Cookie Policy

Last updated: September 18, 2026

This policy explains the cookies and similar technologies (localStorage, pixels, SDK identifiers) used by Blossom — the websites at blossai.com, the Blossom web application, and the Blossom mobile applications. It supplements our Privacy Policy.

"Cookies" here covers both browser cookies and browser storage such as localStorage; the same rules apply to both.

1. How Consent Works

On your first visit a banner tells you about non-essential cookies and offers the two choices below. Where the law requires consent before anything loads, which includes the European Economic Area, the United Kingdom, and Switzerland, nothing non-essential runs until you answer. Elsewhere the cookies in Sections 4 and 5 run while you browse and stop as soon as you choose essential only.

  • Accept all: analytics and advertising-measurement cookies (Sections 4 and 5) are enabled
  • Essential only: only the cookies in Sections 2 and 3 are used; Google Analytics, the Meta Pixel, and the Reddit Pixel never load, and no advertising attribution data is stored or sent

Your choice is stored on your device (in the blossom_consent entry) so we don't ask again. Change it any time:

2. Essential Cookies and Storage

Required for the Service to function; they cannot be switched off. Blocking them in your browser will break sign-in.

  • Authentication session (Supabase Auth, sb-* keys): keeps you signed in; for the life of your session
  • Consent record (blossom_consent, bl_ft_withdrawn): remembers your banner choice and, once you withdraw advertising consent, that the attribution data in Section 5 was already deleted; until you clear it
  • Preferences (blossom_theme, language, layout): remembers how you set up the interface; until you clear them
  • Landing assignment (blsm_lp_variant): keeps the landing-page version you first saw consistent across visits; up to 90 days, permanent after sign-up
  • Payment cookies (Paddle): set during checkout to process the transaction, under Paddle's own policy
  • Sign-in cookies (Google): set when you use Google sign-in, under Google's own policy

3. First-Party Analytics

Our own tracker (blsm_analytics_session) records page views, scroll depth, and product events, and sends them only to our servers — no third party receives them and no cross-site tracking is involved. We use this on the basis of our legitimate interest in understanding how the product is used; Section 13 of the Privacy Policy explains how to object.

4. Analytics Cookies (Consent-Gated)

Loaded when you choose "Accept all", or, outside the regions named in Section 1, while you browse until you choose "Essential only":

  • Google Analytics 4 (_ga, _ga_*) — aggregate usage measurement of our websites and web app; persists up to 2 years. Google's processing is described in Google's cookie policy

5. Advertising-Measurement Cookies (Consent-Gated)

Loaded when you choose "Accept all", or, outside the regions named in Section 1, while you browse until you choose "Essential only":

  • Meta Pixel (_fbp, _fbc): measures whether our advertising on Meta platforms (Facebook, Instagram) leads to visits, sign-ups, trial starts, and purchases. _fbp identifies your browser and _fbc holds the ad click id when you arrive from a Meta ad; both persist up to 90 days. Meta may associate these events with your Meta account under Meta's privacy policy; manage this in Meta's ad preferences
  • Reddit Pixel (_rdt_uuid, _rdt_cid): measures whether our advertising on Reddit leads to visits, sign-ups, trial starts, and purchases. _rdt_uuid identifies your browser and _rdt_cid holds the ad click id when you arrive from a Reddit ad; both persist up to 90 days. Reddit may associate these events with your Reddit account under Reddit's privacy policy; manage this in the privacy settings of your Reddit account
  • First-touch attribution (bl_ft): our own first-party cookie, set when you arrive from an ad or a campaign link. It stores the ad click id (fbclid, rdt_cid), the UTM campaign values, the path of the page you landed on, and the time of that visit, so a later sign-up can be credited to the campaign that produced it; persists up to 90 days. It is set only with your advertising consent and deleted as soon as you withdraw it. A companion bl_ft_sent entry in browser storage records that these values were already sent to our servers, so they are sent once; it is removed when you withdraw consent

When you accept advertising cookies, our servers also report three account events to Meta and Reddit: sign-up, trial start, and first purchase. Each report carries a hashed (SHA-256) copy of your email address and account id, your IP address and browser user agent as recorded when that data was saved (at sign-up or in the first 7 days after it), the ad click id and browser identifier from the cookies above, and the amount and currency for a purchase. Meta and Reddit use them to match the event to the ad that produced it and to avoid counting it twice. If you do not accept advertising cookies, none of this is stored or sent. Withdrawing consent deletes the bl_ft cookie immediately. The attribution data stored for your account is deleted right away if you withdraw while signed in to the web app, or otherwise the next time you open the web app signed in on that browser, and the reports stop once it is gone. You can also ask us to delete it at privacy@blossai.com.

We do not run third-party ad networks inside the product, and we do not sell your data.

6. Mobile Apps

The mobile apps do not use browser cookies, but use equivalent technologies:

  • AppsFlyer — attributes app installs to the campaign that produced them, using device identifiers where your OS settings allow
  • Push notifications (Apple APNs, Firebase Cloud Messaging) — device tokens used only to deliver notifications you enable

Control these through your device: on iOS, App Tracking Transparency (Settings → Privacy → Tracking) and notification settings; on Android, "Delete advertising ID" / ads personalization and notification settings.

7. Browser Controls

Beyond our banner, every browser lets you block or delete cookies in its settings, and tracking-protection features (and the Google Analytics opt-out add-on) work independently of our controls. Blocking essential storage will prevent sign-in from working.

8. Changes and Contact

If we add or change a cookie category, we will update this page and, where the change requires it, ask for your consent again. Questions: privacy@blossai.com.