Legal
Privacy Policy
What we collect, what we deliberately do not, who else sees anything, and how long any of it lives.
Last updated: 13 September 2026
1. The short version
We collect the minimum that lets an account work and money move: a way to reach you, the addresses and transactions of your top-ups, and the ledger of what you own. There is no analytics in the Blomo app, no advertising pixel anywhere, and no third-party cookies. Server logs are deleted after seven days.
Where you came from. The campaign tag in the link you arrived by, the click identifier an advertising platform adds to it, and the address of the page that linked to you. We keep it on your account so we can tell which advertising works. If you arrived through an advertisement, we report back to that platform that its click led to a sign-up or a top-up; section 7 sets out exactly what is sent. We do not use any of it to build a profile of you.
We do not ask for identity documents for virtual cards, and card numbers never reach us at all.
2. What you give us
- An email address or a Telegram account. One of them is enough to open an account. A linked Telegram account is required before money can move, because that is where notifications go.
- A second-factor secret, if you enable two-factor authentication. It is stored encrypted.
- Messages you send to support, and anything you choose to include in them.
- Evidence you provide during a check on funds, if one is opened under section 6 of the Terms.
For a physical card, the partner issuer collects identity documents directly. That verification is the issuer's process, not ours.
3. What we generate about your account
- Deposit addresses derived for your top-up requests, and the on-chain transactions that arrive at them.
- Ledger entries recording every movement of your balance.
- Card requests and card metadata — which product, when issued, its status. Not the card number.
- Session records, so you can be signed in and so that a session can be revoked.
4. What we observe
- Your IP address. Used to rate-limit abuse and to record the country a top-up request came from. Kept in server logs for seven days.
- Ordinary request data — the time, the path, the response code, the browser's user-agent string. The same seven days.
Blockchain data is public by its nature. An address we give you and the transactions to it are visible to anyone, including people we have no relationship with. That is a property of the networks, not a choice we made.
5. What we deliberately do not collect
- Identity documents for virtual cards. No passport, no selfie, no proof of address, no source-of-funds questionnaire at sign-up.
- Card numbers, expiry dates and security codes. They are rendered by the partner issuer inside the issuer's own frame and never pass through our systems. They are in neither our database nor our logs.
- Your passcode, and the private key of your Blomo Wallet. The key is created and used on your device; we hold it only encrypted and cannot open it.
- Behavioural analytics in the app. There is no analytics script, no tag manager and no session recorder in the Blomo app, and no advertising pixel anywhere. On this website, analytics runs only if you agree to it in the cookie banner: press Reject and it never loads.
6. Cookies
One cookie: your session. It is first-party, it is what keeps you signed in, and it disappears when you sign out.
There are no advertising cookies and no third-party cookies.
Your choice in the cookie banner is remembered in your browser own storage, not in a cookie, and nothing about it leaves your device. You can change it at any time from the footer of any page.
7. Who else sees anything
- Cloudflare. Sits in front of this site and the app and therefore sees the IP address of every request. It also runs the captcha that protects registration.
- Google Fonts. Serves the typefaces the site uses, and therefore sees the IP address of a browser loading them.
- Telegram. Receives the notifications we send you and, if you sign in or link your account through Telegram, the fact that you did.
- The partner card issuer. Receives what it needs to issue and operate a card. For physical cards, it collects identity documents directly from you.
- Blockchain networks. Receive the transactions we broadcast, which are public.
- The advertising platform that sent you. If you arrived through an advertisement, Blomo reports back that the click led to a sign-up, a completed questionnaire, or a top-up, together with the amount of the top-up. Your email address and your account identifier are sent as irreversible hashes, never in the clear, and only so that the platform can match the event to the click it already knows about. If you did not arrive through an advertisement, nothing about you is sent.
We do not sell your data. The one thing we share for advertising is the report described above: we tell the platform that sent you that its click worked. Nothing else, and to nobody else.
8. Why we use it
- To run your account and move money you asked us to move.
- To notify you when your money moves — that is what the linked Telegram account is for.
- To check funds where section 6 of the Terms applies, and to meet obligations that come with handling money.
- To protect the service from abuse: rate limits, captcha, and detecting suspicious attempts to spend.
9. How long we keep it
- Server logs: seven days, then deleted. Data that no longer exists cannot leak, cannot be demanded and cannot be sold by someone who left.
- Account data: for as long as the account exists.
- Ledger entries: permanently, and they cannot be edited or deleted. The database itself refuses. This is deliberate — see section 10.
- Evidence provided during a check: for as long as the record of that check needs to stand.
10. The ledger, and what it means for deletion
Your balance is not a number in a column. It is the sum of entries that are never edited and never deleted; a mistake is corrected by a reversing entry, so the history of what happened stays whole. The database enforces this, not our code — even our own application cannot alter a posted entry.
This has an honest consequence. Closing an account removes your account data, but it cannot erase the entries that record money moving, because those entries are what makes the accounting truthful. What we can do — and do — is separate them from the identifiers that point at you. We would rather tell you this plainly than promise an erasure the system is built to refuse.
11. Your choices
- See what we hold. Ask, and we will tell you what is on your account.
- Correct it. If something about your account is wrong, tell us and we will fix it.
- Close the account. Section 9 of the Terms covers this, including the refund of your balance. Closure is permanent, and section 10 above explains what survives it and why.
- Turn off notifications. You can, but an account without a linked Telegram cannot move money — that is a condition of the service, not a setting.
12. Security
How an account and its money are protected — two-factor authentication, card data that never reaches us, an append-only ledger — is described in detail on the account security page. How a non-custodial wallet key is protected, and what a breach of Blomo would and would not give an attacker, is on the wallet security page.
13. Children
Blomo is not for anyone under 18, and we do not knowingly hold data about children. If you believe we do, tell us and we will remove it.
14. Changes to this policy
If we change what we collect or who sees it, we announce it through your notification channel before the change takes effect. The date at the top of this page always reflects the current version.
15. How to reach us
Blomo.
Privacy questions and requests: t.me/blomo_bot. Email delivery is currently disabled, so this is the channel that actually reaches us.