Privacy
Privacy policy
Controller
Moellenbeck-Digital UG
Luisenstraße 59
45892 Gelsenkirchen
Deutschland
E-Mail: admin@moellenbeck-digital.io
What data does BloomMD process?
BloomMD processes account data such as email address, login and session data where required for registration, login and closed-beta access.
Markdown files are processed locally by the local-first core. Data is transmitted to BloomMD only when an optional sync or cloud service is actively used.
No payments in M1
The closed M1 beta offers no paid plans, collects no payment data and provides no checkout. Payment providers become relevant only if BloomMD explicitly offers paid features later.
Transactional email with Resend
BloomMD may use Resend for account email such as email verification, password resets and important product notices. Markdown content is not sent to Resend as email content.
Error monitoring and product analytics
Sentry may be used for error monitoring. Plausible loads when the direct configuration is present; it is configured without cookies or persistent identifiers. The optional PostHog integration is consent-gated separately. Autocapture, session recording and pageleave capture are disabled. Only page paths and allowlisted events are collected; Markdown content, file names, node titles, search terms, complete URLs and document paths are excluded.
Optional sync
Realtime sync is initially optional and may be operated as a beta feature. Without sync enabled, Markdown files remain local. With sync enabled, the document structures required for collaboration are transmitted through the sync service.
Cookies and sessions
BloomMD uses technically necessary session cookies so signed-in users can be recognised and protected areas can work.
Only if a consent-required analytics service is enabled, the marketing app stores that choice in the browser under `bloommd:analytics-consent:v1`. Plausible itself does not require this choice because it is configured without cookies or persistent identifiers.
Waitlist
Anyone joining the waitlist leaves an email address, registration time and the source page. The address is stored and used only after confirmation through a double-opt-in link; unconfirmed entries are not contacted. The legal basis is consent (Art. 6(1)(a) GDPR). Unconfirmed entries are deleted after 30 days if not confirmed.
The address is used only to notify people about an available beta place — no newsletter and no advertising. Consent can be withdrawn through the unsubscribe link in each message, without an account or sign-in. After unsubscribing, the entry remains for up to 90 days as a suppression record so the address is not contacted accidentally. Entries are deleted no later than the end of the closed beta.
Legal bases
Processing is based in particular on contract performance, pre-contractual measures, legal obligations and legitimate interests in secure operation.
Data subject rights
Users may request access, rectification, erasure, restriction of processing, data portability and objection where the statutory requirements are met.
As of
13. August 2026