Bivio Privacy Policy
This policy explains what personal data Bivio processes, why, and what your choices are. It applies to the Bivio iOS application, currently offered as an invited beta through Apple's TestFlight, and to the Bivio website pages that link to this policy (together, the "Service").
Bivio is operated by Eugeniu Cozlenco, an individual based in Prague, Czech Republic ("Bivio", "we", "us"). Where the EU General Data Protection Regulation (GDPR) or the UK GDPR applies, Eugeniu Cozlenco is the controller of the personal data described in this policy.
Contact for privacy, support, and legal questions: hello@getbivio.app
1. The short version
Bivio is a private decision journal. You record a decision before you know how it turns out, come back later to review it, and over time see readings and possible patterns in how you decide. Because the whole point of Bivio is private reflection, this policy is built around one idea: your record belongs to you.
- What we collect: your account details (email address and the name you choose to share), the decision records you write or dictate, and limited, content-free usage data that helps us keep the app working.
- Your decision records are encrypted on your device before they are stored on our servers. Section 9 explains exactly what is and is not covered, because precision matters more than a slogan here.
- Voice and AI processing: when you dictate a decision, your recording is transcribed by OpenAI, and your words may be processed by Anthropic to arrange them into a decision record or to suggest a possible lens on your thinking. Typed decisions skip the audio and transcription steps, but eligible typed text may still be processed for a lens. Sections 7 and 8 describe exactly what is sent and when.
- Usage analytics is on by default during the beta. It is privacy-preserving usage data identified only by a random installation ID, not by your account; it never contains your decision text, and you can turn it off any time in You → Privacy & Analytics.
- We do not sell your personal information and we show no ads. We do not use your journal to train AI models, and our AI providers' API terms exclude submitted content from training.
- You can delete your account, and its data, from inside the app.
The summary is for convenience; the full policy below is the authoritative description of our practices.
2. Who this policy is for
This policy covers people who use the Bivio app or contact us at our email address. It does not cover Apple's own processing when you download the app, use TestFlight, use Sign in with Apple, or share crash reports with Apple — Apple acts under its own privacy policy for those activities — or third-party websites you reach through links.
Bivio is intended for people aged 16 or older. The friend beta is offered to invited testers; we currently expect public availability, when it comes, to begin in the United States, Canada, Australia, the European Union and EEA, and the United Kingdom.
3. Account information
To create an account we collect:
- your email address;
- the name you choose to be called (typed at signup, or, if you use Sign in with Apple and choose to share it, the name Apple provides);
- a Bivio account identifier created for you;
- authentication metadata needed to keep your session secure (sign-in timestamps and session tokens, managed by our authentication provider, Supabase).
If you use Sign in with Apple, Apple sends us a stable identifier for your account and, depending on your choice in Apple's sign-in sheet, either your real email address or an Apple private relay address that forwards to you. We treat a relay address like any other email address and do not attempt to unmask it. Bivio never sees your Apple ID password.
Email/password accounts and Sign in with Apple accounts are separate sign-in identities. If you try to sign in with Apple using an email that already has a Bivio password account, the app shows a calm conflict message; accounts are not automatically merged.
Your profile also stores a timezone value and, if you set them up, the names of the context signals you chose to track (for example "sleep" or "stress" as labels — the values you record for them live inside your encrypted decision records, not your profile). We do not ask for your date of birth, gender, country, or any other demographic information.
If you forget your password, you can request a reset from the app; the reset link returns you to Bivio to set a new password. Password resets never affect your Recovery Key or your encrypted records.
4. Decision records
Depending on which fields you fill in, a decision record may include: the decision in your own words, the result you expect, your confidence, a category, context signal values, alternative paths you considered, review dates, and — when you close the loop — what actually happened and how you rate the call and the result. Free-text fields can contain whatever you choose to write.
Decision records can be sensitive: what you write may reveal information about your health, finances, relationships, work, or anything else you decide to record. We do not ask for any special category of data, and we suggest not entering sensitive details that your reflection doesn't need. Whatever you record, we treat it as private content and protect it as described in Section 9.
Your records are used only to provide the Service to you — storing them, reminding you to review, computing your own readings and patterns, and powering the voice and AI assistance described below. We do not use them for advertising, we do not sell them, and we do not use them to train AI models.
5. Feedback and support
If you send feedback through the app (You → Send feedback), we receive: the category you pick (bug, idea, confusing, other), your message, an optional reply email if you want an answer, and a small set of technical details — app version, platform, OS version, the screen you were on, and (only if analytics is enabled) the same random installation identifier used for analytics. Feedback is stored in our database and a copy is emailed to us through Resend so we actually see it. Because feedback rows are tied to your account and may include a reply address, feedback is not anonymous. Your feedback message is never sent to our analytics provider.
If you email us, we receive your address and the content of your message.
6. Notifications and reminders
Bivio uses local notifications only — reminders are scheduled on your device, and no remote push infrastructure or push token is used. iOS asks for your permission before any reminder can be shown, and the app asks only after you have saved your first decision. Reminders exist for one purpose: telling you a decision is ready to review (one reminder, and one follow-up three days later if you haven't reviewed).
Reminder notifications never contain your decision text, whether or not a record is marked Private. The notification simply invites you back; the content stays in the app. Delivery depends on your device and iOS settings, so reminders are not guaranteed to arrive. You can turn notifications off any time in iOS Settings or in Bivio's reminder settings, and the app works without them.
7. Voice capture and transcription
If you use voice capture, we process audio of your voice to turn it into text. iOS asks for your permission before Bivio can use the microphone or speech recognition. The full path:
- Live preview (Apple). While you speak, Apple's speech recognition provides a provisional on-screen preview. Bivio requests on-device recognition whenever your device supports it; where it does not, Apple may process the audio through its own servers under Apple's terms. The preview is never the final transcript and is never saved.
- Final transcript (OpenAI). When cloud transcription is active in your version of the app, the dictation is recorded as a temporary audio clip on your device and sent through a Bivio server function to OpenAI's transcription API. The transcript OpenAI returns becomes the authoritative text of your note, replacing the preview. If the cloud step fails or you are offline, the preview text is used instead — you are never asked to repeat yourself.
- Deletion. The temporary audio clip is deleted from your device when the transcription attempt finishes — on success, failure, timeout, or cancellation — and a cleanup sweep removes any leftover clips from interrupted sessions. Bivio does not store your audio: our server function passes the clip to OpenAI and keeps nothing, and no recording is written to our database. Under OpenAI's current published API policy, its audio transcription endpoint does not retain submitted audio for abuse monitoring and API content is not used to train OpenAI's models.
We do not use your voice to identify you and we do not create voiceprints.
8. Smart Capture, Lens, and what reaches AI providers
Two parts of Bivio use large-language-model services operated by third parties. Both run through Bivio's own servers: the app never talks to an AI provider directly, requests are authenticated, our server functions log no content, and requests carry no name, email, or account identifier alongside the text.
- Smart Capture. When you dictate a decision, your final transcript is sent — once — to be arranged into the parts of a decision record (the decision, the expected result, confidence, category, context, alternative paths). The only things sent are the transcript itself and the names of the context signals you track. You see the result and can edit everything before saving. Review dates you speak ("remind me in two weeks") are worked out on your device, not by the AI.
- Lens. As you capture a decision, Bivio may show one possible lens — a known thinking pattern that might be present — with a short reflective question. Lens detection runs on your device first. Only when the on-device matcher finds nothing, and remote lookup is active in your version of the app, is a snapshot of the decision text, your expected result, and any alternatives sent to the AI provider, which may answer only with one lens identifier from an approved list, or nothing. A lens is a possibility to consider, not a finding about you; you can dismiss it as "Not relevant," and dismissing it is final for that record.
Providers. Voice transcription is served by OpenAI. Smart Capture and Lens are served by Anthropic; our server configuration allows either of these two providers to serve either text feature, so both are named here and on our processors page. If we add or change providers, we will update this policy first.
Typed decisions. Typing avoids the audio, transcription, and voice Smart Capture steps entirely. It is not a guaranteed "no AI" mode: eligible typed decision text can still be sent for the remote Lens lookup described above. If a decision is marked Private, or the on-device sensitivity check recognizes an acutely sensitive situation, no remote Lens lookup happens for it.
Timing matters, so we say it plainly. In the voice flow, transcription and Smart Capture run before the editing form — and its Private toggle — appears. Marking a decision Private stops AI processing of that record from that moment on; it cannot undo a request that already happened earlier in the same capture. Bivio does not currently offer a mode that guarantees a decision is captured with no AI processing at all.
Provider retention and training. Under both providers' current published API terms, content submitted through the API is not used to train their models and is retained only briefly: OpenAI keeps abuse-monitoring logs up to 30 days (none for its audio transcription endpoint), and Anthropic deletes API inputs and outputs within 30 days.
What is not sent to AI providers: your history, profile, patterns, or any record other than the one being processed; your Recovery Key or any encryption material; records the on-device sensitivity check recognizes as acutely sensitive; and any record after you have marked it Private.
If an AI step is unavailable, the app degrades gracefully: your words are kept as you said or typed them, and you fill in the fields yourself.
9. Encryption and your Recovery Key
Bivio encrypts the content of your decision records on your device before they are stored on our servers. Precisely:
Encrypted on your device (we store only the sealed version):
- the decision text and expected result;
- category, confidence values, and how the record was captured;
- context signal values and alternative paths;
- the review you write when you close a loop — what happened and your ratings;
- the lens kept with a record, if any.
Not encrypted (needed to operate the Service):
- your profile (email address, display name, timezone, the names of context signals you track);
- record metadata: record identifiers, status, review dates and reminder scheduling state, whether a record is marked Private, and timestamps;
- feedback you send us (Section 5), which is stored as ordinary text so we can read and act on it.
How the key works. Your records are sealed with a data key that exists in usable form only on your device. That data key is itself locked with your Recovery Key — a 32-character code generated on your device when you set up Bivio. Our servers store only the locked version of the data key; the Recovery Key itself never leaves your device. This means Bivio cannot read the content of your sealed records, and Bivio cannot reset or recover your Recovery Key. There is deliberately no backdoor.
What that costs you. If you lose access to the device that holds your key and you lose your Recovery Key, the sealed content of your records cannot be opened again — by you or by us. On a new device, you enter your Recovery Key once to unlock your records. You can view your Recovery Key again in the app (You → Recovery key) after confirming with Face ID or your device passcode; if you copy it, the app clears it from your clipboard shortly afterward.
Honest boundaries. We describe this as client-side encryption rather than "end-to-end encryption," because some processing necessarily happens outside the sealed records: when you use voice capture, or when a decision is processed by Smart Capture or Lens (Sections 7–8), the relevant text is sent for that request; the profile data and metadata listed above are readable by our systems; and while our staff cannot open your sealed content, they can see the unencrypted metadata. Encryption reduces risk substantially; it does not eliminate all risk.
10. Usage analytics
We use PostHog to understand which parts of the app are used and where it fails. Bivio sends product analytics to PostHog's EU cloud endpoint and uses its EU hosting region (Frankfurt, Germany) — the app is built so it can send analytics events only to that endpoint. This describes the selected primary hosting region for analytics; PostHog's own operations remain governed by our agreement with it (Section 17).
The usage data is pseudonymous and installation-scoped: events are identified only by a random identifier generated for your app installation. That identifier is not your name, email, Bivio account identifier, Apple ID, advertising identifier, or a platform device identifier; the app never uses PostHog's identify features and does not attempt to connect the identifier to your account.
Default and control. During the friend beta, analytics is on by default from first launch. You can turn it off at any time in You → Privacy & Analytics. Turning it off stops collection immediately and deletes the random installation identifier; if you later turn it back on, a brand-new identifier is created, so the old and new data cannot be joined. Turning analytics off affects future collection — events already sent are not retroactively removed, because they were never linked to your account and we have no way to tell which ones are yours; they are covered by our retention approach below.
What analytics contains:
- which screens are visited and roughly how long they're used, in coarse buckets;
- onboarding progression and feature usage (for example "decision created", "review completed") as fixed event names;
- coarse categories for save success or failure;
- Patterns and Knowledge Center interaction events (for Knowledge Center search, only a count of results — never the search text);
- app version, platform, and OS version;
- a random per-installation identifier, generated in the app. It is not derived from your device or account and is never connected to your account.
What analytics never contains:
- your decision text, expectations, paths, or any journal content;
- transcripts or audio;
- lens content or explanations;
- your Recovery Key, passwords, or any encryption material;
- your email address, name, or Apple identifiers;
- your Bivio account identifier — events are not linked to your account;
- feedback message text;
- search queries, record identifiers, raw URLs, or free-form error text.
These exclusions are enforced in the app itself: the analytics layer has a closed, content-free list of allowed events and properties, and all automatic capture in the app (session replay, autocapture, lifecycle events, and location enrichment from IP addresses) is disabled. PostHog receives a network IP address when an analytics event is delivered. Our live PostHog project is configured to discard the client IP rather than store it with the event; PostHog may use the IP transiently for transformations such as GeoIP enrichment or bot detection before discarding it. Bivio does not include IP addresses or location fields in its analytics event schema and does not use PostHog Session Replay or autocapture. Deleting your account also removes the analytics identity from the device.
Retention. Product analytics events are retained according to the retention available under our active PostHog Cloud plan and project configuration. We review this data periodically and delete or aggregate it when it is no longer needed for product improvement, reliability, security, or legal compliance. We do not use the advertising identifier (IDFA), we do not track you across other companies' apps or websites, and we show no ads.
11. Private decisions
Marking a decision Private does the following:
- its text is masked on Home, in lists, and anywhere it would appear at a glance;
- it is shown normally once you deliberately open the record;
- from the moment you mark it Private, it is excluded from AI processing — no further Smart Capture refinement and no Lens lookup for that record;
- lens-related analytics for it omit even the lens identifier.
One honest limitation. The Private toggle lives on the decision's editing form. If you captured the decision by voice, the transcription and Smart Capture steps in Sections 7–8 (and possibly a Lens lookup) ran before that form appeared, so content processed in that initial step was already sent for that one request before Private could take effect. Marking a decision Private cannot undo processing that has already happened.
Private is a display-and-processing setting layered on top of encryption: every decision's content is client-side encrypted (Section 9) whether or not it is marked Private.
12. Patterns, Blind Spot, and readings
Bivio computes readings from your own closed decision loops: descriptive counts, early observations, and — only with enough evidence — possible patterns. The Blind Spot view works the same way with stricter thresholds.
- Computation happens on your device, over your own records after they are decrypted locally. No AI provider receives your Patterns data, and no server computes them.
- Minimum evidence. Nothing is shown below three closed loops; stronger wording requires more loops and a genuine like-for-like comparison.
- Early signals are uncertain. Readings describe what you recorded; they are not causal claims, statistics about you as a person, or clinical conclusions, and they can soften as more loops close.
- Private records are counted but never displayed in Patterns surfaces.
Patterns and Lens are reflective tools. They do not make decisions about you, and nothing in Bivio produces legal or similarly significant effects about you by automated means.
13. Knowledge Center
The Knowledge Center is a built-in library of short, educational entries about decision-making. It is bundled inside the app and works offline; reading and searching it sends nothing off your device (searching reports only a count of results to analytics, never your search text). It is general educational material, not advice.
14. Transactional email
We send only email that the Service needs: signup confirmation, password reset, a single welcome email after your first save, and copies of feedback you submit (delivered to us). Welcome and feedback emails are delivered by Resend from a Bivio address. We keep a minimal record that a welcome email was sent to your account so we never send it twice. We send no marketing email; if that ever changes, it will be opt-in and this policy will be updated first.
15. Purposes and legal bases
Where GDPR or UK GDPR applies, we process personal data on these bases:
| Purpose | Data | Legal basis |
|---|---|---|
| Providing your journal: account, storage, sync, display, reminders | Account data; encrypted records; metadata | Performance of a contract |
| Voice transcription and AI-assisted structuring of a capture you initiate | The audio clip or text for that request | Performance of a contract; where the app asks your permission before content is shared with an AI provider, consent for that sharing |
| Readings and Patterns (computed on your device) | Your own records, locally | Performance of a contract |
| Account security and authentication | Account and session data | Contract; our legitimate interest in keeping the Service secure |
| Usage analytics | Pseudonymous, installation-scoped events not linked to your account (Section 10) | Our legitimate interest in understanding and improving the app, honoring your in-app choice; where a stricter consent rule applies to you, we are moving to an explicit first-launch choice before wider release |
| Feedback handling | Feedback fields (Section 5) | Our legitimate interest in acting on feedback; consent for the optional reply email |
| Transactional email | Email address; message content | Performance of a contract |
| Legal compliance | The minimum needed for the specific obligation | Legal obligation |
We do not intentionally collect special categories of personal data. Content you choose to record may nonetheless reveal such information; we process it only because you chose to record it, only to provide the Service to you, and we protect it with client-side encryption.
16. Processors
We share personal data only with service providers that process it to run Bivio, with authorities where the law requires, and with a successor if the Service is ever transferred (this policy would continue to apply and you would be notified). We do not share personal data with data brokers, ad networks, or social platforms.
Our providers: Supabase (authentication, database, server functions), OpenAI (voice transcription), Anthropic (Smart Capture and Lens), PostHog (usage analytics, EU hosting region), Resend (transactional email), and Apple (distribution, TestFlight, Sign in with Apple, and speech recognition where server-assisted; Apple acts under its own terms). The current list, with each provider's role and privacy documentation, is published at https://getbivio.app/privacy (processors section) and kept up to date as providers change.
17. International transfers
Bivio sends product analytics to PostHog's EU cloud endpoint and uses its EU hosting region. Several other providers process data in the United States. Where GDPR or UK GDPR applies and personal data is transferred outside the EEA or UK, we rely on recognized safeguards — an adequacy decision where available, including the EU–US Data Privacy Framework for certified recipients, or Standard Contractual Clauses in our data-processing agreements — together with encryption in transit and, for record content, the client-side encryption described in Section 9. You can ask us about the safeguard applying to a specific provider at hello@getbivio.app.
18. Retention
| Data | How long |
|---|---|
| Account data and decision records | For the life of your account; deleted when you delete your account (Section 20) |
| Voice audio | Transient: deleted from your device when the transcription attempt ends; never stored on Bivio's servers |
| AI request content held by providers | Up to 30 days under the providers' current published API policies (none for OpenAI's audio transcription endpoint; provider policies can change and are re-checked regularly) |
| Product analytics events | According to the active PostHog Cloud retention settings; reviewed periodically and kept no longer than needed for the purposes described in Section 10 |
| Feedback and support messages | Up to 24 months after we resolve them |
| Welcome-email record (that it was sent) | Life of your account |
| Technical server logs | Short-term, rotated on our infrastructure provider's standard schedule |
| Backups | Deleted data may persist briefly in our storage provider's routine encrypted backups before those backups rotate out |
Where an exact period is not fixed, we keep data no longer than needed for the purpose, for security, or for a legal obligation.
19. Security
We apply technical and organizational measures appropriate to a private journal: client-side encryption of record content, TLS for all transport, encryption at rest at our infrastructure provider, row-level access rules so accounts can only reach their own rows, server functions that verify your identity on every request and log no content, and least-privilege administration. No service can promise absolute security. If we learn of a breach affecting your personal data, we will notify you and the relevant authorities as the law requires.
20. Account deletion
You can delete your account from inside the app: You → Account → Delete account. Deletion is permanent. When you confirm:
- your decision records, reviews, context data, profile, feedback rows, and stored key material are deleted from our production database, and your authentication account is deleted;
- if you signed in with Apple, we ask Apple to revoke the sign-in connection (if that step fails, the deletion completes anyway, and you can also revoke Bivio in your Apple ID settings);
- on your device, the app removes your local keys, your Recovery Key copy, cached data, drafts, scheduled reminders, and the analytics identifier;
- copies in our provider's routine encrypted backups age out on the provider's rotation schedule; analytics events already collected were never linked to your account and are covered by the retention approach in Section 10.
Deletion is irreversible: because record content is sealed with keys destroyed in this process, it cannot be reconstructed afterwards. You can also request deletion by emailing hello@getbivio.app.
21. Your rights
Depending on where you live, you may have the right to access, correct, delete, restrict, or receive a copy of your personal data, to object to processing based on legitimate interests, and to withdraw consent at any time.
You can exercise most of these directly in the app: edit your name and records, turn analytics off, delete individual records, or delete your whole account. For anything else — including a copy of your data — email hello@getbivio.app. We respond within one month (extendable as the law allows), free of charge for a first request, and we may need to verify that a request comes from the account holder. One practical note: we cannot read the content of your sealed records, so a copy of that content is produced with your participation, from your unlocked app.
EEA and UK: you may lodge a complaint with your data-protection authority — in the Czech Republic, the Office for Personal Data Protection (ÚOOÚ, uoou.gov.cz); in the UK, the Information Commissioner's Office (ico.org.uk); or the authority of your own country. We would appreciate the chance to help first, but you do not have to contact us before complaining.
United States and other regions: we do not sell personal information and do not share it for cross-context behavioral advertising, so there is nothing to opt out of. You have the same access, correction, and deletion channels described above, and we will not treat you differently for using them.
22. Children
Bivio is not intended for children. The Service is available only to people aged 16 or older, and we do not knowingly collect personal data from anyone younger. If you believe a child has created an account, contact hello@getbivio.app and we will delete it.
23. Changes to this policy
We may update this policy as the Service or the law changes. For material changes we will tell you in the app or by email before they take effect and update the effective date at the top. Changes are not retroactive. Earlier versions are available on request.
24. Contact
Eugeniu Cozlenco (operating Bivio) · Prague, Czech Republic Email: hello@getbivio.app Privacy Policy: https://getbivio.app/privacy · Terms: https://getbivio.app/terms