All Policies
SECTION 03 • COMMUNICATION ARCHITECTURE

Messaging Privacy

An honest, factual explanation of how messages are transmitted, processed, and safeguarded across our platform.

Technical Disclosure Effective September 2026

1. How Your Messages Are Transmitted

When you send a message, media file, or call signal using Bias, the data is transmitted between your mobile device and our application servers using standard Transport Layer Security (TLS/HTTPS and secure WebSockets).

Transport encryption protects your communications while moving across the public internet, preventing eavesdropping by internet service providers, local network administrators, or actors on public Wi-Fi networks.

2. End-to-End Encryption Status

We believe in direct honesty without misleading technical buzzwords. The current version of Bias does NOT feature end-to-end encryption (E2EE).

Clear Disclosure: Messages sent through Bias are not encrypted in a way that renders them inaccessible to company systems. Our backend servers receive, route, and store message payloads to ensure reliable multi-device delivery, offline queueing, and notification dispatch.

We will never claim zero-knowledge privacy, client-only key custody, or end-to-end encryption unless our engineering architecture genuinely and provably provides it.

3. Storage & Operational Processing

To provide smooth real-time messaging, the platform performs standard operational duties:

Offline Delivery Queues: If a recipient’s device is offline or unreachable, messages are retained in secure transmission queues until the recipient reconnects.
Notification Previews: Depending on your in-app Notification settings, our servers format alert payloads to display either sender/message previews or privacy-preserving "New message" notifications.
Abuse Escalations: When a user submits an in-app report flagging illegal content or harassment, the flagged chat excerpt is provided to our human safety review team for verification.

4. Safeguarding Against Internal Misuse

Company access to transmission databases is strictly restricted by role-based access controls, audited authentication logs, and explicit internal privacy policies.

Employees are strictly prohibited from inspecting private user communications except when directly required for verified safety investigations, technical debugging requested by the user, or compliance with valid, binding legal subpoenas.