Bivio — Service Providers and Subprocessors
Bivio is operated by Eugeniu Cozlenco, an individual based in Prague, Czech Republic. The providers below process personal data to run Bivio — the mobile application and the public Bivio website — each for the purpose stated and no other. We update this page when providers change; material changes are announced in the app or by email first. Questions: hello@getbivio.app.
Supabase (Supabase, Inc.)
- Purpose: account authentication (email/password, Sign in with Apple, password reset), database storage, and the server functions that power Bivio's features.
- Information processed: account details (email address, display name, timezone); decision records — content stored in client-side-encrypted form, with operating metadata (record status, review dates, Private flag, timestamps) readable; feedback you submit; short-term technical logs.
- Processing location: Supabase hosts projects on major cloud regions; support access may occur from other countries under its data-processing terms.
- Privacy: https://supabase.com/privacy · DPA: https://supabase.com/legal/dpa
OpenAI (OpenAI, L.L.C.)
- Purpose: turning your dictation into the authoritative transcript.
- Information processed: the temporary audio clip of a dictation, sent through Bivio's own server function; no name, email, or account identifier accompanies it. Under OpenAI's current published API policy, audio sent to its transcription endpoint is not retained for abuse monitoring and API content is not used to train its models unless a customer explicitly opts in.
- Processing location: United States.
- Privacy: https://openai.com/policies/privacy-policy · API data controls: https://developers.openai.com/api/docs/guides/your-data
Anthropic (Anthropic, PBC)
- Purpose: Smart Capture (arranging your dictated words into a decision record) and Lens (suggesting one possible thinking pattern for reflection).
- Information processed: for Smart Capture, the final transcript and the names of context signals you track; for Lens, a snapshot of the decision text, expected result, and alternatives. No name, email, or account identifier accompanies the text. Under Anthropic's current published commercial API policy, inputs and outputs are deleted within 30 days and are not used to train its models by default.
- Processing location: United States.
- Privacy: https://www.anthropic.com/legal/privacy · Data retention: https://privacy.claude.com/en/articles/7996866-how-long-do-you-store-my-organization-s-data
- Note: Bivio's servers can route Smart Capture and Lens to either Anthropic or OpenAI; both providers are listed here for that reason. Voice transcription is served by OpenAI.
PostHog (PostHog, Inc.)
PostHog serves two separate Bivio analytics projects with different configurations. They are described separately below because their settings differ, and neither project's settings should be read as describing the other.
PostHog — analytics inside the Bivio app
- Purpose: product usage analytics — understanding which parts of the app are used and where it fails.
- Information processed: pseudonymous, installation-scoped usage events (screens, feature usage, coarse duration buckets, app and OS version), identified only by a random per-installation identifier that is not linked to your Bivio account. No decision content, transcripts, names, emails, or account identifiers, and no Session Replay. For this app project only, the project is configured to discard the client IP address rather than store it with events; PostHog may use the IP transiently (for example for bot detection) before discarding it. This app-only setting does not apply to the website project below. Events are retained under the project's PostHog Cloud retention settings and reviewed periodically. You can turn analytics off in You → Privacy & Analytics.
- Processing location: selected primary hosting region is PostHog Cloud EU (Frankfurt, Germany); PostHog's own operations and support are governed by its privacy terms and data-processing agreement.
PostHog — analytics on the public Bivio website
- Purpose: understanding how the public website is used and how many people reach the app or ask for release updates — measuring release interest and conversion, improving the site, and keeping it reliable and free of abuse.
- Information processed: page views and page leaves; which sections of the page are reached; clicks on the TestFlight link, on release-updates links, on legal links, and on FAQ items (recorded as an item number); the fact that the release-updates form was started and successfully submitted; a bounded set of carousel interactions; referrer and UTM attribution; and the technical event properties PostHog generates for a web request — browser, device, operating system, viewport, and page URL. Autocapture is restricted to approved click and submit interactions on links, buttons, and forms; all other events are manual and bounded.
- Cookieless measurement: the website loads PostHog with cookieless mode set to
always, and the project uses PostHog's cookieless server hash mode. In this configuration PostHog stores no identifier in cookies,localStorage, orsessionStoragein your browser; visitors are counted using a privacy-preserving hash computed on PostHog's servers. Person profiles are limited to identified users (identified_only), Bivio makes noidentify()calls on the website, and no person profile is created for an anonymous visitor. Cookieless does not mean anonymous: this is still processing of personal data and is described here as such. - Client IP: the website project is configured to capture client IP data rather than discard it at ingestion. This may permit IP-based processing such as approximate geographic enrichment, security, or bot detection. We have verified that capture is enabled; we make no claim about how long, or in what form, PostHog's own systems retain the raw IP address — that is governed by PostHog's privacy terms and our data-processing agreement with it.
- What this project never receives: the email address you submit to the release-updates form, or any other form field value; your name; your Bivio account identifier; decision records, decision text, transcripts, Recovery Keys, or journal content. The release-updates form and its email input are excluded from autocapture, and the manual events recorded when the form is started or submitted carry only bounded placement metadata. Session Replay is disabled.
- Separation: PostHog does generate a cookieless, server-side analytics identifier so that website visits can be measured. Separation does not rest on the absence of an identifier: Bivio does not send the Netlify submission email address or any shared linking key to PostHog, does not receive a mapping between the two systems, and does not attempt to join Netlify form submissions to PostHog analytics events or to Bivio app accounts.
- Retention: events are retained under the active PostHog Product Analytics configuration for this project, reviewed periodically, and deleted or aggregated when no longer needed for the purposes above.
- Processing location: selected primary hosting region is PostHog Cloud EU (
https://eu.i.posthog.com, Frankfurt, Germany); PostHog's own operations and support are governed by its privacy terms and data-processing agreement.
PostHog documentation (both projects): https://posthog.com/privacy · DPA: https://posthog.com/dpa · Data collection controls: https://posthog.com/docs/privacy/data-collection
Netlify (Netlify, Inc.)
- Purpose: hosting and delivering the public Bivio website; processing the voluntary release-updates form; spam prevention, security, and the operational handling those functions require.
- Information processed: the email address you submit through the
release-updatesform, together with the submission and service-level technical and security metadata Netlify needs to accept, filter, and protect that submission; and the ordinary website request and hosting logs Netlify keeps to operate the service. All form submissions to Netlify Forms are screened for spam by Akismet (Automattic) as part of Netlify's standard service. - What Netlify never receives: your Bivio journal content, your decision records, your Recovery Key, or any other content from the app. Bivio makes no intentional transfer of the submitted email address to PostHog, and does not add it to PostHog as an identity or person property.
- Retention of the submitted address: release-update email addresses are retained until the requested release notifications have been sent or the subscriber unsubscribes, whichever occurs first. They are deleted within 30 days after that point and, unless the subscriber renews the request, are retained for no longer than 24 months from submission. Netlify's own service and security logs are kept on Netlify's operational schedule, which we do not set.
- Processing location: Netlify is a United States company operating a globally distributed platform, and personal data may be processed outside the country where it was collected. We rely on Netlify's data-processing addendum, its published subprocessor arrangements, and the transfer safeguards described there — Standard Contractual Clauses under Commission Implementing Decision 2021/914 and Netlify's certification under the EU–U.S. Data Privacy Framework, the UK Extension, and the Swiss–U.S. Data Privacy Framework. We do not claim that Netlify Forms data is stored only in the EU.
- Privacy: https://www.netlify.com/privacy/ · GDPR and DPA: https://www.netlify.com/gdpr-ccpa/ · Security: https://www.netlify.com/security/
Resend (Resend, Inc.)
- Purpose: delivering Bivio's transactional email — the welcome email and copies of feedback you submit.
- Information processed: recipient email address and the content of those emails.
- Processing location: United States.
- Privacy: https://resend.com/legal/privacy-policy
Apple (Apple Inc.)
- Purpose: App Store distribution, Sign in with Apple, and the live speech-recognition preview while you dictate (on-device where your device supports it; otherwise Apple's servers may assist under Apple's terms).
- Information processed: per Apple's own privacy policy — Apple acts independently for these services rather than on Bivio's instructions.
- Privacy: https://www.apple.com/legal/privacy/
What no provider receives: your Recovery Key or any encryption material, and the sealed (encrypted) content of your records in readable form. AI providers receive only the specific text or audio of the individual request described above, at the moment that feature runs.
Website and app are kept apart. An email address submitted to the release-updates form on the public website is held by Netlify and is not sent to PostHog, not attached to a website analytics visitor, and not connected to a Bivio app account. Deleting a Bivio account therefore does not remove a release-update subscription, and a release-update subscription tells us nothing about whether you have an account. The Privacy Policy explains how to unsubscribe or ask us to delete the address.