This policy describes how BAUGEY MATHEO, trading as DEVOLIM, processes personal data in connection with the Bimo mobile app and the website https://bimo.devolim.fr. It is drawn up in accordance with Regulation (EU) 2016/679 of 27 April 2016 (the “GDPR”) and French Act No. 78-17 of 6 January 1978 as amended.
In short. Bimo works without sign-up: no email, no password, no identity. The message you submit is analysed and then not kept: neither on our servers nor in our logs. What we retain from a check is an irreversible fingerprint of the message and the verdict that goes with it, for a few days, so that the thousands of people who receive the same text as you get an instant answer. Your history stays on your phone. A screenshot never leaves your device: only the text read locally is analysed. Payments are handled entirely by Apple or Google: we see neither your identity nor your card details. Your content is never used to train an AI model.
1. Data controller
BAUGEY MATHEO, trading as DEVOLIM
Sole trader, micro-enterprise
248 rue de Bègles, 33800 Bordeaux, France
SIREN: 948 000 757, SIRET: 948 000 757 00021
Data protection contact: [email protected]
The controller is not required to appoint a data protection officer under Article 37 GDPR: its core activities consist neither of regular and systematic monitoring of data subjects on a large scale, nor of large-scale processing of special category data. All data-related questions are handled directly at the address above.
2. Our principles
What passes through Bimo are messages received by real people: names, amounts, sometimes bank details. Four rules govern the whole architecture of the app, and they take precedence over convenience:
- Content does not outlive the check. The message you submit is written to no database and to no technical log.
- Your phone only talks to us. The app contacts no third-party service directly: not an AI provider, not a reputation service, not the suspicious site itself. Everything goes through our servers, which control what leaves.
- No training. Your content is never used to train, fine-tune or evaluate an AI model, by us or by our providers.
- The minimum, by default. What we don't need isn't collected: we ask you for no name, no email address and no phone number.
3. What stays on your device
The following is stored locally on your phone and is not transmitted to us:
- your check history: the date, the type of content, the score, the level, the codes of the findings and a short excerpt used as a visual reminder;
- your settings: language, country, simplified mode, display and notification preferences;
- the guides and reference data downloaded so the app works offline.
You can delete an entry or clear the history from within the app. Uninstalling erases all of it. We have no way of accessing or restoring this data.
4. The content you submit
This is the app's central processing operation, and the one that deserves the most precision.
4.1 What is sent
When you run a check, the text you submit (message, email, link, phone number or IBAN) is sent to our server functions, hosted in the European Union. For a screenshot, the image is read on your device by the operating system's text recognition (Vision on iOS, ML Kit on Android): the picture never leaves the phone, only the recognised text is sent, exactly as if you had pasted it. The same applies to dictation: the microphone is handled by the operating system's speech recognition, under Apple's or Google's terms, and we receive only the resulting text.
4.2 What is done with it
The text goes through a cascade: extraction of verifiable elements, factual checks (domain age, a link's real destination, public phishing lists, IBAN validity, the nature of a phone number), then, if doubt remains, it is passed to a language model whose task is to match the message to a known scam family. That model does not write your result: it returns only codes from a closed catalogue, whose wording we write in advance.
One exception, and it deserves saying: asking a relative for advice. When you send a message to one of your trusted people, an extract of that message (400 characters at most) is passed to the language model every time, without waiting for doubt to remain, so that the two-to-four-sentence note your relative reads can be written. Without it, a dense screenshot reaches them as a pile of unreadable labels.
That request carries no user identifier. It does not happen if we switch off the AI stage remotely: the request then goes out with no note, and the raw text alone.
4.3 What is kept, and what is not
The content of a check is not kept anywhere. It is written to no database, appears in no technical log, and leaves the server's memory when the check ends. Here too, asking a relative for advice is the exception: the extract sent to them and its summary note are stored for the length of the conversation, since they must be able to reopen it. They are erased when the link ends or when either account is deleted.
What we do keep is an irreversible cryptographic fingerprint (a hash) of the message once normalised (links, email addresses, IBANs, amounts, phone numbers and variable reference numbers replaced by placeholders; first names and the rest of the text are not), together with the verdict: score, level, finding codes, scam family, country. This fingerprint cannot be used to reconstruct the message; it exists so the next person to receive the same text gets the same verdict instantly. It expires after 96 hours by default.
We also keep, separately and briefly, the result of technical checks run on the domains and addresses encountered (age, certificate, reputation). That data is about websites, not about you, and is not linked to any user.
4.4 Usage counters
A counter attached to your technical identifier records the number of checks you run, so that free-tier quotas can be applied and abuse prevented. It contains no content: numbers and dates, nothing else.
5. Third-party data inside a message
A message you submit almost always contains data about people other than you: the sender, someone mentioned, a phone number, a name. Those people have not installed Bimo and are unaware of this processing.
This processing relies on the legitimate interest (Article 6(1)(f) GDPR) in protecting people against fraud, an interest expressly recognised by Recital 47 GDPR. It is strictly limited to what the diagnosis requires, involves no profiling of those third parties, no enrichment, no resale, and does not outlive the check.
Informing those individuals directly would require a disproportionate effort within the meaning of Article 14(5)(b) GDPR: by design, we have no means of identifying or contacting them. This policy serves as that information. Anyone who believes their data has been processed during a check may nonetheless exercise their rights at [email protected].
On your side, you should only submit content you have legitimately received, and limit yourself to what the check requires. Do not submit documents covered by professional secrecy, or content you are not allowed to disclose.
6. Special category data
Bimo is not intended to process special category data within the meaning of Article 9 GDPR (health, opinions, beliefs, sex life, trade union membership, biometric or genetic data). A submitted message may nonetheless contain such data incidentally: a fake health-insurance letter, or a blackmail attempt, for instance.
In that case the processing, strictly limited to the duration of the check, relies on your explicit consent under Article 9(2)(a) GDPR, given through the deliberate act of submitting that content. We encourage you to redact sensitive information that is not needed for the diagnosis before pasting a message: the analysis looks at links, senders and message structure, not at the information about you.
7. Anonymous account and profile
On first launch the app automatically creates an anonymous account (Firebase Authentication): a random technical identifier, with no email, no password and no link to your civil identity. It is used to attach your quotas and, where applicable, your subscription and your trusted links.
The following are associated with that identifier in our database:
- your country and language, which determine the scam reference data and the reporting bodies shown;
- whether simplified mode is on;
- if (and only if) you use trusted people: a first name or nickname of your choosing and, optionally, a compressed photo you provide. That is what your trusted person sees. You are not required to use your real first name or your face;
- your subscription status (active or not) and your usage counters.
Account deletion is available inside the app, in the settings. It erases your profile, your counters, your trusted links, the related advice requests and your feedback, then deletes the identifier itself.
8. Trusted people
This feature lets one person (the “helped”) send a check to someone they trust (the “helper”) for a second opinion. It works entirely on your initiative.
- Linking: through a short-lived six-digit code generated by the helper and entered by the helped person. No directory, no user search, no access to your contacts.
- Consent on both sides, and either party can break the link at any time.
- What is shared: only the check you choose to send: the score, the level, the finding codes and a short, capped excerpt. Never your history, never your other checks, never your location.
- Automatic alerts: optional, off by default, explicitly accepted on both sides and limited to the highest risk level. The helped person can switch them off at any time.
The advice request and the reply are kept for as long as the link exists, so both people can consult them; they are deleted when the link is broken or when either account is deleted.
Reporting abuse. From that person's page or from an advice request, “Report abuse” sends us a reason chosen from a list (hurtful messages, attempted scam, unwanted contact, something else), the link identifier and, where the report concerns an advice request, a copy of the excerpt and reply at issue — without that copy, the break that usually follows would erase the very thing to be examined. Reporting can break the link in the same gesture. The person reported is not told about it and has no access to it. These items are kept for one year, under our legitimate interest in putting a stop to abuse, then erased automatically.
9. Notifications
If you allow notifications, a device token issued by Firebase Cloud Messaging (Apple Push Notification service on iOS) is stored so we can tell you in four cases, and only those: a trusted person replies to your request for advice; a request for advice is addressed to you; a trusted person with whom automatic alerts are enabled on both sides has just run into a clear scam; your weekly peanut is back.
No notification carries analysed content or a verdict. The text is not written by our servers: they send only a type of message, and the device writes the sentence itself in your language. The title, however, may carry the first name or nickname your relative chose to display (“Martine needs you” rather than “someone needs you”), because a helper looking after several people would otherwise have to open the app to find out which one. That name is the one on the mini profile, which nothing requires to be real, and it appears only on the screen of someone already linked to the person who carries it.
The token identifies an installation, not a person; it is rotated by the system and deleted with the account. You can withdraw the permission at any time in your phone settings without losing the use of the app.
10. Subscription and payment
Bimo Premium is sold exclusively through the App Store or the Google Play Store. Payment, invoicing and renewal are handled by those platforms: we collect, see and store no payment data, no identity and no billing address.
Subscription validation is entrusted to RevenueCat, Inc., which receives an anonymous app identifier, the purchase receipt passed on by the platform, and technical data (platform, version, store country). This validation is required to unlock paid features and to restore your subscription after you change device.
11. Peanuts and referrals
Without a subscription, your checks are counted. That count is kept on our servers, because it is the only place where it cannot be reset from the phone. It contains no content: no message, no link, no verdict.
What your counter holds: the number of checks left, the date of the last refill, a lifetime total, and technical anti-abuse markers (how many checks in the past twenty-four hours, random identifiers for checks in progress).
Those check identifiers exist only so that we do not charge you twice for the same matter when you refine it: they are random strings, unrelated to the content, erased after twenty-four hours.
Referrals
If you use referrals, we keep: a referral code drawn at random and attached to your account, the identifier of the account that referred you where applicable, and the number of referrals you have completed.
This creates a link between two anonymous accounts: the referrer's and the referred person's. It is unavoidable: without that link the reward could not be granted. It reveals no identity, no content and no usage: your referrer will never know what you checked, or when.
Referral codes are readable neither by you nor by other users: only our server functions access them, precisely so that a code can never be traced back to an account. When you delete your account, your code is released and the link disappears.
The installation fingerprint
On iPhone, the app draws a random installation identifier on first launch and puts it in the
phone's keychain. On Android, where that storage is wiped when the app is uninstalled, it derives it from the
app-specific Android identifier (ANDROID_ID), which no other app can read, is not
the advertising ID and only changes when the phone is reset; it is hashed on the device before anything is
sent. That identifier is never stored as such on our servers: we keep only an
irreversible cryptographic digest of it (SHA-256), in an entry that holds nothing but the
date of the welcome grant and the number of accounts opened from that device.
What it is for: the peanuts given on installation can be claimed only once per device per thirty-day period. Without this fingerprint, deleting your account and creating a new one handed out five free checks again, endlessly, which made the subscription pointless and the service unsustainable.
What it cannot do: it does not identify you, does not follow your usage, is attached to no account and never leaves our servers. It is not erased when you delete your account, since that is precisely the situation it guards against; it disappears on its own after 90 days. Uninstalling the app removes the identifier from the phone.
12. Analytics and crash reports
The app uses Firebase Analytics and Firebase Crashlytics to understand which features are used and to fix failures.
- What is sent: content-free events (“a check started”, “a check ended at the suspicious level”, “the paywall was shown”, “a result was disputed”), along with technical data (device model, OS version, app version, country, language) and, on a crash, the corresponding stack trace.
- What is never sent: the analysed content, links, phone numbers, addresses or excerpts: a rule written into the app's source code.
- The onboarding questionnaire may record, if you answer it, an age range and a declared gender, never a date of birth. This tells us which scams target which audience and lets us adapt the examples shown. Answering is optional: “I'd rather not say” is offered for each of the two questions, and refusing never stops you from carrying on. What you keep to yourself is sent to no one.
The app shows no advertising and contains no advertising trackers: there is no advertising identifier, no data sharing for targeting purposes and no cross-app tracking. Accordingly, no tracking authorisation prompt is displayed on iOS.
This analytics can be switched off inside the app, under “About” in the settings: the “Analytics” switch immediately stops both usage statistics and crash reports. It rests on our legitimate interest in understanding usage so that we can fix what does not work, and that switch is your right to object (Article 21 GDPR), exercisable without writing to us. To also ask for already-collected data to be erased, write to [email protected] from any address, quoting your installation identifier (settings, under “About”).
Deleting your account cuts the thread: the app's analytics identifier is reset, so nothing links past measurements to the installation that carries on. Events already sent are not erased retroactively: they expire at the 14-month retention limit, or sooner if you ask us.
13. Permissions requested
| Permission | What it is for | Optional? |
|---|---|---|
| Photos / camera | Choosing or taking a screenshot to check. The text is read on the device; the image is not transmitted. | Yes |
| Microphone | Dictating a message instead of typing it. Speech recognition is the operating system's. | Yes |
| Notifications | Being told about an advice request or a reply from a trusted person. | Yes |
| Clipboard | Offering to check what you have just copied. It is read only when the app opens, and the content is sent only if you start a check. | Yes |
The app requests no location, no access to your contacts, and no access to your text messages or calls. The country used to tailor the reference data is inferred from your device settings and can be changed manually.
14. Service security and abuse prevention
Every call to our servers is authenticated by Firebase App Check, which attests that the request comes from a genuine installation of the app and not from a script. This relies on Apple's App Attest and Google's Play Integrity services. Rate counters and per-user caps complete the arrangement. This processing relies on our legitimate interest in protecting the service, its costs and its users against abusive use.
15. No automated decision-making
The score Bimo produces is decision support. It produces no legal effect concerning you and does not similarly significantly affect you: it gates access to no service, blocks no call, message or payment, is disclosed to no third party on its own initiative, and the decision whether to do what the message asks remains entirely yours. The processing therefore does not fall under Article 22 GDPR. You may in any event dispute a result from within the app, and request an explanation at [email protected].
16. Legal bases
| Processing | Legal basis |
|---|---|
| Analysing submitted content and returning the result | Performance of a contract (Art. 6(1)(b)) |
| Anonymous account, quotas, usage counters | Performance of a contract (Art. 6(1)(b)) |
| Trusted people, advice requests | Performance of a contract (Art. 6(1)(b)) |
| Automatic alerts to a trusted person | Consent of both people (Art. 6(1)(a)) |
| Notifications | Consent (Art. 6(1)(a)) |
| Subscription management and purchase validation | Performance of a contract (Art. 6(1)(b)) |
| Verdict cache by fingerprint, domain cache | Legitimate interest: sustainability and speed of the service (Art. 6(1)(f)) |
| Third-party data present in a message | Legitimate interest: fraud prevention (Art. 6(1)(f) and Recital 47) |
| Security, App Check, rate limiting | Legitimate interest: security of the service (Art. 6(1)(f)) |
| Abuse reports between trusted people | Legitimate interest: safety of people and prevention of abuse (Art. 6(1)(f)) |
| Analytics and usage statistics | Legitimate interest: understanding usage in order to improve the service (Art. 6(1)(f)), with a right to object under Article 21 GDPR |
| Declared age range and gender | Consent (Art. 6(1)(a)), given by answering, refused with “I'd rather not say” |
| Crash reports | Legitimate interest: reliability of the app (Art. 6(1)(f)) |
| Special category data incidentally present in a message | Explicit consent (Art. 9(2)(a)) |
| Retention of accounting records | Legal obligation (Art. 6(1)(c)) |
17. Recipients and processors
Your data is not sold, rented, exchanged, or passed to data brokers or advertisers. It is disclosed only to the technical providers required to run the service, acting as processors on documented instructions:
| Provider | Role | What it receives | Location |
|---|---|---|---|
| Google Ireland Limited (Firebase, Google Cloud) | Hosting, database, server functions, anonymous authentication, notifications, analytics, crash reports | The content, for the duration of the check; the anonymous identifier, the profile, the counters, the trusted links | Database and server functions: European Union, region europe-west1 (Belgium).
Anonymous authentication, notifications (Cloud Messaging), analytics and crash reports: global Google
services, with possible processing in the United States (see § 18) |
| OpenAI Ireland Limited / OpenAI, L.L.C. | Language model: matching the message to a scam family, listing pressure tactics, and writing the note that accompanies a request for advice | The analysed text where the factual checks are not conclusive, and the extract of every request for advice sent to a relative, in both cases with no user identifier | Ireland, with possible processing in the United States |
| Google LLC (Safe Browsing) | Reputation of web addresses | The addresses found in the content, with no user identifier | United States |
| RevenueCat, Inc. | Subscription validation and restoration | Anonymous app identifier, purchase receipt, technical data | United States |
| Apple Inc. / Google LLC | Distribution, payment, notifications | The data belonging to your store account, which we do not receive | Independent controllers for those operations |
None of these providers uses the content you submit to train an AI model. Under the terms applicable to OpenAI's application programming interfaces, content submitted through them is not used to train its models; it may be retained by that provider for a limited period solely for abuse detection, and then deleted.
Data may further be disclosed to a competent judicial or administrative authority upon a valid legal request. Given the architecture described in § 4, such a request could not produce the content of your past checks: it no longer exists.
18. Transfers outside the European Union
Primary hosting and the analysis functions are located in the European Union. Some of the providers listed in § 17 may process data in the United States. Those transfers are governed by the standard contractual clauses adopted by the European Commission (Implementing Decision (EU) 2021/914), supplemented (where the provider is certified under it) by the EU-US Data Privacy Framework (adequacy decision of 10 July 2023), together with technical measures: minimisation of the data transmitted, absence of any user identifier in the calls concerned, and encryption in transit. A copy of the applicable safeguards can be obtained at [email protected].
19. Retention periods
| Data | Period |
|---|---|
| Content submitted for checking | Not retained, destroyed when processing ends |
| Irreversible message fingerprint and associated verdict | 96 hours by default, configurable, never beyond 30 days |
| Results of checks on a domain or address | A few hours to a few days |
| Your check history | On your device, until you delete it or uninstall the app |
| Profile (country, language, first name, photo) and usage counters | Until account deletion, which you can request at any time from the app settings |
| Referral code, referrer/referred link | Until the account is deleted |
| Random identifiers of checks in progress | 24 hours |
| Trusted links, advice requests and replies | Until the link is broken or the account deleted |
| Notification token | Until invalidated by the system or the account is deleted |
| Bug reports and suggestions | 24 months, or until account deletion |
| Abuse reports between trusted people | 1 year, including after either person deletes their account |
| Installation fingerprint (digest, section 11) | 90 days, including after the account is deleted |
| Subscription events received from RevenueCat (account identifier, event type) | 90 days, including after the account is deleted |
| Server technical logs (no content) | 30 days |
| Analytics | 14 months |
| Crash reports | 90 days |
| Email correspondence | 3 years from the last exchange |
| Accounting records relating to subscriptions | 10 years (Article L.123-22 of the French Commercial Code) |
20. Security
The following measures are in place:
- encryption of communications in transit (TLS) and encryption of data at rest at the hosting provider;
- no secrets in the app: no third-party access key is embedded in the program installed on your phone; keys live in a managed vault (Secret Manager);
- database access rules that deny by default: a user can read only what concerns them, and sensitive records are written by the server alone;
- no user content in the logs, including on errors;
- the submitted content is treated as hostile data: it can neither steer the model's behaviour nor cause unexpected text to be displayed, the output being restricted to a closed catalogue;
- protections against server-side request forgery when inspecting a link, spending caps and rate limiting.
In the event of a data breach likely to result in a high risk to your rights and freedoms, you will be informed in accordance with Article 34 GDPR, and the French supervisory authority will be notified within 72 hours.
21. Your rights
You have the rights of access, rectification, erasure, restriction, objection and portability, as well as the right to withdraw your consent at any time, without affecting the lawfulness of processing carried out beforehand. You may also give directions on what happens to your data after your death (Article 85 of the French Data Protection Act).
The most direct routes are inside the app:
- Clear your history: from the History screen.
- Delete your account and all associated data: Settings → Delete my account. The operation is immediate and permanent. The detailed steps, and what happens to each piece of data, are set out on the Delete my account page.
- Break a trusted link: from that person's page, at any time and without their agreement.
- Withdraw consent to notifications: in the app or phone settings.
- Object to analytics: Settings → About → “Analytics”. It takes effect immediately. To also ask for already-collected data to be erased, write to [email protected]. Deleting your account resets the analytics identifier, without retroactively erasing events already sent (section 12).
- Report abuse: from that person's page, or from an advice request, under “Report abuse”. Reporting can break the link in the same gesture, and the person reported is not told about it.
For anything else, write to [email protected]. You will receive a reply within one month, extendable by two months where the request is complex.
One limitation worth knowing. Because the app asks you for no identity, we cannot link an email address to an account. To exercise a right of access or erasure by email, you will need to give us your installation identifier, shown at the bottom of the settings screen, under “About”, and copied with a single tap. Failing that, and in accordance with Article 11(2) GDPR, we will be unable to identify the data relating to you: deletion from within the app then remains the safest and fastest route.
22. Children
Bimo is aimed at an adult audience and is neither designed nor intended for children. Nothing in the app addresses them: not the subject, not the tone, not the examples.
We do not verify age, and we would rather write that than let you assume otherwise. The app asks for no date of birth and puts no age check in the way at installation: the age range you may declare when signing up is optional, self-reported, and conditions nothing. We are therefore not in a position to know whether an account belongs to a minor.
In France, processing based on consent requires the person to be 15 (Article 7-1 of the French Data Protection Act); elsewhere in the European Union the applicable age is the one set by national law, between 13 and 16. Below that age, consent must be given by the holder of parental responsibility. In Bimo this covers three things only, all optional and all switchable off: notifications, automatic alerts to a relative, and the declared age range and gender. The rest of the service rests on performance of the contract.
No data is knowingly collected from a child. If you hold parental responsibility and find that an account has been opened by a minor, write to [email protected]: the account and the data attached to it are deleted without delay, with nothing to justify.
23. The website
https://bimo.devolim.fr is a static brochure site. It sets no cookies, uses no trackers, no analytics tool and no resource loaded from a third-party domain: the fonts are served from this same domain. There is no form on the site: contact is by email. The hosting provider keeps connection logs (IP address, date, page requested) for security and technical statistics, for a limited period, in accordance with its own obligations.
24. Changes
This policy may be amended to reflect changes to the app or to the law. The version in force is the one published at https://bimo.devolim.fr/en/privacy.html. Any substantial change will be signalled in the app and, where the law requires it, your consent will be sought again.
25. Lodging a complaint
If, after contacting us, you believe your rights have not been respected, you may lodge a complaint with the French supervisory authority:
CNIL, 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France
Telephone: +33 1 53 73 22 22, www.cnil.fr
If you live in another EU Member State, you may contact the supervisory authority of your country of residence.