Security and Vulnerability Disclosure Policy

Effective October 7, 2026

This page explains how BizMeet LLC, a Wisconsin limited liability company ("BizMeet", "we", "us") protects the BizMeet app, website and backend. It also covers the limits you should know about, simple ways to keep your account safe, what we do if something goes wrong, and how security researchers can report a vulnerability to us.

For details on what personal data we collect and why, see our Privacy Policy. Questions about this page can go to contact@bizmeetapp.org.

1. Our approach

We build security into how BizMeet stores data and decides who can see it. The rules that protect your data are enforced by our database and servers, not only in the app. They are designed so that a modified app or a direct request to our servers cannot read or change data it is not allowed to see.

No online service can be perfectly secure, and we do not claim to be. We describe below what we actually do, and we say plainly where our protections stop.

2. How we protect your data

Hosting. Our database, sign-in, photo storage and server functions run on Supabase. We rely on Supabase and our other providers for the physical and network security of their systems.

Encrypted connections. The app and our servers talk only over HTTPS. Your data is encrypted while it travels between your phone and our systems.

Database access rules. Every table in our database has row-level security and explicit permissions. A signed-out visitor can read or write nothing. Our database functions act only for the member who is signed in. Helper functions that take another member's ID are closed to members. Other members only ever receive a limited public view of your profile. They never receive your birthday, email address, phone number, LinkedIn details, coordinates, settings or plan.

Private photo storage. Photos are kept in private storage, not on public links. Only signed-in members can load them from our servers, and only when our visibility rules allow it. For example, a member you block can no longer load your photos from us. When you replace or remove a photo, we delete it from our storage, usually right away and otherwise within about a day. Before a photo leaves your phone, the app crops it and saves a fresh JPEG copy. That copy carries no location or camera details. Our storage accepts only JPEG files of 1 MB or less.

Rate limits. We limit how often an account can send connection requests and messages, file reports, block members, record profile visits, load the Discover feed, look up profiles, load its activity and connection lists, read or mark chat read status, update its location, change its profile and privacy settings, and start chats. These limits slow down spam, scraping and abuse.

Account deletion. Deleting an account asks for the account password again just before deletion. Our server deletes an account only for a sign-in made in the last 10 minutes, so a session taken from an old sign-in cannot delete the account.

Checks on server endpoints. Our server endpoints accept only the kind of request they expect. Each one checks either the member's signed-in session or a shared secret before it saves or sends anything. The one exception is the page LinkedIn sends your browser back to when you connect LinkedIn. It saves nothing, and it passes the result on only for a LinkedIn sign-in started in the app in the last 10 minutes. The app then finishes the step with your signed-in session. When a request fails, our endpoints return a general error rather than internal details.

Verification details. If you use Get verified, we keep only the last four digits and a keyed fingerprint of the phone number you confirm, never the full number, and the LinkedIn member ID and first name, all stored privately. Other members see only the badge. We never ask for or receive your LinkedIn password. You sign in to LinkedIn only on LinkedIn's own page, in your phone's browser.

The Android app. App data backups are turned off, so your BizMeet data is not copied into device or cloud backups. Release builds are obfuscated. The app contains no server secrets. It holds only the public keys that the app is designed to use, and all sensitive keys stay on our backend.

Payments. Google Play handles all payments. We never receive or store your card number or other payment method details. We keep only a record of what you bought, such as the product and the store's transaction id.

3. Limits you should know about

We want you to understand what our protections do not cover.

Messages are not end-to-end encrypted. Messages are encrypted in transit and stored on the servers of our hosting provider, Supabase. They are not end-to-end encrypted. This means BizMeet can technically access them. For example, when a member reports, blocks or disconnects from someone, we keep a copy of recent messages as moderation evidence. We aim to delete these copies 180 days after we make them, and we keep them for that time even if an account is deleted. Our Privacy Policy explains this in full.

Who at BizMeet can see your data. Only the people who run BizMeet can open our database dashboard. We look at messages or evidence copies only to handle reports, legal requests, or security and abuse problems.

Notifications pass through Google. Push notifications are delivered through Google's Firebase Cloud Messaging service. They never include message text: a new-message notification says only "New message" and "Open BizMeet to read it." A Priority message notification can show the sender's first name, and notifications may appear on your lock screen. If you prefer that a type of notification not pass through Google, you can mute it in Settings. Muted notifications are never created on our servers.

Copies on other phones. Once another member has viewed your photos or messages, a copy may stay on their phone, for example in the app's image cache or as a screenshot. A block stops our servers from sending them anything new, but we cannot remove what is already on their device.

Distance shows your general area. Other members can see your city and a rounded distance in whole miles or kilometers, never your coordinates. We round locations to about 2 km, but someone determined could still estimate your general area from distances. To prevent this, turn on Hide location in Settings.

No two-step sign-in. BizMeet does not offer multi-factor authentication for members. Your password and access to your email inbox are what protect your account. There is no phone sign-in: a phone number you confirm in Get verified counts only toward the badge, and a code texted to it can't be used to get into your account.

The badge is not an identity check. The verified badge shows only that a member confirmed a phone number with a texted code and connected a LinkedIn account whose first name matches their BizMeet first name. LinkedIn names are chosen by their owners, so the badge does not prove who someone is or where they work.

We do not scan content or links. We do not use automated tools to scan profiles or messages for scams, malware or harmful links, and we do not check links that members paste into chats. A person at BizMeet reviews reports. Our Safety Policy and Safety Tips explains how to report.

4. Keeping your account safe

If you think someone else got into your account, reset your password right away from the sign-in screen. If you typed your password into a page that was not the BizMeet app, change it right away, and change it anywhere else you used the same password. A password reset signs you out of BizMeet on your other devices. Their current session may keep working for a short time, usually no more than an hour, before it ends. Then email contact@bizmeetapp.org from the address on your account and tell us what happened, so we can help.

If you no longer control that email address, write to us from another address with as much detail about the account as you can. We will work with you to confirm it is yours before we act.

5. If something goes wrong

If we learn of a security incident that may affect your personal information, we will investigate promptly, work to contain it, and take steps to prevent it from happening again.

If the incident is a breach that the law says we must report, we will notify the people affected, including former members whose information we still held. We will also notify regulators and others when the law requires it. We will do this within the time the law allows. Wisconsin law requires notice within a reasonable time, and no later than 45 days after we learn of the breach. Some states require notice within 30 days. We will follow the shortest deadline that applies to each affected person.

We will send notice to the email address we have for you and, where it helps, show a notice in the app. A real notice from us will never ask for your password or the codes we email you.

Our notice will explain what happened, what information was involved, what we are doing about it and what you can do to protect yourself. We may delay notice if a law enforcement agency asks us to, so we do not interfere with an investigation, or for as long as the law otherwise allows, for example to find out what happened and secure our systems. We will not delay longer than the law permits.

6. Reporting a vulnerability

We welcome reports from security researchers and members who find a weakness in BizMeet. This section explains what you may test, how to report, and the rules we ask you to follow.

In scope

Out of scope

These services are run by other companies. Please report problems with them directly to the company that runs them:

The platforms themselves are out of scope. How BizMeet configures or uses them is in scope, for example our Supabase project, our RevenueCat webhook, our Firebase project settings, our email domain records and the way BizMeet runs the LinkedIn connection step in Get verified. Test those only through BizMeet's own endpoints, never by attacking the vendor.

We also do not consider these to be vulnerabilities by themselves: reports from automated scanners with no working proof, and findings that need a rooted device or physical access to someone else's unlocked phone.

How to report

Email contact@bizmeetapp.org with the subject line "Security report". Please include:

Please do not include other people's personal data in your report. If you came across any, describe it instead of sending it.

If your report includes sensitive details, say so in a short first email and we will agree with you on how to send the rest.

Rules for testing

7. Safe harbor

If you make a good-faith effort to follow this policy while researching a vulnerability, we will consider your research authorized. We will not pursue legal action against you or refer your research to law enforcement. We will also not treat that research as a breach of our Terms of Service. This includes decompiling or analyzing the BizMeet Android app, which our Terms otherwise prohibit, and sending test requests to our backend. We will not bring a claim under anti-circumvention laws for research that follows this policy. If a third party takes legal action against you over research that followed this policy, we will make it known that your work was authorized by us.

This policy binds BizMeet only. It cannot bind other companies, courts or prosecutors.

Good faith means you test only to find and fix security flaws, you avoid harm to members and to BizMeet, and you do not use what you find for any other purpose. Research that goes beyond what a reasonable proof needs, or that harms members, is not covered.

We can only authorize testing of systems that we control. We cannot give permission to test services run by other companies, including those listed as out of scope above. Their own rules apply. If you are unsure whether something is allowed, ask us at contact@bizmeetapp.org before you test.

If your research exposed members' personal information, the law may require us to tell the people affected or regulators. We will describe the issue without naming you unless you agree or the law requires it.

8. What you can expect from us

When you report a vulnerability in line with this policy, we will:

We will not share your name or contact details outside BizMeet without your permission, unless the law requires it.

BizMeet does not offer a bug bounty. We do not pay monetary rewards for reports.

9. Not a security issue?

This policy is for technical security weaknesses. For other problems, please use these channels instead:

10. security.txt

We publish a security.txt file at https://bizmeetapp.org/.well-known/security.txt, following the RFC 9116 standard. It lets researchers and tools find our security contact quickly. It lists:

11. Changes to this policy

We may update this policy from time to time. The date at the top of this page shows when it last changed. A change will not remove safe harbor for research you started, in good faith, under an earlier version.