Privacy Policy
Last updated: August 2026
1. Who we are (the data controller)
The controller of your data is Bloomia. Contact for any personal data matter: neaua_neaua@yahoo.com.
We have not appointed a Data Protection Officer (DPO), because our activity does not fall under the situations that require one (Art. 37 GDPR). Requests about personal data are handled directly by our team, at the address above.
2. What data we collect and why
| Category | Purpose | Legal basis |
|---|---|---|
| Email, name, avatar | Creating and managing the account | Performance of the contract |
| Created activities, folders, settings | Providing the service | Performance of the contract |
| Game results, XP, badges, streaks | Progress, leaderboards, statistics for teachers | Performance of the contract |
| Billing data and payment history | Issuing invoices, accounting | Legal obligation |
| Technical logs, IP address at sign-in | Security, abuse and fraud prevention | Legitimate interest |
| Audience measurement (no IP, no persistent identifier) | Knowing how many visitors we have and where they come from | Legitimate interest |
| Email address for newsletters | Platform updates | Consent (revocable anytime) |
Your card details never reach us — they're entered directly at Stripe, a PCI-DSS certified processor. We only receive payment confirmation and the card's last digits.
3. Student data
This is the most sensitive part of the platform, so we explain it separately.
Students who play without an account
We only keep the first name they type and the game score. No email, no account, no profile. The first name is shown on the activity leaderboard and visible to the teacher who created it. We recommend teachers only ask students for their first name — never their full name or other personal data.
Students with an account
An account can be created from age 16 onward. Below this age, a parent's or guardian's consent is required (Art. 8 GDPR). A parent can request access to, correction of, or deletion of their child's data at any time by writing to our contact address.
Who is responsible for student data
When a teacher or institution uses the platform with their students, the teacher or institution is the controller of that data — they decide what activity to assign, what questions to ask and what information to request. We act as a processor (Art. 28 GDPR): we only process the data according to their instructions and to provide the service.
Institutions that need a signed Data Processing Agreement (DPA) can request one from us at neaua_neaua@yahoo.com.
4. How long we keep data
- Account data — for as long as the account exists. You can delete it yourself at any time.
- Activities and results — for as long as the author's account exists (see below what happens on deletion).
- Invoices and payment records — 10 years, the term required by Romanian accounting and tax law.
- Audience-measurement data — 14 months, then automatically deleted.
- Technical security logs — up to 12 months.
- The deletion registry — only a hash of the email, kept as proof that we honored your request.
You can delete your account from Profile → Security → My data . Deletion through the interface is immediate; requests sent by email are handled within 30 days at most. On deletion:
- Permanently deleted: the login account, name, email, avatar, settings, progress (XP, coins, badges, avatars, streaks), favorites, notifications, folders and email preferences.
- Anonymized: results from games you've played — they stay in other authors' activity statistics, but with no link to you (the name becomes "Deleted account").
- Stay, disassociated from you: published activities — they transfer to the platform under the license in the Terms, without your name as author.
- Stay, as a legal obligation: invoices and payment records, if you had a paid subscription. Tax law requires us to archive them, and Art. 17(3)(b) GDPR expressly provides this exception to the right to erasure.
5. Your rights
Under GDPR, you have the right to:
- Access: request a copy of your data
- Rectification: correct inaccurate data
- Erasure: request deletion of your data ("the right to be forgotten")
- Portability: receive your data in a structured format
- Restriction: request that processing be limited while you contest it
- Objection: object to processing based on legitimate interest, including marketing
- Withdrawal of consent, at any time, without affecting the lawfulness of prior processing
You can exercise these yourself, immediately
- Access and portability: Profile → Security → "Download my data" (a JSON file with everything we hold).
- Rectification: Profile → edit your name and avatar directly.
- Erasure: Profile → Security → "Delete account and personal data".
- Objection to marketing: the "Newsletter emails" toggle in Profile, or the "Unsubscribe" link in any email you receive from us.
- Objection to audience measurement: the "Data preferences" link in the site footer.
For any other request, write to us at neaua_neaua@yahoo.com. We reply within 30 days at most and charge no fee. You also have the right to lodge a complaint with ANSPDCP (dataprotection.ro).
6. Automated decisions and profiling
We do not make automated decisions with legal or similarly significant effects on you, and we do not carry out profiling for advertising purposes (Art. 22 GDPR). Leaderboards, levels and leagues are simple calculations based on the score achieved in the game and produce no effects outside the platform.
7. Data security
We apply appropriate technical and organizational measures (Art. 32 GDPR): encrypted traffic (HTTPS), encryption of stored data, passwords kept only as a cryptographic hash (never in plain text), data isolation between accounts at the database level, restricted team access, and backups.
What's up to you: choose a strong, unique password, don't reuse it from other sites and don't share it. No security measure on our part can make up for a leaked or reused password. Details in Terms of Service, "Your responsibilities" section.
If a data security breach occurs that could affect your rights, we notify ANSPDCP within 72 hours and inform you directly when the risk is high (Art. 33–34 GDPR).
8. Cookies and audience measurement
We use cookies strictly necessary for authentication (the Supabase session) and local storage for interface preferences (language, sound, dismissed banners). We don't use Google Analytics, Facebook Pixel or any other third-party tracking tool, and we don't track your activity on other sites.
We measure audience with our own system, hosted on our infrastructure. Per visit, we keep: the landing page, the source (link parameters or the referring domain, e.g. "tiktok.com"), device type, browser, operating system and country. From this data we calculate how many visitors we have and where they come from.
Why we don't ask for your consent for this
Our system meets the conditions under which audience measurement is exempt from consent (Art. 5(3) ePrivacy Directive, as interpreted by European data-protection authorities):
- data is used exclusively internally and are not shared with any third party;
- there is no persistent identifier — the visit identifier lives only as long as the tab stays open and disappears when it's closed, so we can't recognize you tomorrow or on another device;
- the IP address is not stored — we only use it to derive the country, then discard it;
- the referrer is reduced to the domain, not the full address;
- raw data is automatically deleted after 14 months;
- you can opt out of measurement anytime from the "Data preferences" link in the site footer.
We don't track navigation on game pages opened by students via a shared link(/play, /embed) — there we only record whether a game was started and finished, with no data about the person.
Full details in the Cookie Policy. If we ever add third-party analytics or marketing tools, we'll show a consent banner before activating them.
9. Who we share data with
We don't sell your data and don't share it for advertising purposes. We only entrust it to providers necessary for the platform to run, who process it strictly according to our instructions, under data-processing agreements:
| Provider | Role | Location |
|---|---|---|
| Supabase | Database and authentication | EU |
| Vercel | Application hosting | EU / US |
| Stripe | Payment processing (PCI-DSS) | EU / US |
| Brevo | Sending emails | EU |
We may also share data with authorities, when required by law.
10. Transfers outside the EU
Data is stored in the European Union. Some providers in the table above (Vercel, Stripe) are US companies and may process data in the US as part of their services. In these cases, the transfer takes place under the safeguards provided by GDPR — the standard contractual clauses approved by the European Commission and, where applicable, the EU–US Data Privacy Framework (Art. 45–46 GDPR). You can request a copy of these safeguards at our contact address.
11. Changes to this policy
When we change this policy, we update the date at the top of the page. If the change is significant, we notify you by email or with a message in the platform before it takes effect.
12. Contact
For any question about privacy: neaua_neaua@yahoo.com