Who is responsible
The author and owner of the Bija project is responsible for the processing. The project has no legal entity yet: Bija is run by a private individual as an independent project in early testing. The service lives at bija.app; you can reach the owner by writing to help@bija.app — that is the only official channel, and a human answers it.
A representative in the European Union and a data protection officer have not been appointed yet: the project is small and runs in testing mode. Once the project has a legal entity, or the number of EU users grows noticeably, we will appoint them and update this page — the version date is shown at the top.
What data appears
Almost all of it you create yourself. We do not buy information about you and do not collect it from other services.
- Account: email address, password in encrypted form, name, language, time zone, role (for yourself or as a specialist).
- Access request: email, role and answers to a few questions about how you plan to use Bija.
- Your entries: notes, journal, dreams, results of practices and questionnaires, conversations with the assistant.
- Capsule: a psychological portrait built from your own entries, with the source shown for every observation.
- Sessions: uploaded recordings of meetings, transcripts, notes and analyses. These are uploaded by a specialist.
- Working together: links between a client and a specialist, invitations, the calendar, assignments and the working agreement.
- Technical: the email address for letters, the Telegram chat link, notification delivery marks, logs of model requests with spending counted.
Some of this is information about your mental state. Under European law that is a special category of data, and we process it only because you provided it yourself and gave explicit consent at registration.
Why we process it
- To make the service work: show your entries to you, keep the history, remind you about meetings.
- To do what you ask: transcribe a recording, build a summary, answer in the chat.
- To connect a client and a specialist and show each of them exactly what was opened to them.
- To answer your letters and tell you about things that matter in the service.
- To understand which sections people use: anonymous event statistics.
Legal bases: performance of our agreement with you, your consent (especially for data about your state) and our legitimate interest in keeping the service working and secure.
Whom we share data with
We do not sell data and do not pass it to advertising networks. We share only with processors the service cannot run without, and only as much as needed.
- Supabase — database, authentication and file storage. The data is in the us-west-1 region, that is, in the United States.
- Vercel — website hosting and request handling.
- Cloudflare — the domain, form protection against bots and incoming mail forwarding.
- Anthropic — the main language model: analyses, assistant, copilot.
- OpenAI — speech synthesis: reading practice texts aloud.
- Groq — transcription of voice messages and dictation.
- AssemblyAI — transcription of session recordings by speaker; a fallback for voice messages.
- Resend — sending email.
- Telegram — if you linked the bot chat, your messages and voice notes pass through it.
- PostHog — anonymous event statistics, server in the European Union.
The data sits in the United States while you may be in Europe. That is a cross-border transfer. Its basis is the European Commission's standard contractual clauses: they are already part of the data processing agreements of Supabase, Resend, AssemblyAI and the model providers, and we accept them by using those services. The project has no separate agreement with you on top of that, because it has no legal entity yet; once it does, we will offer specialists who work with clients a separate data processing agreement.
Artificial intelligence
When you ask for a session analysis, put a question to the assistant or request a summary, the relevant piece of text goes to a model provider and comes back as an answer. What exactly goes depends on the action: a session analysis sends the transcript, a conversation with the assistant sends the entries it relies on.
- We do not train models on your data and do not pass it on for training.
- Under their commercial API terms, Anthropic and OpenAI do not train their models on what is sent. Their abuse-monitoring logs are kept for up to 30 days and then deleted.
- By contract, Groq may not train models on what is sent and does not retain requests by default; logs for troubleshooting and abuse checks are kept for up to 30 days.
- Under its terms AssemblyAI may use what is sent to improve its models. This concerns transcription of session recordings, the association test and some voice messages. We are preparing to opt out of training and will update this page when that happens. If this matters to you, do not upload session recordings until then: text entries, conversations with the assistant and voice messages handled by Groq are not affected.
- The model does process private conversations and entries marked “Personal”: otherwise the assistant could not answer you. But they never go into material for a specialist or into the assistant's nightly memory.
- Other people's names and text from cards are sanitised before sending, so content cannot substitute instructions to the model.
Client and specialist
These are two different roles with different rights, and they must not be confused.
- A specialist sees only what the client opened and what the specialist created themselves: their notes, sessions, assignments.
- Entries marked “Personal” and private conversations are never visible to a specialist.
- Until a link is confirmed by both sides, nothing is opened.
- Material about a client uploaded by a specialist is controlled by that specialist, who is also responsible for the client's consent to the upload.
- Breaking the link closes the specialist's access to the client's material.
How long we keep it
Your entries are kept while the account exists. Most data has no automatic deletion period: a journal loses its point if it disappears after a year.
- Short-lived service records: linking and verification codes live fifteen minutes, invitations fourteen days, registration passes thirty days.
- Logs of model requests are kept to count spending and to protect against abuse.
- Database backups are made by Supabase and expire on their own schedule.
Deleting your account
You can delete the account yourself from the settings. We remove the files from storage, the data from the application tables and the account record itself.
- Deletion is irreversible: we cannot restore entries afterwards.
- Material a specialist created about you on their side stays with them: those are their professional records.
- Something may linger in backups and logs until they roll over as usual.
Your rights
- Find out what data about you exists and get a copy of it.
- Correct what is wrong.
- Delete your account and data.
- Withdraw consent: this does not undo processing that was already lawful.
- Object to processing based on legitimate interest.
- Complain to the supervisory authority in your country.
There is no one-click data export yet. Write to help@bija.app and we will put a copy together by hand. We answer such letters within a reasonable time, usually within a month.
Cookies and statistics
We set only what the service cannot work without: the sign-in cookie, the chosen language and the colour theme. We have no advertising cookies and no tracking pixels. Event statistics are sent anonymously through our own server, so no third-party analytics script runs in your browser.
Children
The service is not intended for anyone under 18. If we learn that a minor created an account, we will delete it.
Security
What exactly is done to protect the data, and what is not there yet, is described on the Security page. In short: the channel is encrypted, access to other people's rows is closed at the database level, sign-in is protected by a password or an email link, and there is no end-to-end encryption or two-factor sign-in yet.
Changes
This policy may change along with the service. The version date is shown at the top. We will announce material changes in advance and ask for consent again.
Contact
Questions about data and requests about your rights: help@bija.app.
This document describes the actual behaviour of the code at the version date. Bija is an early-stage project, and this page changes together with it. Where the mandatory law of your country gives you more rights than this page describes, that law applies.