← Back to Bloomkeeper

BLOOMKEEPER / PRIVACY

Your Mac. Your choice.

Updated September 26, 2026.

Usage sharing is optional and off by default. Saying no does not reduce Bloomkeeper features. Your earnings and Darkbloom account data stay on your Mac.

If you choose to share usage

Bloomkeeper sends a small daily summary to Bloomkeeper’s own reporting service, with updates no more than every six hours apart from changes such as setup changes:

This reporting is pseudonymous, not fully anonymous: the random ID connects one Mac’s reports across days. It does not tell us your identity. We do not collect earnings, prompts, account identifiers, licensing IDs, serial numbers, personal names, email addresses, account tokens, passwords, private phone URLs or raw logs through usage reporting.

Control and deletion

Change your choice in Bloomkeeper on your Mac. Turning sharing off immediately stops collection and queues deletion of that reporting ID and its reports from the service. If offline, Bloomkeeper keeps only the credentials needed to retry deletion and shows that deletion is pending. It confirms removal only after the service responds. A one-way deletion receipt, containing no reports or raw reporting ID, remains for 30 days to prevent delayed requests from recreating deleted reports.

The service keeps a rolling 30-day app-reporting window. Expired records are removed during reporting requests and owner-dashboard refreshes. It keeps aggregate download counts for up to 90 days under the same cleanup process. Reports are visible only in the private owner dashboard; they are not sold or used for advertising.

Optional problem reports

When Bloomkeeper detects certain interface, connection or control problems, it can offer to send a short report with one tap (“Send report”). You can also open a fully reviewable report from Help & feedback. Detection and dismissal stay on your device. Nothing is uploaded until you choose Send report, or until you turn on “Send these automatically from now on.” That setting is off by default; with it on, Bloomkeeper sends the same short report without asking each time, and you can turn it off at any time in Help & feedback. This works independently of usage sharing, and does not turn it on.

A report contains a random per-report ID, time, app version, Mac/phone surface, broad issue category, macOS major version, chip family, memory-size group, and limited connection/optimizer status codes. It excludes earnings, raw logs, stack traces, account and license identifiers, credentials and private URLs. Description and reply contact are optional, blank fields that you fill in deliberately. Please avoid sensitive information in them.

Reports go to Bloomkeeper’s private owner inbox and remain for up to 30 days; expired reports are removed during submissions and owner reads. Contact Andrew with the report ID to request earlier deletion. Deletion removes the report and contact details; a content-free receipt remains within the same retention window so a delayed retry cannot recreate it. Reports are never joined to app usage IDs. The service uses bounded storage and rate limits, and does not store IP addresses in its reporting database.

A successful send gives you a receipt. Failed sends do not start background retries; you choose whether to retry. A crash that prevents Bloomkeeper from opening, a dead collector, or loss of internet may require contacting support directly. Unless you have turned on automatic reports, no report is sent automatically, including on your next launch.

Website traffic

Public pages send a small page-view count to Bloomkeeper’s own service. We store aggregate UTC daily counts by page, referring website domain, approximate country and broad device category for a rolling 30 days. We do not use analytics cookies, persistent visitor identifiers or fingerprinting, and do not store IP addresses, full user-agent strings, referring URL paths or query strings in these reports. Owner pages are excluded. Browser Do Not Track and Global Privacy Control preferences are respected. Known automated clients are excluded where recognizable; these counts are not unique people. Expired totals are removed during traffic collection and owner-dashboard refreshes.

Downloads and hosting

The website counts installer requests by UTC day and version, without a cookie or device identifier for that count. Bloomkeeper checks bloomformac.com for updates about every six hours while it runs, and the website counts how many Macs check each UTC day, per app version, whether or not you share usage. To count each Mac once a day, it keeps a one-way hash of the request’s network address and the app’s update-check name (which includes the app version from 1.36.56) under a random key for that day; the key and the hashes are deleted when the day ends, so no address can be recovered or linked across days. Only the daily count per version is kept, for 30 days. Repeat downloads can be counted more than once. These totals do not tell us how many people installed or used Bloomkeeper.

Hosting and network providers necessarily process IP addresses and other request metadata to deliver and secure the website. Bloomkeeper’s app-reporting database does not store IP addresses. To stop abuse, Cloudflare briefly counts requests from each IP address to Bloomkeeper’s service; those counts are not stored with anything you send. The private owner dashboard is limited to Andrew through Cloudflare Access; downloading Bloomkeeper or using the beta needs no account.

Optional contact details

In version 1.36.35 and later, More → About Bloomkeeper has an optional “Stay in touch” field. If you type an email address or Slack handle and tick the box agreeing to be contacted, Bloomkeeper sends it to Bloomkeeper’s service with your Bloomkeeper version and a random ID that lets your Mac change or delete it later. Nothing is sent if you leave it blank. It is not linked to usage sharing, problem reports, earnings or your Darkbloom account.

Only Andrew can see it, and uses it only to contact you about Bloomkeeper: updates, fixes, the beta, or replies to your feedback. It is never sold or shared. Choose Remove in the same place to delete it from the service right away, or ask Andrew to delete it. An entry your Mac hasn’t re-saved for a year is deleted automatically.

Optional pay summaries for starting estimates

Bloomkeeper ships with starting estimates of what each model pays, so the optimizer can make reasonable choices on a new Mac. They are built from Andrew’s own Macs and, if you turn on “Improve starting estimates” in More → About Bloomkeeper (version 1.36.37 and later, off by default), from a weekly summary from your Mac.

A summary contains the name of each model with at least 2 hours of steady paid work in the last 30 days and, for each, two numbers describing how its pay rose with network demand, the typical spread, and the hours measured; plus chip family, memory range, Bloomkeeper version and a random ID used only to replace or delete it. It contains no Darkbloom account or device IDs, balances, individual payments, times or anything that names you, and is not linked to usage sharing, problem reports or contact details. Summaries are kept for up to 45 days, seen only by Andrew, and combined across Macs into the estimates in future Bloomkeeper versions. Turning the option off deletes your summary from the service right away.

Free optimizer access and feedback

Optimizer access is free with no scheduled expiration. It does not depend on usage sharing. Updating does not enable automation or resume a paused plan. Existing local access records remain unchanged.

Information you voluntarily send in Slack or by email is separate from optional app reporting. Please review diagnostics and screenshots before sharing them. For privacy questions, contact Andrew on Slack or by email.