Mama Bloom
Consumer Health Data Privacy Policy
1. Purpose and scope of this document
This is a separate, standalone Consumer Health Data Privacy Policy published under the Washington My Health My Data Act. It is hosted at its own dedicated address (https://mamabloom.app/consumer-health-data) and is not part of, and is not merged into, the general Mama Bloom Privacy Policy. It addresses only consumer health data as that term is defined by MHMDA (RCW 19.373.010).
Nevada’s consumer health data privacy law (SB 370, codified in NRS chapter 603A) imposes closely parallel obligations. We extend the protections, consent model, and rights described in this policy to Nevada consumers, and handle their requests under the same process and timeframes.
This document describes:
- the categories of consumer health data that Mama Bloom collects;
- the sources from which that data is collected;
- the purposes for which it is collected and used;
- the categories of consumer health data that are shared, and the categories of third parties and affiliates with which it is shared (here: service providers/processors only — there is no sale or sharing for advertising);
- how a Washington consumer exercises their rights, the response timeframe, and the appeal path if a request is denied;
- a statement that Mama Bloom does not use any geofence around health-care facilities; and
- the consent model, including the separate opt-in consent to collect and the distinct consent to share.
In this document, “we,” “us,” and “our” mean Mama Bloom UG (haftungsbeschränkt). “You” means a Washington consumer and, where this policy extends to Nevada, a Nevada consumer.
2. Who we are
Mama Bloom UG (haftungsbeschränkt)HRB 47918, Amtsgericht Dresden
Oskarstr. 14, 01219 Dresden, Germany
Consumer health data contact (for the rights described in Section 8): privacy@mamabloom.app
Telephone: +49 152 5826 2078
We are the entity that determines the purposes and means of processing the consumer health data described here.
3. What “consumer health data” means
Under MHMDA, “consumer health data” is personal information that is linked or reasonably linkable to a consumer and that identifies the consumer’s past, present, or future physical or mental health status. For Mama Bloom, this can include reproductive, pregnancy, loss, postpartum, baby-care, mental-wellbeing, nutrition, sleep, and perimenopause information; information you type, photograph, dictate, import, or choose to include in an AI request; and health-related inferences produced from those inputs.
Mama Bloom is a wellness app. It is not a medical device and does not diagnose, treat, or provide medical advice. The fact that information is treated as “consumer health data” for the purposes of this policy does not change that the app is a wellness product.
4. Categories of consumer health data we collect
Depending on the features you choose to use, Mama Bloom may process the following categories. Most saved records remain locally in the app; Section 7 identifies the narrower categories that can leave your device.
- Journey, reproductive, and pregnancy information — selected stage, cycle and fertility entries, basal body temperature, pregnancy week or due date, milestones, symptoms, pregnancy-test records or photos, loss-related context, postpartum recovery, and perimenopause information you enter.
- Physical-wellness and care records — sleep, movement, hydration, nutrition, weight, blood pressure, glucose, medicines, appointments, vaccine records, and other symptom or routine entries you choose to save.
- Mood and mental-wellbeing information — mood entries, journal text, reflection or screening answers, locally derived severity bands, support preferences, and the patterns the app displays from your own records. A band or pattern is not a diagnosis.
- Baby and caregiving information — approximate age, feeding, sleep, diaper, growth, measurement, routine, milestone, and development information you choose to record.
- Apple Health data you authorize — the specific Apple Health metrics you grant Mama Bloom permission to read (for example sleep, steps, resting heart rate, menstrual flow, body weight, and blood pressure). With your permission, Mama Bloom can also write certain entries you record in the app back to Apple Health (for example mood check-ins, weight, blood pressure, and mindful-session minutes). Mama Bloom reads and writes only the categories you authorize, and you can control these in Apple Health at any time.
- AI request content — text you type or dictate to the general companion or a specialist AI tool; an ingredient-label photo you choose to submit; and, when you enable the relevant context control, the limited structured saved context assembled for that request. Structured context can include your first name, selected stage, country-level region, pregnancy or baby context, recent logs or summaries, and other health-related fields described by the feature.
- AI outputs and inferences — the response, reflection, summary, suggestion, or classification generated from an AI request, to the extent it identifies or infers physical or mental health status.
- Support content — the message and references in a support or privacy request, if you choose to include health information.
We do not collect precise location data to infer health status, and we do not derive consumer health data from your location. Country-level region is used for language and local safety signposting.
5. Sources of the consumer health data
- Directly from you — the profile choices, entries, logs, journal text, photographs, dictated or typed AI requests, and support messages you provide. This is the primary source.
- From your device, with your permission — Apple Health data that you explicitly authorize Mama Bloom to read and text produced by on-device speech transcription when available.
- Derived inside Mama Bloom — trends, recent-record summaries, reflection bands, and AI outputs produced from information you supplied. These are wellness features, not clinical findings.
We do not buy consumer health data, and we do not obtain it from data brokers, advertising networks, or third-party trackers. Mama Bloom contains no advertising SDK, no third-party analytics SDK, no advertising identifier (IDFA), and no App Tracking Transparency prompt.
6. Purposes for which we collect and use consumer health data
We collect and use consumer health data only to provide and operate the wellness features you choose to use, namely:
- to save and display the pregnancy, postpartum, cycle/fertility, mood/journaling, baby-tracking, nutrition, sleep, and other wellness features you request, including trends from your own records;
- to provide the general AI companion when you send a message;
- to provide a specialist AI feature you deliberately start, such as a nutrition or ingredient question, a mental-wellbeing reflection, a pregnancy or baby-care question, or a limited feeding or sleep review;
- to personalize an AI response with limited structured saved context when you have enabled the relevant context-sharing control;
- to apply safety wording or direct you to real-world support when an input indicates possible urgent distress; Mama Bloom does not contact emergency services or another person on your behalf;
- to deliver the reminders and notifications you enable; and
- to respond to your support requests and exercise of rights.
We do not use consumer health data for targeted advertising, for any sale, or to build advertising or marketing profiles.
7. Categories of consumer health data shared, and the third parties and affiliates with whom we share it
We do not sell consumer health data, and we do not share it for advertising, marketing, or with data brokers. When you deliberately use an AI feature, the request may contain health-related text, an optional ingredient-label photo, or limited structured saved context you have permitted. The request and generated output pass through our proxy to our AI provider. Mama Bloom does not upload your entire local wellness database merely because you open a tool.
The categories of recipients and the data they may process are:
- AI provider — Anthropic PBC (United States). Receives the content included in the AI request and returns a generated output. With saved-context sharing off, the general companion request contains the words you send, without additional saved context. A specialist route receives the text, photo, or structured fields required for the feature you deliberately start and permit. Anthropic may retain commercial API inputs and outputs for up to 30 days and does not use them to train its models.
- Hosting and proxy — Vercel Inc. (United States). Relays AI requests between the app and Anthropic and necessarily processes the request while doing so. The proxy keeps no separate prompt, photo, wellness-record, or baby-log database and is configured not to log prompt content. It does process limited security and operational metadata, including request and device identifiers, IP address, User-Agent, and token usage.
- Platform and health services — Apple. Provides App Store distribution, subscriptions, push-notification infrastructure, device services, and Apple Health. Health categories are read or written only when you grant the corresponding Apple Health permission. Audio is not sent to Mama Bloom’s AI providers; supported voice entry is converted to text on the device.
- Operational data store — Upstash Inc. (United States). Stores rate-limit counters, idempotency keys, App Attest challenges, and consented analytics aggregates. It is not used as a prompt, photo, or wellness-record database.
- Transactional email — Resend (Germany / United States). Delivers account and support email. If you include health information in a support or privacy email, that content is processed to deliver and answer the message.
We have no affiliates with which we share consumer health data. Where these providers process data outside the United States, that processing is governed by appropriate contractual safeguards (including Standard Contractual Clauses where applicable).
8. Your rights and how to exercise them
If you are a Washington consumer, MHMDA gives you the following rights with respect to your consumer health data:
- Right to access / confirm. You may ask us to confirm whether we are collecting, sharing, or selling your consumer health data, and to access that data, including a list of all third parties and affiliates with whom your consumer health data has been shared or sold, together with an active email address or other online mechanism you may use to contact each such recipient. Because the recipients are limited to the service providers named in Section 7, our response will provide each provider’s contact or privacy address.
- Right to withdraw consent. You may withdraw the consent you gave to the collection and/or the sharing of your consumer health data. Withdrawing consent is a separate and distinct action from deletion: you may withdraw consent without deleting your data, and you may delete your data without first withdrawing consent. Withdrawing consent stops further collection and/or sharing on a going-forward basis.
- Right to delete. You may ask us to delete your consumer health data. On an authenticated request, we delete in-scope data from systems we control and notify the processors, contractors, and other recipients to which we disclosed it, as RCW 19.373.040(1)(c) requires. A recipient is responsible for honoring the notice under applicable law. We do not claim that the in-app delete button can instantly erase an independent provider’s systems; archived systems may take up to the period allowed by MHMDA, and Anthropic’s standard API-retention window is up to 30 days.
How to use in-app controls. You can turn off Personalised AI to stop additional saved context from accompanying future general-companion requests, decline or stop using a specialist AI flow, revoke Apple Health permissions in Health settings, delete individual local records, export your data, or start account deletion. Turning off context does not send a deletion request and does not remove words you deliberately send in a future AI question.
How to make a formal request. For access or confirmation, withdrawal of collection or sharing consent, downstream deletion notice, appeal, or any request you prefer to send to us, email privacy@mamabloom.app. An in-app account is not required to email us. We may take commercially reasonable steps to authenticate you or an authorized agent before acting. For consumer-health-data deletion that may have reached a provider, email is the reliable way to ask us to notify the applicable recipients; account deletion alone does not promise immediate deletion from their independently operated systems.
Response timeframe. We will respond to your request within forty-five (45) days of receipt. When reasonably necessary, we may extend this period by an additional forty-five (45) days, and we will tell you within the first 45-day period if we need the extension and why.
No charge / no retaliation. You may exercise these rights free of charge up to twice per year; for additional, excessive, or manifestly repetitive requests we may charge a reasonable fee or decline, as MHMDA permits. We will not deny you goods or services, charge a different price, or provide a different quality of service because you exercised a right.
9. Appeal path if we deny a request
If we decline to act on your request, we will tell you in writing, with the reason. You may appeal that decision by replying to our decision message or by writing to privacy@mamabloom.app with the word “Appeal” in the subject line. We will review the appeal and respond in writing, with the reason for our decision, within forty-five (45) days of receipt.
If your appeal is denied, you may contact the Washington State Attorney General’s Office to submit a complaint: Washington State Office of the Attorney General — File a Complaint.
10. No geofencing around health-care facilities
Mama Bloom does not establish, use, or operate any geofence around any health-care facility or any other location. We do not use a geofence to identify or track consumers, to collect consumer health data, or to send notifications, messages, or advertising related to a consumer’s health data or health-care services. The app does not collect precise location data for these purposes.
11. Our consent model: separate consent to collect and a distinct consent to share
Consent for collection and consent for sharing are distinct under MHMDA. Locally recording information is initiated by you. A feature that transfers consumer health data to an AI provider requires the applicable in-app acknowledgement or consent, and the separate Personalised AI control determines whether additional saved context may accompany a general-companion request. You can use non-AI areas without sending a prompt, photo, or saved context to Anthropic.
- Collection choice. You choose whether to enter a local record or start the feature that needs it. Where processing is optional rather than necessary to provide the feature you requested, the app asks for the applicable affirmative choice.
- Separate sharing choice. AI transfer and saved-context sharing are presented separately from general website or account terms. A specialist request may still need the text, photograph, or limited structured fields described for that route; do not submit it if you do not want that request sent through Vercel to Anthropic.
You may withdraw either consent at any time, as described in Section 8. Withdrawal does not affect processing that already took place while consent was in force.
12. Changes to this policy
If we make a material change to this Consumer Health Data Privacy Policy, we will update the effective date above and, where the change affects how we collect or share consumer health data, seek any further consent required by MHMDA before that change applies to data we have already collected. The 13 August 2026 update expands the previously incomplete AI disclosure from general companion text to the text, ingredient-label photos, and limited structured saved context used by user-initiated specialist AI routes; it also distinguishes local deletion controls from a formal downstream deletion request.
13. Contact
Mama Bloom UG (haftungsbeschränkt)privacy@mamabloom.app
+49 152 5826 2078
Oskarstr. 14, 01219 Dresden, Germany