Privacy policy
Last updated: July 2026
What this is
Bloom Onward is a small, independently-run tool for tracking job applications. This page explains what information it collects, why, and what you control.
Account information
If you sign up directly, we store your email, display name, username, and password - the password as a bcrypt hash, never in plain text, and never visible to anyone, including whoever runs this site. If you sign in with Google instead, we receive your name, email, and profile photo from them and never see your password on their service at all.
Application data
Companies, roles, dates, notes, salary, and locations you enter are private by default and stay private no matter what - regardless of your garden's sharing setting. If you choose to share your garden (link-only), visitors only ever see which plants exist and what stage they're in, never the company name, role, notes, salary, or location behind any of them.
Chrome extension
The Bloom Onward Chrome extension reads the page you're on only when you click its icon, never continuously and never in the background. Whatever it finds (company, role, salary, location, a job posting link) lands in an editable form in the popup for you to review before anything is sent anywhere. Once you submit, those fields go to your own connected account through the same API the website itself uses, nothing more.
The extension doesn't collect analytics, doesn't sell or share data, and doesn't talk to any third party besides the account you connected it to. The token that connects it to your account can be regenerated or fully revoked any time from Settings โ Chrome extension, which immediately signs the extension out everywhere it was used.
Hiring trends analysis
We may review application data in aggregate - for example, response rates by day of week or by country - to understand hiring trends and improve the app. Only the person running this site can access individual account data; it is never sold, shared, or used for advertising. Aggregate trends may occasionally be shared publicly (e.g. a blog post), but never in a way that identifies you. This is separate from, and not conditional on, the optional Google Analytics cookie described below.
Cookies
- One essential session cookie keeps you signed in. It can't be turned off - the app doesn't work without it.
- Google Analytics is optional and only runs if you accept it in the cookie banner (or opt in later via "Cookie preferences" in the footer).
- No ad trackers, ever - full stop.
Third parties this app relies on
- Google - only if you choose to sign in that way. Standard OAuth sign-in; we receive your name, email, and profile photo, nothing else.
- Google Analytics - only with consent. Aggregate usage data - nothing sold, no ad profiles built.
- Resend - delivers "forgot password" emails.
- Neon - hosts the Postgres database this data lives in.
- Render - hosts the application itself.
None of these receive more data than they need to do their specific job, and none are used for advertising.
What we don't do
- We don't sell or rent your data to anyone, ever.
- We don't show ads.
- We don't use tracking cookies beyond the optional, consent-gated Google Analytics above.
Your choices
- You control your garden's privacy setting - private or link-only - any time.
- You can opt in or out of analytics any time via "Cookie preferences" in the footer.
- To request a copy of your data, or ask that your account be deleted, use the Feedback button anywhere in the app - it goes straight to the person running this, and requests are handled by hand.
Changes to this policy
If this policy changes in a meaningful way, the "last updated" date at the top will change too.
Questions
Reach out any time via the Feedback button.