Signing in
You can sign in with a password or with a link from an email. The password is stored in an irreversibly transformed form: even we cannot read it. Password requirements: at least eight characters, lower and upper case letters, digits and symbols.
Registration is closed: an account is created only by invitation, and that is enforced in the database, not only on the screen.
Separating data
Every row in the database knows whose it is. The access rules live in the database itself, so a request for someone else's entries returns nothing even if the application code makes a mistake. This is not an interface setting you can bypass by opening another address.
What a specialist sees
- Only what you opened yourself, and what they created about you: their own notes, sessions, assignments.
- Entries marked “Personal” and private conversations are never visible to them.
- Until you confirm the link nothing is opened: an invitation link alone grants no access.
- The link can be broken, and the access closes.
Artificial intelligence and privacy
- Only what is needed for the action you asked for goes to the model.
- The model processes private conversations and entries marked “Personal” only for you: they never go into material for a specialist or into the assistant's nightly memory.
- We do not train models on your data. By contract, Anthropic, OpenAI and Groq do not train on what is sent. AssemblyAI, which transcribes session recordings, may use them to improve its models under its terms; we are preparing to opt out and will say so here.
- Text from other people's cards is sanitised before sending: otherwise someone's name could substitute an instruction to the model.
- Actions that change your data are performed by the copilot only after you press a button.
Channel and keys
The site and the app work only over a secure channel. Keys to the database and to the models live on the server and in secrets; they do not reach the application code or the phone build.
Email and the bot
Letters are sent from a verified domain with a signature so they cannot be forged in our name. To create an account through the Telegram bot you must confirm the email with a code from a letter: otherwise someone else's address could be claimed. The number of code letters is limited.
Deletion
The account is deleted from the settings. We remove the files, the application data and the account record. This is irreversible. Notes a specialist kept about you on their side stay with them: those are their professional records.
What we do not have yet
An honest list, so you decide knowing the real picture.
- There is no end-to-end encryption. We can technically read the contents of the database, and without that search, analyses and access recovery would not work.
- There is no two-factor sign-in in the interface yet.
- There is no one-click export of all your data yet: we will put it together by hand on request.
- We have no external security audit and no certifications.
- The data is stored in the United States at our database provider. For users in Europe that is a cross-border transfer.
Found a vulnerability
Write to help@bija.app, ideally with the steps to reproduce. We answer and we are grateful. Please do not touch other people's data to prove a finding: a description is enough.