JustBloom Connect privacy policy
JustBloom Connect has one purpose: read the doTERRA reports you authorize and sync team members, volumes and orders to your authenticated JustBloom workspace. JustBloom is independent software and is not affiliated with or endorsed by doTERRA.
Information the extension handles
Genealogy reports may include names, member IDs, email addresses, phone numbers, sponsor and enroller relationships, ranks and monthly volume. Order reports include order IDs, dates, member IDs, order types, product names and codes, quantities, product volume, currency and purchase amounts. The extension also handles a one-use pairing code, browser connection credential, sync progress, report URLs and completion timestamps.
The extension does not extract passwords, browser cookies, shipping addresses, payment card or bank credentials, health records, or your CRM messages. Purchase amounts are financial purchase information and are included when invoices expose them. It reads only the report pages needed for this sync, not unrelated browsing history.
Your authorization and how information is used
Before connecting, the extension displays the report-data disclosure and requires your affirmative authorization. Collection starts when you choose Sync now or separately enable daily sync. Reports are read in your signed-in Chrome session and sent over HTTPS only to your authenticated workspace at login.justbloom.app. Passwords and cookies are not copied to JustBloom. A browser grant alone cannot bypass workspace login.
The extension itself does not send data to advertising services, analytics services or AI providers. The JustBloom hosting infrastructure uses Cloudflare and OpenAI Sites to operate the web app and store imported records. Other web-app features have separate behavior; this policy describes the extension’s report-sync path.
Storage, security and retention
Connection credentials and in-progress report checkpoints are encrypted locally with AES-GCM. The encryption key remains in the Chrome profile and is restricted to trusted extension contexts. Someone who controls your operating system or Chrome profile may still access that key. Server-side browser grants store a hash of the secret rather than the secret itself, expire after 90 days, and can be revoked in Connections. Pairing codes expire after ten minutes and can be used once.
Local report checkpoints are cleared when a sync completes, is stopped, or the browser is disconnected. Paused jobs keep encrypted checkpoints until resumed, stopped, disconnected or the extension is uninstalled. Local connection information remains until disconnect or uninstall. Imported CRM records and server audit timestamps remain in your workspace until deleted there or removed through a deletion request. Disconnecting or uninstalling the extension does not delete already imported CRM records.
Sharing and Limited Use
Information is used only for the user-facing sync and related security and support. It is not sold, used for advertising, used to determine creditworthiness, or transferred for unrelated purposes. Hosting providers process information as necessary to operate JustBloom. JustBloom Connect’s use of data complies with the Chrome Web Store User Data Policy, including the Limited Use requirements.
Your controls and contact
Daily sync is off by default. You can stop a sync, disable daily sync, disconnect a browser, revoke it from JustBloom → Connections, or uninstall the extension. To request access, correction or deletion of imported records, or ask about this policy, email jdmorgenstein@gmail.com. Only collect and sync information you are authorized to access and use.
Extension setup and support · Marketing website privacy notice