Privacy policy
Effective September 14, 2026
Data stored on your device
Bijou stores a session token in protected device storage and keeps local copies of your ranked titles, watchlist, streaming-service selections, region, streak history, analytics preference, and restored backup data. Local copies remain until you clear them, clear browser/app storage, or uninstall the app. You can copy a portable backup from Data & privacy.
Account and synced data
Bijou stores your account ID, display name, username, optional email, the last four digits of your phone number, a keyed one-way lookup value for your phone number, the Terms version and server time accepted at sign-in, profile photo if previously provided, friend relationships, private Watch Together lists (with one friend, or a group of friends with an optional list name) and their title snapshots, account blocks and report categories, ranked list, watchlist, settings, streak, and session records on Cloudflare. Full phone numbers pass through Bijou’s Cloudflare service and are sent to Stytch when a verification text is requested. Bijou does not retain the full number in an active account record. Entries on the former access waitlist are described below. Suggested usernames are random and are not derived from the phone number.
Verification, abuse prevention, and retention
When you request a sign-in code, Bijou temporarily stores an opaque challenge, an encrypted copy of the full phone number, its last four digits and keyed one-way lookup value, Stytch’s opaque verification identifiers, an optional friend-invite digest, attempt count, and expiry time. Challenges expire after ten minutes and are eligible for deletion by scheduled authentication cleanup. Anyone with an eligible US or Canadian mobile number can create an account; no invitation or waitlist is required. A friend's invite link only connects you as friends when you join.
Bijou also stores keyed one-way rate-limit records derived from the phone lookup value, client IP address, or opaque account identifier. Those records expire with their abuse-prevention windows. Before sign-up opened to everyone, people could join an access waitlist; Bijou no longer adds anyone to it. Those entries keep an encrypted full phone number, keyed one-way lookup value, last four digits, status, and timestamps. When a waitlisted number creates an account, Bijou erases its encrypted waitlist number and outstanding waitlist claims. Phone-linked challenge, waitlist, and rate records are deleted when the associated Bijou account is deleted. You may ask Bijou support to remove a waitlist entry at any time.
Cloudflare hosts Bijou’s website, API, database, image storage, caching, and security controls. Cloudflare therefore processes network information such as IP address and request metadata, plus the content submitted to or returned by the API, to deliver and protect the service. Automatic Worker invocation URL logging is disabled; Bijou may retain limited intentional application error and security logs. Cloudflare’s own processing and retention are governed by its applicable service terms and privacy commitments.
Contacts and profile photos
Contact access is requested only after you choose Find friends. Phone numbers are normalized and hashed on your device; up to 500 hashes may be sent to Bijou to find matches. Contact names and readable phone numbers are not uploaded or stored by Bijou. You can use Bijou without granting Contacts access.
Profile-photo upload and visibility are temporarily disabled while image moderation is added. A photo previously provided may remain privately stored until you delete your account, but Bijou does not serve it to you or other members. Bijou does not perform face recognition or create biometric identifiers.
Data sent to other services
- Cloudflare processes Bijou website and API traffic and hosts the service data described above.
- Your phone number is sent to Stytch to deliver and validate one-time sign-in codes.
- Search text and title identifiers pass through Bijou’s Cloudflare service and are sent to TMDB to return title information and streaming availability. Poster and provider images are loaded from TMDB.
- If you explicitly enable product analytics, Bijou sends limited usage events and technical app/device information to PostHog. Bijou does not send ranked-list contents, Watch Together contents, friend or list identifiers, search text, title names, or title identifiers as analytics properties.
- Choosing Find showtimes opens a Google search outside Bijou. That page is governed by Google’s policies.
Sharing, sales, and advertising
People signed in to Bijou can see your display name, username, and ranked-title count on the global leaderboard. Profile photos are not currently displayed. A Watch Together list and its added/watched attribution are visible only to the accepted friend pair that created it. A group Watch Together list, its optional name, and its added/watched attribution are visible only to its current members, who must all be accepted friends with one another. Personal watchlists are never browsable. If you and an accepted friend both turn on mutual watchlist matches, Bijou may show each of you an exact movie or show that you both independently saved; every other saved title stays private. Rankings are not shared unless you deliberately create a revocable ranking share. Bijou does not sell personal information and does not use targeted advertising.
Your choices
You can deny Contacts or Photos access, omit a profile photo and email, turn mutual watchlist matches on or off, disable analytics, report or block accounts, manage your blocked list, copy or restore a backup, clear synced rankings and settings, or delete your account and cloud data from You → Data & privacy. Removing or blocking a friend deletes that pair’s Watch Together list, removes you from group Watch Together lists you share with them, and removes mutual-match visibility. Account deletion removes the hosted profile, photo, friendships, Watch Together lists with one friend, your membership in group lists (titles you added there stay for the other members without your name), blocks, reports tied to the account, sessions, synced app data, and phone-linked verification and rate-limit records. Providers such as Cloudflare, Stytch, TMDB, PostHog, or Google may retain limited information under their own policies and legal obligations.
Changes and contact
This policy will be updated when the app’s data practices change. For support or privacy questions, email bijouapp@proton.me.