🔒 Bloomling — Privacy Policy
Last updated: October 6, 2026 (added "Get name from website" for parents, 1.2.20261005; Puzzle Garden since 1.1.20261002; tip jar and passcode since 1.0.20260912)
← Back to Bloomling · Support
Contact: [email protected]
In one line
The developer of Bloomling never receives personal data about you or your child. Everything you set up stays on your own device — no server of ours stores anything, no account, no analytics or advertising SDKs.
Please note, however: when the child opens a web card — a page a parent added, a YouTube video, an Instagram post, or one of our own Puzzle Garden games — that site receives standard request data, exactly as ordinary web browsing does. Bloomling does not send anything to them; this is simply what connecting to a website entails. Details below.
Who receives data
| Party | When | What they receive | Purpose | How a parent can avoid it |
|---|---|---|---|---|
| The developer (rexcode) | Never receives personal data (for our own game pages, see the next row) | Nothing | — | Nothing to do |
| rexcode.app Puzzle Garden (the developer's own game pages, built in since 1.1.20261002) | When the child opens a Puzzle Garden card | Standard web request data (IP address, user-agent, URL and time), handled by the site's host, Cloudflare, as for any website. The pages load no analytics and no third-party scripts | Delivering the page; the developer sees only aggregate request totals, never who made them | Delete those cards, or switch off the Web List entirely |
| Websites the parent adds (e.g. Wikipedia) | When the child opens that card | Standard web request data: IP address, browser/device user-agent, the URL and time visited; the site may also set cookies on the device | Governed by that site's privacy policy | Don't add the page, or switch off the Web List entirely |
| Google / YouTube | When the child opens a parent-added YouTube card | The above, plus playback activity | Governed by Google's privacy policy; may include advertising | Don't add YouTube cards |
| Meta / Instagram | When the child opens a parent-added Instagram card | The above | Governed by Meta's privacy policy | Don't add Instagram cards |
| Apple (App Store) | Only if a parent, past the parental gate, chooses to tip or opens another app's page | Handled by Apple under Apple's terms; Bloomling never sees payment details | Apple's | Don't tip — every feature is free |
Bloomling itself contains no third-party analytics, advertising, or tracking SDKs (no Google Analytics, no Facebook SDK, no ad SDK) and never sends anything over the network for measurement purposes.
About the YouTube embed — please don't misread it
Bloomling embeds videos through youtube-nocookie.com ("privacy-enhanced mode"). What that mode actually means is: before the child presses play, YouTube does not write cookies used for personalized advertising.
It does not mean ad-free, and it does not mean no data is sent. Once playback starts, Google still receives request data, and ads may still appear before, during, or after the video. If you want your child to see no advertising at all, do not add YouTube cards.
Where data is stored
Everything you create in the app — the parent-approved site list, activity toggles, card photos, on-device usage counts and durations, and the parental-gate passcode setting — is stored only in the app's sandbox on this device. It never leaves the device, and the developer cannot see it.
When the child browses a page, that website may leave cookies and cache on the device. These likewise stay on this device, are invisible to the developer, and can be cleared at any time (see "How to delete data").
Microphone & speech
The Math Tutor's voice-answer feature requests microphone access to recognize the number your child speaks. Speech recognition runs entirely on-device (requiresOnDeviceRecognition); audio is never uploaded or stored and is discarded immediately after matching. If on-device recognition isn't available, the app automatically falls back to tap-to-answer and does not use the microphone.
Network use
Bloomling uses the network only to:
- Load the exact parent-approved URL (a strict allow-list; the child cannot browse beyond it) — data flows to that site, as described above.
- Load a Puzzle Garden game from rexcode.app — the same allow-list rule, one exact URL per card; the page loads no analytics or third-party scripts.
- Play a parent-added YouTube video or Instagram post — data flows to Google / Meta, as described above.
- When a parent, past the parental gate, adds a card with "Get name from website" turned on: read the title of the URL the parent just pasted, from the parent's device (for YouTube links, through YouTube's official oEmbed address on youtube.com). That site receives standard request data, just as when the card is opened; nothing goes through the developer. Turn the switch off and type the name yourself to skip this.
- Optionally send settings device-to-device over the same Wi-Fi — a local, encrypted peer connection that never goes through a server and needs no Apple account.
- Open "More from rexcode" or a tip, if a parent chooses to — handled by the App Store; Bloomling never touches your payment details.
The app launches and works without a network connection (Math Tutor, Story Machine, and Read-Along are fully offline).
Children's privacy (COPPA / GDPR-K)
Bloomling is a child-directed app. We accept the obligations of COPPA and related children's privacy rules on that basis — independent of which App Store category we select. A category choice does not, and should not, change whether an app is in fact directed to children.
In practice:
- The developer collects no personal information from children; there are no accounts or sign-ins.
- The app contains no third-party advertising or tracking SDKs.
- Every exit from the kids' area (settings, external links, tipping) sits behind a parental gate (a math question, or a parent-chosen 4-digit passcode).
- All third-party content is added by a parent. A child cannot add URLs and cannot navigate out of an embed. A parent adds each URL individually, from behind the parental gate; that act is the parent's informed choice to expose their child to that third party. We disclose plainly what happens so that the choice is an informed one.
- A parent who wants no web contact at all can switch off the Web List in parent settings (this also hides the Puzzle Garden), making Bloomling a 100% offline learning app.
What parents can control
- Fully offline: Parent Settings → turn off Web List. The child's home screen keeps only the built-in offline activities.
- Pick item by item: add only URLs you trust; remove any Puzzle Garden card you don't want; adding no YouTube/Instagram means no data flows to those two companies.
- Per-weekday scheduling: each card can be limited to specific days.
- Parental gate: a math question or a 4-digit passcode, so the child cannot reach settings.
How to delete data
| What | How |
|---|---|
| A card and its photo | Parent Settings → Web Settings → swipe to delete (the photo goes with it) |
| Usage statistics | Parent Settings → Usage Stats → Clear all usage stats |
| Cookies and cache left by websites | Parent Settings → Tools → Clear Browsing Data |
| Everything | Delete the app. All data is local with no cloud backup, so removing the app removes it all |
Because the developer holds none of your data, there is no "request deletion from us" process — deletion is entirely in your hands.
Changes to this policy
If this policy changes, the "Last updated" date at the top of this page will be updated. Material changes will also be noted in the app's release notes.
Contact
Privacy questions? Email [email protected].