We take reasonable steps to protect the information you share with balance pi. This policy describes what safeguards are in place. We do not claim perfect security — no online service can. We describe only controls that are genuinely implemented; we do not make aspirational claims.
All communication between your browser and the balance pi server is encrypted using TLS (HTTPS). Data is not transmitted in plaintext over the network.
User authentication is handled by a dedicated authentication service that provides industry-standard password hashing, email verification, and session token management. Passwords are never stored in plaintext. Access to the session API requires a valid authenticated session token.
An optional invite-code gate can be enabled by the operator to restrict access to the service during limited-access periods.
This section explains how balance pi uses cookies and browser storage on this website. We list only the cookies and storage mechanisms that are actually in use — we do not describe controls we haven't implemented.
| Name | Purpose | Duration | Type |
|---|---|---|---|
bp_access |
Access gate token. Set when a valid invite code is entered. Required to use the service. | 7 days | Essential — HttpOnly, SameSite=Strict |
This cookie is strictly necessary for the service to function. It cannot be disabled without preventing access to balance pi.
balance pi uses your browser's localStorage — a client-side storage mechanism — to retain session state locally on your device. No data stored in localStorage is transmitted to any server except when explicitly submitted by you as part of a session.
| Key | Purpose |
|---|---|
bp_user | Stores your authenticated user profile for the current session (name, email). |
bp3_sessions | Stores a local history of your past session titles for the session-history sidebar. Not synced to any server. |
bp3_tone_* | Remembers your selected tone/mode preference across page reloads. |
bp_chat_* | Stores the current active chat log so it survives a page refresh. |
bp_timer_* | Stores session timer state so it survives a page refresh. |
localStorage data is stored on your device only and is cleared when you clear your browser data. It is not shared with third parties. We do not use advertising cookies, tracking pixels, or third-party analytics tools.
You can control cookies through your browser settings. Note that disabling the bp_access cookie will prevent access to the service.
To clear localStorage data, use your browser's "Clear site data" or developer tools function. Clearing localStorage will remove your local session history and preferences.
Links to cookie controls for common browsers:
Information you enter during sessions — your inputs, responses, and session content — is processed by balance pi's underlying AI processing engine and is subject to that provider's own data handling and security practices. Session content is not stored server-side by balance pi beyond what is necessary to deliver your current session response.
Your account registration data (name, email, and optional fields) is stored with our authentication and account data provider, under its own infrastructure security controls.
Session content is not persistently stored on balance pi's servers. Account data is retained for as long as you have an active account. To request deletion of your account and associated data, email privacy@balancepi.com. We will action deletion requests within a reasonable timeframe.
LocalStorage data on your device (session history, preferences) is under your control and can be cleared at any time via your browser settings.
No internet-based service is completely secure. Despite the safeguards described above, we cannot guarantee that data will never be subject to unauthorised access, disclosure, alteration, or loss. You use the service understanding this inherent limitation.
If we become aware of a security incident that affects your data, we will take reasonable steps to investigate and address it. Where required by applicable law, we will notify affected users and relevant authorities. We do not make specific response-time guarantees.
balance pi relies on the following third-party infrastructure, some of which may set their own cookies. Their security practices are governed by their own policies:
fonts.googleapis.com. Google may log this request. See Google's Privacy Policy.If you discover a potential security vulnerability in balance pi, please report it responsibly to privacy@balancepi.com. We will acknowledge your report and investigate promptly.
We will update this policy if our security practices, cookies, or storage mechanisms change materially, and increment the version number above. We will not add claims for controls we have not implemented.