Home / Trust & privacy

Practical controls. Visible choices.

Updated 13 September 2026

Security includes how your account connects, how workspace information is separated, and how you can stop an automated action.

Connection and access

BIGI uses Instagram’s authorisation flow rather than asking for your Instagram password. Connection tokens are encrypted on the server. Connection requests use state verification to protect the return from Instagram.

Account access is controlled through authenticated sessions. Protect access to your email and professional Instagram account, review authorised connections and notify us if access may be compromised.

Workspace and event protection

The application uses workspace-scoped access controls to separate records. Incoming Meta webhooks are checked for a valid signature, and server-side rules limit which actions can proceed.

Secrets are handled on the server rather than published in the browser. The website uses HTTPS in its hosted configuration and security response headers. Access to operational records should be limited to authorised personnel for a service purpose.

Controls for automated actions

Observe, Review and Automatic modes let owners choose the level of supervision. Human takeover and pause controls help stop automatic activity when a person needs to handle the conversation.

Approved sources, scope restrictions and checks on business claims reduce the risk of unsupported replies. These checks do not make AI infallible. Use appropriate review for sensitive content and do not automate consequential decisions about individuals.

Retention and incident handling

Export and deletion requests are supported, with scheduled retention cleanup for relevant record types. See the privacy notice for the current retention schedule.

We investigate suspected incidents, contain affected access and assess the records and individuals involved. Where BIGI acts as processor, applicable incidents must be communicated to the controller without undue delay. Legal notification obligations depend on the facts and the responsible party’s role.

Report a vulnerability

Send a private report to info@heybigi.com with the affected URL, steps to reproduce and the minimum evidence needed. Do not include other people’s private records, passwords or active tokens.

Avoid destructive testing, social engineering, accessing another user’s data or publicly disclosing exploit details before a reasonable opportunity to investigate. This page does not promise a bug bounty, security certification or a contractual service-level guarantee.

Useful links

Contact the privacy team · Company details · Privacy notice · Request deletion · GDPR & processing · Data processing agreement · Subprocessors · Terms

Your rights: Swedish Authority for Privacy Protection · EU General Data Protection Regulation