BivioClose ✕
Legal · Privacy

Bivio Privacy Policy

Effective date: July 22, 2026

This policy explains what personal data Bivio processes, why, and what your choices are. It applies to the Bivio iOS application, currently offered as an invited beta through Apple's TestFlight, and to the Bivio website pages that link to this policy (together, the "Service").

Bivio is operated by Eugeniu Cozlenco, an individual based in Prague, Czech Republic ("Bivio", "we", "us"). Where the EU General Data Protection Regulation (GDPR) or the UK GDPR applies, Eugeniu Cozlenco is the controller of the personal data described in this policy.

Contact for privacy, support, and legal questions: hello@getbivio.app


1. The short version

Bivio is a private decision journal. You record a decision before you know how it turns out, come back later to review it, and over time see readings and possible patterns in how you decide. Because the whole point of Bivio is private reflection, this policy is built around one idea: your record belongs to you.

The summary is for convenience; the full policy below is the authoritative description of our practices.

2. Who this policy is for

This policy covers people who use the Bivio app or contact us at our email address. It does not cover Apple's own processing when you download the app, use TestFlight, use Sign in with Apple, or share crash reports with Apple — Apple acts under its own privacy policy for those activities — or third-party websites you reach through links.

Bivio is intended for people aged 16 or older. The friend beta is offered to invited testers; we currently expect public availability, when it comes, to begin in the United States, Canada, Australia, the European Union and EEA, and the United Kingdom.

3. Account information

To create an account we collect:

If you use Sign in with Apple, Apple sends us a stable identifier for your account and, depending on your choice in Apple's sign-in sheet, either your real email address or an Apple private relay address that forwards to you. We treat a relay address like any other email address and do not attempt to unmask it. Bivio never sees your Apple ID password.

Email/password accounts and Sign in with Apple accounts are separate sign-in identities. If you try to sign in with Apple using an email that already has a Bivio password account, the app shows a calm conflict message; accounts are not automatically merged.

Your profile also stores a timezone value and, if you set them up, the names of the context signals you chose to track (for example "sleep" or "stress" as labels — the values you record for them live inside your encrypted decision records, not your profile). We do not ask for your date of birth, gender, country, or any other demographic information.

If you forget your password, you can request a reset from the app; the reset link returns you to Bivio to set a new password. Password resets never affect your Recovery Key or your encrypted records.

4. Decision records

Depending on which fields you fill in, a decision record may include: the decision in your own words, the result you expect, your confidence, a category, context signal values, alternative paths you considered, review dates, and — when you close the loop — what actually happened and how you rate the call and the result. Free-text fields can contain whatever you choose to write.

Decision records can be sensitive: what you write may reveal information about your health, finances, relationships, work, or anything else you decide to record. We do not ask for any special category of data, and we suggest not entering sensitive details that your reflection doesn't need. Whatever you record, we treat it as private content and protect it as described in Section 9.

Your records are used only to provide the Service to you — storing them, reminding you to review, computing your own readings and patterns, and powering the voice and AI assistance described below. We do not use them for advertising, we do not sell them, and we do not use them to train AI models.

5. Feedback and support

If you send feedback through the app (You → Send feedback), we receive: the category you pick (bug, idea, confusing, other), your message, an optional reply email if you want an answer, and a small set of technical details — app version, platform, OS version, the screen you were on, and (only if analytics is enabled) the same random installation identifier used for analytics. Feedback is stored in our database and a copy is emailed to us through Resend so we actually see it. Because feedback rows are tied to your account and may include a reply address, feedback is not anonymous. Your feedback message is never sent to our analytics provider.

If you email us, we receive your address and the content of your message.

6. Notifications and reminders

Bivio uses local notifications only — reminders are scheduled on your device, and no remote push infrastructure or push token is used. iOS asks for your permission before any reminder can be shown, and the app asks only after you have saved your first decision. Reminders exist for one purpose: telling you a decision is ready to review (one reminder, and one follow-up three days later if you haven't reviewed).

Reminder notifications never contain your decision text, whether or not a record is marked Private. The notification simply invites you back; the content stays in the app. Delivery depends on your device and iOS settings, so reminders are not guaranteed to arrive. You can turn notifications off any time in iOS Settings or in Bivio's reminder settings, and the app works without them.

7. Voice capture and transcription

If you use voice capture, we process audio of your voice to turn it into text. iOS asks for your permission before Bivio can use the microphone or speech recognition. The full path:

  1. Live preview (Apple). While you speak, Apple's speech recognition provides a provisional on-screen preview. Bivio requests on-device recognition whenever your device supports it; where it does not, Apple may process the audio through its own servers under Apple's terms. The preview is never the final transcript and is never saved.
  2. Final transcript (OpenAI). When cloud transcription is active in your version of the app, the dictation is recorded as a temporary audio clip on your device and sent through a Bivio server function to OpenAI's transcription API. The transcript OpenAI returns becomes the authoritative text of your note, replacing the preview. If the cloud step fails or you are offline, the preview text is used instead — you are never asked to repeat yourself.
  3. Deletion. The temporary audio clip is deleted from your device when the transcription attempt finishes — on success, failure, timeout, or cancellation — and a cleanup sweep removes any leftover clips from interrupted sessions. Bivio does not store your audio: our server function passes the clip to OpenAI and keeps nothing, and no recording is written to our database. Under OpenAI's current published API policy, its audio transcription endpoint does not retain submitted audio for abuse monitoring and API content is not used to train OpenAI's models.

We do not use your voice to identify you and we do not create voiceprints.

8. Smart Capture, Lens, and what reaches AI providers

Two parts of Bivio use large-language-model services operated by third parties. Both run through Bivio's own servers: the app never talks to an AI provider directly, requests are authenticated, our server functions log no content, and requests carry no name, email, or account identifier alongside the text.

Providers. Voice transcription is served by OpenAI. Smart Capture and Lens are served by Anthropic; our server configuration allows either of these two providers to serve either text feature, so both are named here and on our processors page. If we add or change providers, we will update this policy first.

Typed decisions. Typing avoids the audio, transcription, and voice Smart Capture steps entirely. It is not a guaranteed "no AI" mode: eligible typed decision text can still be sent for the remote Lens lookup described above. If a decision is marked Private, or the on-device sensitivity check recognizes an acutely sensitive situation, no remote Lens lookup happens for it.

Timing matters, so we say it plainly. In the voice flow, transcription and Smart Capture run before the editing form — and its Private toggle — appears. Marking a decision Private stops AI processing of that record from that moment on; it cannot undo a request that already happened earlier in the same capture. Bivio does not currently offer a mode that guarantees a decision is captured with no AI processing at all.

Provider retention and training. Under both providers' current published API terms, content submitted through the API is not used to train their models and is retained only briefly: OpenAI keeps abuse-monitoring logs up to 30 days (none for its audio transcription endpoint), and Anthropic deletes API inputs and outputs within 30 days.

What is not sent to AI providers: your history, profile, patterns, or any record other than the one being processed; your Recovery Key or any encryption material; records the on-device sensitivity check recognizes as acutely sensitive; and any record after you have marked it Private.

If an AI step is unavailable, the app degrades gracefully: your words are kept as you said or typed them, and you fill in the fields yourself.

9. Encryption and your Recovery Key

Bivio encrypts the content of your decision records on your device before they are stored on our servers. Precisely:

Encrypted on your device (we store only the sealed version):

Not encrypted (needed to operate the Service):

How the key works. Your records are sealed with a data key that exists in usable form only on your device. That data key is itself locked with your Recovery Key — a 32-character code generated on your device when you set up Bivio. Our servers store only the locked version of the data key; the Recovery Key itself never leaves your device. This means Bivio cannot read the content of your sealed records, and Bivio cannot reset or recover your Recovery Key. There is deliberately no backdoor.

What that costs you. If you lose access to the device that holds your key and you lose your Recovery Key, the sealed content of your records cannot be opened again — by you or by us. On a new device, you enter your Recovery Key once to unlock your records. You can view your Recovery Key again in the app (You → Recovery key) after confirming with Face ID or your device passcode; if you copy it, the app clears it from your clipboard shortly afterward.

Honest boundaries. We describe this as client-side encryption rather than "end-to-end encryption," because some processing necessarily happens outside the sealed records: when you use voice capture, or when a decision is processed by Smart Capture or Lens (Sections 7–8), the relevant text is sent for that request; the profile data and metadata listed above are readable by our systems; and while our staff cannot open your sealed content, they can see the unencrypted metadata. Encryption reduces risk substantially; it does not eliminate all risk.

10. Usage analytics

We use PostHog to understand which parts of the app are used and where it fails. Bivio sends product analytics to PostHog's EU cloud endpoint and uses its EU hosting region (Frankfurt, Germany) — the app is built so it can send analytics events only to that endpoint. This describes the selected primary hosting region for analytics; PostHog's own operations remain governed by our agreement with it (Section 17).

The usage data is pseudonymous and installation-scoped: events are identified only by a random identifier generated for your app installation. That identifier is not your name, email, Bivio account identifier, Apple ID, advertising identifier, or a platform device identifier; the app never uses PostHog's identify features and does not attempt to connect the identifier to your account.

Default and control. During the friend beta, analytics is on by default from first launch. You can turn it off at any time in You → Privacy & Analytics. Turning it off stops collection immediately and deletes the random installation identifier; if you later turn it back on, a brand-new identifier is created, so the old and new data cannot be joined. Turning analytics off affects future collection — events already sent are not retroactively removed, because they were never linked to your account and we have no way to tell which ones are yours; they are covered by our retention approach below.

What analytics contains:

What analytics never contains:

These exclusions are enforced in the app itself: the analytics layer has a closed, content-free list of allowed events and properties, and all automatic capture in the app (session replay, autocapture, lifecycle events, and location enrichment from IP addresses) is disabled. PostHog receives a network IP address when an analytics event is delivered. Our live PostHog project is configured to discard the client IP rather than store it with the event; PostHog may use the IP transiently for transformations such as GeoIP enrichment or bot detection before discarding it. Bivio does not include IP addresses or location fields in its analytics event schema and does not use PostHog Session Replay or autocapture. Deleting your account also removes the analytics identity from the device.

Retention. Product analytics events are retained according to the retention available under our active PostHog Cloud plan and project configuration. We review this data periodically and delete or aggregate it when it is no longer needed for product improvement, reliability, security, or legal compliance. We do not use the advertising identifier (IDFA), we do not track you across other companies' apps or websites, and we show no ads.

11. Private decisions

Marking a decision Private does the following:

One honest limitation. The Private toggle lives on the decision's editing form. If you captured the decision by voice, the transcription and Smart Capture steps in Sections 7–8 (and possibly a Lens lookup) ran before that form appeared, so content processed in that initial step was already sent for that one request before Private could take effect. Marking a decision Private cannot undo processing that has already happened.

Private is a display-and-processing setting layered on top of encryption: every decision's content is client-side encrypted (Section 9) whether or not it is marked Private.

12. Patterns, Blind Spot, and readings

Bivio computes readings from your own closed decision loops: descriptive counts, early observations, and — only with enough evidence — possible patterns. The Blind Spot view works the same way with stricter thresholds.

Patterns and Lens are reflective tools. They do not make decisions about you, and nothing in Bivio produces legal or similarly significant effects about you by automated means.

13. Knowledge Center

The Knowledge Center is a built-in library of short, educational entries about decision-making. It is bundled inside the app and works offline; reading and searching it sends nothing off your device (searching reports only a count of results to analytics, never your search text). It is general educational material, not advice.

14. Transactional email

We send only email that the Service needs: signup confirmation, password reset, a single welcome email after your first save, and copies of feedback you submit (delivered to us). Welcome and feedback emails are delivered by Resend from a Bivio address. We keep a minimal record that a welcome email was sent to your account so we never send it twice. We send no marketing email; if that ever changes, it will be opt-in and this policy will be updated first.

15. Purposes and legal bases

Where GDPR or UK GDPR applies, we process personal data on these bases:

PurposeDataLegal basis
Providing your journal: account, storage, sync, display, remindersAccount data; encrypted records; metadataPerformance of a contract
Voice transcription and AI-assisted structuring of a capture you initiateThe audio clip or text for that requestPerformance of a contract; where the app asks your permission before content is shared with an AI provider, consent for that sharing
Readings and Patterns (computed on your device)Your own records, locallyPerformance of a contract
Account security and authenticationAccount and session dataContract; our legitimate interest in keeping the Service secure
Usage analyticsPseudonymous, installation-scoped events not linked to your account (Section 10)Our legitimate interest in understanding and improving the app, honoring your in-app choice; where a stricter consent rule applies to you, we are moving to an explicit first-launch choice before wider release
Feedback handlingFeedback fields (Section 5)Our legitimate interest in acting on feedback; consent for the optional reply email
Transactional emailEmail address; message contentPerformance of a contract
Legal complianceThe minimum needed for the specific obligationLegal obligation

We do not intentionally collect special categories of personal data. Content you choose to record may nonetheless reveal such information; we process it only because you chose to record it, only to provide the Service to you, and we protect it with client-side encryption.

16. Processors

We share personal data only with service providers that process it to run Bivio, with authorities where the law requires, and with a successor if the Service is ever transferred (this policy would continue to apply and you would be notified). We do not share personal data with data brokers, ad networks, or social platforms.

Our providers: Supabase (authentication, database, server functions), OpenAI (voice transcription), Anthropic (Smart Capture and Lens), PostHog (usage analytics, EU hosting region), Resend (transactional email), and Apple (distribution, TestFlight, Sign in with Apple, and speech recognition where server-assisted; Apple acts under its own terms). The current list, with each provider's role and privacy documentation, is published at https://getbivio.app/privacy (processors section) and kept up to date as providers change.

17. International transfers

Bivio sends product analytics to PostHog's EU cloud endpoint and uses its EU hosting region. Several other providers process data in the United States. Where GDPR or UK GDPR applies and personal data is transferred outside the EEA or UK, we rely on recognized safeguards — an adequacy decision where available, including the EU–US Data Privacy Framework for certified recipients, or Standard Contractual Clauses in our data-processing agreements — together with encryption in transit and, for record content, the client-side encryption described in Section 9. You can ask us about the safeguard applying to a specific provider at hello@getbivio.app.

18. Retention

DataHow long
Account data and decision recordsFor the life of your account; deleted when you delete your account (Section 20)
Voice audioTransient: deleted from your device when the transcription attempt ends; never stored on Bivio's servers
AI request content held by providersUp to 30 days under the providers' current published API policies (none for OpenAI's audio transcription endpoint; provider policies can change and are re-checked regularly)
Product analytics eventsAccording to the active PostHog Cloud retention settings; reviewed periodically and kept no longer than needed for the purposes described in Section 10
Feedback and support messagesUp to 24 months after we resolve them
Welcome-email record (that it was sent)Life of your account
Technical server logsShort-term, rotated on our infrastructure provider's standard schedule
BackupsDeleted data may persist briefly in our storage provider's routine encrypted backups before those backups rotate out

Where an exact period is not fixed, we keep data no longer than needed for the purpose, for security, or for a legal obligation.

19. Security

We apply technical and organizational measures appropriate to a private journal: client-side encryption of record content, TLS for all transport, encryption at rest at our infrastructure provider, row-level access rules so accounts can only reach their own rows, server functions that verify your identity on every request and log no content, and least-privilege administration. No service can promise absolute security. If we learn of a breach affecting your personal data, we will notify you and the relevant authorities as the law requires.

20. Account deletion

You can delete your account from inside the app: You → Account → Delete account. Deletion is permanent. When you confirm:

Deletion is irreversible: because record content is sealed with keys destroyed in this process, it cannot be reconstructed afterwards. You can also request deletion by emailing hello@getbivio.app.

21. Your rights

Depending on where you live, you may have the right to access, correct, delete, restrict, or receive a copy of your personal data, to object to processing based on legitimate interests, and to withdraw consent at any time.

You can exercise most of these directly in the app: edit your name and records, turn analytics off, delete individual records, or delete your whole account. For anything else — including a copy of your data — email hello@getbivio.app. We respond within one month (extendable as the law allows), free of charge for a first request, and we may need to verify that a request comes from the account holder. One practical note: we cannot read the content of your sealed records, so a copy of that content is produced with your participation, from your unlocked app.

EEA and UK: you may lodge a complaint with your data-protection authority — in the Czech Republic, the Office for Personal Data Protection (ÚOOÚ, uoou.gov.cz); in the UK, the Information Commissioner's Office (ico.org.uk); or the authority of your own country. We would appreciate the chance to help first, but you do not have to contact us before complaining.

United States and other regions: we do not sell personal information and do not share it for cross-context behavioral advertising, so there is nothing to opt out of. You have the same access, correction, and deletion channels described above, and we will not treat you differently for using them.

22. Children

Bivio is not intended for children. The Service is available only to people aged 16 or older, and we do not knowingly collect personal data from anyone younger. If you believe a child has created an account, contact hello@getbivio.app and we will delete it.

23. Changes to this policy

We may update this policy as the Service or the law changes. For material changes we will tell you in the app or by email before they take effect and update the effective date at the top. Changes are not retroactive. Earlier versions are available on request.

24. Contact

Eugeniu Cozlenco (operating Bivio) · Prague, Czech Republic Email: hello@getbivio.app Privacy Policy: https://getbivio.app/privacy · Terms: https://getbivio.app/terms

BivioPrivacyTermsSubprocessorshello@getbivio.app© 2026 BIVIO · PRAGUE, CZ