Bloom is licensed by your residence and runs on iPads your team deploys —
it isn't a consumer-direct app, and there is no general-purpose API into
your data.
One residence, one tenant.
Every table that holds facility data is governed by PostgreSQL
row-level security keyed to the facility, so a facility can read
and write only its own rows. There is no cross-facility data
bridge: that is a property of the schema, not a setting. A dedicated
single-tenant database is available for facilities that require
physical isolation.
Private things stay private.
Resident journals, gratitude entries, and personal goals are
database-scoped to the resident. Staff cannot read them, and the
rule is enforced at the storage layer, not just in the UI.
No ads, no analytics SDKs.
No Facebook SDK, no Google Analytics, no tracker of any kind
inside the apps. The only outbound traffic is to your facility's
backend and Apple Push Notification service.
White-labeled for your residence.
Your name on the iPad, your colors, your activities, your library.
Your Lumon account manager handles provisioning; you stay in
control of what residents see.