Skip to content

Privacy and personal data

Privacy hub TooBloom

The project uses a single public hub on `.com`, but separates the privacy texts for SITE, APP and API to avoid mixed or confusing documents.

Use this page as an index. The detailed policies are at the dedicated paths `/site/privacy`, `/app/privacy` and `/api/privacy`.

Privacy paths

Choose the correct surface

Each path below is built on the technical behaviour the repository currently demonstrates.

Marketing site

SITE privacy

Covers the scope of the `.com` marketing site: navigation, contact forms, quiz flows, quote builder and GTM consent. Go to /site/privacy.

Application

APP privacy

Covers the scope of the `www.toobloom.io/app` application: TooBloom account, Google OAuth, local storage, saved reports, billing and AI. Go to /app/privacy.

Backend services

API privacy

Covers the scope of the `api.toobloom.com` backend: accounts, consent records, logs, invoices, notifications and third-party server-side services. Go to /api/privacy.

Operational note

What remains to be verified outside the repository