Privacy
This private Bloom installation uses Authentik for authentication. Only the two configured users may connect, with a verified email address.
Bloom stores the provider issuer and subject, the initial email address, the display name, and its own session. Bloom has no account passwords.
The owner's cycle, symptoms, journal, and daily readings are stored in the server's SQLite database. The partner sees Bloom's partner dashboard and can receive notifications through the configured service (such as Discord) when the owner enables them.
Private pages are never cached by the service worker. The owner can export data in Settings. Contact the server administrator to erase data or revoke Bloom sessions.
Logging out ends the Bloom session. Authentik logout is optional and disabled by default.
The server operator controls storage and optional encryption keys. This application does not provide end-to-end encryption. Backup passphrases encrypt downloaded files; they are not account passwords.