BloomOS
Privacy Statement
Last updated July 29, 2026
Scope
This statement describes how the BloomOS platform, operated by Bloom Lending LLC, handles information. It covers the software. It does not replace the consumer privacy notice Bloom Lending provides to borrowers regarding a mortgage transaction.
Information we process
- Account data — your name, work email, role, and authentication factors.
- Borrower and loan data — contact details, application and loan file information, documents, and correspondence entered by authorized users or received from integrated systems.
- Connected mailbox and calendar content — messages, attachments, and events accessed through Microsoft Graph when you connect a Microsoft 365 account.
- Operational data — audit and security logs, access times, IP address, and error diagnostics.
Microsoft 365 permissions
When you connect a Microsoft account, BloomOS requests only the permissions needed for the features it operates. Tokens are stored encrypted and are refreshed without re-prompting while the connection remains active. Disconnecting from Settings revokes them.
| Permission | Why it is used |
|---|---|
| Mail.ReadWrite / Mail.Send | Read and send loan correspondence, and ingest lender rate-sheet attachments. |
| Calendars.ReadWrite | Create and read appointments tied to loan milestones. |
| Files.ReadWrite.All / Sites.ReadWrite.All | Store and retrieve loan documents in SharePoint/OneDrive. |
| Team.ReadBasic.All / Channel.ReadBasic.All / ChannelMessage.Read.All | Surface Teams channel activity in the AI Agents workspace. |
| User.Read / openid / profile / email | Identify the signed-in user. |
| offline_access | Refresh access without prompting you to sign in repeatedly. |
How we use it
To operate the platform: originate and service loan files, communicate with borrowers and partners, generate documents, price loans, automate workflow, and maintain security and audit records. We do not sell personal information, and we do not use borrower data to train third-party AI models.
Service providers
BloomOS runs on infrastructure and services operated by third parties who process data on our behalf under contract — including Cloudflare (hosting, storage, databases), Microsoft (identity, mail, files, Teams), and providers used for email delivery, database hosting, and AI features. Providers may change as the platform evolves.
Retention and security
Records are retained as long as needed for the loan relationship and for the periods required by lending, tax, and records-retention rules, then deleted or archived. Access is restricted by role, transmission is encrypted in transit, sensitive fields are encrypted at rest, and access is logged. No system can be guaranteed perfectly secure.
Your choices
Authorized users may disconnect integrations at any time from Settings. Borrowers with questions about their own information, including any rights available under applicable state privacy law, should contact us using the address below.
Contact
Bloom Lending LLC — james@bloomlending.com. See also our Terms of Service.