Security and Vulnerability Disclosure Policy
Effective October 7, 2026
This page explains how BizMeet LLC, a Wisconsin limited liability company ("BizMeet", "we", "us") protects the BizMeet app, website and backend. It also covers the limits you should know about, simple ways to keep your account safe, what we do if something goes wrong, and how security researchers can report a vulnerability to us.
For details on what personal data we collect and why, see our Privacy Policy. Questions about this page can go to contact@bizmeetapp.org.
1. Our approach
We build security into how BizMeet stores data and decides who can see it. The rules that protect your data are enforced by our database and servers, not only in the app. They are designed so that a modified app or a direct request to our servers cannot read or change data it is not allowed to see.
No online service can be perfectly secure, and we do not claim to be. We describe below what we actually do, and we say plainly where our protections stop.
2. How we protect your data
Hosting. Our database, sign-in, photo storage and server functions run on Supabase. We rely on Supabase and our other providers for the physical and network security of their systems.
Encrypted connections. The app and our servers talk only over HTTPS. Your data is encrypted while it travels between your phone and our systems.
Database access rules. Every table in our database has row-level security and explicit permissions. A signed-out visitor can read or write nothing. Our database functions act only for the member who is signed in. Helper functions that take another member's ID are closed to members. Other members only ever receive a limited public view of your profile. They never receive your birthday, email address, phone number, LinkedIn details, coordinates, settings or plan.
Private photo storage. Photos are kept in private storage, not on public links. Only signed-in members can load them from our servers, and only when our visibility rules allow it. For example, a member you block can no longer load your photos from us. When you replace or remove a photo, we delete it from our storage, usually right away and otherwise within about a day. Before a photo leaves your phone, the app crops it and saves a fresh JPEG copy. That copy carries no location or camera details. Our storage accepts only JPEG files of 1 MB or less.
Rate limits. We limit how often an account can send connection requests and messages, file reports, block members, record profile visits, load the Discover feed, look up profiles, load its activity and connection lists, read or mark chat read status, update its location, change its profile and privacy settings, and start chats. These limits slow down spam, scraping and abuse.
Account deletion. Deleting an account asks for the account password again just before deletion. Our server deletes an account only for a sign-in made in the last 10 minutes, so a session taken from an old sign-in cannot delete the account.
Checks on server endpoints. Our server endpoints accept only the kind of request they expect. Each one checks either the member's signed-in session or a shared secret before it saves or sends anything. The one exception is the page LinkedIn sends your browser back to when you connect LinkedIn. It saves nothing, and it passes the result on only for a LinkedIn sign-in started in the app in the last 10 minutes. The app then finishes the step with your signed-in session. When a request fails, our endpoints return a general error rather than internal details.
Verification details. If you use Get verified, we keep only the last four digits and a keyed fingerprint of the phone number you confirm, never the full number, and the LinkedIn member ID and first name, all stored privately. Other members see only the badge. We never ask for or receive your LinkedIn password. You sign in to LinkedIn only on LinkedIn's own page, in your phone's browser.
The Android app. App data backups are turned off, so your BizMeet data is not copied into device or cloud backups. Release builds are obfuscated. The app contains no server secrets. It holds only the public keys that the app is designed to use, and all sensitive keys stay on our backend.
Payments. Google Play handles all payments. We never receive or store your card number or other payment method details. We keep only a record of what you bought, such as the product and the store's transaction id.
3. Limits you should know about
We want you to understand what our protections do not cover.
Messages are not end-to-end encrypted. Messages are encrypted in transit and stored on the servers of our hosting provider, Supabase. They are not end-to-end encrypted. This means BizMeet can technically access them. For example, when a member reports, blocks or disconnects from someone, we keep a copy of recent messages as moderation evidence. We aim to delete these copies 180 days after we make them, and we keep them for that time even if an account is deleted. Our Privacy Policy explains this in full.
Who at BizMeet can see your data. Only the people who run BizMeet can open our database dashboard. We look at messages or evidence copies only to handle reports, legal requests, or security and abuse problems.
Notifications pass through Google. Push notifications are delivered through Google's Firebase Cloud Messaging service. They never include message text: a new-message notification says only "New message" and "Open BizMeet to read it." A Priority message notification can show the sender's first name, and notifications may appear on your lock screen. If you prefer that a type of notification not pass through Google, you can mute it in Settings. Muted notifications are never created on our servers.
Copies on other phones. Once another member has viewed your photos or messages, a copy may stay on their phone, for example in the app's image cache or as a screenshot. A block stops our servers from sending them anything new, but we cannot remove what is already on their device.
Distance shows your general area. Other members can see your city and a rounded distance in whole miles or kilometers, never your coordinates. We round locations to about 2 km, but someone determined could still estimate your general area from distances. To prevent this, turn on Hide location in Settings.
No two-step sign-in. BizMeet does not offer multi-factor authentication for members. Your password and access to your email inbox are what protect your account. There is no phone sign-in: a phone number you confirm in Get verified counts only toward the badge, and a code texted to it can't be used to get into your account.
The badge is not an identity check. The verified badge shows only that a member confirmed a phone number with a texted code and connected a LinkedIn account whose first name matches their BizMeet first name. LinkedIn names are chosen by their owners, so the badge does not prove who someone is or where they work.
We do not scan content or links. We do not use automated tools to scan profiles or messages for scams, malware or harmful links, and we do not check links that members paste into chats. A person at BizMeet reviews reports. Our Safety Policy and Safety Tips explains how to report.
4. Keeping your account safe
- Use a password of at least 8 characters that you do not use anywhere else. A password manager makes this easy.
- Protect the email account linked to BizMeet. Anyone who controls your inbox can receive the codes we send to confirm your email and reset your password.
- Never share the codes we email or text you, including the code for Get verified. They are for you alone. Scammers ask for these codes to take over accounts.
- BizMeet will never ask you for your password, or for a code we emailed or texted you, by email, phone call, text message, in a chat, or in any other way. You enter them only on the BizMeet app's own screens. Anyone who asks is not us.
- We do not send messages in BizMeet chats. Anyone who messages you in a chat claiming to be BizMeet support or a BizMeet recruiter is not acting for us. Report them.
- BizMeet never asks you to pay to unlock, restore or verify your account. Plans and packs are sold only through Google Play's checkout in the app.
- If you confirmed a phone number, keep it under your control. Ask your mobile carrier about a PIN or lock that stops anyone moving your number to another SIM card.
- When you connect LinkedIn, sign in only on LinkedIn's own page, and never send anyone the "Finish in BizMeet" page or its link.
- Use a screen lock on your phone. BizMeet keeps you signed in, so anyone who can unlock your phone can open the app.
- To keep notifications off your lock screen, change your phone's notification settings or mute notification types in BizMeet.
- Be careful with links and requests from other members. Do not enter your BizMeet password on a page someone sends you, and do not install an app or share your screen because a new contact asks you to. Our Safety Policy and Safety Tips page has tips on spotting scams and fake job offers.
- Sign out on devices you no longer use.
If you think someone else got into your account, reset your password right away from the sign-in screen. If you typed your password into a page that was not the BizMeet app, change it right away, and change it anywhere else you used the same password. A password reset signs you out of BizMeet on your other devices. Their current session may keep working for a short time, usually no more than an hour, before it ends. Then email contact@bizmeetapp.org from the address on your account and tell us what happened, so we can help.
If you no longer control that email address, write to us from another address with as much detail about the account as you can. We will work with you to confirm it is yours before we act.
5. If something goes wrong
If we learn of a security incident that may affect your personal information, we will investigate promptly, work to contain it, and take steps to prevent it from happening again.
If the incident is a breach that the law says we must report, we will notify the people affected, including former members whose information we still held. We will also notify regulators and others when the law requires it. We will do this within the time the law allows. Wisconsin law requires notice within a reasonable time, and no later than 45 days after we learn of the breach. Some states require notice within 30 days. We will follow the shortest deadline that applies to each affected person.
We will send notice to the email address we have for you and, where it helps, show a notice in the app. A real notice from us will never ask for your password or the codes we email you.
Our notice will explain what happened, what information was involved, what we are doing about it and what you can do to protect yourself. We may delay notice if a law enforcement agency asks us to, so we do not interfere with an investigation, or for as long as the law otherwise allows, for example to find out what happened and secure our systems. We will not delay longer than the law permits.
6. Reporting a vulnerability
We welcome reports from security researchers and members who find a weakness in BizMeet. This section explains what you may test, how to report, and the rules we ask you to follow.
In scope
- The website at https://bizmeetapp.org
- The BizMeet Android app (com.bizmeetllc.bizmeet), as distributed on Google Play
- BizMeet's own backend: our database access rules, our storage rules and our server endpoints
Out of scope
These services are run by other companies. Please report problems with them directly to the company that runs them:
- Google Play and Google Play Billing
- The Supabase platform
- Google Firebase
- RevenueCat
- Resend
- Twilio
- Cloudflare, which hosts our website and runs Turnstile
- Your phone's built-in location and geocoding services
The platforms themselves are out of scope. How BizMeet configures or uses them is in scope, for example our Supabase project, our RevenueCat webhook, our Firebase project settings, our email domain records and the way BizMeet runs the LinkedIn connection step in Get verified. Test those only through BizMeet's own endpoints, never by attacking the vendor.
We also do not consider these to be vulnerabilities by themselves: reports from automated scanners with no working proof, and findings that need a rooted device or physical access to someone else's unlocked phone.
How to report
Email contact@bizmeetapp.org with the subject line "Security report". Please include:
- the affected part (website, app version, or backend feature)
- clear steps to reproduce the issue
- what an attacker could do with it, and which data or accounts it could affect
- any proof of concept, screenshots or requests that help us confirm it
- the email addresses of your test accounts
- whether and how you would like to be credited
Please do not include other people's personal data in your report. If you came across any, describe it instead of sending it.
If your report includes sensitive details, say so in a short first email and we will agree with you on how to send the rest.
Rules for testing
- Test only with accounts you create and control. You must be 18 or older to create a BizMeet account.
- Put "Security test account" in the Professional Statement of each test account, use obviously non-real details, and delete your test accounts in Settings when you finish.
- Do not contact, message, send requests to, or otherwise interact with real members as part of your testing.
- Your test accounts may appear to real members in Discover. Ignore or decline any requests you get from real members.
- Do not open real members' full profiles. Opening a profile tells that member you visited.
- Access no more data than you need to show the problem.
- Do not change or delete any data that is not yours.
- If you reach another person's data, stop right away, do not keep, copy or share it, and report to us promptly.
- Do not run denial-of-service tests or anything that could degrade the service for others.
- Do not send spam, and do not use social engineering or phishing on our members or on us.
- Do not attempt physical attacks on any person, device or property.
- Do not run high-volume automated scans. Keep your traffic modest and respect our rate limits.
- Do not make real purchases for testing, and do not keep paid features you obtain through a flaw.
- Give us 90 days from your report before you disclose it publicly. If we need more time, we will explain why and agree on a date with you. If we fix it sooner, we can agree on an earlier date together.
7. Safe harbor
If you make a good-faith effort to follow this policy while researching a vulnerability, we will consider your research authorized. We will not pursue legal action against you or refer your research to law enforcement. We will also not treat that research as a breach of our Terms of Service. This includes decompiling or analyzing the BizMeet Android app, which our Terms otherwise prohibit, and sending test requests to our backend. We will not bring a claim under anti-circumvention laws for research that follows this policy. If a third party takes legal action against you over research that followed this policy, we will make it known that your work was authorized by us.
This policy binds BizMeet only. It cannot bind other companies, courts or prosecutors.
Good faith means you test only to find and fix security flaws, you avoid harm to members and to BizMeet, and you do not use what you find for any other purpose. Research that goes beyond what a reasonable proof needs, or that harms members, is not covered.
We can only authorize testing of systems that we control. We cannot give permission to test services run by other companies, including those listed as out of scope above. Their own rules apply. If you are unsure whether something is allowed, ask us at contact@bizmeetapp.org before you test.
If your research exposed members' personal information, the law may require us to tell the people affected or regulators. We will describe the issue without naming you unless you agree or the law requires it.
8. What you can expect from us
When you report a vulnerability in line with this policy, we will:
- confirm we received your report within 7 business days
- let you know whether we can reproduce the issue, and keep you updated while we work on it
- tell you when the issue is fixed
- if you would like, credit you by name on this page once the issue is fixed
We will not share your name or contact details outside BizMeet without your permission, unless the law requires it.
BizMeet does not offer a bug bounty. We do not pay monetary rewards for reports.
9. Not a security issue?
This policy is for technical security weaknesses. For other problems, please use these channels instead:
- For a fake profile, harassment, a scam, inappropriate content or someone who seems underage, use Report on the member's profile or chat in the app.
- If someone pretends to be BizMeet, or a website, app or ad misuses our name, see section 11 of our Copyright and Trademark Policy (DMCA).
- If you lost money or personal details to a scam, our Safety Policy and Safety Tips lists where to report it.
- For account help, billing questions or anything else, email contact@bizmeetapp.org.
- To delete your account, see Delete Your BizMeet Account.
- For the rules members must follow, see Community Guidelines.
- Law enforcement agencies should use our Law Enforcement Guide.
10. security.txt
We publish a security.txt file at https://bizmeetapp.org/.well-known/security.txt, following the RFC 9116 standard. It lets researchers and tools find our security contact quickly. It lists:
- Contact: mailto:contact@bizmeetapp.org
- Expires: a date no more than one year ahead, which we renew before it passes
- Policy: https://bizmeetapp.org/security/
- Preferred-Languages: en
- Canonical: https://bizmeetapp.org/.well-known/security.txt
11. Changes to this policy
We may update this policy from time to time. The date at the top of this page shows when it last changed. A change will not remove safe harbor for research you started, in good faith, under an earlier version.