: Confirm whether We are processing Your Personal Data and access that data.
- Right to Correction: Correct inaccuracies in Your Personal Data.
- Right to Deletion: Delete Personal Data You provided to Us or that We collected about You.
- Right to Data Portability: Obtain a copy of Your Personal Data in a portable, readily usable format.
- Right to Opt Out: Opt out of targeted advertising, the sale of Personal Data, and profiling in furtherance of decisions that produce legal or similarly significant effects. We do not engage in any of these activities.
To exercise these rights, contact Us at capsmol@gmail.com.
Right to Appeal
If You are a resident of a state that provides an appeal right — including Colorado, Connecticut, Delaware, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, or Virginia — and We deny Your privacy request, You may appeal Our decision. To appeal, email capsmol@gmail.com with “Privacy Request Appeal” in the subject line and include:
- Your original request and Our response
- The reason You believe We should reconsider
We will respond to Your appeal within the timeframe required by applicable law. If You are not satisfied with Our response, You may contact Your state’s attorney general to file a complaint.
Consumer Health Data
We do not collect, process or infer consumer health data as defined by the Washington My Health My Data Act, Nevada SB 370, or similar laws. We do not use Your location to identify visits to health care services, and We do not derive health-related inferences from Your User Content.
EEA, UK and Switzerland Resident Rights
If You are located in the European Economic Area, the United Kingdom, or Switzerland, You have the rights described in Your Privacy Rights under the General Data Protection Regulation (GDPR) or equivalent law, as well as the right to lodge a complaint with Your local data protection authority if You believe We have not complied with applicable data protection law.
You can find Your local data protection authority here:
- EEA residents: https://edpb.europa.eu/about-edpb/about-edpb/members_en
- UK residents: Information Commissioner’s Office (ICO) at https://ico.org.uk/
- Switzerland residents: Federal Data Protection and Information Commissioner (FDPIC) at https://www.edoeb.admin.ch/
The authority You may contact is typically that of Your habitual residence, Your place of work, or the location where the alleged infringement occurred.
Brazil Resident Rights (LGPD)
If You are located in Brazil, You have rights under the Lei Geral de Proteção de Dados (LGPD), including the rights to access, correct, delete and port Your Personal Data, to obtain information about the sharing of Your data, and to revoke consent.
To exercise these rights, contact Us at capsmol@gmail.com. You also have the right to file a complaint with the Autoridade Nacional de Proteção de Dados (ANPD).
Data Controller Information
The controller responsible for Your Personal Data under this Privacy Policy is Aleksei Smolygin, an individual developer doing business as Floom, located in the State of Texas, United States. You can reach Us regarding any privacy matter at capsmol@gmail.com.
Children’s Privacy
Our Service does not address anyone under the age of 18. We do not knowingly collect personally identifiable information from anyone under the age of 18, and We do not knowingly collect personal information from children under 13 as defined by the U.S. Children’s Online Privacy Protection Act (COPPA).
If You are a parent or guardian and You are aware that Your child has provided Us with Personal Data, please contact Us at capsmol@gmail.com and We will delete that information. If We become aware that We have collected Personal Data from anyone under the age of 18 without verification of parental consent, We take steps to remove that information from Our servers.
If We need to rely on consent as a legal basis for processing Your information and Your country requires consent from a parent, We may require Your parent’s consent before We collect and use that information.
Links to Other Websites
Our Service may contain links to other websites that are not operated by Us. If You click on a third party link, You will be directed to that third party’s site. We strongly advise You to review the Privacy Policy of every site You visit.
We have no control over and assume no responsibility for the content, privacy policies or practices of any third party sites or services.
Changes to this Privacy Policy
We may update Our Privacy Policy from time to time. We will notify You of any changes by posting the new Privacy Policy on this page and updating the “Last updated” date at the top.
Where the change is material — as with the introduction of server-side storage in Floom 2.0 — We will let You know in advance by email and/or a prominent notice in the Application, before the change becomes effective. Where applicable law requires Your consent for a change, We will obtain it before the change applies to You.
You are advised to review this Privacy Policy periodically for any changes. Changes to this Privacy Policy are effective when they are posted on this page.
Contact Us
If you have any questions about this Privacy Policy, You can contact us:
- By email: capsmol@gmail.com