BIJOU · PRIVACY

Privacy policy

Effective August 17, 2026

The short version: Bijou uses phone-number verification for accounts and syncs your app data so it works across devices. Contact discovery and profile photos are optional. Contact names and readable address-book phone numbers are not uploaded. Optional product analytics is off by default.

Data stored on your device

Bijou stores a session token in protected device storage and keeps local copies of your ranked titles, watchlist, streaming-service selections, region, streak history, analytics preference, and restored backup data. Local copies remain until you clear them, clear browser/app storage, or uninstall the app. You can copy a portable backup from Data & privacy.

Account and synced data

Bijou stores your account ID, display name, username, optional email, the last four digits of your phone number, a keyed one-way lookup value for your phone number, profile photo if provided, friend relationships, private Watch Together lists and their title snapshots, account blocks and report categories, ranked list, watchlist, settings, streak, and session records on Cloudflare. Raw phone numbers pass through Bijou’s Cloudflare service and are sent to Stytch when a verification text is requested, but Bijou does not retain the raw number in its account database. Suggested usernames are random and are not derived from the phone number.

Verification, abuse prevention, and retention

When you request a sign-in code, Bijou temporarily stores an opaque challenge, the phone number’s last four digits and keyed one-way lookup value, Stytch’s opaque verification identifiers, an optional invite-token digest, attempt count, and expiry time. Challenges expire after ten minutes and are eligible for deletion by scheduled authentication cleanup. Bijou also stores keyed one-way rate-limit records derived from the phone lookup value, client IP address, or opaque account identifier. Those records expire with their abuse-prevention windows. Phone-linked challenge and rate records are deleted when the associated Bijou account is deleted.

Cloudflare hosts Bijou’s website, API, database, image storage, caching, and security controls. Cloudflare therefore processes network information such as IP address and request metadata, plus the content submitted to or returned by the API, to deliver and protect the service. Automatic Worker invocation URL logging is disabled; Bijou may retain limited intentional application error and security logs. Cloudflare’s own processing and retention are governed by its applicable service terms and privacy commitments.

Contacts and profile photos

Contact access is requested only after you choose Find friends. Phone numbers are normalized and hashed on your device; up to 500 hashes may be sent to Bijou to find matches. Contact names and readable phone numbers are not uploaded or stored by Bijou. You can use Bijou without granting Contacts access.

A profile photo is optional. You may choose an existing image or take a new one. Profile photos are used only to display your account to you and accepted friends; Bijou does not perform face recognition or create biometric identifiers.

Data sent to other services

Sharing, sales, and advertising

People signed in to Bijou can see your display name, username, and ranked-title count on the global leaderboard. Your profile photo remains visible only to you and accepted friends. A Watch Together list and its added/watched attribution are visible only to the accepted friend pair that created it; personal watchlists and rankings are not shared through that feature. Bijou does not sell personal information and does not use targeted advertising.

Your choices

You can deny Contacts or Photos access, omit a profile photo and email, disable analytics, report or block accounts, manage your blocked list, copy or restore a backup, clear synced rankings and settings, or delete your account and cloud data from Profile → Data & privacy. Removing or blocking a friend deletes that pair’s Watch Together list. Account deletion removes the hosted profile, photo, friendships, Watch Together lists, blocks, reports tied to the account, sessions, synced app data, and phone-linked verification and rate-limit records. Providers such as Cloudflare, Stytch, TMDB, PostHog, or Google may retain limited information under their own policies and legal obligations.

Changes and contact

This policy will be updated when the app’s data practices change. For support or privacy questions, email bijouapp@proton.me.